Compliance evidence

Compliance evidence

Compliance evidence is the documented body of proof that a company actually complies with certain rules. For AI systems, this includes, for example, documentation on the training data used, on tests conducted, and on human oversight.

Many rules apply to companies: laws, contracts, and their own internal regulations. But it is not enough to simply comply with them. One must also be able to prove that one has complied with them. This proof is precisely what is meant by compliance evidence. “Compliance” refers to adherence to rules, that is, meeting requirements. The evidence usually consists of documents, logs, and audit reports that an uninvolved person can follow and verify.

Why authorities want to see paper

An authority cannot look inside a company. It only sees what is presented to it. Without documentation, any oversight would remain a matter of trust. That is why laws almost always require not just certain behavior, but also its documentation.

This is especially sensitive with AI systems. A program that sorts job applications or evaluates loans makes decisions about people. The European AI regulation, often called the AI Act, classifies such applications as particularly high-risk. Providers must then record what data the system was developed with, what tests it underwent, and how humans supervise it.

For investors and journalists, this is therefore not a minor detail. Missing evidence can trigger fines, and in extreme cases even a ban on selling a product. Major customers such as banks or hospitals demand the documentation anyway before signing a contract. Anyone who cannot provide it loses business, regardless of the technology involved.

What the evidence consists of

At the outset there is a list of applicable requirements. Each item on it needs an associated piece of evidence. This can be technical documentation, a test report, a training list, or a screenshot of a setting. Experts call this mapping a control matrix.

A large part is generated automatically during operation. Software writes log files, that is, continuous records of who did what and when. With AI systems, records of individual queries and responses are added. It is important that such logs cannot be altered afterward without being noticed.

A comparison helps: the evidence works like an airline’s logbook and maintenance records. No one believes an airline has inspected its engines just because it says so. What counts is the signed entry with a date. Often, an external body ultimately reviews the collection and issues a certificate. A certificate, in this context, is the result; the evidence is the underlying material.

Compliance evidence in news and products

In the quarterly reports of large technology corporations, the costs of regulatory compliance appear as a separate line item. Reports about delayed product launches in Europe often relate to this. A language model appears in the US earlier because the necessary documentation for the European market is still missing.

Even without a corporate balance sheet, one encounters this principle. Anyone choosing cloud software for a school or club will find sections on manufacturer websites labeled things like ISO 27001 or GDPR compliance. Behind these labels are exactly such collections of evidence. An entire industry has emerged around this need, selling tools for automated evidence collection.

A common misconception: evidence says nothing about whether a system is good or fair. It only proves that specified rules were checked and documented. A cleanly documented system can still make bad decisions. However, the evidence makes such errors traceable after the fact, and that is its actual purpose.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.