AI Governance Institute
← Audit & Logging
ALC · Audit & LoggingALC-002High effortAgent-relevant

High-Risk AI Audit Trail

Added May 2026

Keep tamper-evident audit trails for AI in regulated domains. Cover the lifecycle from input through decision to outcome.

Objective

Provide regulators, auditors, and affected individuals with verifiable evidence of how AI-driven decisions were made and on what basis.

Maturity Levels

1

Initial

No audit trail exists for high-risk AI decisions.

2

Developing

Partial audit records exist but are not tamper-evident and do not cover the full decision lifecycle.

3

Defined

A complete audit trail is maintained covering inputs, model selection, outputs, human review steps, and final outcomes.

4

Managed

Audit trail integrity is verified periodically; completeness gaps are tracked and remediated.

5

Optimizing

Audit trail generation is automated and tested; records meet documented regulatory requirements validated by legal.

Evidence Requirements

What an auditor or assessor would expect to see for this control.

  • —Complete audit trail record for a sample of decisions, confirming all required components are present (AI output, input context, human review, outcome)
  • —WORM (write once, read many: records cannot be edited once saved) or equivalent tamper-evident storage (storage that reveals any alteration) configuration evidence with access control documentation
  • —Integrity verification records showing periodic hash checks (automated checks confirming records have not been altered) were run and passed
  • —Quarterly reconstruction exercise records demonstrating sampled decisions can be fully reconstructed from audit records
  • —Regulatory requirement mapping confirming audit trail design satisfies each applicable legal obligation

Implementation Notes

Key steps

  • Scope 'high-risk' using your risk classification (HOC-001), audit trail requirements should be proportionate to system risk tier.
  • Include the human review record alongside the AI output: who reviewed, when, what they saw, and what decision they made.
  • Store audit records separately from day-to-day operational logs with stricter access controls and longer retention periods.
  • Test audit trail completeness before regulatory exams, not during, run a dry-run reconstruction of a sample of past decisions.

Example Implementation

EU-regulated financial firm using AI for automated trading signals reviewed by human traders

High-Risk AI Audit Trail: Trading Signal System

Audit record components (per decision):

  1. AI output record, signal type, asset, confidence, model version, timestamp
  2. Input context record, market data snapshot hash, prompt version, retrieved context references
  3. Human review record, trader ID, review timestamp, decision (execute / modify / reject), rationale code
  4. Outcome record, whether trade was executed, execution details, outcome (appended post-execution)

Tamper-evidence: All records written to WORM (write-once read-many) storage; SHA-256 hash of each record stored in a separate integrity log

Access controls: Read access: Compliance, Legal, Regulators (on request). No write or delete access for any operational role.

Retention: 10 years from decision date (EU AI Act Art. 12; MiFID II record-keeping requirement)

Pre-audit test: Compliance team runs quarterly reconstruction exercise, selects 10 random past decisions and verifies all four record components are present and consistent

Control Details

Control ID
ALC-002
Typical owner
Compliance / AI Governance Team
Implementation effort
High effort
Agent-relevant
Yes

Tags

audit trailtamper-evidentregulatory compliancehigh-risk AI

Templates for this control

Get control updates weekly

New and updated controls, maturity guidance, and the regulatory changes behind them. Every Thursday.

Powered by Buttondown.