Skip to content

Evidence request lists

Brazil AI Framework

Evidence request list. 29 controls, 29 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Brazil AI (PL 2338/2023) Cap. I: Preliminary Provisions

BRAI-A1
Scope and general national norms

Scope. Article 1 establishes general national norms for the development, implementation and responsible use of artificial intelligence systems in Brazil, to protect fundamental rights and ensure safe and reliable systems.

Artefacts an auditor will ask for
  • Determination of AI systems and roles (provider/operator) in scope
  • Inventory of AI systems subject to the law
Where this commonly fails
  • AI systems not assessed against the law
  • Provider/operator roles not identified
BRAI-A2
Foundations

Foundations. Article 2 sets the foundations of AI regulation, including human dignity, autonomy, privacy and data protection, free enterprise and innovation.

Artefacts an auditor will ask for
  • Documentation that AI development reflects the statutory foundations
  • Alignment of AI policy with the foundations
Where this commonly fails
  • Foundations not reflected in AI governance
  • No linkage of policy to foundations
BRAI-A3
Principles

Principles. Article 3 sets the principles governing AI: non-discrimination, transparency, explainability, auditability, reliability, human oversight, accountability and others.

Artefacts an auditor will ask for
  • AI governance policy reflecting the Article 3 principles
  • Evidence each principle is operationalised (transparency, human oversight, accountability)
Where this commonly fails
  • Principles not operationalised
  • No evidence of auditability/explainability
BRAI-A4
Definitions

Definitions. Article 4 defines the key terms (artificial intelligence system, AI agent, provider, operator, affected person, algorithmic discrimination and others).

Artefacts an auditor will ask for
  • Mapping of statutory definitions to internal terminology
  • Classification of systems as AI / roles per Art 4
Where this commonly fails
  • Definitions not applied
  • Roles misclassified

Brazil AI (PL 2338/2023) Cap. II: Rights of Affected Persons

BRAI-A12
Right to non-discrimination

Right to non-discrimination. Article 12 gives affected persons the right to non-discrimination and to the correction of discriminatory bias, direct or indirect, produced by AI systems.

Artefacts an auditor will ask for
  • Bias detection and mitigation evidence
  • Assessment of discriminatory outcomes and corrective action
Where this commonly fails
  • No bias assessment
  • Discriminatory outcomes not corrected
BRAI-A5
Rights of affected persons

Rights of affected persons. Article 5 establishes the rights of persons affected by AI systems, including the right to information, explanation, contestation and human review.

Artefacts an auditor will ask for
  • Procedures to honour affected-person rights
  • Records of rights requests and responses
Where this commonly fails
  • Rights not honoured
  • No procedure for affected persons
BRAI-A7
Right to prior information about AI interaction

Right to information. Article 7 gives affected persons the right to know, prior to or at the time of interaction, that they are interacting with an AI system.

Artefacts an auditor will ask for
  • Notices informing users they are interacting with an AI system
  • Process to provide AI-interaction disclosure
Where this commonly fails
  • No AI-interaction disclosure
  • Notice not provided before interaction
BRAI-A8
Right to explanation of AI decisions

Right to explanation. Article 8 gives affected persons the right to an explanation about decisions, recommendations or predictions made by AI systems that affect them.

Artefacts an auditor will ask for
  • Explanation procedures for AI decisions affecting persons
  • Records of explanations provided
Where this commonly fails
  • No explanation mechanism
  • Explanations not meaningful
BRAI-A9
Right to contest and to human review

Right to contest. Article 9 gives affected persons the right to contest AI decisions and to request human review of decisions that produce relevant legal effects or significantly affect them.

Artefacts an auditor will ask for
  • Mechanism to contest AI decisions and obtain human review
  • Records of contestations and human reviews
Where this commonly fails
  • No contestation mechanism
  • Human review not available

Brazil AI (PL 2338/2023) Cap. III: Risk Categorization of AI Systems

BRAI-A13
Preliminary risk assessment

Preliminary assessment. Article 13 requires AI agents to perform a preliminary assessment to classify the risk of an AI system before placing it on the market or putting it into use.

Artefacts an auditor will ask for
  • Preliminary risk-classification assessment per AI system
  • Documentation supporting the risk classification
Where this commonly fails
  • No preliminary risk assessment
  • Classification not documented
BRAI-A14
Excessive-risk (prohibited) AI systems

Excessive-risk AI. Article 14 prohibits the implementation and use of AI systems posing excessive risk, including subliminal techniques, exploitation of vulnerabilities and certain social-scoring uses.

Artefacts an auditor will ask for
  • Assessment that no excessive-risk/prohibited AI use is deployed
  • Controls preventing prohibited AI uses
Where this commonly fails
  • Prohibited AI uses deployed
  • No screening for excessive-risk uses
BRAI-A15
Biometric identification in public security

Biometric identification. Article 15 restricts the use of remote biometric identification systems in publicly accessible spaces for public-security purposes to defined cases and safeguards.

Artefacts an auditor will ask for
  • Legal basis and safeguards for any remote biometric identification
  • Authorisation records for public-security biometric use
Where this commonly fails
  • Biometric ID used without legal basis/safeguards
  • No authorisation records
BRAI-A17
High-risk AI systems

High-risk AI. Article 17 designates the categories of high-risk AI systems (e.g. critical infrastructure, education, employment, essential services, justice, biometrics) subject to enhanced governance.

Artefacts an auditor will ask for
  • Classification of AI systems against the high-risk categories
  • Enhanced governance applied to high-risk systems
Where this commonly fails
  • High-risk systems not identified
  • Enhanced governance not applied
BRAI-A18
Updating the high-risk list

Updating the high-risk list. Article 18 empowers the competent authority to update the list of high-risk AI systems, requiring agents to monitor for changes.

Artefacts an auditor will ask for
  • Process to monitor updates to the high-risk list
  • Re-classification when the list changes
Where this commonly fails
  • High-risk list updates not monitored
  • Re-classification not performed

Brazil AI (PL 2338/2023) Cap. IV: Governance of AI Systems

BRAI-A19
Governance measures for AI agents

Governance measures. Article 19 requires AI agents to establish governance structures and internal processes to ensure security and the rights of affected persons throughout the AI lifecycle.

Artefacts an auditor will ask for
  • Documented AI governance structures and internal processes
  • Lifecycle controls for security and rights
  • Roles and responsibilities for AI governance
Where this commonly fails
  • No governance structure
  • Lifecycle controls absent
  • Roles undefined
BRAI-A20
Additional governance for high-risk AI

High-risk governance. Article 20 imposes additional governance measures for high-risk AI, including documentation, testing, data management, logging and human oversight.

Artefacts an auditor will ask for
  • Additional high-risk governance documentation
  • Testing, data-management and logging records
  • Human-oversight mechanisms for high-risk AI
Where this commonly fails
  • Additional measures not applied to high-risk AI
  • No logging/testing
  • Human oversight absent
BRAI-A22
Algorithmic impact assessment

Algorithmic impact assessment (AIA). Article 22 requires an algorithmic impact assessment for high-risk AI systems, evaluating risks and mitigation measures.

Artefacts an auditor will ask for
  • Algorithmic impact assessment for high-risk systems
  • Identified risks and mitigation measures
  • Review/update of the AIA
Where this commonly fails
  • No AIA for high-risk systems
  • Risks/mitigations not documented
  • AIA not updated
BRAI-A24
AIA methodology

AIA methodology. Article 24 sets out the minimum content and methodology of the algorithmic impact assessment.

Artefacts an auditor will ask for
  • Documented AIA methodology meeting the minimum content
  • Evidence the methodology was applied
Where this commonly fails
  • AIA lacks the required content
  • Methodology not followed
BRAI-A26
Publicity of AIA conclusions

Publicity of the AIA. Article 26 requires publication of the conclusions of the algorithmic impact assessment, protecting industrial and commercial secrets.

Artefacts an auditor will ask for
  • Published AIA conclusions (with secrets protected)
  • Process for publishing AIA outcomes
Where this commonly fails
  • AIA conclusions not published
  • No process for publication

Brazil AI (PL 2338/2023) Cap. V: Civil Liability

BRAI-A27
Civil liability of AI agents

Civil liability. Article 27 establishes the civil liability of providers and operators of AI systems for patrimonial, moral, individual or collective damage caused.

Artefacts an auditor will ask for
  • Awareness of civil-liability exposure
  • Insurance/risk-transfer for AI liability where used
  • Records of damage claims and handling
Where this commonly fails
  • Liability exposure not assessed
  • Claims not handled
  • No risk transfer considered
BRAI-A29
Liability allocation between agents

Liability allocation. Article 29 sets out how civil liability is allocated among the AI agents in the value chain.

Artefacts an auditor will ask for
  • Contractual allocation of AI liability across the value chain
  • Records identifying provider/operator roles for liability
Where this commonly fails
  • Liability allocation undefined
  • Roles not documented for liability

Brazil AI (PL 2338/2023) Cap. VI-VII: Incident Communication and Supervision

BRAI-A31
Communication of serious security incidents

Incident communication. Article 31 requires AI agents to communicate serious security incidents to the competent authority, including risks to life, safety, critical infrastructure or fundamental rights.

Artefacts an auditor will ask for
  • Procedure to assess and report serious AI incidents to the authority
  • Records of incident notifications and timelines
  • Incident register
Where this commonly fails
  • Serious incidents not reported
  • No notification criteria/timelines
  • Incident register absent
BRAI-A33
Competent authority (central body)

Competent authority. Article 33 designates the competent authority as the central body for applying the law and issuing norms and guidelines (the national AI governance system, coordinated with the ANPD).

Artefacts an auditor will ask for
  • Engagement and cooperation with the competent authority
  • Responses to authority norms, guidelines and requests
Where this commonly fails
  • Authority requirements not met
  • No cooperation with the authority
BRAI-A36
Administrative sanctions

Administrative sanctions. Article 36 sets out the administrative sanctions for infractions of the law (warnings, fines, publication of the infraction, suspension or prohibition of the AI system).

Artefacts an auditor will ask for
  • Awareness of sanction exposure under the law
  • Controls preventing sanctioned conduct
  • Records of any sanctions and remediation
Where this commonly fails
  • Sanction exposure not assessed
  • No controls against infractions
  • Sanctions not remediated

Brazil AI (PL 2338/2023) Cap. VIII-IX: Codes, Sandbox and Final Provisions

BRAI-A37
Codes of good practice and governance

Codes of good practice. Article 37 enables AI agents to adopt codes of good practice and governance, and the authority to recognise them.

Artefacts an auditor will ask for
  • Adoption of applicable AI codes of good practice
  • Evidence of alignment with recognised codes
Where this commonly fails
  • No code of good practice adopted
  • Practices not aligned to codes
BRAI-A38
Regulatory sandbox

Regulatory sandbox. Article 38 empowers the authority to authorise experimental regulatory environments (sandboxes) for AI innovation under supervision.

Artefacts an auditor will ask for
  • Sandbox participation authorisation and conditions
  • Supervision and reporting during sandbox testing
Where this commonly fails
  • Sandbox use without authorisation
  • No supervision/reporting
BRAI-A42
Text and data mining / copyright

Copyright and TDM. Article 42 provides that the automated use of works for text and data mining by research and other entities does not, under defined conditions, constitute copyright infringement.

Artefacts an auditor will ask for
  • Assessment of TDM/copyright conditions for AI training data
  • Records of lawful basis for using protected works
Where this commonly fails
  • Protected works used without meeting TDM conditions
  • No copyright assessment of training data
BRAI-A43
AI incident database

Incident database. Article 43 tasks the authority with creating and maintaining a database of AI incidents, to which agents contribute.

Artefacts an auditor will ask for
  • Contribution of AI incidents to the authority's database
  • Internal incident records aligned to the database
Where this commonly fails
  • Incidents not contributed to the database
  • No internal incident records
BRAI-A45
Entry into force

Entry into force. Article 45 provides that the law enters into force one year after its publication, requiring a transition/implementation plan.

Artefacts an auditor will ask for
  • Implementation/transition plan for compliance by the effective date
  • Milestones tracking readiness
Where this commonly fails
  • No transition plan
  • Readiness not tracked to the effective date
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Brazil AI Framework framework page.