An internal auditor, a certification assessor or a supervisor has put AI on the agenda. The question is rarely “do you have a policy”. It is show me. Here is what gets asked for, why it cannot be manufactured the week before, and what a prepared state actually looks like.
Audits do not test opinions, they test records. Four things get asked for, in some form, in nearly every regime: a list of the AI systems in scope, a record of what each one does and who owns it, the assessment made before it went live, and evidence that the oversight you describe actually happens. Documents written for the audit are visible as such. Records produced by the work are not.
The wording varies by auditor and by regime, but the substance converges. Most AI questions in an audit are one of five, and each one is answered by an artifact rather than by a person explaining. The five are not our invention — they are the operational form of what ISO/IEC 42001’s Annex A controls and the EU AI Act’s documentation and record-keeping articles (11, 12, 26) require.
| The question | What satisfies it | Where it usually lives |
|---|---|---|
| Which AI systems do you use? | One dated list with an owner per entry — not four spreadsheets that disagree | An inventory or register |
| What does this one do? | A record per system: purpose, data it uses, vendor feature or built in-house, where it is deployed | The same register |
| How did you decide it was acceptable to use? | The assessment made before go-live — its date, its author, its conclusion, and what it was based on | Attached to the system’s entry |
| Who oversees it, and what do they do? | A named role, plus traces: reviews performed, outputs overridden, incidents raised | Ticket history, review logs |
| Does that still hold? | A re-check after a material change, or on a stated cadence, with a date | Change history on the entry |
Notice what is not on the list: the policy document. A policy is how the audit starts, not how it ends. Once it exists, every sentence in it becomes a testable claim — which is exactly the gap the next question opens.
“An auditor asked about AI” covers at least three conversations, and it is worth knowing which one you are in before assembling anything:
Evidence carries dates, and that is the whole problem with a last-minute effort:
Evidence is a by-product, not a deliverable. The organisations that answer audit questions cheaply are not the ones with better documents. They are the ones where introducing an AI system, approving it and reviewing it each leave a dated record behind as a side effect of doing the work.
A workable definition, with no maturity model attached:
The test is simple. Can someone other than you answer the five questions above from the record alone, without calling a meeting? If the answer needs a meeting, the record is not evidence yet.
The EU AI Act compliance checklist walks one system through classification and then lists the obligations that attach to it, each with the evidence an assessor usually asks for. It is the single-system version of the question an audit asks across your whole portfolio.
Open the checklistIf the question has already landed and the meeting is booked:
In Model Inventory for Jira, each AI system is a Jira work item: owner, classification, purpose and status on the item, reviews and approvals as linked work, and an immutable change history behind all of it. The judgement stays with your people; what changes is that the decision, the date and the person are recorded when they happen, not reconstructed when someone asks.
See how it worksA list of AI systems with owners; a record per system covering purpose, data and origin; the pre-deployment assessment with its date and author; and traces showing that the oversight described in your policy actually takes place. The artifact matters more than the assurance.
Partly. A week is enough to freeze scope, build one dated list and collect evidence that already exists. It is not enough to create a pre-deployment assessment for a system that went live last year, or a review trail that never existed. Naming those gaps yourself is usually the stronger position.
No. Certification against ISO/IEC 42001 is certification against that management system standard, not against the Act — the Act has no equivalent organisation-level certificate. A 42001 system can nonetheless produce much of the evidence an AI Act question would ask for; describe the two separately rather than as one claim.
This page is a practical explanation, not legal advice. Confirm obligations against the official text of Regulation (EU) 2024/1689, the standards that apply to you, and where the stakes warrant it, qualified counsel.