Skip to content

Evidence request lists

OECD AI Principles

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Accountability and Documentation

OECDAI-4
Accountability, Lifecycle Coverage, Documentation, and Record-Keeping

Adhere to OECD AI Principles Section 1.5 (Accountability). AI actors should be accountable for the proper functioning of AI systems and for the respect of the above principles based on their roles + the context + and consistent with the state of the art. Implement (a) accountability framework for AI systems with defined roles + responsibilities + decision authority across providers + deployers + users + distributors + importers per AI system type and applicable regulatory regime, (b) AI system documentation requirements covering design + development + training + validation + deployment + monitoring + maintenance + decommissioning, (c) record-keeping for AI decisions with retention aligned to regulatory + investigative + litigation + governance needs, (d) lifecycle coverage of AI Principles ensuring each principle is honoured at each lifecycle phase, (e) common understanding of AI system

Artefacts an auditor will ask for
  • AI actor role matrix per AI system per function (Provider / Deployer / User)
  • AI system documentation covering design + training + validation + deployment + monitoring + decommissioning
  • record-keeping for AI decisions per regulatory + governance need
  • integration with corporate governance (board + audit + risk committee)
Where this commonly fails
  • AI actor roles ambiguous across SaaS + foundation model + deployer relationships
  • documentation incomplete missing training or validation phase
  • record-keeping retention insufficient for litigation defence

Audit, Impact Assessments, Metrics

OECDAI-7
Third-Party AI Audit, Impact Assessments, and Metrics for Trustworthy AI

Operate third-party AI audit + impact assessments + metrics per OECD AI Principles + emerging assurance standards. Third-party AI audit must (a) engage independent assessors for high-risk AI systems per applicable regulation + voluntary assurance scheme (EU AI Act conformity assessment + ISO/IEC 42001 certification + NIST AI RMF profile assessment + sector-specific), (b) maintain auditability of AI systems including documentation + access to model + data + logs + decision history + (c) implement findings remediation tracking through closure. Impact Assessments Aligned to OECD Principles must (a) conduct AI impact assessments per use case covering OECD Principles + applicable regulation (AI Conformity Assessment per EU AI Act + Algorithmic Impact Assessment per Canadian Directive + DPIA per GDPR + EHRIA + similar), (b) involve diverse stakeholders + affected communities + subject matter e

Artefacts an auditor will ask for
  • third-party audit evidence per high-risk AI system
  • impact assessments per use case aligned to applicable regulation
  • operational metrics per OECD Principle reported to governance + benchmarked
Where this commonly fails
  • high-risk AI deployed without independent assessment
  • impact assessments performed but not embedded in deployment decision
  • metrics measured but not reported or benchmarked

Data Governance and Bias

OECDAI-5
Data Governance, Training Data Quality, Privacy, and Bias Mitigation

Operate data governance underpinning trustworthy AI per OECD Principles. Data governance must address (a) training data quality and governance with documented sourcing + provenance + consent + licensing + curation + quality controls + (b) data bias assessment and mitigation across training + validation + testing + production data, (c) data provenance and lineage tracking with metadata management + chain of custody + reproducibility support, (d) privacy protection in AI training data per applicable privacy regimes (GDPR + state privacy laws + sector-specific) + including data minimisation + purpose limitation + lawful basis + data subject rights handling for training data + model output containing training data + (e) data retention for AI models including training data + model snapshots + audit trails + inference logs per regulatory + investigative + governance need, (f) bias detection an

Artefacts an auditor will ask for
  • data lineage + provenance + licensing + consent evidence per training data corpus
  • bias assessment + mitigation per AI use case
  • privacy lawful basis + data subject rights handling for AI
  • data retention per regulatory + governance need
Where this commonly fails
  • training data provenance undocumented producing IP + privacy + competition law exposure
  • bias mitigation performed at one lifecycle stage without ongoing monitoring
  • privacy lawful basis unclear for AI training of personal data

Human Oversight and Redress

OECDAI-6
Human Oversight, Redress, and Contestation Mechanisms

Operate human oversight + redress + contestation per OECD AI Principles. Human oversight must (a) implement appropriate human-in-the-loop + human-on-the-loop + human-out-of-the-loop based on risk + impact + context + with documented decision per AI system, (b) ensure human override capability + escalation pathway + delegation policy + (c) support human reviewer capability through training + tooling + workload management + decision support, (d) prevent automation bias through review independence + sample testing + outcome monitoring. Redress and contestation mechanisms must (a) provide effective + accessible + and proportionate mechanisms for affected individuals to challenge AI decisions including appeal + investigation + remediation, (b) document the redress process + timelines + decision criteria + remediation options, (c) preserve records sufficient to support contestation including m

Artefacts an auditor will ask for
  • human oversight model per AI system (in-the-loop / on-the-loop / out-of-the-loop)
  • human reviewer training + tooling + workload management
  • redress process documentation + accessibility testing + remediation tracking
Where this commonly fails
  • human oversight nominal not operational (automation bias)
  • redress process exists but inaccessible
  • no testing of redress accessibility with diverse populations

Incident Reporting, Compliance, International

OECDAI-8
AI Incident Reporting, Regulatory Compliance, Public Reporting, and International Cooperation

Operate AI incident reporting + regulatory compliance + public reporting + international cooperation per OECD AI Principles + applicable regulation + voluntary commitment. AI incident reporting and response must (a) detect + assess + respond to AI incidents including model failure + bias incident + safety event + adversarial attack + privacy breach + misuse + emergent capability + agentic action gone wrong + (b) report incidents per applicable regulation (EU AI Act Article 73 serious incident reporting + sector-specific reporting + voluntary commitments) + (c) maintain incident learning loop feeding back to risk management + design + deployment. Regulatory compliance for AI must (a) maintain AI-regulatory inventory across applicable jurisdictions (EU AI Act + UK AI regulation + US federal + state + sectoral + Canada + Australia + Japan + similar) + (b) monitor for change + integrate new

Artefacts an auditor will ask for
  • AI incident detection + response + reporting per applicable regulation
  • AI regulatory inventory + change monitoring + cross-functional integration
  • public reporting + civil society engagement + voluntary commitment participation
  • international AI governance dialogue participation + cross-border deployment alignment
Where this commonly fails
  • AI incident reporting nominal not operational producing late or missed regulatory reports
  • regulatory inventory incomplete missing emerging jurisdictions
  • no public reporting of AI use or outcomes

Inclusive Growth and Human-Centred Values

OECDAI-1
Inclusive Growth, Human-Centred Values, Fairness, and Sustainable Development

Adhere to OECD AI Principles Section 1.1 (Inclusive growth + sustainable development + well-being) and Section 1.2 (Human-centred values + fairness) per the OECD Recommendation of the Council on Artificial Intelligence adopted 22 May 2019 + updated 3 May 2024 (OECD/LEGAL/0449). AI actors must (a) proactively engage in responsible stewardship of trustworthy AI in pursuit of beneficial outcomes for people and the planet such as augmenting human capabilities and enhancing creativity + advancing inclusion of underrepresented populations + reducing economic + social + gender + and other inequalities + protecting natural environments thereby invigorating inclusive growth + well-being + sustainable development, (b) respect the rule of law + human rights + democratic values + and diversity + including freedom + dignity + autonomy + privacy + data protection + non-discrimination + equality + dive

Artefacts an auditor will ask for
  • AI strategy aligned to OECD Principles with inclusive growth + sustainable development + well-being objectives
  • impact assessments per AI use case engaging diverse stakeholders
  • redress mechanism evidence + multi-stakeholder engagement records
Where this commonly fails
  • AI strategy generic without OECD Principles alignment
  • impact assessments performed without affected community engagement
  • no multi-stakeholder governance forum

Robustness, Security, Safety

OECDAI-3
Robustness, Security, Safety, and Adversarial Attack Protection

Adhere to OECD AI Principles Section 1.4 (Robustness + security + safety). AI systems should be robust + secure + and safe throughout their entire lifecycle so that in conditions of normal use + foreseeable use or misuse + or other adverse conditions they function appropriately and do not pose unreasonable safety risk. To this end AI actors should ensure traceability + auditability + ability to log + and apply a systematic risk management approach to each phase of the AI system lifecycle on a continuous basis to address risks related to AI systems + including privacy + digital security + safety + and bias. Implement (a) AI risk identification and assessment aligned with NIST AI RMF + ISO/IEC 23894 + ISO/IEC 42001, (b) AI system categorisation by risk level + (c) AI model validation and testing covering performance + robustness + fairness + safety + security + (d) ongoing AI risk monitori

Artefacts an auditor will ask for
  • AI risk assessment aligned to NIST AI RMF + ISO/IEC 23894
  • AI system categorisation by risk level
  • model validation + testing + adversarial robustness evidence
  • ongoing monitoring + drift + adversarial detection + red-team programme
Where this commonly fails
  • one-time validation without continuous monitoring
  • no adversarial robustness testing
  • robustness for foundation models limited to provider claims without independent verification

Transparency and Explainability

OECDAI-2
Transparency, Explainability, and Public-Facing Disclosure

Adhere to OECD AI Principles Section 1.3 (Transparency and explainability). AI actors should commit to (a) transparency and responsible disclosure regarding AI systems to foster understanding of AI systems + make stakeholders aware of their interactions with AI systems including in the workplace + provide meaningful information appropriate to the context and consistent with the state of the art to those adversely affected by an AI system + enable those adversely affected by an AI system to challenge its output based on plain and easy-to-understand information on the factors and the logic that served as the basis for the prediction + recommendation + or decision. Implement (a) explainability requirements proportionate to risk and impact level with documented explainability capability per AI system, (b) algorithmic transparency measures including system documentation + model cards + datash

Artefacts an auditor will ask for
  • explainability capability documentation per AI system with risk-level proportionate methods
  • model cards + datasheets + system documentation per AI system
  • user notification of AI interactions evidence
  • public-facing AI use disclosure
Where this commonly fails
  • explainability methods not matched to risk level
  • model cards absent or generic
  • user notification not implemented despite EU AI Act Article 50 requirement
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the OECD AI Principles framework page.