Back to blogAI assurance

What outside-in AI assurance actually means

Most AI risk questions get answered with a questionnaire and a leap of faith. Outside-in assurance starts somewhere more honest — the evidence anyone can already see.

TRUSTYCYBER teamSeptember 8, 20263 min read

Ask most organisations how they assess a vendor's AI, and the answer is a spreadsheet. A questionnaire goes out, answers come back, someone files them, and the relationship proceeds. The trouble is that a questionnaire records what a vendor is willing to say about itself. It does not, on its own, show whether any of it is true.

Outside-in assurance starts from a different place: the evidence that already exists in public, before anyone is asked a single question.

Reading what is already there

Every vendor of any size leaves a public trail — AI disclosures, trust and security pages, policies, certifications, privacy documentation, and the technical fingerprints in their DNS records and certificates. An AI Trust Scan resolves the entity, locates those sources, reads them, and extracts claims.

The discipline is in what gets rejected. A claim without a source reference and an exact excerpt does not survive to influence the result. Nothing is taken on faith because it was repeated often enough.

Every claim carries an evidence class

Not all evidence is equal, and pretending otherwise is how assurance loses its meaning. Each claim is labelled with how strong its source is — from vendor-published (stated by the vendor, no independent corroboration found), through externally corroborated (stated by a source independent of the vendor), to registry-verified (confirmed against an official third-party register, such as an accredited certification body's public registry).

Just as important is what a scan will say is absent. When a topic is actively searched for and no statement is found, that verified absence is recorded — not quietly dropped. Absence of public evidence is not proof of a weak control, but it is a fact a buyer deserves to see.

From evidence to a defensible result

Application code — never the model — computes the weighted dimension scores, the TRUSTYCYBER Score and the grade. Eight dimensions are graded with fixed weights, so two vendors are measured the same way rather than by whichever story each tells best. Every figure links back to the evidence behind it, and every published scan resolves to a full, source-linked report in the Trust Directory that anyone can check.

Where outside-in stops

Being honest about the method means being honest about its edge. A scan reads public evidence. It cannot see inside a control, watch it operate, or test a sample. A policy shows intent; it does not always show operation.

That is where inside-out, human-led assurance takes over: an engagement examines internal evidence, verifies operation where a document alone will not do, and results in a signed opinion from a qualified auditor. The scan tells you what is knowable from the outside, quickly and consistently. The engagement is what you commission when the decision genuinely warrants it.

Used together, they cover the ground that a questionnaire on its own never quite does — what a vendor claims, what the public record supports, and what still needs to be tested in person.


Know what you're trusting. Run a free AI Trust Scan on a vendor, product or organisation, and see every figure link back to its evidence.

Get in touch

We'd love to hear from you.

Contact us