Complete your audit · aud_01KS3CZM2CQWN9W2PDK1F1
External evidence questionnaire
4 clausesneed supporting evidence that we can’t extract from code alone. Answer each below; partial saves persist across reloads. Sections completed: 0 / 4.
GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)
Purposes for processing personal data are specified, explicit, and documented for each data flow used by the AI system.*
Expected evidence: Purpose register
Data minimisation is enforced: only fields required for the stated purpose are collected and retained.
Expected evidence: Data minimisation review
Risk review
If any answer above is "No", record how the residual risk is handled.
GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)
A DPIA has been carried out for the AI system's processing of personal data, prior to deployment.*
Expected evidence: DPIA document
The DPIA was reviewed by the DPO and signed off, with mitigations tracked to completion.
Expected evidence: DPO sign-off
Risk review
If any answer above is "No", record how the residual risk is handled.
ISO/IEC 42001:2023 — Artificial Intelligence Management System
An AI policy exists, approved by top management, that defines the organization's commitments around AI development and use.*
Expected evidence: AI policy document
Roles for AI governance reach a named senior decision-maker.
Expected evidence: Senior accountability
Risk review
If any answer above is "No", record how the residual risk is handled.
ISO/IEC 42001:2023 — Artificial Intelligence Management System
RACI or equivalent document assigns AI-system responsibilities across the lifecycle: development, deployment, monitoring, incident response.*
Expected evidence: RACI / accountability matrix
Risk review
If any answer above is "No", record how the residual risk is handled.