Tier 2: Evidence-grade controls
AI auditability and logging
The ability to reconstruct what an AI system did, when it did it, who approved it, and what data and model version were involved.
Board-defensible evidence
- Logging standard defining required events (inputs, outputs, confidence scores, overrides, model version, feature set, user actions) and retention periods, with alignment to legal holds and regulatory timelines.
- System logs and immutable audit trails showing who accessed the system, who changed configurations, who approved releases, and when governance gates were completed.
- Traceability evidence linking a specific decision to the exact model version, dataset version, and configuration at the time, including unique identifiers and time synchronization controls.
- Audit access procedures showing who can retrieve logs, how requests are approved, how chain-of-custody is preserved, and how log integrity is validated.
- Periodic log review and control testing evidence showing that logging is complete, tamper-resistant, monitored for gaps, and remediated when failures occur.
Why this matters
If you cannot produce an audit trail quickly, your defense collapses into assertions instead of evidence.
How ready is your board on evidence-grade controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.