A causal model of safety assurance for machine learning