What we solve ·What do I say when they ask?
Taskforce · Sustain
Can you prove in writing what a machine generates and decides in your organization?
They are asking me to declare what a machine decides and nobody has the list.
The inventory of where you generate and decide with AI, the determination of which obligation falls on each point and the file that proves it.
AI regulatory evidence fileSend this page to whoever decides
Use this today, without hiring anyone
Two exercises that get done in an afternoon and give you half the diagnosis. The first tells you whether you can prove it; the second, how exposed you are.
The provenance test. Take a piece your organization published, or a decision it made, last week and try to answer four things.
- Which system produced it and in what version.
- What went in, with what instruction and from whom.
- Who reviewed it before it went out and what they changed.
- Where all of that got recorded and for how long.
Time it. That number is your reconstruction time and it is what will be measured on you.
The four classification questions. Run them over the three systems that worry you most.
- Who does it decide about, and does it affect their access to a job, credit, an essential service or a right?
- What happens if it gets it wrong, and can the affected person notice and challenge it?
- How much autonomy does it have in practice, not in the manual?
- In what context is it used today, not what it was bought for?
Two warnings from experience. The generation nobody recorded is in customer service, communications, internal reports that go out to third parties and the code someone pasted from an assistant. And the systems that show up late are not the big ones: they are the spreadsheets with a model behind them and the tools one area contracted on its own.
This sounds like you if
- The obligation arrived drafted for the group and has to be translated into the local operation.
- You suspect there are areas using AI without recording it.
- Reconstructing how a piece from months ago was produced is not possible with what gets logged today.
How we solve it
The method, not the promise.
- Where generation happens and where decisions happen gets inventoried, by real context of use, starting with the places that are never recorded.
- What falls inside and outside each obligation gets determined, and every exclusion gets written with its argument. That argument is what gets defended later.
- What gets logged at the source gets designed, which is the only thing that makes reconstruction possible months later.
- The file gets assembled in the format a reviewer asks for, not the one that suits the team.
- It gets tested: a real piece gets reconstructed, or a specific classification gets defended. If it does not hold, the file does not work yet.
What you receive
- The inventory of generation and decision points, with their real context of use.
- The written argument for why each point falls inside or outside the obligation.
- The disclosure and provenance logging specification, or the obligations matrix by system.
- The evidence file, tested against a real case of yours.
The proof that applies here
- Eight years of operation under regulatory supervision with zero audit findings.
- Reconstruction of decisions in front of audit over an infrastructure of 60,000 servers, with the logging that supported it.
- The legal day one of a banking separation, met on the contractual date and with zero failures.
Before you hire
The scope determination is informed judgment, not a legal opinion: every decision comes with its argument so your lawyer can review it before it gets published.
Evidence that holds up in front of a reviewer gets prepared by someone who has already been on the side that answers to a supervisor. Here that is eight years without a finding.
Take a piece your organization published last month. How long would it take you to prove how it was produced?
If the problem is a different one
The regulator asks why that case was rejected and nobody can reconstruct it.
Automated decision governance
The integrator says it works and I am the one who signs.
Independent implementation review
They no longer ask whether we have controls. They ask whether I can prove it holds.
Operational resilience readiness
