AI governance has to work outside the policy document

Writing an AI policy is an important step. But a policy is only useful if the people responsible for carrying it out understand the technology, the risks, and the ways AI systems can be tested.

An organization can create rules about how employees use AI, which AI systems are approved, when human review is required, and what types of data can be shared with an AI tool.

Those are useful rules. They also raise harder questions. What counts as adequate human review? How should an AI feature from a software vendor be evaluated? How do you determine whether an AI system is accurate enough for its intended use? What happens if its performance changes after deployment?

These are not just policy questions. They require some understanding of how AI works, how it fails, and how it can be evaluated. That is why AI testing and AI assurance can be important parts of effective AI governance.

Knowing how to use AI is not the same as knowing how to test it

Millions of people now use generative AI tools. They know how to write prompts, summarize documents, generate ideas, write code, or automate parts of their jobs.

That knowledge is useful, but it is different from knowing how to question an AI system.

Someone involved in AI assurance may need to understand issues such as hallucinations, bias, training and test data quality, non-deterministic results, privacy and security risks, automation bias, concept drift, adversarial attacks, data poisoning, weak acceptance criteria, overreliance, and prompt injection.

The NIST AI Risk Management Framework calls for organizations to measure and manage AI risks. Its Measure function discusses testing AI systems before deployment and regularly while they are operating. The OWASP AI Testing Guide reaches a similar conclusion from a testing perspective, including risks such as hallucinations, bias, sensitive information leakage, adversarial manipulation, model drift, and unsafe agency.

For the application-level version, see testing LLM applications.

In other words, organizations need more than people who know how to use AI. They also need people who know how to challenge it.

Good AI governance needs testable questions

Governance rules are easier to trust when someone can translate them into practical assurance questions.

Policy

AI-generated work must be reviewed by a person.

Assurance questions
  • What should the reviewer check?
  • What qualifies as adequate review?
  • How do you detect overreliance?
Policy

Confidential information must not be exposed through AI systems.

Assurance questions
  • What data can the AI access?
  • Can sensitive information be exposed?
  • How is that tested?
Policy

Important AI systems must be monitored.

Assurance questions
  • What should be measured?
  • How often?
  • What amount of change should trigger action?

A governance team does not necessarily need to perform all of this testing itself. But it helps to have people who understand these questions well enough to recognize the risks, communicate with technical teams, and understand the evidence testing produces. For the management side of that capability, see AI Assurance Pro for managers.

Software testers already have part of the right mindset

Software testing professionals are trained to ask questions that are useful in AI assurance: What could go wrong? How would we know? What should the expected result be? What happens at the edges? What evidence do we have that the system meets its requirements?

AI changes some of the answers. Traditional software often has predictable inputs and outputs. AI systems can be probabilistic, dependent on data, vulnerable to new types of manipulation, and capable of changing in ways that require different testing approaches.

That means traditional testing experience is valuable, but additional AI knowledge can be important.

This is where AI Assurance Pro fits

ASTQB AI Assurance Pro™ is designed to bring several areas of knowledge together for software quality professionals.

To earn the designation through AT*SQA, a professional must earn three ISTQB certifications: ISTQB Foundation Level, ISTQB AI Testing, and ISTQB Testing with Generative AI. Together, they cover software testing fundamentals, testing AI-based systems, and the use and testing of generative AI. The designation also includes an annual continuing education requirement.

That combination matters because AI assurance is not simply about understanding AI terminology. It involves understanding testing principles and applying them to problems that are specific to AI.

AI Assurance Pro does not make someone responsible for every part of AI governance. It does not replace legal, privacy, security, compliance, management, or specialized AI expertise.

It provides something more specific: evidence that a software quality professional has been assessed on a defined body of knowledge covering software testing, AI system testing, and testing with generative AI.

Why that can be valuable to an organization

AI governance usually involves people from several parts of an organization. Management may establish acceptable risk. Legal and privacy teams may address regulatory and data issues. Security teams may focus on threats. Product teams understand how a system will be used.

Someone still needs to understand the testing side.

Having a person with AI assurance knowledge can help an organization ask better questions, recognize testing needs, interpret technical findings, and connect broad AI rules with the work required to evaluate AI systems.

A designation alone cannot guarantee that someone will solve every AI problem. No responsible credential should make that promise. But when an organization needs people who understand both software testing and the additional challenges created by AI, demonstrated knowledge in those areas can be quite useful.

That is the role AI Assurance Pro is intended to fill.