What are auditors asking for around AI?
Who decided, did the model write unchecked, and which rulebook applies. How to prepare a first evidence pack this quarter without a huge project.
Auditors asking about AI usually want to follow one change: who decided, whether software could write without a person, and which rulebook you claim to follow. They pick a journal, a credit, a customer email, or a model connection, and they walk it from prompt to record.
This is showing up now because models sit on live systems, and existing control texts already care how a number became the number. You do not need every framework on day one. You need artefacts you can produce without asking anyone to remember.
This guide is a first evidence pack you can start this quarter. What is AI governance is the rest of the access picture. RBAC for enterprise AI is who may see the job. Write-back governance is the write checklist.
What are auditors asking for around AI?
Two operational questions arrive first.
Can you show who decided? A named person, on a clock the company trusts, bound to a quote that matches the write. “The team aligned” is not an answer. “The channel approved” is not an answer. “The bot user posted” is not an answer.
Can you show the model did not write unchecked? Write-back means the AI changes a live system. Fail-closed means if nobody approves, nothing happens. A prompt that says “ask first” is not the gate. A weekly sampling of logs is not the gate if the write already landed.
Role-based access control (RBAC) means who is allowed to do what. It explains why that person, and not a guest, was offered the button. Auditors understand roles. They do not understand “the workspace.”
A payload is the exact change: fields, old and new values, target record — or the exact text and recipient for a message.
Then comes the mapping question: which framework applies to us? Not every company is under every text. Pretending otherwise produces a pile of mappings and no artefact.
Collaborative AI for legal and compliance review still needs a signer when the review becomes a filing. Several departments on one job is not a shared identity.
If the decision was “we will not write,” that is still a decision. Store it. A read-only connector with a date and an owner is evidence.
Why is this showing up now?
Models are in the path of records that already had auditors: financial reporting, customer commitments, legal filings, operational tickets.
Sarbanes-Oxley (2002) is still the text many US-listed teams feel first. Internal control over financial reporting does not care that the proposer is a model. If AI can post, the control environment includes that path.
NIST’s AI Risk Management Framework (2023) is organised as govern, map, measure, and manage. Measure, here, is the stored outcome, including the no. Govern is the roles and the owners. The framework will not click the refuse button for you.
ISO/IEC 42001 (2023) adds a management system for AI: policies, roles, risk assessment, documented processes, and evidence that those processes run. Useful if you will be asked for a certificate. Not a substitute for a payload screen.
The EU AI Act (2024/1689) is from 2024. A deployer is the organisation that uses an AI system under its authority, as the Act defines that role. You may also be a provider if you place a system on the market. Map the role with counsel. Human oversight that cannot refuse a write is not oversight.
DORA (2022) is about digital operational resilience for financial entities and their ICT third parties. If you are in that sector, the AI vendor is an ICT provider conversation, not only an innovation conversation.
Customers and boards ask for structure even when a text is voluntary. That is why the questions arrive before a regulator has written your company’s name.
How do you prepare evidence without a huge project?
Do the one-change walk before anyone external does.
Pick a change a model proposed. Follow it from prompt to record. See whether you can produce a named person, a frozen payload, and a stored outcome without anyone’s memory.
Show:
- A connector in read-only mode, and a failed write attempt.
- One object class with a frozen payload and a named signer — or a dated decision that no class is enabled yet.
- The live system’s own validation still firing, if a write ran.
- A success and a rejection.
- A person who was removed and could not sign the next day.
If you cannot show the failed attempt, assume an auditor will treat write as on.
Unchecked also includes send. A customer message is a write to the relationship. If mail can go out because the connector was on for retrieval, that is an unchecked write with no field names to screenshot.
Do not start with a coverage matrix against every clause. Breadth without a sample fails the first request. Depth on one change lets you map the same artefact twice if two texts apply.
Federal Rule of Civil Procedure 37(e) (2015) is about preserving electronically stored information you should have kept. Chat retention sliders are not that programme. Put approvals where a new manager can find them.
What is a reasonable first evidence pack?
One page plus exports:
- Job name, system, connector mode, date, owner.
- Roster: guest, member, admin, signer — or “signer not yet named; write off.”
- One stored refusal (sandbox is fine).
- One stored success if you have enabled a class; otherwise omit.
- Clock and retention note: where the artefact lives, how long, who can export it without a vendor ticket.
- Which texts you claim: SOX ICFR if you file; NIST AI RMF as structure; ISO 42001 if you are on that path; EU AI Act role if in scope; DORA if you are a financial entity.
Your compliance programme should hold that page.
ISO 42001, if you take it seriously, adds an owner for AI, a statement of which systems models may connect to and in which mode, a way to handle incidents and model or prompt changes that alter write behaviour, and records that last longer than a chat default. It does not add object-level tokens. You can be certified and still have an admin token on a model. Ask the auditor of that management system to sample a stored rejection from a live job.
For deployers under the EU AI Act, the operational match is: know you are using AI, use it as intended, monitor, keep required records, and ensure human oversight where the Act requires it. “The vendor is the provider” does not move your ERP posting into their audit file. Your token, your records, your signer. High-risk classification is legal work. This guide will not guess it.
How do you start this quarter?
This month: pick one real job. Run the one-change walk. Write the one-page pack. Fill blanks as findings, not as a reason to delay the page.
Next month: fix the first hole — usually the stored no, the read-only proof, or the named signer.
If you cannot complete the walk, keeping write off is the honest state of the control. Mapping will not replace it.
Write-back governance and RBAC for enterprise AI are the two product habits that make the pack easier to gather later.
One change you can walk
If we are not in the EU, can we ignore the AI Act?
You can ignore it as a legal duty only if you are not in its scope. You should still answer the same operational questions — who decided, and did the model write unchecked — because auditors and customers will ask them in other words.
Does ISO 42001 certification mean our CRM writes are governed?
No. Certification speaks to a management system. It does not replace a named person on a payload, a stored rejection, or a connector that can be read-only. Ask to see those artefacts in your product, not only the certificate.
What is the smallest evidence pack that still helps?
One change a model proposed: named person, frozen payload, stored outcome including a no, plus the connector mode and the roster on that job. Map that pack to whichever texts apply. Do not start with a matrix of empty controls.
Do we need this if AI is still read-only?
A dated decision to stay read-only, with an owner and the connector name, is evidence. You need the full write pack before the first production write class.
See what governed AI looks like on your stack.
Connect your tools, run a workstream, and keep every decision on your ledger - free for 7 days.