Skip to content
AIAC AI ASSURANCE COUNCIL

Auditing AI systems

The evidence file

Every artefact named across the Auditing AI systems collection, and what makes each sufficient. Assembled from the evidence column on each obligation, so every entry traces back to the provision that demands it.

§ 1 — How to read this

19 artefacts appear across Auditing AI systems. 0 of them are demanded by more than one obligation, which makes them the ones worth building first: the same document, properly made, discharges several duties at once. An artefact that is merely present does not discharge anything, so each entry records what makes it sufficient — that sentence is the part an assessor is testing.

§ 2 — Artefacts

What you will be asked for

  • A boundary statement separating the model from the process around it

    One obligation

    • IIA Standard 13.3 — Engagement Objectives and Scope

      What sits inside the engagement: artefact, pipeline, environment, and the human step after the output. Findings land badly where the line was never drawn, because the control that failed turns out to sit just beyond it.

  • A cause analysis that terminates at a control

    One obligation

  • A corroboration record where one source carried a conclusion

    One obligation

  • A finding sheet carrying criteria and condition as separate fields

    One obligation

  • A likelihood count taken from the population, not the sample

    One obligation

  • A reperformance note written by a second person

    One obligation

  • A reperformance trace for every procedure run against the model

    One obligation

    • IIA Standard 14.6 — Engagement Documentation

      Artefact identifier, input set, output set, and the comparison method used to decide pass or fail, held together in one place. This is the addition the prescribed format does not name and the repeatability test cannot do without.

  • A retention record checked against the artefacts the papers rely on

    One obligation

    • IIA Standard 14.6 — Engagement Documentation

      Not merely the period for the papers, but confirmation that extracts, model versions and endpoints are kept for as long as the papers are. Attachment beats citation for anything that can be decommissioned by somebody else.

  • A scope memorandum stating the versions and the period

    One obligation

    • IIA Standard 13.3 — Engagement Objectives and Scope

      Named system, the versions in service across the window, the environment they ran in, and the dates. A scope expressed only as a calendar quarter cannot tell a reader how many configurations the conclusion covers.

  • A work programme with a step against each objective

    One obligation

  • An effects statement separating what occurred from what could occur

    One obligation

  • An engagement risk assessment naming the AI systems excluded

    One obligation

  • An evidence register keyed to the procedure it supports

    One obligation

  • An indexed and cross-referenced engagement file

    One obligation

    • IIA Standard 14.6 — Engagement Documentation

      Every conclusion traceable to the paper supporting it, and every paper to the objective it serves. Indexing is the part that survives staff turnover, and it lets a reviewer test the chain instead of re-reading the fieldwork.

  • Management assertions scheduled apart from tested material

    One obligation

  • Supervisory review notes recording what was asked and how it cleared

    One obligation

    • IIA Standard 14.6 — Engagement Documentation

      Named reviewer, date, the query raised, and its resolution. A note recording only that review occurred proves the step ran and nothing about whether it caught anything, which is the entire reason the step is in the standard.

  • The chief audit executive’s approval of the file

    One obligation

  • The disposition record for potential findings not elevated

    One obligation

  • The unobtainable-evidence memorandum and its 14.1 determination

    One obligation