Governance is not the same as verification
Governance defines responsibilities, policies, limits and approval requirements. Verification checks whether the system actually follows them. Auditing provides an organised and sufficiently independent evaluation of the evidence.
Where verification is essential
Verification should occur at the input, prompt, authority, workflow, claim, output, independent-review, human-approval, runtime and reliance stages.
Before deployment
Confirm intended use, data suitability, permissions, workflow logic, stopping conditions, escalation paths and acceptance criteria.
During operation
Monitor drift, unexpected behaviour, policy breaches, tool use, anomalies and attempted authority escalation.
After change or incident
Recheck the affected controls, trace the evidence, record corrective action and determine whether continued reliance remains justified.
Standards set requirements. Verification and auditing provide evidence that the requirements are working in practice.
Revision history
Version 1.0 — 26 July 2026: Initial publication.