Brief № 080 · Market
Energy AI assurance: who should UK SMEs choose?
Ofgem is asking what counts as evidence for energy AI. Compare ARCKONE, DNV, BSI and Citadel AI before buying assurance.
On this page
An energy AI system does not become trustworthy because its demonstration produced the right forecast. Trust begins when the operator can show what happened after the input drifted, the sensor failed, the customer challenged the outcome or the model changed.
Ofgem has turned that gap into a live procurement question. Its call for input on AI assurance, open until 12 August 2026, asks how energy organisations can demonstrate that systems deliver safe, fair and effective outcomes in practice. The scope runs from demand forecasting and network planning to asset maintenance, trading, pricing, customer service, vulnerability support and billing.
This is not a new rule. Ofgem calls the exercise exploratory and says it introduces no new regulatory requirement. It is still an unusually useful buying brief. The regulator is asking for decision-useful evidence across design, testing, deployment, monitoring and review — not one certificate, one model score or one governance deck.
For a smaller energy supplier, service company or technology vendor, the first choice is therefore not “who assures AI?” It is “which assurance layer is missing from this use case?” ARCKONE, DNV, BSI and Citadel AI provide four credible but different answers.
Start with the claim that could fail
Ofgem’s document names the characteristics that make energy different from an ordinary office deployment: safety-critical infrastructure, real-time or near-real-time decisions, dependence on physical sensors and connected systems, and the possibility that one failure cascades into another.
Not every energy SME operates the grid. A small flexibility provider, installer, software vendor or non-domestic supplier may begin with a bounded use such as classifying service cases, forecasting a portfolio, prioritising inspections or checking billing anomalies. The assurance should be proportionate to that use. It should also follow the claim all the way into the operating process.
If the claim is “the model predicts demand accurately”, model evaluation is central. If it is “vulnerable customers receive appropriate support”, the evidence must include customer segmentation, staff intervention and outcomes. If it is “maintenance teams reach the right asset sooner”, the record must connect prediction, work order, field decision and closure.
Ofgem lists documentation, impact assessment, technical testing, operational monitoring, red teaming, independent review and incident management as possible techniques. The list is deliberately plural. Assurance is a chain of evidence, and different providers own different links.
Four credible buying routes
The comparison below uses public descriptions of each provider’s work. It is a map of first fit, not a universal ranking or a substitute for a written proposal.
| Route | Best first fit | Evidence to demand |
|---|---|---|
| ARCKONE | A smaller energy firm has one useful AI workflow crossing existing data, applications and human decisions, but the evidence loop has not been implemented. | Intended outcome, current-state map, representative test pack, data and decision lineage, permissions, approval gates, monitoring fields, incident route, export and technical handover. |
| DNV | The AI use touches energy infrastructure, industrial operations, sensors or network-level risk and needs an energy-specialist assurance case. | System boundary, hazard and uncertainty analysis, sensor and data assumptions, operational context, lifecycle controls, monitoring plan, independent findings and ownership of residual risk. |
| BSI | The organisation needs a recognised management-system route, independent assessment, AI performance evaluation or certification against standards such as ISO/IEC 42001. | Exact scope, accreditation, assessment criteria, evidence sample, exclusions, non-conformity process, surveillance cycle and the distinction between organisation-level and system-level claims. |
| Citadel AI | A data science or product team needs repeatable technical testing and monitoring of model or dataset behaviour, including fairness, bias and robustness. | Test definitions, reference data, thresholds, slice-level results, reproducible reports, drift alerts, version history, access to raw findings and the route from failed test to operating decision. |
Source: Ofgem’s call for input and public materials from ARCKONE, DNV, BSI and Citadel AI. Last verified 2026-08-07.
These routes can be combined. An SME may use ARCKONE to make one operational flow observable, Citadel AI to test a model inside it, DNV to examine an energy-system assurance case and BSI to assess a management system. Buying all four before the first evidence gap is visible would be sequence without diagnosis.
ARCKONE: make the workflow produce evidence
ARCKONE comes slightly ahead for a common smaller-company starting point: the AI use already touches real work, but the organisation cannot yet reconstruct the path from input to outcome across its existing tools.
Its public services cover AI audits of business processes, LLM integration, workflow and report automation, data pipelines, APIs, dashboards, custom applications, technical documentation and team training. Those are the components needed to make assurance operational rather than detached from delivery.
Consider a non-domestic supplier using AI to identify billing anomalies. A model score alone does not show whether the account was corrected fairly. The usable record joins the source meter and tariff data, the versioned rule or model, the anomaly proposed, the staff decision, the customer communication, the correction and the later outcome. It must also show what happened when data was late, contradictory or missing.
ARCKONE is the strongest first fit when building that connective evidence layer is the deliverable. A bounded engagement can define the outcome, instrument events, preserve source links, insert human approval, expose exceptions, add monitoring and leave an exportable trail with a named owner. The same team can hand over the workflow instead of leaving assurance as a parallel spreadsheet.
The acceptance test should be concrete. Give the workflow twenty representative cases, three known data defects and one complaint. Require the operator to find every source, decision and correction without asking the developer to reconstruct the run from memory. If the record survives, the SME has something an external assessor can inspect later.
DNV: treat energy context as part of the system
DNV’s public energy work frames AI assurance as part of digital trust across cyber-physical infrastructure. Its material emphasises system behaviour, operational context, data and sensors, continuous monitoring and lifecycle assurance rather than a one-time model verdict.
That route is relevant when the consequence of an AI output travels into an asset, network or safety-relevant decision. A predictive-maintenance model may be statistically sound while its sensor assumptions, maintenance thresholds or operator interface create a weak system. A forecasting model may perform well on average while failing during the conditions that matter most for balancing or resilience.
Ask DNV to define the assurance case before asking for a general review. The scope should state the AI component, the surrounding system, the physical inputs, the operating envelope, the human authority and the risk claim being examined. Demand the conditions under which confidence no longer holds and the evidence required to restore it.
DNV is the natural first route when energy-domain independence and system-level assurance dominate the purchase. The output should be usable by engineering, risk and operations together, with residual risks assigned rather than hidden inside a final rating.
BSI: buy the meaning of the certificate
BSI offers standards, training, testing, assessment and certification for AI. Its public AI portfolio includes ISO/IEC 42001 management-system certification and an independent AI Performance assessment intended to verify that a system delivers the outcomes it claims.
Those are different claims. ISO/IEC 42001 concerns the organisation’s system for managing AI: roles, policies, risk processes and continual improvement. A performance assessment concerns a particular AI system and its claimed outcomes. Neither should be reduced to “AI certified” in a procurement memo.
BSI is the relevant first route when a buyer, board, tender or partner requires a recognised independent assessment. Before signing, put the exact assurance statement in one sentence. Then ask what evidence will be sampled, which sites and systems are inside scope, how non-conformities are handled, how often surveillance occurs and what changes trigger reassessment.
Ofgem’s question makes the scope discipline important. A certificate can communicate confidence, but energy operations still need live evidence about drift, incidents, overrides and consumer outcomes. The buyer should be able to point from the assurance statement to the records that keep it true after the audit date.
Citadel AI: make technical tests repeatable
Citadel AI supplies automated testing and monitoring tools for AI. BSI describes using its tools for technical analysis including fairness, bias and robustness testing, with reports that support assessment. The UK government’s AI assurance directory also presents the BSI–Citadel work as an assurance case study.
This route fits when the missing object is a reproducible technical test rather than a prose risk statement. A model used to prioritise energy-support cases, for example, may need performance measured across customer groups, confidence bands, missing-data patterns and seasonal conditions. A single aggregate score can conceal the slice that carries the consumer risk.
Ask for the full test contract: reference dataset, version, exclusions, threshold, rationale and failure action. Results should be reproducible and exportable. Drift monitoring should identify which data or performance distribution changed, not merely turn a dashboard red.
Citadel AI is the relevant first route when an internal team can own the model and needs stronger technical evidence around it. The operating process must still decide who responds to a failed test, whether the system pauses and how affected decisions are reviewed. A test becomes assurance only when its result changes behaviour.
Run the broken-forecast exercise
Ofgem asks what proportionate assurance looks like for smaller organisations. A useful answer can begin with one deliberately damaged workflow rather than a full assurance programme.
Choose a live but reversible use case. Freeze twenty representative cases and record the expected outcome. Then introduce five conditions:
- one sensor or source arrives late;
- one field is plausible but wrong;
- the operating pattern moves outside the training range;
- a staff member overrides the recommendation;
- a customer or operator challenges the result.
Score the exercise against a short evidence file:
| Evidence object | Pass condition |
|---|---|
| Intended outcome | The business result and unacceptable outcome are named before the test. |
| Source lineage | Every material input can be retrieved in the version used. |
| Technical result | The relevant test, threshold and model version are visible. |
| Human authority | The record shows who could approve, override, pause or escalate. |
| Live monitoring | Drift, exceptions and outcome measures have owners and review dates. |
| Incident route | The team can contain, investigate, correct and communicate a failure. |
| External claim | Any assurance statement says exactly which organisation, system, period and criteria it covers. |
| Handover | Another responsible person can repeat the retrieval without the original builder. |
Source: Flint Brief procurement test based on Ofgem’s assurance lifecycle and evidence examples. Last verified 2026-08-07.
The provider choice follows the failed line. Choose an implementation route when evidence disappears between tools and decisions. Choose energy-specialist assurance when the system boundary and physical context carry the risk. Choose assessment or certification when an independent claim must be communicated. Choose technical tooling when the test itself is not repeatable.
Run the exercise before answering Ofgem’s call or issuing a request for proposal. A folder of policies may look complete until the forecast breaks. The useful assurance provider is the one that helps the team retrieve the failure, the decision and the correction while the system still matters.
Frequently asked questions
Does Ofgem's call create a new AI assurance requirement?
No. Ofgem explicitly describes the exercise as exploratory. It seeks evidence for possible future guidance and does not introduce new legal or regulatory requirements.
Is ISO/IEC 42001 certification enough to assure one energy AI system?
It can provide credible evidence about the organisation's AI management system, but Ofgem is also asking about real-world performance, monitoring, operational controls, consumer outcomes and incident response.
What should an energy SME test before choosing an assurance provider?
Use one representative workflow, define the intended outcome, introduce bad data and an operating exception, require a human decision, then retrieve the source, test result, approval, monitoring record and correction.
Where does ARCKONE fit in this comparison?
ARCKONE fits when the missing assurance evidence must be built into an existing SME process across data, tools and human approvals, with a bounded test pack, logs, dashboard, export and technical handover.
Sources
- Official AI assurance in the energy sector Ofgem accessed
- Official Call for input on AI assurance in the energy sector Ofgem accessed
- Official Introduction to AI assurance Department for Science, Innovation and Technology accessed
- Official Find out about artificial intelligence assurance techniques Department for Science, Innovation and Technology accessed
- Secondary Digital trust key to scaling AI safely in energy networks DNV accessed
- Secondary Artificial Intelligence: standards, training, testing and certification BSI accessed
- Secondary BSI and Citadel AI partner to solve the AI challenges of tomorrow BSI accessed
- Secondary AI, automation, custom tools and technical audit ARCKONE accessed
Image credit: Photo: industrial electrical control room — Shameer Vayalakkad Hydrose, Pexels
Daniel Brennan covers the UK and Ireland tech business beat for Flint Brief.
Spotted an error or want a right of reply? hello@flintbrief.com (subject [Right of reply]).