Skip to content

Evidence request lists

ASEAN Guide on AI Governance and Ethics

Evidence request list. 37 controls, 37 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Guiding Principles

AIGE-P1
Transparency and Explainability

Provide disclosure on when an AI system is used and the involvement of AI, and communicate the reasoning behind AI decisions in an understandable way.

Artefacts an auditor will ask for
  • Policy requiring disclosure of AI use
  • Explainability approach/documentation for model decisions
  • User-facing notices of AI involvement
Where this commonly fails
  • AI use not disclosed to affected users
  • No explainability method for high-impact decisions
  • Disclosure inconsistent across products
AIGE-P2
Fairness and Equity

Ensure AI systems do not produce unjust bias or discriminatory outcomes and that similar individuals are treated similarly across the AI lifecycle.

Artefacts an auditor will ask for
  • Fairness/bias assessment results
  • Definition of fairness metrics for the use case
  • Remediation records for identified bias
Where this commonly fails
  • Fairness not defined or measured
  • Bias testing absent
  • No remediation when bias found
AIGE-P3
Security and Safety

Ensure the safety of developers, deployers and users by conducting impact and risk assessments, applying technical security measures, and minimising harm.

Artefacts an auditor will ask for
  • Safety/security risk assessments
  • Security testing (e.g. vulnerability assessment) records
  • Fail-safe / harm-minimisation measures
Where this commonly fails
  • No security testing of AI systems
  • Safety risks unassessed before deployment
  • No fallback when the AI fails
AIGE-P4
Human-centricity

Design, develop and deploy AI to benefit humans and respect human values throughout the AI system lifecycle, prioritising human well-being and safety.

Artefacts an auditor will ask for
  • Evidence human well-being is a design objective
  • User testing with varied/representative groups
  • Decision to withhold or modify AI where not beneficial
Where this commonly fails
  • Human impact not considered in design
  • No mechanism to halt harmful AI
  • Vulnerable users not considered
AIGE-P5
Privacy and Data Governance

Respect and uphold data privacy and protection during design, development and deployment, including privacy-by-design and adherence to applicable data protection laws.

Artefacts an auditor will ask for
  • Data protection/governance framework for AI
  • Privacy-by-design evidence
  • Compliance with applicable data protection law (e.g. PDPA)
Where this commonly fails
  • Privacy not embedded in design
  • No lawful basis for training data
  • Data protection obligations unmet
AIGE-P6
Accountability and Integrity

Establish clear accountability for AI outcomes with appropriate oversight, integrity of data and systems, and mechanisms to take responsibility for decisions.

Artefacts an auditor will ask for
  • Accountability framework assigning responsibility for AI decisions
  • Oversight and audit records
  • Integrity controls over data and models
Where this commonly fails
  • No one accountable for AI outcomes
  • Oversight informal or absent
  • Integrity of data/models unverified
AIGE-P7
Robustness and Reliability

Ensure AI systems function reliably and as intended, including in unexpected conditions, with access control and protection of critical or sensitive systems.

Artefacts an auditor will ask for
  • Robustness/reliability testing
  • Access control over critical AI systems
  • Performance monitoring evidence
Where this commonly fails
  • Robustness untested against edge cases
  • No protection of critical AI systems
  • Reliability not monitored in production

Human Involvement in AI-Augmented Decision-Making

AIGE-HI-1
Establish AI objectives and assess against principles and risks

During design, establish the intended commercial objectives of the AI system, ensure compatibility with the guiding principles, and weigh objectives against the risks of using AI, guided by corporate values.

Artefacts an auditor will ask for
  • Documented AI objectives per system
  • Assessment of objectives against principles and risks
  • Documented rationale for deviations from corporate values
Where this commonly fails
  • Objectives undefined
  • No assessment against the guiding principles
  • Deviations from values undocumented
AIGE-HI-2
Assess probability and severity of harm

Evaluate AI solutions along the probability and severity of harm to users and individuals, considering nature, reversibility and durability of harm and impact on vulnerable groups.

Artefacts an auditor will ask for
  • Risk matrix scoring probability and severity of harm
  • Factors considered (nature/reversibility/vulnerable groups)
  • Risk tier assigned per AI system
Where this commonly fails
  • Harm not assessed on probability and severity
  • Vulnerable populations not considered
  • Reversibility/durability of harm ignored
AIGE-HI-3
Determine the level of human involvement

Based on the risk assessment, determine the category of human involvement, human-in-the-loop, human-over-the-loop, or human-out-of-the-loop, commensurate with the assessed risk.

Artefacts an auditor will ask for
  • Documented human-involvement category per AI system
  • Mapping of risk tier to oversight level
  • Evidence the chosen oversight is operating
Where this commonly fails
  • Oversight level not tied to risk
  • High-risk AI run autonomously
  • Human involvement only nominal
AIGE-HI-4
Document risk impact assessments

Keep proper documentation of AI risk impact assessments (per the Annex A template) for audit purposes, and continually review and update them as systems and risks change.

Artefacts an auditor will ask for
  • Completed AI risk impact assessments (Annex A style)
  • Audit trail of assessments
  • Update records as systems/risks change
Where this commonly fails
  • Risk assessments undocumented
  • Assessments not updated as models iterate
  • No audit trail for challenges
AIGE-HI-5
Mitigate automation bias and protect affected groups

Guard against automation bias (rubber-stamping) where humans defer to AI outputs, and give special consideration to impacts on vulnerable or marginalised populations.

Artefacts an auditor will ask for
  • Controls/checks to counter automation bias
  • Evidence humans meaningfully assess AI outputs
  • Special consideration of vulnerable groups
Where this commonly fails
  • Humans approve AI outputs without scrutiny
  • No measure of override/disagreement rates
  • Vulnerable groups not specifically protected

Internal Governance Structures and Measures

AIGE-IG-1
Establish internal AI governance structures and oversight body

Put in place internal governance structures (e.g. an AI Ethics Board or Committee, multi-disciplinary) for oversight of how AI is designed, developed and deployed, with escalation of higher-risk use cases.

Artefacts an auditor will ask for
  • Terms of reference for an AI oversight body
  • Escalation procedure for higher-risk AI
  • Records of governance body decisions
Where this commonly fails
  • No oversight body or designated function
  • No escalation path for high-risk AI
  • Governance structure not suited to org culture/size
AIGE-IG-2
Define roles and responsibilities for AI oversight

Establish clear roles, terms of reference and responsibilities for personnel involved in responsible design, development and deployment of AI, including risk assessment and documentation duties.

Artefacts an auditor will ask for
  • RACI / role definitions for AI governance
  • Terms of reference for oversight roles
  • Evidence responsibilities are exercised
Where this commonly fails
  • Roles undefined or unassigned
  • Oversight composition not representative of functions
  • Responsibilities documented but not performed
AIGE-IG-3
AI ethics policies, standards and code of conduct

Develop AI governance policies, standards and a code of conduct for the ethical use of data and AI, with oversight mechanisms to ensure they are followed.

Artefacts an auditor will ask for
  • AI ethics policy / code of conduct
  • AI design principles and standards
  • Oversight/compliance monitoring of policy
Where this commonly fails
  • No AI-specific policy or code of conduct
  • Policies not enforced
  • AI design principles undocumented
AIGE-IG-4
Training, awareness and capability building

Provide guidance and training to personnel in the governance process and raise organisation-wide awareness of AI ethics, risks, benefits and limitations.

Artefacts an auditor will ask for
  • AI ethics/governance training records
  • Awareness materials and reach
  • Capability-building / certification of key personnel
Where this commonly fails
  • No AI ethics training
  • Awareness limited to a small team
  • Personnel cannot interpret AI outputs or detect harm
AIGE-IG-5
Periodic review of the governance model

Periodically review and assess the sufficiency and effectiveness of the governance model and controls across the AI lifecycle, updating to keep pace with AI developments.

Artefacts an auditor will ask for
  • Periodic governance review records
  • Assessment of control effectiveness across the lifecycle
  • Updates resulting from reviews
Where this commonly fails
  • Governance model never reviewed
  • No assessment of control effectiveness
  • Reviews not acted upon
AIGE-IG-6
Apply risk-based proportionality

Take account of organisation size and capabilities, applying a risk-based approach where a full multi-disciplinary body is too onerous, focusing on the risks the structure addresses.

Artefacts an auditor will ask for
  • Rationale for the chosen governance scale
  • Risk-based prioritisation of governance effort
  • Evidence key risks are still addressed
Where this commonly fails
  • One-size-fits-all governance regardless of risk
  • Small org abandons governance entirely
  • Key risks left unaddressed when scaling down

National-level Recommendations

AIGE-NR-1
Nurture AI talent and upskill the workforce

Governments should nurture AI talent and upskill the workforce to support AI adoption and governance.

Artefacts an auditor will ask for
  • National AI talent / upskilling programmes
  • Workforce development initiatives
Where this commonly fails
  • No national AI skills strategy
  • Workforce upskilling not funded
AIGE-NR-2
Invest in AI research and development

Governments should invest in AI research and development, build talent pools and digital infrastructure, and foster research partnerships.

Artefacts an auditor will ask for
  • National AI R&D investment
  • Digital infrastructure for AI
  • Triple-helix (research/private/government) partnerships
Where this commonly fails
  • No national AI R&D investment
  • Inadequate digital infrastructure
  • No research partnerships
AIGE-NR-3
Support the AI innovation ecosystem and investment

Governments should foster the AI innovation ecosystem, promote investment in AI start-ups, and enable cross-border data flows with appropriate data protection.

Artefacts an auditor will ask for
  • Measures supporting AI start-ups and investment
  • Cross-border data flow facilitation with safeguards
  • Enabling policy environment
Where this commonly fails
  • No support for AI start-ups
  • Cross-border data flows blocked or unsafe
  • Policy environment hostile to AI investment

Operations Management

AIGE-OM-1
Project governance and problem statement definition

Define the problem statement, conduct risk-based assessments before data collection or modelling, assign roles and accountability, and consider third-party and environmental impacts.

Artefacts an auditor will ask for
  • Documented problem statement and objectives
  • Pre-development risk assessment
  • Defined roles/accountability and third-party considerations
Where this commonly fails
  • Development begins without risk assessment
  • Roles/accountability undefined
  • Third-party/environmental impact ignored
AIGE-OM-10
Third-party and vendor AI governance

Where AI or components are sourced from third-party developers or vendors, define responsibilities, due diligence and governance over the third-party AI and foundation models.

Artefacts an auditor will ask for
  • Third-party/vendor AI due diligence
  • Contractual responsibilities for AI governance
  • Ongoing oversight of third-party AI components
Where this commonly fails
  • Third-party AI used without due diligence
  • Responsibilities with vendor undefined
  • No oversight of foundation-model suppliers
AIGE-OM-2
Data quality and representativeness

Ensure data used for training, testing and validation is sufficiently representative and of adequate quality, monitored across target populations to mitigate bias.

Artefacts an auditor will ask for
  • Data quality and representativeness checks
  • Performance evaluation across population segments
  • Separate training/testing/validation datasets
Where this commonly fails
  • Training data not representative
  • Quality of data unassessed
  • Single dataset reused for train/test/validate
AIGE-OM-3
Bias identification and mitigation

Identify and mitigate types of bias (representation, societal, labelling, measurement, activity, proxy) through dataset design, labelling quality assurance, and regular bias evaluation.

Artefacts an auditor will ask for
  • Bias type analysis across the pipeline
  • Labelling quality assurance and labeller training
  • Regular bias evaluation and mitigation records
Where this commonly fails
  • Bias types not analysed
  • Labelling bias uncontrolled
  • Bias evaluated once, not regularly
AIGE-OM-4
Data provenance, minimisation and protection

Track data provenance and lineage, apply data minimisation and protection, and conduct a data protection impact assessment when sourcing and processing data for AI.

Artefacts an auditor will ask for
  • Data provenance/lineage records
  • Data protection impact assessment for AI data
  • Minimisation and security controls over AI data
Where this commonly fails
  • Provenance of training data unknown
  • No DPIA for AI data processing
  • Excessive data retained without basis
AIGE-OM-5
Model explainability

Adopt explainability practices so the functioning of the model and how it arrives at decisions can be communicated to relevant stakeholders.

Artefacts an auditor will ask for
  • Explainability techniques applied and documented
  • Explanations suited to the audience
  • Evidence explanations are available for review
Where this commonly fails
  • Black-box models with no explanation
  • Explanations not meaningful to users
  • Explainability not documented
AIGE-OM-6
Repeatability and reproducibility

Ensure the AI system can consistently obtain the same results given the same scenario (repeatability) and that results can be reproduced, supporting reliability and trust.

Artefacts an auditor will ask for
  • Repeatability/reproducibility test results
  • Recorded scenarios and outcomes
  • Configuration captured to reproduce results
Where this commonly fails
  • Results not reproducible
  • No repeatability testing
  • Model/config not version-captured
AIGE-OM-7
Robustness and security testing

Test the robustness and security of AI systems, including against adversarial inputs, especially for public-facing systems (e.g. robustness tests, red teaming).

Artefacts an auditor will ask for
  • Robustness/adversarial test results
  • Red-teaming or bug-bounty records
  • Mitigations for identified weaknesses
Where this commonly fails
  • No adversarial/robustness testing
  • Public-facing AI not hardened
  • Weaknesses found but not mitigated
AIGE-OM-8
Traceability and auditability

Maintain traceability and audit trails of AI system and user behaviour to support periodic risk assessment, accountability and review.

Artefacts an auditor will ask for
  • Logging of system and user behaviour
  • Audit trail enabling traceability
  • Retention sufficient for review/challenge
Where this commonly fails
  • No logging of AI decisions
  • Audit trail incomplete
  • Logs not retained long enough
AIGE-OM-9
Deployment, monitoring and review

Validate before deployment and continue to monitor and review deployed AI systems for performance and drift, with regular tuning to ensure they perform as intended.

Artefacts an auditor will ask for
  • Pre-deployment validation records
  • Production monitoring incl. drift detection
  • Tuning/retraining and review records
Where this commonly fails
  • No pre-deployment validation
  • No monitoring for drift
  • Models not re-tuned as performance degrades

Regional-level Recommendations

AIGE-RR-1
Establish an ASEAN Working Group on AI Governance

Set up an ASEAN Working Group on AI Governance to drive and oversee the technical and operational implementation of AI governance action plans in the region.

Artefacts an auditor will ask for
  • Established ASEAN Working Group on AI Governance
  • Defined responsibilities and action plans
  • Member State representation
Where this commonly fails
  • No regional coordinating body
  • Action plans undefined
  • Uneven Member State participation
AIGE-RR-2
Foster regional alignment, cooperation and interoperability

Promote regional alignment of AI frameworks, international cooperation on AI governance, and interoperability across jurisdictions.

Artefacts an auditor will ask for
  • Initiatives aligning AI frameworks across ASEAN
  • International cooperation activities
  • Interoperability/compendium efforts
Where this commonly fails
  • Fragmented national approaches
  • No international cooperation
  • Frameworks not interoperable

Stakeholder Interaction and Communication

AIGE-SI-1
Stakeholder communication policy and AI-use disclosure

Develop a stakeholder communication policy identifying audience, purpose and context, and disclose to users when AI is used and how it affects them.

Artefacts an auditor will ask for
  • Stakeholder communication policy
  • User disclosure that AI is in use
  • Tailoring of communication to audience
Where this commonly fails
  • No communication policy
  • AI use not disclosed
  • Communication not suited to the audience
AIGE-SI-2
Feedback channels

Provide feedback channels and mechanisms for users to raise issues and, where relevant, correct their data, and manage that feedback.

Artefacts an auditor will ask for
  • Operational feedback channel
  • Process for managing and actioning feedback
  • Mechanism for users to correct their data
Where this commonly fails
  • No feedback channel
  • Feedback received but not actioned
  • No way for users to correct data
AIGE-SI-3
Decision review and recourse channels

Where reasonable, provide channels for AI-influenced decisions to be reviewed by a human and for users to seek recourse.

Artefacts an auditor will ask for
  • Decision review channel with human review
  • Recourse/appeal process
  • Records of reviewed decisions and outcomes
Where this commonly fails
  • No human review of contested decisions
  • No recourse mechanism
  • Review channel exists but unused/unstaffed
AIGE-SI-4
Acceptable use policies

Set up acceptable use policies that outline the boundaries for interacting with AI systems.

Artefacts an auditor will ask for
  • Acceptable use policy for AI systems
  • Communication of usage boundaries to users
  • Enforcement of acceptable use
Where this commonly fails
  • No acceptable use policy
  • Boundaries not communicated
  • Policy not enforced
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ASEAN Guide on AI Governance and Ethics framework page.