Services · Continuous Assurance

Retest the controls as the agent changes.

Scope regression tests and evidence reviews around changes to models, prompts, tools, permissions and deployment.

Clarity. Control. Confidence.From review to remediation.

What the engagement covers

Change register

Record what changed and which controls may be affected.

Regression suite

Repeat agreed high-risk scenarios against the current version.

Evidence updates

Refresh requirement mappings and record unresolved gaps.

Review cadence

Scheduled readouts and escalation responsibilities agreed in the contract.

Scope and responsibilities

Ongoing review requires an agreed baseline, versioned tests, access and named control owners. Trigger integrations, review cadence, retention and reporting are defined for your environment. It does not include 24×7 incident response unless a separate operating agreement establishes that coverage.

A practical example

A supplier adds a tool that can export data. Recheck identity scope, destination restrictions and approval behaviour before relying on the previous baseline. Historical test success does not cover the new capability.

When to retest an AI agent

A review baseline applies to a particular configuration. A new model, changed prompt, added MCP tool, broader service identity or new export destination can alter the actions available to the agent. Retesting should follow the changed boundary rather than repeat an unrelated benchmark score.

An agreed change register identifies the owner, affected controls and review decision. High-impact changes can require testing before rollout; lower-impact changes can follow the scheduled cadence defined for the engagement.

See the practical MCP tool change-review sequence and the limits of headline guardrail benchmarks.

Evidence that stays connected to the deployment

Each review should connect the system version, change record, control configuration, test scenarios and observed results. Keep failed tests and coverage exclusions alongside successful results so the owner can assess the whole picture.

A useful readout distinguishes controls that remain effective, new findings requiring remediation, accepted residual risks and paths that could not be tested. The next review date and responsible owners should be explicit.

Ongoing review questions

Do we need an initial assessment?

A defined baseline is required. It can come from an agreed assessment or existing evidence that is reviewed for scope, currency and reproducibility during discovery.

Does this include continuous monitoring or incident response?

The engagement covers the tests, evidence reviews and escalation responsibilities specified in the contract. Monitoring integrations or incident response require explicit operating coverage and responsibilities; they are not implied by the service name.

Turn security challenges into a clear plan

Tell us what you need to protect, improve or achieve. We will help you identify the control gaps, prioritise the work and define practical steps towards your goal.