Use when preparing evidence for internal or external audit of AI capabilities. Use when audit announced or during examination...
Prepare comprehensive evidence packages that address auditor questions efficiently and present AI capabilities in an accessible, well-organized manner.
Core principle: Auditors don't need to understand AI deeply. They need to see that (1) you know what you're doing, (2) controls exist, and (3) controls are working.
Organize evidence for auditor consumption, not internal convenience:
1. Executive Summary (start here)
2. System Documentation (how it works)
3. Policies and Procedures (how it's governed)
4. Control Evidence (proof controls work)
5. Operating Evidence (proof it's running)
6. Governance Evidence (proof of oversight)
7. Interview Preparation (for personnel)
audit_evidence_package:
capability: "[AI Capability Name]"
audit_type: "[Internal Audit | External Audit | Regulatory Exam]"
audit_scope: "[What's being examined]"
package_date: "[Date]"
package_owner: "[Who prepared]"
evidence_period: "[Time period covered]"
executive_summary:
for_auditors: |
[2-3 paragraph summary in plain language]
- What does this system do?
- How long has it been operating?
- Key statistics (volume, accuracy, issues)
- Oversight mechanisms in place
capability_in_plain_language: |
[Explain how it works without technical jargon]
[Use analogies if helpful]
[Focus on what auditors care about: inputs, processing, outputs, controls]
evidence_inventory:
category_1_system_documentation:
- document: "[Document name]"
location: "[Where to find it]"
description: "[What it contains]"
audit_relevance: "[Why auditor cares]"
last_updated: "[Date]"
category_2_policies_and_procedures:
- document: "[Document name]"
# ... same structure
category_3_control_evidence:
- document: "[Document name]"
description: "[What it shows]"
audit_relevance: "[Control it demonstrates]"
samples_available: "[What samples can be pulled]"
category_4_operating_evidence:
- document: "[Document name]"
# ... same structure
category_5_governance:
- document: "[Document name]"
# ... same structure
audit_question_mapping:
likely_questions:
- question: "[Anticipated question]"
evidence:
- "[Document 1]"
- "[Document 2]"
prepared_response: |
[Draft response with evidence references]
control_evidence_summary:
control_N:
control: "[Control name]"
description: "[What it does]"
evidence:
- type: "[Evidence type]"
showing: "[What it demonstrates]"
effectiveness: "[Operating effectively | Issue identified]"
known_gaps_and_limitations:
disclosed_proactively:
- gap: "[Known limitation]"
context: "[Why it exists]"
mitigation: "[How addressed]"
evidence: "[Supporting documentation]"
areas_for_improvement:
- area: "[Enhancement area]"
status: "[Planned timeline]"
evidence: "[Roadmap or plan]"
interview_preparation:
key_personnel:
- name: "[Name or role]"
role: "[Responsibility]"
topics: "[What they'll be asked about]"
preparation: "[What they should review]"
talking_points:
- "[Key message 1]"
- "[Key message 2]"
topics_to_handle_carefully:
- topic: "[Sensitive topic]"
guidance: "[How to respond]"
document_request_response_plan:
immediate_availability:
- "[Documents ready now]"
requires_preparation:
- item: "[Document needing prep]"
lead_time: "[How long]"
owner: "[Who prepares]"
sensitive_handling:
- item: "[Sensitive document]"
handling: "[Special procedures]"
package_completeness_checklist:
- category: "[Category name]"
status: "[Complete | Partial | Pending]"
The executive summary is often all auditors read initially. Make it count:
Good:
"The Trade Surveillance system monitors approximately 200,000 trades daily for potential market manipulation. It has operated since January 2025, generating about 150 alerts per day for analyst review. Four matters were escalated to SAR consideration during the review period."
Bad:
"The AI-powered surveillance platform leverages state-of-the-art transformer-based NLP models with attention mechanisms to perform real-time inference on trade flow data, achieving 0.85 AUC-ROC on held-out test sets."
Auditors want to see controls exist AND operate effectively:
| Evidence Type | What It Shows | Example |
|---|---|---|
| Design evidence | Control is designed | Policy document, procedure |
| Operating evidence | Control is functioning | Report showing control operated |
| Testing evidence | Control was verified | Validation report, test results |
| Exception evidence | Issues were caught | Exception log, remediation |
Prepare for common audit questions:
Disclose limitations before auditors discover them:
limitation:
what: "False positive rate is approximately 77%"
context: "System is intentionally tuned for sensitivity over precision"
why_acceptable: "Cost of missing true positive exceeds cost of reviewing false positive"
mitigation: "Analyst review filters false positives efficiently"
evidence: "Model documentation Section 5; tuning rationale memo"
Prepare personnel before auditor interviews:
| Role | Topics | Preparation |
|---|---|---|
| Business Owner | Purpose, value, oversight | Review statistics, committee minutes |
| Model Owner | Technical, validation, changes | Review model docs, validation reports |
| Operations | Day-to-day operation, issues | Review recent logs, exceptions |
| Compliance | Regulatory alignment, controls | Review procedures, control evidence |
| Topic | Guidance |
|---|---|
| "Why so many false positives?" | Explain intentional sensitivity trade-off |
| "Have there been any failures?" | Be honest; show remediation |
| "How do you know you're not missing things?" | Point to validation methodology |
| Questions outside expertise | "Let me connect you with [right person]" |
Plan for efficient response:
| Mistake | Why It's Wrong | Do This Instead |
|---|---|---|
| Document dump | Auditors lose patience | Organize with index and summary |
| Technical language | Creates confusion | Translate to business language |
| Capabilities only | Auditors seek weaknesses | Disclose limitations proactively |
| Documents without context | Hard to navigate | Map documents to questions |
| Unprepared personnel | Inconsistent messages | Brief everyone on key messages |
| Reactive posture | Looks like hiding | Proactively offer information |
If your package has these, it's not ready:
Audit evidence for financial services AI requires: