AI Compass
Compass

Preparing for audit

What an inspection actually asks for, which eight documents suffice, and where organisations routinely fail.

·1 min read·By Fachbereich Governance
DETAIL
2 sections

The eight documents

DocumentContent
InventoryEvery system with role, class, purpose, ownership
Classification reasoningPer system, with date and categories assessed
Purpose description and boundaryFor what, and expressly not for what
Data descriptionProvenance, categories, representativeness, bias assessment
Evaluation resultsFixed evaluation set, quality per category, with date
Oversight arrangementWho, with what authority, on what basis
LogsPer transaction, with model version and review note
Competence evidenceWho, for which system, when

How an inspection runs

  1. 01

    Is it known what is deployed?

    The inventory is held against reality, often via network logs or invoices.

  2. 02

    Is the classification traceable?

    Not whether it is right but whether it is reasoned and dated.

  3. 03

    Is operation under control?

    Measurement, oversight, logs, reporting routes. This is where it is decided.

  4. 04

    Do documents and reality agree?

    Samples from operation against the documentation. The most common finding sits here.

Annex IV, for the provider role

  • General description: purpose, version, interaction with other software, form of deployment.
  • Detailed description: development steps, prior decisions, architecture, computational resources.
  • Monitoring, functioning and control: accuracy, limits, foreseeable misuse.
  • Risk management: risks identified and measures taken.
  • Changes across the lifecycle.
  • Standards and specifications applied.
  • Declaration of conformity.
  • Post-market monitoring plan.

What actually shortens preparation

  • Dated documents. Without a date a document cannot be examined.
  • A fixed evaluation set. It makes quality comparable across model changes and is the only number that carries.
  • Trigger-based updating. Model change, purpose extension, new data category. Not an annual rhythm.
  • A register of where things are. Searching for documents costs more time in practice than producing them.
  • Named people. A department cannot be questioned; a person can.

The question that decides everything

An inspector rarely asks about the model. They ask: how would you have noticed it getting worse? Anyone who can name a number, a threshold and a reporting route passes. Anyone who answers that nobody complained does not.

The complete evidence list

FREE ACCOUNT

Evidence list for an audit

Four blocks covering the documents an audit actually asks for, each with a location and an owner.

Checklist4 items

No password needed. We send you a sign-in link. An account does not subscribe you to anything. The newsletter is separate.

Related courses and sources

ArticleFreeDE · EN

Fraunhofer IAIS on artificial intelligence

German-language guidance on auditing, certifying and operating AI systems, from applied research.

For German-language audit and certification questions where English sources do not help.

Fraunhofer IAISGo to offer
BookFreeEN

Interpretable Machine Learning

What explainability methods deliver and where they get over-interpreted. The most sober treatment of the topic, freely available.

For anyone who has to promise explainability and should know what the methods actually deliver.

PaperFreeEN

Model Cards for Model Reporting

The proposal to document purpose, limits and tested groups for every model. Today effectively a precondition for any audit.

For anyone preparing an audit; model cards have effectively become a precondition.

ArticleFreeEN

NIST AI Risk Management Framework

A structured frame for your own risk assessment, independent of the AI Act. Useful as an outline when none exists internally yet.

For building your own risk assessment, independent of the AI Act.

ArticleFreeEN

NIST AI RMF Playbook

The practical build-out of the risk framework: concrete suggestions per function on what to do and what to document.

For anyone building an internal risk assessment who wants an outline that has already been thought through.

Was this page helpful?
Preparing for audit