>
Organisations do not lack assurance activity. They lack a way to connect it. Assurance Intelligence is the layer between how an organisation operates, how it assures, and how it governs.
Most organisations run a great deal of assurance. Supplier questionnaires, CAF evidence, Secure by Design trackers, DPIAs, vulnerability scans, risk registers, policy libraries, board packs. Each is defensible on its own terms.
The difficulty is that each one holds a different part of the answer and nothing holds the whole. The supplier assessed eleven months ago underpins the service the business impact assessment calls mission-critical, and no system connects those two facts. The vulnerability closed on one system was never linked to the CAF conclusion that relied on it. The Secure by Design approval was given before the architecture changed twice. Every workflow reports green in isolation, and the real exposure sits in the space between them.
Assurance capacity is finite, and too much of it is spent reconstructing what the organisation already knows. None of this is anyone's fault. It is what happens when assurance is organised around mandates rather than around evidence.
Practitioners rebuild what the organisation already knows from reports, tickets, spreadsheets and email.
The same service, system, supplier and control facts are captured again in every workflow.
Evidence is requested again from people who have already provided it, in a different format.
A change identified in one workflow never reaches the assurance decision it should have reopened.
Assurance is repeated in full because nobody can establish what remains valid.
Executive questions take weeks, because the answer has to be assembled by hand each time.
A board pack showing every metric complete is a measure of activity. It is not a measure of assurance. Reporting without operational linkage creates confidence the underlying record does not support.
An assessment finished last year is counted the same as one finished last week.
A closed vulnerability says nothing about the service that depended on the system.
Full coverage of a register that never included the critical dependency is still full coverage.
The decision was sound when it was made. Nothing has re-tested it since.
Most organisations cannot answer these from a single source. Answering them continuously, rather than once a year, is what we mean by Assurance Intelligence.
Which business services, and the systems, suppliers and dependencies beneath them, are genuinely critical.
What assurance, evidence, findings, remediation, risks and decisions already exist.
What has changed since the last substantive assurance, and what now needs revalidation.
Where criticality, change, unresolved risk and assurance gaps justify scarce effort.
Most organisations have operational tools and a governance layer. Very little connects them. Assurance Intelligence sits in that gap: it reads what the organisation actually runs on, and it directs the specialist assurance workflows that govern it.
Critical services, systems and OT, applications, suppliers, assets, data and organisational structure, as the organisation actually runs them rather than as a flat asset inventory.
Relationship analysis, impact analysis, assurance confidence, change intelligence, prioritisation and revalidation, with provenance preserved and human judgement retained.
Supplier Assurance, Threat Centre, Secure by Design, NCSC CAF, GRC and Risk, BIA and Resilience, DPO Centre and the Governance Library.
One Evidence Model is the connected assurance record beneath every workflow. It is not a document repository, and it is not one universal assurance answer.
A shared model does not make every piece of evidence universally reusable. Evidence is always a historical record: observed within a defined scope, at a defined time, sufficient for the conclusion it was gathered to support and not automatically for another. What the model preserves is the context needed to judge it, so a receiving workflow can decide whether it is suitable for its own purpose. Specialist accountability is preserved. Duplication is not.
Create the underlying entity, fact or assurance record once rather than rebuilding it in each workflow.
Records are referenced across workflows rather than copied, with provenance preserved.
Connect assurance work to the business service, system, supplier and dependency it protects.
Retain source, scope, date, ownership and the activity that produced the evidence or judgement.
Turn material change, evidence expiry or unresolved risk into a focused review of the assurance it may affect.
Link findings to remediation, verification, residual risk and the decision that closes or accepts them.
Context on its own is a diagram. It becomes useful when a change in the world produces a directed piece of assurance work with a defensible outcome. A trigger starts a review. It does not, by itself, invalidate evidence or force a full reassessment.
Business context including critical services, criticality and ownership. Assurance context including evidence, controls, assessments, findings, risks and decisions. Change signals including threats, vulnerabilities, supplier events, architecture change and evidence expiry.
Relationship analysis establishes what is connected. Impact analysis establishes what may be affected. Assurance confidence establishes what can still be relied upon. Prioritisation establishes what matters most. Revalidation establishes what needs human review.
Refresh evidence, targeted review, full reassessment, remediation, risk treatment or acceptance, or executive escalation. The response is proportionate to the finding rather than automatic.
Assurance is a lifecycle, not a series of assessments. Each stage writes back to the same connected record, so the next stage starts from what is already known rather than from a blank form.
| Stage | Purpose | Result |
|---|---|---|
| 1 · Identify | Map the business service to the systems, suppliers and dependencies that support it, and establish criticality | A defensible basis for what matters |
| 2 · Prioritise | Use criticality, existing assurance, material change, unresolved risk and the decision being made to set assurance depth | Capacity directed to the right work |
| 3 · Assure | Reuse existing information and evidence, obtain what is missing, and apply the relevant assurance method | Evidence and judgement in context |
| 4 · Decide | Record remediation, exception, approval or risk acceptance with owner, rationale and date | A traceable assurance decision |
| 5 · Maintain | Track the reasons to revisit: material change, review dates, evidence expiry, supplier events, open findings and regulatory triggers | Revalidation as managed work |
| 6 · Report | Aggregate the underlying record into operational, risk-owner, executive and compliance views | Reporting that reconciles |
The same record serves the practitioner, the risk owner and the board, because it is the same record.
AI here is an acceleration layer, not the accountable decision-maker. It removes the manual load. It does not take the judgement.
Per-tenant choice of AI provider, including bring-your-own-key. No single model provider is hardcoded.
Each module is a specialist assurance workflow, licensed independently and entitled per tenant, so a customer sees only the modules they buy. Every module they buy reads and writes the same connected context.
Status below reflects where each workflow genuinely stands today rather than where the architecture is heading.
Third-party assurance from onboarding questionnaire through to continuous attestation. SAQ v30, 205 questions across 21 domains, domain-weighted scoring, evidence upload with malware scanning, supplier portal and Nth-party visibility. Late-stage pre-production.
NCSC Secure by Design assurance run as a live, evidenced process rather than a tracked spreadsheet. Versioned corpus, multi-stage assessment, second-line review, confidence profile and SRO sign-off. Late-stage pre-production.
External threat and exposure intelligence matched to the suppliers and technology you actually depend on. CVE and KEV ingestion, exploit-prediction enrichment, blast-radius calculation and SBOM ingestion. In development.
Cyber Assessment Framework alignment for GovAssure, with submission tooling. CAF v4.0 objectives, principles and indicators, per-indicator evidence, remediation tracking and heatmaps. In development.
The formal risk spine: assets, risks, controls, threats and vulnerabilities in one place, with threat modelling and vulnerability management. In development.
What the organisation cannot afford to lose, and what it depends on to keep running. Recovery objectives, dependency mapping and continuity planning. In development.
UK GDPR Article 35 Data Protection Impact Assessments, run as a register rather than a folder of documents, with sign-off flow and audit trail. In development.
Version-controlled policy and procedure, linked to the controls and evidence that prove it, so a control can cite the version that was in force on the day. In development.
Some lifecycle, revalidation and cross-module mechanisms described here form part of the target architecture and will be delivered progressively.
An Assurance Intelligence platform should be assessed on whether it improves real work and real decisions, not on how many records it can hold. These are the questions worth putting to us, and to anyone else.
Critical services, systems, suppliers and dependencies, as your organisation actually runs them.
Criticality and prioritisation should be transparent and arguable, not hidden inside an opaque score.
Existing assurance history reused without losing source, scope, date, ownership or historical context.
Material change and evidence expiry should start an explainable review, not an automatic revalidation claim.
Findings through remediation, verification, residual risk and decision, in one traceable chain.
Every board-level figure should trace back to the underlying record, and one information model should not collapse distinct assurance methods into a single generic workflow.
E2ERisk connects what matters, what is known and what has changed, so attention goes where it is needed and the decision holds up afterwards.
We map how assurance runs today, where the context breaks, and which of the four questions you cannot yet answer.
Take a small set of critical services and prove connected assurance on your own data.
Managed SaaS, or into your own Azure subscription, with the modules you license and the context shared across them.