8RR8← Back to audit

Complete your audit · aud_01KS3CZM2CQWN9W2PDK1F1

External evidence questionnaire

4 clausesneed supporting evidence that we can’t extract from code alone. Answer each below; partial saves persist across reloads. Sections completed: 0 / 4.

GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)

Article 5Principles relating to processing of personal data
Code-side findings are recorded; supplement with the items below.
Waiting
gdpr-5.q1

Purposes for processing personal data are specified, explicit, and documented for each data flow used by the AI system.*

Expected evidence: Purpose register

gdpr-5.q2

Data minimisation is enforced: only fields required for the stated purpose are collected and retained.

Expected evidence: Data minimisation review

Risk review

If any answer above is "No", record how the residual risk is handled.

GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)

Article 35Data protection impact assessment (DPIA)
Code-side findings are recorded; supplement with the items below.
Waiting
gdpr-35.q1

A DPIA has been carried out for the AI system's processing of personal data, prior to deployment.*

Expected evidence: DPIA document

gdpr-35.q2

The DPIA was reviewed by the DPO and signed off, with mitigations tracked to completion.

Expected evidence: DPO sign-off

Risk review

If any answer above is "No", record how the residual risk is handled.

ISO/IEC 42001:2023 — Artificial Intelligence Management System

Article 5.1Leadership and commitment for AI management
Code-side findings are recorded; supplement with the items below.
Waiting
iso-5-1.q1

An AI policy exists, approved by top management, that defines the organization's commitments around AI development and use.*

Expected evidence: AI policy document

iso-5-1.q2

Roles for AI governance reach a named senior decision-maker.

Expected evidence: Senior accountability

Risk review

If any answer above is "No", record how the residual risk is handled.

ISO/IEC 42001:2023 — Artificial Intelligence Management System

Article 5.3Roles, responsibilities and authorities
Code-side findings are recorded; supplement with the items below.
Waiting
iso-5-3.q1

RACI or equivalent document assigns AI-system responsibilities across the lifecycle: development, deployment, monitoring, incident response.*

Expected evidence: RACI / accountability matrix

Risk review

If any answer above is "No", record how the residual risk is handled.