CloseIT  /  AI governance · Audit readiness
AI governance · Evidence

When the auditor asks about your AI

An internal auditor, a certification assessor or a supervisor has put AI on the agenda. The question is rarely “do you have a policy”. It is show me. Here is what gets asked for, why it cannot be manufactured the week before, and what a prepared state actually looks like.

Short answer

Audits do not test opinions, they test records. Four things get asked for, in some form, in nearly every regime: a list of the AI systems in scope, a record of what each one does and who owns it, the assessment made before it went live, and evidence that the oversight you describe actually happens. Documents written for the audit are visible as such. Records produced by the work are not.

What auditors actually ask for

The wording varies by auditor and by regime, but the substance converges. Most AI questions in an audit are one of five, and each one is answered by an artifact rather than by a person explaining. The five are not our invention — they are the operational form of what ISO/IEC 42001’s Annex A controls and the EU AI Act’s documentation and record-keeping articles (11, 12, 26) require.

The questionWhat satisfies itWhere it usually lives
Which AI systems do you use?One dated list with an owner per entry — not four spreadsheets that disagreeAn inventory or register
What does this one do?A record per system: purpose, data it uses, vendor feature or built in-house, where it is deployedThe same register
How did you decide it was acceptable to use?The assessment made before go-live — its date, its author, its conclusion, and what it was based onAttached to the system’s entry
Who oversees it, and what do they do?A named role, plus traces: reviews performed, outputs overridden, incidents raisedTicket history, review logs
Does that still hold?A re-check after a material change, or on a stated cadence, with a dateChange history on the entry

Notice what is not on the list: the policy document. A policy is how the audit starts, not how it ends. Once it exists, every sentence in it becomes a testable claim — which is exactly the gap the next question opens.

Three audits, three different questions

“An auditor asked about AI” covers at least three conversations, and it is worth knowing which one you are in before assembling anything:

Why it cannot be produced the week before

Evidence carries dates, and that is the whole problem with a last-minute effort:

Evidence is a by-product, not a deliverable. The organisations that answer audit questions cheaply are not the ones with better documents. They are the ones where introducing an AI system, approving it and reviewing it each leave a dated record behind as a side effect of doing the work.

What “prepared” looks like

A workable definition, with no maturity model attached:

The test is simple. Can someone other than you answer the five questions above from the record alone, without calling a meeting? If the answer needs a meeting, the record is not evidence yet.

Free, no sign-up

Not sure which obligations attach in the first place?

The EU AI Act compliance checklist walks one system through classification and then lists the obligations that attach to it, each with the evidence an assessor usually asks for. It is the single-system version of the question an audit asks across your whole portfolio.

Open the checklist

Five-point first aid

If the question has already landed and the meeting is booked:

  1. Freeze the scope in writing. Which systems, which period, which entities. A good deal of audit panic is caused by answering a broader question than the one that was asked.
  2. Build one list today, with owners. Incomplete and dated beats complete and imagined. Record how the list was built — that method is itself evidence.
  3. Collect what already exists before writing anything new. Ticket histories, change logs, procurement approvals, vendor documentation, security reviews, meeting records. Most organisations hold more evidence than they think, in places nobody files under “governance”.
  4. Name your own gaps, with owners and dates. A known gap with a remediation date is a manageable finding. The same gap discovered by the auditor is a different conversation.
  5. Fix the record-keeping, not just the answer. The next question is coming — from a customer, a different assessor, or the same one next year. If the answer has to be rebuilt each time, the cost repeats each time.
Track this in your Jira

Make the record a by-product of the work

In Model Inventory for Jira, each AI system is a Jira work item: owner, classification, purpose and status on the item, reviews and approvals as linked work, and an immutable change history behind all of it. The judgement stays with your people; what changes is that the decision, the date and the person are recorded when they happen, not reconstructed when someone asks.

See how it works

FAQ

What evidence do auditors ask for about AI?

A list of AI systems with owners; a record per system covering purpose, data and origin; the pre-deployment assessment with its date and author; and traces showing that the oversight described in your policy actually takes place. The artifact matters more than the assurance.

Can we prepare for an AI audit in a week?

Partly. A week is enough to freeze scope, build one dated list and collect evidence that already exists. It is not enough to create a pre-deployment assessment for a system that went live last year, or a review trail that never existed. Naming those gaps yourself is usually the stronger position.

Does ISO/IEC 42001 certification prove EU AI Act compliance?

No. Certification against ISO/IEC 42001 is certification against that management system standard, not against the Act — the Act has no equivalent organisation-level certificate. A 42001 system can nonetheless produce much of the evidence an AI Act question would ask for; describe the two separately rather than as one claim.

This page is a practical explanation, not legal advice. Confirm obligations against the official text of Regulation (EU) 2024/1689, the standards that apply to you, and where the stakes warrant it, qualified counsel.