Dossier · AI systems audit

Scoping an AI audit: decision, boundary and authority

An audit becomes defensible before the first test. Its mandate must identify the expected decision, the system boundary, the versions examined, authorised access and the person empowered to decide.

On this page
Starting point

The mandate carries a decision, not a topic

“Audit our AI” defines no examinable work. The mandate starts with the decision the organisation must take: commit to a supplier, authorise a version, accept a risk, restrict a use or refuse release. That decision determines the depth required and the authority that will receive the conclusion.

A useful question can be disproved. “Does the candidate version meet the approved conditions for this use and this population?” can lead to yes, no or unable to conclude. “Is our system reliable?” merges several criteria and invites a general opinion that cannot be challenged.

Boundary

Describe the system that actually produces the outcome

The audited unit is not the model’s commercial name. It includes the use, data, transformations, components, versions, parameters, tools, human and automated controls, interfaces and dependencies that contribute to a decision or action.

The declared diagram is only a starting hypothesis. Configurations, logs, technical contracts and observed behaviour confirm the boundary. Any gap between the announced architecture and the operating architecture becomes an audit fact, not a silent diagram correction.

Included
Entities, third parties, uses, populations, periods, environments and interfaces
Frozen
Model, data, parameter, rule and control versions examined
Excluded
Unavailable components or periods, with the expected effect on the conclusion
Owner
Authority that accepts the mandate, receives reservations and decides
Access

Tie every requested access to a defined procedure

A rigorous audit does not request “all access”. For each procedure, it states the item, trace, environment or interview required, its sensitivity and how the result will be retained. Minimum access means the least access that still allows the procedure to run and the expected conclusion to be supported.

When access is refused, unavailable or technically impossible, the auditor does not replace observation with a favourable assumption. The restriction is qualified, alternative evidence is sought, and the conclusion is narrowed when that alternative does not carry the same strength.

Independence

Give the conclusion operational authority

The mandate names the sponsor, system owner, scope owners and the authority able to decide. It also records prior work, commercial relationships or conflicts that could affect the examination. A conclusion addressed to someone without the power to correct, restrict or accept risk may be administratively neat but remains operationally inert.

Scoping test

Read the mandate as if you were already reviewing the conclusion

Before work begins, someone outside the scoping discussion must be able to answer five questions: which decision will be taken, about which system and version, against which criteria, with which access, and by which authority. Any missing answer will reappear later as ambiguity in sampling, severity or closure.

Primary sources

Sources this page relies on

Last documentary review: 5 September 2026.

Before you write to us

Frequently asked questions

Why is the model name insufficient to define scope?

Because the result also depends on the data, rules, tools, interfaces, human controls, versions and suppliers actually involved. The boundary follows the delivered service, not the product sheet.

What happens when part of the system is inaccessible?

The restriction is recorded, alternative evidence is sought, and the conclusion is narrowed when that alternative does not provide equivalent strength.

Audit dossier

Does your mandate actually allow a conclusion?

Name the decision, version and expected authority. We verify whether the question can become a bounded audit programme.

Tell us about your situation