Resource
Evidence expectations for AI governance
Governance is judged by what can be produced. This guide sets out the record a regulator, auditor or enterprise customer expects to see for a single AI system, and how to hold it without a documentation project.
The record for one AI system
- Register entry with business and technical owners
- Intake record capturing purpose, data, autonomy and population
- Assessment outcome, ruleset version and explanation trace
- Screening result for prohibited and restricted practice
- Applicable obligations with owners, dates and status
- Artefacts proving each control operates in practice
- Independent review and the attributable decision
- Monitoring, incident and material-change history
Documents are not evidence on their own
A policy proves intent. A completed template proves that a template was completed. Evidence is the artefact showing that a specific control operated for a specific system at a specific time: the test result, the approval, the log extract, the sign-off, the monitoring record.
The distinction becomes visible under questioning. An organisation that produces policies when asked for evidence has usually documented governance rather than performed it.
Show gaps honestly
Completeness that is asserted rather than computed is a liability. Each obligation should show whether the required evidence is attached, partial or absent, and that status should be derived from what is actually present.
A visible gap with an owner and a date is a defensible position. A silent gap is not.
Integrity and attribution
Evidence must be attributable and tamper-evident. Artefacts are hashed on upload, associated with the obligation and system they support, and linked to the person who provided them.
Every governance action is written to an append-only history: who acted, when, on what, under which policy and ruleset version. Corrections are recorded as new entries, never as edits to the original.
Export on demand
The practical test of an evidence model is the export. A single AI system's complete governance record — intake, assessment, obligations, evidence, review, decision, monitoring and audit history — should be producible as one coherent package for a regulator, an auditor or an enterprise customer's due diligence.
If assembling that package requires chasing individuals across email and shared drives, the evidence exists but the governance does not.
Frequently asked questions
- What evidence should an organisation hold for each AI system?
- A register entry with named owners, the intake record, the assessment outcome with its ruleset version and explanation trace, the applicable obligations with owners and dates, the artefacts proving those controls operate, the independent review, the attributable decision, monitoring records, and the append-only audit trail.
- Why is an append-only audit trail important?
- Because editable records cannot support a claim about what was known and decided at a point in time. Append-only history means corrections are added as new entries rather than overwriting the original, so the sequence of decisions remains provable.
- What does inspection-ready actually mean?
- That the complete record for a given AI system can be produced on request, in a coherent package, without a documentation project. It also means the record shows where evidence is missing rather than presenting gaps as completeness.
- How long should AI governance records be retained?
- Retention should follow the organisation's regulatory and contractual obligations for the relevant domain, and should outlast the AI system itself, since questions frequently arise after a system has been retired or replaced.
Make your AI record producible on request
See how intake, assessment, obligations, evidence, review, decision and audit history assemble into one exportable package.
No pricing commitment. No confidential information required.