YOU DO NOT COPY PROFESSIONALISM. YOU ALIGN WITH IT.
HOME / SERVICES / AI SECURITY

AI ASSURANCE - KING V

King V is effective for financial years beginning on or after 1 January 2026. It requires the governing body to be accountable for the effective, compliant and ethical acquisition, development, use and distribution of technology, with demonstrable accountability for decisions, actions, outputs and outcomes, human oversight and override mechanisms proportionate to risk, and periodic assurance.

ASSURANCE PROVIDED BY THE VENDOR BEING ASSURED IS NOT ASSURANCE.

DEFINITION

THE INDEPENDENCE PROBLEM, STATED PLAINLY

Most AI governance suites are sold by the platform the agents run on. Those tools are useful and we work alongside them.

But a platform assuring its own agents is the vendor assuring the vendor. The zero-click exfiltration flaw in one major assistant, CVE-2025-32711, was found by a third party rather than by the platform vendor. That is the argument in a single fact.

WHAT THE STATEMENT CONTAINS

  • Scope. What was assured, what was not, and why. Stated plainly enough that a director can see the edges.
  • The control environment, as found rather than as documented.
  • Test results. What we attempted, what succeeded, what did not, and what changed as a result.
  • Accountability mapping. Each King V expectation, and the specific evidence that meets it or the gap that does not.
  • Human oversight assessment, including whether override mechanisms have ever been exercised in a rehearsal rather than described in a policy.
  • A dated opinion, in language that can be quoted in an integrated report without rewriting.
  • Matters for the governing body’s attention, ranked.

WRITTEN FOR THE AUDIT COMMITTEE

  • Most technical reports fail in the boardroom because they were written for engineers and then summarised by somebody who did not do the work. This one is written for the audit committee from the first line, and presented by the operator who ran the testing, so a question gets an answer rather than an action item.

WHY A TEST RATHER THAN A QUESTIONNAIRE

  • A questionnaire records what your team believes to be true. Assurance backed by adversarial testing records what an operator was able to do. When a director asks how you know, those two answers sound very different.

FREQUENTLY ASKED QUESTIONS

FAQ

No. This is an independent assurance statement on the AI control environment, produced by a security firm rather than by a registered auditor, and it says so on its face. It is designed to give the governing body evidence for the periodic assurance King V expects, and to sit alongside your assurance arrangements rather than replace them.

The statement and the dated opinion are written to be quotable in an integrated report. The detailed findings are not, and should not be, because they describe live exposures. We provide both, separately, for that reason.

TAKE ACTION

TEST IT BEFORE SOMEBODY ELSE DOES

Thirty minutes on your agent estate and what this risk looks like in your environment.