8RR8← Back to audit

Complete your audit · aud_01KS3E6JAH8WNVWPSZ36C1

External evidence questionnaire

20 clausesneed supporting evidence that we can’t extract from code alone. Answer each below; partial saves persist across reloads. Sections completed: 0 / 20.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 9Risk management system established, implemented, documented
Code-side findings are recorded; supplement with the items below.
Waiting
art-9.q1

The risk-management process is documented, signed off by an accountable owner, and reviewed at least quarterly.*

Expected evidence: Internal documentation + sign-off record

art-9.q2

Residual risks that cannot be eliminated have been formally accepted by a designated risk owner (DPO, head of engineering, or equivalent).*

Expected evidence: Internal documentation (signed)

art-9.q3

Risk-management outputs are fed back into the development lifecycle (e.g. as design constraints, evaluation criteria, or release-gate checks).

Expected evidence: Cross-reference to issue tracker / CI

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §5.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 10Data and data governance practices documented
Code-side findings are recorded; supplement with the items below.
Waiting
art-10.q1

Training data provenance is documented (sources, licence, collection date, consent basis where applicable).*

Expected evidence: DATA_CARD.md or equivalent provenance record

art-10.q2

A bias / representativeness review has been performed on the training data and gaps are disclosed.*

Expected evidence: Bias-evaluation report or subgroup-performance breakdown

art-10.q3

A data deletion / rectification procedure exists for data subjects whose data is in the training corpus (GDPR alignment).

Expected evidence: SOP or runbook

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §2.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 11Technical documentation drawn up before placing on market
Code-side findings are recorded; supplement with the items below.
Waiting
art-11.q1

The technical-documentation dossier contains all eight Annex IV sections and is signed off by the provider.*

Expected evidence: Annex IV dossier (PDF/DOCX) with signature

art-11.q2

The documentation is kept up-to-date — last review within the past 12 months or after any substantial change.*

Expected evidence: Change log or revision history

Feeds Annex IV §1 §2.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 12(1)Automatic recording of events over the lifetime
Code-side findings are recorded; supplement with the items below.
Waiting
art-12-p1.q1

Logs are retained for the period required by Article 19 (at least 6 months unless EU or national law dictates otherwise).*

Expected evidence: Internal documentation + system export

art-12-p1.q2

A documented incident-response procedure exists for tampering with or loss of the log store, including escalation paths and target restoration times.*

Expected evidence: Internal documentation (SOP / runbook)

art-12-p1.q3

Logs are made available to national competent authorities upon request in a machine-readable format.

Expected evidence: Internal documentation

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §2 §3.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 13Transparent operation and instructions for use
Code-side findings are recorded; supplement with the items below.
Waiting
art-13.q1

Deployer instructions describe intended use, out-of-scope use, input requirements, and known limitations.*

Expected evidence: Deployer instructions document

art-13.q2

Instructions are delivered to deployers through a controlled channel (versioned doc site, customer portal, signed PDF).

Expected evidence: Distribution method

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §1.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 14(1)Effective human oversight designed and built-in
Code-side findings are recorded; supplement with the items below.
Waiting
art-14.q1

Personnel acting as overseers have been trained on the system's limitations, intended use, and escalation procedures.*

Expected evidence: Training records or attendance log

art-14.q2

An escalation procedure is documented covering anomaly types, response targets, and accountable roles.*

Expected evidence: Runbook / SOP

art-14.q3

Oversight effectiveness is reviewed periodically (incidents, override frequency, false positives).

Expected evidence: Review minutes or KPI dashboard

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §3.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 15(1)Appropriate level of accuracy declared and tested
Code-side findings are recorded; supplement with the items below.
Waiting
art-15-p1.q1

Accuracy targets are declared in technical documentation or model card (e.g., per-class precision/recall, calibration error, confidence intervals) with the test conditions and dataset used.*

Expected evidence: Accuracy declaration document

art-15-p1.q2

Accuracy results are reproducible from a versioned eval suite tied to the current model release.

Expected evidence: Eval suite + model version pin

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §4.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 15(4)Resilience to errors, faults, inconsistencies
Code-side findings are recorded; supplement with the items below.
Waiting
art-15-p4.q1

Fail-safe behaviour is implemented and tested: graceful degradation, retries with backoff, or human-handoff when the model is uncertain or unavailable.*

Expected evidence: Fail-safe test results

art-15-p4.q2

Robustness evals run against adversarial inputs, edge cases, and out-of-distribution samples. Results documented per release.

Expected evidence: Robustness eval report

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §3.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 15(5)Cybersecurity measures appropriate to circumstances
Code-side findings are recorded; supplement with the items below.
Waiting
art-15-p5.q1

Threat model documented for the AI system covering at least prompt injection, data poisoning, model extraction, and adversarial inputs relevant to the intended use.*

Expected evidence: Threat model document

art-15-p5.q2

Mitigations implemented for each threat (input validation, rate limiting, prompt firewalling, output filtering, key rotation). Mapped to the threat model.*

Expected evidence: Mitigation mapping

art-15-p5.q3

Independent security review or penetration test completed within the last 12 months.

Expected evidence: Pentest report

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §3.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 26(6)Deployer log-retention capability supported
Code-side findings are recorded; supplement with the items below.
Waiting
art-26-p6.q1

Deployer-facing documentation describes log retention duration, storage location, and access controls for automatically generated logs.*

Expected evidence: Deployer logging guide

art-26-p6.q2

Logs are exportable in a machine-readable format (JSON, NDJSON, or a documented schema) to support deployer retention obligations.

Expected evidence: Log export format

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §3.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 50(1)Users informed they are interacting with an AI
Code-side findings are recorded; supplement with the items below.
Waiting
art-50-p1.q1

End users are informed they are interacting with an AI system at the start of the interaction (visible in UI, spoken in voice agents, written in chatbots).*

Expected evidence: AI-presence disclosure

art-50-p1.q2

Disclosure language is reviewed for clarity by an audience outside the development team.

Expected evidence: Plain-language review

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §1.

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Article 50(3)Emotion recognition / biometric categorisation disclosure
Code-side findings are recorded; supplement with the items below.
Waiting
art-50-p3.q1

Subjects are informed when an emotion recognition or biometric categorisation system is in use, before processing begins.*

Expected evidence: Subject disclosure mechanism

art-50-p3.q2

Legal basis (consent, vital interest, etc.) for the processing is documented per GDPR Article 6 and Article 9 where applicable.*

Expected evidence: GDPR legal basis record

Risk review

If any answer above is "No", record how the residual risk is handled.

Feeds Annex IV §1.

NIST AI Risk Management Framework 1.0 (NIST AI 100-1)

Article GOVERN 1.4Risk management process documented and accountable
Code-side findings are recorded; supplement with the items below.
Waiting
govern-1-4.q1

Roles, responsibilities, and accountability lines across the AI lifecycle are documented and reach a named senior decision-maker.*

Expected evidence: RACI / accountability matrix

govern-1-4.q2

Risk-management policies are reviewed at a defined cadence (annual or trigger-based) with sign-off recorded.

Expected evidence: Review cadence record

Risk review

If any answer above is "No", record how the residual risk is handled.

NIST AI Risk Management Framework 1.0 (NIST AI 100-1)

Article MAP 1.1Context of use established and understood
Code-side findings are recorded; supplement with the items below.
Waiting
map-1-1.q1

Intended purposes, beneficial uses, and context of deployment are documented for the AI system. Out-of-scope uses are explicitly enumerated.*

Expected evidence: Context-of-use document

map-1-1.q2

Affected user populations, including vulnerable groups, are identified and documented.

Expected evidence: Affected-populations register

Risk review

If any answer above is "No", record how the residual risk is handled.

NIST AI Risk Management Framework 1.0 (NIST AI 100-1)

Article MANAGE 2.3Mechanisms to supersede or deactivate AI systems
Code-side findings are recorded; supplement with the items below.
Waiting
manage-2-3.q1

A documented mechanism exists to supersede, disengage, or deactivate the AI system in production (kill switch, feature flag, or graceful rollback).*

Expected evidence: Deactivation mechanism documentation

manage-2-3.q2

The deactivation mechanism has been tested under realistic conditions within the last 6 months.

Expected evidence: Deactivation test record

Risk review

If any answer above is "No", record how the residual risk is handled.

GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)

Article 5Principles relating to processing of personal data
Code-side findings are recorded; supplement with the items below.
Waiting
gdpr-5.q1

Purposes for processing personal data are specified, explicit, and documented for each data flow used by the AI system.*

Expected evidence: Purpose register

gdpr-5.q2

Data minimisation is enforced: only fields required for the stated purpose are collected and retained.

Expected evidence: Data minimisation review

Risk review

If any answer above is "No", record how the residual risk is handled.

GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)

Article 22Automated individual decision-making, including profiling
Code-side findings are recorded; supplement with the items below.
Waiting
gdpr-22.q1

Where the AI system makes decisions with legal or similar significant effect on individuals, a documented human-review path exists.*

Expected evidence: Human-review path doc

gdpr-22.q2

Data subjects can appeal or request human intervention on automated decisions affecting them.*

Expected evidence: Appeal mechanism

Risk review

If any answer above is "No", record how the residual risk is handled.

GDPR — Regulation (EU) 2016/679 (General Data Protection Regulation)

Article 35Data protection impact assessment (DPIA)
Code-side findings are recorded; supplement with the items below.
Waiting
gdpr-35.q1

A DPIA has been carried out for the AI system's processing of personal data, prior to deployment.*

Expected evidence: DPIA document

gdpr-35.q2

The DPIA was reviewed by the DPO and signed off, with mitigations tracked to completion.

Expected evidence: DPO sign-off

Risk review

If any answer above is "No", record how the residual risk is handled.

ISO/IEC 42001:2023 — Artificial Intelligence Management System

Article 5.1Leadership and commitment for AI management
Code-side findings are recorded; supplement with the items below.
Waiting
iso-5-1.q1

An AI policy exists, approved by top management, that defines the organization's commitments around AI development and use.*

Expected evidence: AI policy document

iso-5-1.q2

Roles for AI governance reach a named senior decision-maker.

Expected evidence: Senior accountability

Risk review

If any answer above is "No", record how the residual risk is handled.

ISO/IEC 42001:2023 — Artificial Intelligence Management System

Article 5.3Roles, responsibilities and authorities
Code-side findings are recorded; supplement with the items below.
Waiting
iso-5-3.q1

RACI or equivalent document assigns AI-system responsibilities across the lifecycle: development, deployment, monitoring, incident response.*

Expected evidence: RACI / accountability matrix

Risk review

If any answer above is "No", record how the residual risk is handled.