Guide · AI governance evidence

What an auditor asks about an AI decision

When an AI-assisted decision is questioned, the questions are predictable. The evidence that answers them is easy to keep while the work happens and close to impossible to rebuild afterwards.

The questions

The questionThe evidence that answers it
What was the AI asked to do?The objective or request, as it was written at the time — not a summary written later.
Which AI system did the work, and who owns it?An entry in an AI system register: provider, model, purpose, owners and environment.
What data did it touch?A data classification on the work, and whether personal or sensitive data was involved.
Who decided, and on what basis?The approver's identity, what they were shown, their decision and their reason.
Which controls applied, and which version?The controls the work was held to, how each was met, and the version of the policy or framework it was assessed under.
What actually ran?A record of the action taken, compared with what was allowed.
Was anything waived?Exceptions with a reason, an owner, the risk accepted, what compensates, and an expiry.
Can you show the record was not altered?An append-only log and an export with a digest, so a changed copy can be told apart.

Why it has to be recorded as it happens

Reconstructing a decision months later means searching chat logs, email and the history of three tools, and hoping each kept what you need. Some of it — what the approver was shown, which version of a policy applied — usually was not kept anywhere. A record written as the work happens answers each question with the thing itself rather than with somebody's recollection of it.

Frameworks such as NIST AI Risk Management Framework, ISO/IEC 42001 AI management system, EU AI Act and UK AI regulatory principles ask for versions of the same evidence: an inventory of AI systems, risk assessment, human oversight, and records that show it was done. Mapping your controls to a framework is a starting point for your own review, not proof of compliance, and whether a requirement applies is for your organisation to decide.

What to keep, at minimum

  • A register of the AI systems in use, each with an owner.
  • For each consequential piece of work: its purpose, the system that did it, the data involved and its risk.
  • Every human decision with who made it, when, and why — including the ones that said no.
  • What ran, set against what was allowed.
  • Exceptions, with owners and expiry dates, kept apart from controls that were met.
  • An export someone outside the team can check.

How Deliverd keeps it

Compliance Mode, included in Business and Enterprise, turns a task into governed work: an AI system from the register, owners, risk, data classification and how people oversee it. The profile decides the controls; evidence, approvals and exceptions meet or waive them; and an agent asks the governance gate before it acts. One evidence pack holds the system, the profile, the controls, the evidence, the decisions and the audit timeline, with a sha256 digest. It records governance — it does not certify compliance.