8RR8← Back to audit

Complete your audit · aud_01KS3DVZXZE8GG6G0XXRHQ

External evidence questionnaire

19 clausesneed supporting evidence that we can’t extract from code alone. Answer each below; partial saves persist across reloads. Sections completed: 0 / 19.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 9Risk management system established, implemented, documented
Code-side findings are recorded; supplement with the items below.
Waiting
art-9.q1

The risk-management process is documented, signed off by an accountable owner, and reviewed at least quarterly.*

Expected evidence: Internal documentation + sign-off record

art-9.q2

Residual risks that cannot be eliminated have been formally accepted by a designated risk owner (DPO, head of engineering, or equivalent).*

Expected evidence: Internal documentation (signed)

art-9.q3

Risk-management outputs are fed back into the development lifecycle (e.g. as design constraints, evaluation criteria, or release-gate checks).

Expected evidence: Cross-reference to issue tracker / CI

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §5.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 10Data and data governance practices documented
Code-side findings are recorded; supplement with the items below.
Waiting
art-10.q1

Training data provenance is documented (sources, licence, collection date, consent basis where applicable).*

Expected evidence: DATA_CARD.md or equivalent provenance record

art-10.q2

A bias / representativeness review has been performed on the training data and gaps are disclosed.*

Expected evidence: Bias-evaluation report or subgroup-performance breakdown

art-10.q3

A data deletion / rectification procedure exists for data subjects whose data is in the training corpus (GDPR alignment).

Expected evidence: SOP or runbook

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §2.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 11Technical documentation drawn up before placing on market
Code-side findings are recorded; supplement with the items below.
Waiting
art-11.q1

The technical-documentation dossier contains all eight Annex IV sections and is signed off by the provider.*

Expected evidence: Annex IV dossier (PDF/DOCX) with signature

art-11.q2

The documentation is kept up-to-date — last review within the past 12 months or after any substantial change.*

Expected evidence: Change log or revision history

Feeds Annex IV §1 §2.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 12(1)Automatic recording of events over the lifetime
Code-side findings are recorded; supplement with the items below.
Waiting
art-12-p1.q1

Logs are retained for the period required by Article 19 (at least 6 months unless EU or national law dictates otherwise).*

Expected evidence: Internal documentation + system export

art-12-p1.q2

A documented incident-response procedure exists for tampering with or loss of the log store, including escalation paths and target restoration times.*

Expected evidence: Internal documentation (SOP / runbook)

art-12-p1.q3

Logs are made available to national competent authorities upon request in a machine-readable format.

Expected evidence: Internal documentation

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §2 §3.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 13Transparent operation and instructions for use
Code-side findings are recorded; supplement with the items below.
Waiting
art-13.q1

Deployer instructions describe intended use, out-of-scope use, input requirements, and known limitations.*

Expected evidence: Deployer instructions document

art-13.q2

Instructions are delivered to deployers through a controlled channel (versioned doc site, customer portal, signed PDF).

Expected evidence: Distribution method

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §1.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 14(1)Effective human oversight designed and built-in
Code-side findings are recorded; supplement with the items below.
Waiting
art-14.q1

Personnel acting as overseers have been trained on the system's limitations, intended use, and escalation procedures.*

Expected evidence: Training records or attendance log

art-14.q2

An escalation procedure is documented covering anomaly types, response targets, and accountable roles.*

Expected evidence: Runbook / SOP

art-14.q3

Oversight effectiveness is reviewed periodically (incidents, override frequency, false positives).

Expected evidence: Review minutes or KPI dashboard

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §3.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 15(1)Appropriate level of accuracy declared and tested
Code-side findings are recorded; supplement with the items below.
Waiting
art-15-p1.q1

Accuracy targets are declared in technical documentation or model card (e.g., per-class precision/recall, calibration error, confidence intervals) with the test conditions and dataset used.*

Expected evidence: Accuracy declaration document

art-15-p1.q2

Accuracy results are reproducible from a versioned eval suite tied to the current model release.

Expected evidence: Eval suite + model version pin

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §4.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 15(4)Resilience to errors, faults, inconsistencies
Code-side findings are recorded; supplement with the items below.
Waiting
art-15-p4.q1

Fail-safe behaviour is implemented and tested: graceful degradation, retries with backoff, or human-handoff when the model is uncertain or unavailable.*

Expected evidence: Fail-safe test results

art-15-p4.q2

Robustness evals run against adversarial inputs, edge cases, and out-of-distribution samples. Results documented per release.

Expected evidence: Robustness eval report

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §3.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 15(5)Cybersecurity measures appropriate to circumstances
Code-side findings are recorded; supplement with the items below.
Waiting
art-15-p5.q1

Threat model documented for the AI system covering at least prompt injection, data poisoning, model extraction, and adversarial inputs relevant to the intended use.*

Expected evidence: Threat model document

art-15-p5.q2

Mitigations implemented for each threat (input validation, rate limiting, prompt firewalling, output filtering, key rotation). Mapped to the threat model.*

Expected evidence: Mitigation mapping

art-15-p5.q3

Independent security review or penetration test completed within the last 12 months.

Expected evidence: Pentest report

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §3.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 26(6)Deployer log-retention capability supported
Code-side findings are recorded; supplement with the items below.
Waiting
art-26-p6.q1

Deployer-facing documentation describes log retention duration, storage location, and access controls for automatically generated logs.*

Expected evidence: Deployer logging guide

art-26-p6.q2

Logs are exportable in a machine-readable format (JSON, NDJSON, or a documented schema) to support deployer retention obligations.

Expected evidence: Log export format

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §3.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 50(1)Users informed they are interacting with an AI
Code-side findings are recorded; supplement with the items below.
Waiting
art-50-p1.q1

End users are informed they are interacting with an AI system at the start of the interaction (visible in UI, spoken in voice agents, written in chatbots).*

Expected evidence: AI-presence disclosure

art-50-p1.q2

Disclosure language is reviewed for clarity by an audience outside the development team.

Expected evidence: Plain-language review

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §1.

NIST AI Risk Management Framework 1.0 (NIST AI 100-1)

Article GOVERN 1.4Risk management process documented and accountable
Code-side findings are recorded; supplement with the items below.
Waiting
govern-1-4.q1

Roles, responsibilities, and accountability lines across the AI lifecycle are documented and reach a named senior decision-maker.*

Expected evidence: RACI / accountability matrix

govern-1-4.q2

Risk-management policies are reviewed at a defined cadence (annual or trigger-based) with sign-off recorded.

Expected evidence: Review cadence record

Risk review

If any answer above is "No", record how the residual risk is handled.

NIST AI Risk Management Framework 1.0 (NIST AI 100-1)

Article MAP 1.1Context of use established and understood
Code-side findings are recorded; supplement with the items below.
Waiting
map-1-1.q1

Intended purposes, beneficial uses, and context of deployment are documented for the AI system. Out-of-scope uses are explicitly enumerated.*

Expected evidence: Context-of-use document

map-1-1.q2

Affected user populations, including vulnerable groups, are identified and documented.

Expected evidence: Affected-populations register

Risk review

If any answer above is "No", record how the residual risk is handled.

NIST AI Risk Management Framework 1.0 (NIST AI 100-1)

Article MANAGE 2.3Mechanisms to supersede or deactivate AI systems
Code-side findings are recorded; supplement with the items below.
Waiting
manage-2-3.q1

A documented mechanism exists to supersede, disengage, or deactivate the AI system in production (kill switch, feature flag, or graceful rollback).*

Expected evidence: Deactivation mechanism documentation

manage-2-3.q2

The deactivation mechanism has been tested under realistic conditions within the last 6 months.

Expected evidence: Deactivation test record

Risk review

If any answer above is "No", record how the residual risk is handled.

GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)

Article 5Principles relating to processing of personal data
Code-side findings are recorded; supplement with the items below.
Waiting
gdpr-5.q1

Purposes for processing personal data are specified, explicit, and documented for each data flow used by the AI system.*

Expected evidence: Purpose register

gdpr-5.q2

Data minimisation is enforced: only fields required for the stated purpose are collected and retained.

Expected evidence: Data minimisation review

Risk review

If any answer above is "No", record how the residual risk is handled.

GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)

Article 22Automated individual decision-making, including profiling
Code-side findings are recorded; supplement with the items below.
Waiting
gdpr-22.q1

Where the AI system makes decisions with legal or similar significant effect on individuals, a documented human-review path exists.*

Expected evidence: Human-review path doc

gdpr-22.q2

Data subjects can appeal or request human intervention on automated decisions affecting them.*

Expected evidence: Appeal mechanism

Risk review

If any answer above is "No", record how the residual risk is handled.

GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)

Article 35Data protection impact assessment (DPIA)
Code-side findings are recorded; supplement with the items below.
Waiting
gdpr-35.q1

A DPIA has been carried out for the AI system's processing of personal data, prior to deployment.*

Expected evidence: DPIA document

gdpr-35.q2

The DPIA was reviewed by the DPO and signed off, with mitigations tracked to completion.

Expected evidence: DPO sign-off

Risk review

If any answer above is "No", record how the residual risk is handled.

ISO/IEC 42001:2023 — Artificial Intelligence Management System

Article 5.1Leadership and commitment for AI management
Code-side findings are recorded; supplement with the items below.
Waiting
iso-5-1.q1

An AI policy exists, approved by top management, that defines the organization's commitments around AI development and use.*

Expected evidence: AI policy document

iso-5-1.q2

Roles for AI governance reach a named senior decision-maker.

Expected evidence: Senior accountability

Risk review

If any answer above is "No", record how the residual risk is handled.

ISO/IEC 42001:2023 — Artificial Intelligence Management System

Article 5.3Roles, responsibilities and authorities
Code-side findings are recorded; supplement with the items below.
Waiting
iso-5-3.q1

RACI or equivalent document assigns AI-system responsibilities across the lifecycle: development, deployment, monitoring, incident response.*

Expected evidence: RACI / accountability matrix

Risk review

If any answer above is "No", record how the residual risk is handled.