SILVER
Move from foundations to structured assurance
AIGAS™ Silver is designed for accounting firms that want to demonstrate a more developed and structured approach to AI governance. Where Bronze establishes the foundations, Silver looks more deeply at how AI governance operates across the firm.
It asks whether AI risks are being formally assessed, whether responsibilities are clearly defined, whether controls are embedded into working practices and whether governance is being actively reviewed and improved.
The Standard describes Silver as AI Governance Assured, introducing formal risk assessment, defined governance responsibilities, documented operational controls and monitoring and review processes.
demonstrates that the foundations exist.
demonstrates that AI governance has become part of how the firm operates.
The same six areas. Structured depth.
Silver works across the same six areas of the AIGAS framework as Bronze. The difference is the depth and maturity expected. Rather than simply demonstrating awareness and baseline controls, the firm needs to show that governance is structured, documented and operating in practice.
AI strategy and purposeful adoption
Does your firm have a deliberate approach to AI?
At Silver, simply knowing which tools are being used is no longer enough. The firm should be able to explain how it approaches AI adoption and how approved AI uses fit into its operations. The Standard introduces requirements around an AI strategy, defined use cases and periodic strategic review.
AI adoption can otherwise become a collection of individual tools and experiments with no clear organisational direction. Silver asks the firm to move from “We use some AI tools” to “This is how and why our firm uses AI.”
Formal risk management
Are AI risks being identified, recorded and managed?
Silver introduces a more structured approach to risk. The firm is expected to assess AI risks, maintain appropriate records of those risks and document what is being done to address them. Professional liability implications are also part of the considerations set out in the Standard.
Awareness is important. But once AI becomes more embedded within a firm’s operations, risks need to be managed systematically rather than relying on individuals simply remembering them.
Data protection and supplier governance
Do you understand what happens when third parties process your information?
Silver goes further than basic confidentiality safeguards. Where AI suppliers may process client or personal information, the firm needs a more structured understanding of the supplier relationship and the associated data-protection implications. The Standard covers supplier review, consideration of whether a Data Protection Impact Assessment may be required, and appropriate documentation of relevant processing activities.
Many AI risks do not sit entirely inside the accounting firm. They arise through the technology providers and platforms the firm relies upon. Good AI governance therefore includes understanding the supply chain.
Defined governance and accountability
Is AI governance part of the firm’s management structure?
Silver requires clearer governance arrangements. Responsibilities should be defined rather than informal, and AI governance should be reviewed periodically through appropriate management or governance processes. The Standard introduces a designated AI Governance Lead, documented roles and responsibilities, and periodic governance oversight.
As AI becomes more widely used, governance cannot depend entirely on one enthusiastic individual remembering to deal with it. There needs to be an organisational structure behind it.
Operational controls
How is AI governed in real working processes?
Silver looks at AI where it actually affects work. Where AI outputs form part of operational workflows, firms need appropriate verification controls. The Standard also introduces expectations around AI incident response and documenting workflows where AI is embedded into them.
A policy tells people what should happen. Operational controls help demonstrate that it does happen. Silver therefore places greater emphasis on the connection between governance documentation and day-to-day practice.
Monitoring and continuous improvement
How does the firm know its governance is still working?
Silver expects firms to revisit AI risks, respond to weaknesses and keep track of improvements. The Standard includes periodic risk reassessment, corrective actions and continuous-improvement tracking.
AI governance should not remain frozen while technology continues to change. Silver is designed to demonstrate that the firm has established a management process, not simply completed a project.
What will our firm need to demonstrate?
Silver requires evidence that appropriate governance arrangements have actually been implemented. The assurance process considers documented evidence, implemented controls, risk documentation and governance structures. Unsupported self-declaration is not sufficient.
The exact evidence will depend upon the firm’s circumstances and the AI systems it uses. The purpose of the process is therefore not to create an identical folder of documents for every accounting practice — it is to demonstrate that the firm’s controls are appropriate, implemented and capable of being evidenced.
A firm can have an excellent AI policy sitting in a folder and still have poor AI governance. Silver therefore looks beyond the existence of documents. It considers whether:
The objective is to provide meaningful assurance rather than simply completing a checklist.
Do we need Bronze first?
A firm may progress from Bronze to Silver, but Bronze does not have to be the starting point for every organisation. A firm with more extensive AI use, existing governance arrangements or a greater need for external assurance may decide to begin directly with Silver.
Where a firm has already completed Bronze, relevant work can provide a foundation for its progression.
Yes.
Silver represents a more developed governance programme and some firms will choose to work with an AIGAS Certified Service Provider.
The Service Provider helps implement the framework. Responsibility for how AI is ultimately governed remains with the firm.
Find a Certified Service Provider →A Service Provider can support areas such as
- Understanding your starting position
- Planning implementation
- Developing appropriate governance processes
- Risk assessment
- Policies and documentation
- Staff training
- Evidence preparation
- Preparing the firm for assessment
How long does Silver last?
AIGAS assurance is valid for 12 months. During that period, firms should maintain their governance arrangements and respond appropriately as tools, risks and working practices change. Assurance is then revalidated.
For many firms, Silver may provide the level of AI governance assurance they need. For organisations seeking a more extensive internationally recognised AI management system, AIGAS also provides a pathway towards considering ISO/IEC 42001.
AIGAS has been structured around management-system principles including leadership, risk management, operational control, monitoring and continual improvement, but it does not claim equivalence with ISO certification. ISO/IEC 42001 certification must be undertaken through an accredited certification body.
Silver may be appropriate where
You do not need to know the answer before starting. The AIGAS Self-Assessment can help you understand your current position.
Have we established the foundations?
Can we demonstrate that AI governance is structured, implemented and being actively managed?
