Definition
A structured argument, supported by evidence, that a system is acceptably safe or dependable within a stated scope. An assurance case connects a top-level claim to subclaims about hazards, controls, operation, and recovery, then identifies the tests, analysis, operational data, process evidence, and expert judgment supporting each part.
The claim is always bounded. It should name the system version, intended use, users, environment, threat model, risk threshold, assumptions, exclusions, and responsible owner. Counterevidence and uncertainty belong in the case. A strong case also defines the changes or incidents that force review rather than allowing old evidence to justify a new system indefinitely.
From safety-critical engineering to AI systems
Assurance cases come from safety and dependability practice, where a certificate or checklist could not capture the reasoning behind a safety claim. AI adds learned behavior, nondeterminism, evolving providers, and wide input spaces, which make the argument harder but not less necessary. Evaluation scores become evidence inside the case; they are not the case by themselves.
Distinguish it from nearby terms
A risk assessment identifies and estimates risks. A safety case is an assurance case focused on safety. A compliance report shows conformance with a rule set. A maturity level labels organizational practice. None substitutes for the explicit claim-evidence reasoning of a case.
Check your understanding
The model is replaced behind the same API name. Can the previous assurance case remain unchanged? Only if the case anticipated and bounded that change and fresh evidence supports the relevant claims. Otherwise the system version and evidence basis have changed.