Executive guide · September 2026
The AI CoE Playbook
Independent assurance for AI operating models, governance, and regulatory confidence, written for executives responsible for risk, audit, and AI governance.

This playbook complements, not replaces, AI operating-model design from firms like McKinsey and BCG.
The one-line test
Find whoever owns your AI CoE's roadmap. Find whoever is accountable for testing what that roadmap ships. If it is the same person, or two people reporting to that same person, that is the gap this playbook is built to find and close.
Testing activity alone does not make an AI operating model assurance-ready. Readiness depends on whether an independent function can produce evidence-based challenge, influence deployment decisions, and continue assurance after launch.
Current situation
A separate testing label cannot assure independent challenge
AI CoEs own prioritization, standards, operations, and scaling. Testing can remain tied to the same leadership incentives, budgets, or timelines governing release.
Separate label, shared authority
Testing may be named separately while delivery incentives still shape its mandate and challenge.
Findings without decision rights
Evidence may be documented without clear authority to influence launch decisions.
Evidence arrives too late
Evidence assembled after delivery commitments can make challenge procedural rather than decision-shaping.
"A relabeled team that still answers to the CoE's leadership hasn't solved this. It's reproduced the exact pattern examiners are trained to catch"
SR 11-7 judges independence through actions and outcomes, not reporting lines alone.
What is inside
A decision-led path through six sections
Written for senior leaders assessing whether AI testing is structurally independent from AI delivery.
Define the assurance problem
Clarify why testing independence matters to AI launch decisions.
Set delivery boundaries
Separate the AI CoE's delivery mandate from its assurance mandate.
Design independent assurance
Establish a distinct challenge function with evidence-based outputs.
Work through the AI lifecycle
Connect delivery and assurance through checkpoints, remediation, and escalation.
Assess operating-model maturity
Locate the organization from no assurance to mature recurring assurance.
Decide the next action
Identify the evidence required and consider an Independent Assurance Check.
Integrated roadmap
Evidence, remediation and escalation, made explicit at every gate
Before build
Intake and scope
Before testing
Build and prepare
Pre-deployment
Independent assessment
In operation
Release and ongoing review
Maturity diagnostic
Assurance is not independent until authority and evidence align
The five-level ladder distinguishes assurance by observable authority: from ad hoc use and delivery-led testing at Levels 0 and 1, through nominal independence at Level 2, to structural and recurring assurance at Levels 3 and 4.
Levels 0 to 1
Exposure
Use is ad hoc or centralized, with no shared testing standard or independent challenge.
Level 2
False comfort
Testing exists, but delivery leadership retains control of reporting, budget, or timelines.
"Level 2 is the most common, and the most dangerous, because it looks solved."
Levels 3 to 4
Assurance
Independence has structural authority; mature assurance recertifies regularly with mapped evidence and escalation.
What the guide gives you
A practical basis for separating nominal from structural independence
Executives gain a practical basis for distinguishing nominal independence from structural and recurring assurance, helping board, audit, and risk stakeholders evaluate whether challenge is substantive.
Test independence in practice
Assess authority, incentives, reporting, budget, and the ability to delay or block launch, not organizational labels alone.
Make evidence repeatable
Use defined lifecycle gates, documented testing, remediation records, and escalation to support defensible decisions.
Assure beyond launch
Extend assurance through monitoring, recertification, and traceable decisions rather than relying on a one-time review.
Inside the pages
11 pages of executive briefing, not a brochure
An executive summary, a maturity diagnostic, a lifecycle roadmap, a decision matrix for three implementation paths, and an evidence architecture mapped to recognised reference points.



Who it is written for
Executives accountable for risk, audit, and AI governance
- Risk, audit, and compliance leaders who must judge whether AI challenge is substantive
- AI CoE and delivery leaders setting the boundary between delivery and assurance
- Board and executive stakeholders reviewing deployment and residual-risk decisions
The next action
Establish whether AI assurance is real, nominal, or missing
The final section sets out an Independent Assurance Check: a two week structured review against the five level maturity model, using operating evidence to determine the organization's actual level. No remediation commitment is requested at that stage.
- Scope
- Review the operating evidenceTest reporting relationships, mandate, evidence ownership, and influence over budget and timelines.
- Independence
- Test challenge in practiceAssess escalation rights and whether assurance can credibly affect launch decisions.
- Output
- Identify the actual maturity levelProvide a finding against the five level model and scope what closing any gap would take.
Get The AI CoE Playbook
11 pages. Name and work email only, and we will email you a copy of the download link.