Complete your audit · aud_01KS3E6JAH8WNVWPSZ36C1
External evidence questionnaire
20 clausesneed supporting evidence that we can’t extract from code alone. Answer each below; partial saves persist across reloads. Sections completed: 0 / 20.
Regulation (EU) 2024/1689 — Artificial Intelligence Act
The risk-management process is documented, signed off by an accountable owner, and reviewed at least quarterly.*
Expected evidence: Internal documentation + sign-off record
Residual risks that cannot be eliminated have been formally accepted by a designated risk owner (DPO, head of engineering, or equivalent).*
Expected evidence: Internal documentation (signed)
Risk-management outputs are fed back into the development lifecycle (e.g. as design constraints, evaluation criteria, or release-gate checks).
Expected evidence: Cross-reference to issue tracker / CI
Risk review
If any answer above is "No", record how the residual risk is handled.
Feeds Annex IV §5.
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Training data provenance is documented (sources, licence, collection date, consent basis where applicable).*
Expected evidence: DATA_CARD.md or equivalent provenance record
A bias / representativeness review has been performed on the training data and gaps are disclosed.*
Expected evidence: Bias-evaluation report or subgroup-performance breakdown
A data deletion / rectification procedure exists for data subjects whose data is in the training corpus (GDPR alignment).
Expected evidence: SOP or runbook
Risk review
If any answer above is "No", record how the residual risk is handled.
Feeds Annex IV §2.
Regulation (EU) 2024/1689 — Artificial Intelligence Act
The technical-documentation dossier contains all eight Annex IV sections and is signed off by the provider.*
Expected evidence: Annex IV dossier (PDF/DOCX) with signature
The documentation is kept up-to-date — last review within the past 12 months or after any substantial change.*
Expected evidence: Change log or revision history
Feeds Annex IV §1 §2.
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Logs are retained for the period required by Article 19 (at least 6 months unless EU or national law dictates otherwise).*
Expected evidence: Internal documentation + system export
A documented incident-response procedure exists for tampering with or loss of the log store, including escalation paths and target restoration times.*
Expected evidence: Internal documentation (SOP / runbook)
Logs are made available to national competent authorities upon request in a machine-readable format.
Expected evidence: Internal documentation
Risk review
If any answer above is "No", record how the residual risk is handled.
Feeds Annex IV §2 §3.
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Deployer instructions describe intended use, out-of-scope use, input requirements, and known limitations.*
Expected evidence: Deployer instructions document
Instructions are delivered to deployers through a controlled channel (versioned doc site, customer portal, signed PDF).
Expected evidence: Distribution method
Risk review
If any answer above is "No", record how the residual risk is handled.
Feeds Annex IV §1.
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Personnel acting as overseers have been trained on the system's limitations, intended use, and escalation procedures.*
Expected evidence: Training records or attendance log
An escalation procedure is documented covering anomaly types, response targets, and accountable roles.*
Expected evidence: Runbook / SOP
Oversight effectiveness is reviewed periodically (incidents, override frequency, false positives).
Expected evidence: Review minutes or KPI dashboard
Risk review
If any answer above is "No", record how the residual risk is handled.
Feeds Annex IV §3.
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Accuracy targets are declared in technical documentation or model card (e.g., per-class precision/recall, calibration error, confidence intervals) with the test conditions and dataset used.*
Expected evidence: Accuracy declaration document
Accuracy results are reproducible from a versioned eval suite tied to the current model release.
Expected evidence: Eval suite + model version pin
Risk review
If any answer above is "No", record how the residual risk is handled.
Feeds Annex IV §4.
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Fail-safe behaviour is implemented and tested: graceful degradation, retries with backoff, or human-handoff when the model is uncertain or unavailable.*
Expected evidence: Fail-safe test results
Robustness evals run against adversarial inputs, edge cases, and out-of-distribution samples. Results documented per release.
Expected evidence: Robustness eval report
Risk review
If any answer above is "No", record how the residual risk is handled.
Feeds Annex IV §3.
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Threat model documented for the AI system covering at least prompt injection, data poisoning, model extraction, and adversarial inputs relevant to the intended use.*
Expected evidence: Threat model document
Mitigations implemented for each threat (input validation, rate limiting, prompt firewalling, output filtering, key rotation). Mapped to the threat model.*
Expected evidence: Mitigation mapping
Independent security review or penetration test completed within the last 12 months.
Expected evidence: Pentest report
Risk review
If any answer above is "No", record how the residual risk is handled.
Feeds Annex IV §3.
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Deployer-facing documentation describes log retention duration, storage location, and access controls for automatically generated logs.*
Expected evidence: Deployer logging guide
Logs are exportable in a machine-readable format (JSON, NDJSON, or a documented schema) to support deployer retention obligations.
Expected evidence: Log export format
Risk review
If any answer above is "No", record how the residual risk is handled.
Feeds Annex IV §3.
Regulation (EU) 2024/1689 — Artificial Intelligence Act
End users are informed they are interacting with an AI system at the start of the interaction (visible in UI, spoken in voice agents, written in chatbots).*
Expected evidence: AI-presence disclosure
Disclosure language is reviewed for clarity by an audience outside the development team.
Expected evidence: Plain-language review
Risk review
If any answer above is "No", record how the residual risk is handled.
Feeds Annex IV §1.
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Subjects are informed when an emotion recognition or biometric categorisation system is in use, before processing begins.*
Expected evidence: Subject disclosure mechanism
Legal basis (consent, vital interest, etc.) for the processing is documented per GDPR Article 6 and Article 9 where applicable.*
Expected evidence: GDPR legal basis record
Risk review
If any answer above is "No", record how the residual risk is handled.
Feeds Annex IV §1.
NIST AI Risk Management Framework 1.0 (NIST AI 100-1)
Roles, responsibilities, and accountability lines across the AI lifecycle are documented and reach a named senior decision-maker.*
Expected evidence: RACI / accountability matrix
Risk-management policies are reviewed at a defined cadence (annual or trigger-based) with sign-off recorded.
Expected evidence: Review cadence record
Risk review
If any answer above is "No", record how the residual risk is handled.
NIST AI Risk Management Framework 1.0 (NIST AI 100-1)
Intended purposes, beneficial uses, and context of deployment are documented for the AI system. Out-of-scope uses are explicitly enumerated.*
Expected evidence: Context-of-use document
Affected user populations, including vulnerable groups, are identified and documented.
Expected evidence: Affected-populations register
Risk review
If any answer above is "No", record how the residual risk is handled.
NIST AI Risk Management Framework 1.0 (NIST AI 100-1)
A documented mechanism exists to supersede, disengage, or deactivate the AI system in production (kill switch, feature flag, or graceful rollback).*
Expected evidence: Deactivation mechanism documentation
The deactivation mechanism has been tested under realistic conditions within the last 6 months.
Expected evidence: Deactivation test record
Risk review
If any answer above is "No", record how the residual risk is handled.
GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)
Purposes for processing personal data are specified, explicit, and documented for each data flow used by the AI system.*
Expected evidence: Purpose register
Data minimisation is enforced: only fields required for the stated purpose are collected and retained.
Expected evidence: Data minimisation review
Risk review
If any answer above is "No", record how the residual risk is handled.
GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)
Where the AI system makes decisions with legal or similar significant effect on individuals, a documented human-review path exists.*
Expected evidence: Human-review path doc
Data subjects can appeal or request human intervention on automated decisions affecting them.*
Expected evidence: Appeal mechanism
Risk review
If any answer above is "No", record how the residual risk is handled.
GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)
A DPIA has been carried out for the AI system's processing of personal data, prior to deployment.*
Expected evidence: DPIA document
The DPIA was reviewed by the DPO and signed off, with mitigations tracked to completion.
Expected evidence: DPO sign-off
Risk review
If any answer above is "No", record how the residual risk is handled.
ISO/IEC 42001:2023 — Artificial Intelligence Management System
An AI policy exists, approved by top management, that defines the organization's commitments around AI development and use.*
Expected evidence: AI policy document
Roles for AI governance reach a named senior decision-maker.
Expected evidence: Senior accountability
Risk review
If any answer above is "No", record how the residual risk is handled.
ISO/IEC 42001:2023 — Artificial Intelligence Management System
RACI or equivalent document assigns AI-system responsibilities across the lifecycle: development, deployment, monitoring, incident response.*
Expected evidence: RACI / accountability matrix
Risk review
If any answer above is "No", record how the residual risk is handled.