AI evidence and audit readiness

Build an AI audit trail that a reviewer can actually check.

Last updated: 2026-09-29

An audit trail is useful when it preserves what happened, who or what performed it, when it happened, and how another reviewer can test the record. It is evidence support, not a shortcut to a certification or a legal conclusion.

Try the Zambo demo · Explore Zambo

Short answer

A responsible AI audit trail combines tamper-evident events, trustworthy timestamps, attribution and provenance, exact committed output, replayable verification, retention rules, and controlled access. AER-1 execution receipts can support evidence for individual tool calls. Workflow receipts can bind ordered step receipts. Neither one by itself satisfies SOC 2, ISO/IEC 27001, or any other audit framework.

What an auditor usually needs to inspect

Immutable history

Use append-only storage, signed records, chained hashes, or another tamper-evident design. Document correction and deletion procedures instead of silently rewriting history.

Time and attribution

Keep a reliable timestamp, actor or service identity, tenant or scope, tool name, and provenance class. Distinguish an execution from a report received from another system.

Exact output commitment

Preserve the exact bytes used for the output hash, the algorithm, schema version, and a stable receipt identifier. A summary alone is not a reproducible record.

Replayable verification

Give a reviewer a documented way to retrieve the record, recompute the digest, inspect the source boundary, and compare the result with the owning system.

Retention

Define retention periods, legal holds, archival format, backup coverage, and disposal rules for the record and its restricted cross-reference.

Access controls

Limit who can read, export, annotate, or administer evidence. Record access events and protect private prompts, credentials, personal data, and confidential payloads.

Where execution receipts fit

An AER-1 execution receipt is a narrow record of one AI agent tool call. It can identify the execution, preserve canonical bytes, record the tool and time, state provenance, and expose an independent verification path. A workflow receipt adds a commitment to the ordered hashes of several step receipts. It helps a reviewer detect a missing, reordered, or changed step.

These records support a specific evidence question: what did the recording system observe and commit for this execution? They do not prove that an outside provider was truthful, that a business outcome occurred, that an authorization was valid, or that a control operated effectively over a period of time.

SOC 2 and ISO/IEC 27001 mapping

SOC 2 and ISO/IEC 27001 are organizational frameworks with control, governance, risk, security, and evidence expectations. The responsible organization and its auditor must map the applicable criteria, scope, period, system boundaries, and control operation. A receipt can be one supporting artifact for a mapped control, but it does not establish that the control is designed, implemented, or effective.

Document the relationship explicitly. Name the control objective, explain what the receipt shows, identify what it does not show, and pair it with access reviews, change records, incident records, policies, system logs, and owner attestations where required. Avoid describing the receipt system as certified unless an authorized assessment actually says so.

Audit checklist

  1. Define the claim and the system boundary before collecting evidence.
  2. Confirm each event has a stable identifier, trusted timestamp, actor, tool, scope, and provenance.
  3. Test tamper evidence by changing bytes, order, identity, and timestamps in a controlled fixture.
  4. Recompute hashes from exact bytes and record the verifier version and result.
  5. Check retention, backup, legal hold, deletion, export, and access-review procedures.
  6. Separate executed, observed, reported, blocked, and confirmed states.
  7. Map the artifact to the responsible organization's control narrative, then obtain auditor review.
  8. Redact sensitive content and preserve restricted evidence under its own access policy.

Limits and recovery

If no receipt exists, preserve the gap. Look for the owning system's logs, request IDs, approval records, or post-action read-back, and label each source by provenance. Do not mint a retrospective execution receipt that implies the original event was recorded. If a receipt verifies but the external state disagrees, report execution integrity and outcome evidence separately.