Tier 2: Evidence-grade controls
AI transparency and documentation
Complete, consistent documentation that makes AI design choices, limitations, and operational controls reviewable by auditors, regulators, and internal oversight teams.
Board-defensible evidence
- Documentation baseline defining what must exist per system (purpose, intended use, data sources, model type, training approach, testing results, monitoring plan), including who is responsible for maintaining each artifact.
- Version-controlled artifacts such as model cards, system cards, risk assessments, and control mappings, each with dates, approvers, and change summaries that explain what changed and why.
- Traceability evidence connecting documentation to real systems (repository links, ticket IDs, deployment IDs, monitoring dashboards), so documentation can be tied to the exact model version in production.
- Disclosure and communications review records showing that external statements (marketing, investor relations, customer documentation) were reviewed against actual capabilities and limitations.
- Audit readiness pack checklists showing periodic completeness checks, gap remediation, and a defined process for producing documentation quickly during an inquiry.
Why this matters
In regulatory review, the absence of documentation is treated as the absence of control.
How ready is your board on evidence-grade controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.