Guides
Practical guides on AI governance evidence — written for the teams that have to prove compliance, not just claim it.
What Belongs in an AI Evidence Pack
A reviewer asked you to prove what your AI did. Here are the six parts an evidence pack needs, and the three things that get one rejected.
The AI Questions in a Bank's Vendor-Risk Questionnaire — and What Evidence Answers Them
Banks now ask AI vendors to prove what their models did, not to describe it. The question clusters in a third-party risk review, and what closes each.
DORA for AI Vendors: What Your Financial Customer's Obligation Requires From You
DORA regulates financial entities, not their suppliers — but the obligations reach you through the contract. What an AI vendor is actually asked to provide.
EU AI Act Annex III: What a Record-Keeping Obligation Actually Requires
Credit scoring and insurance pricing are Annex III high-risk. Articles 12 and 14 turn that into two artefacts: a log, and an oversight trail.
Pass, Fail, and the Two States Your AI Compliance Report Is Missing
A control can be met, breached, ambiguous, or impossible to judge from the evidence you hold. Two-state reporting collapses the last two into a pass.
Ready to produce the evidence yourself?
Start free — connect an AI system and export your first audit pack.
Get Started