Guide · AI governance evidence
What an auditor asks about an AI decision
When an AI-assisted decision is questioned, the questions are predictable. The evidence that answers them is easy to keep while the work happens and close to impossible to rebuild afterwards.
The questions
| The question | The evidence that answers it |
|---|---|
| What was the AI asked to do? | The objective or request, as it was written at the time — not a summary written later. |
| Which AI system did the work, and who owns it? | An entry in an AI system register: provider, model, purpose, owners and environment. |
| What data did it touch? | A data classification on the work, and whether personal or sensitive data was involved. |
| Who decided, and on what basis? | The approver's identity, what they were shown, their decision and their reason. |
| Which controls applied, and which version? | The controls the work was held to, how each was met, and the version of the policy or framework it was assessed under. |
| What actually ran? | A record of the action taken, compared with what was allowed. |
| Was anything waived? | Exceptions with a reason, an owner, the risk accepted, what compensates, and an expiry. |
| Can you show the record was not altered? | An append-only log and an export with a digest, so a changed copy can be told apart. |
Why it has to be recorded as it happens
Reconstructing a decision months later means searching chat logs, email and the history of three tools, and hoping each kept what you need. Some of it — what the approver was shown, which version of a policy applied — usually was not kept anywhere. A record written as the work happens answers each question with the thing itself rather than with somebody's recollection of it.
Frameworks such as NIST AI Risk Management Framework, ISO/IEC 42001 AI management system, EU AI Act and UK AI regulatory principles ask for versions of the same evidence: an inventory of AI systems, risk assessment, human oversight, and records that show it was done. Mapping your controls to a framework is a starting point for your own review, not proof of compliance, and whether a requirement applies is for your organisation to decide.
What to keep, at minimum
- A register of the AI systems in use, each with an owner.
- For each consequential piece of work: its purpose, the system that did it, the data involved and its risk.
- Every human decision with who made it, when, and why — including the ones that said no.
- What ran, set against what was allowed.
- Exceptions, with owners and expiry dates, kept apart from controls that were met.
- An export someone outside the team can check.
How Deliverd keeps it
Compliance Mode, included in Business and Enterprise, turns a task into governed work: an AI system from the register, owners, risk, data classification and how people oversee it. The profile decides the controls; evidence, approvals and exceptions meet or waive them; and an agent asks the governance gate before it acts. One evidence pack holds the system, the profile, the controls, the evidence, the decisions and the audit timeline, with a sha256 digest. It records governance — it does not certify compliance.