AI Audit Evidence Tracker
In brief
The AI Audit Evidence Tracker is a free XLSX register for ISO/IEC 42001, NIST AI RMF and EU AI Act. Every piece of evidence the recorded controls expect, one row each, with owner, status, location and review date, so an audit or certification starts from a complete list. It is licensed CC BY 4.0 and is not legal advice.
- Format
- XLSX · Register
- Version
- v1, built 28 Sep 2026
- Duties cited
- 107 from 20 instruments
- Rows from the records
- 105
- Frameworks
- ISO/IEC 42001, NIST AI RMF, EU AI Act
- Written for
- Deployer / user organisation, Provider / developer, Public authority / government body
- Price and licence
- Free · CC BY 4.0
What's inside
- Evidence tracker: control, evidence expected, kind, owner, status, location, last reviewed
- Status colouring for missing and available evidence
- Controls sheet: every control on record with its duties and framework references
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Evidence tracker
| Control | Evidence expected | Kind | Owner | Status ▾ | Where it is kept | Last reviewed | Control record |
|---|---|---|---|---|---|---|---|
| AI governance policy and accountability structure | AI policy | policy document | https://aipolicytracker.org/controls/ai-governance-policy-and-accountability | ||||
| AI governance policy and accountability structure | Board or executive approval of the AI policy | approval record | https://aipolicytracker.org/controls/ai-governance-policy-and-accountability | ||||
| AI governance policy and accountability structure | AI governance forum minutes | meeting record | https://aipolicytracker.org/controls/ai-governance-policy-and-accountability | ||||
| AI governance policy and accountability structure | AI responsibility map | register entry | https://aipolicytracker.org/controls/ai-governance-policy-and-accountability | ||||
| AI impact and fundamental-rights impact assessment | AI impact assessment | impact assessment | https://aipolicytracker.org/controls/ai-impact-assessment | ||||
| AI impact and fundamental-rights impact assessment | Impact assessment approval | approval record | https://aipolicytracker.org/controls/ai-impact-assessment |
Every piece of evidence the controls on record expect, one row each. Fill in owner, status and location as the evidence is gathered; an auditor starts here.
Sheet: Controls
| Control | Kind | Purpose | Typical owner | Frequency | Duties it satisfies | Duties it supports | Evidence it produces | ISO/IEC 42001 | NIST AI RMF | Record |
|---|---|---|---|---|---|---|---|---|---|---|
| AI governance policy and accountability structure | Policy | Gives the organisation a single approved statement of how it will develop, buy and use AI, and names the people who are answerable for it, so that every other A | Executive sponsor for AI | annual | 9 | 7 | AI policy; Board or executive approval of the AI policy; AI governance forum minutes; AI responsibility map | Clause 5.1, 5.2, 5.3, 9.3; Annex A.2, A.3 | GOVERN 1.1, 1.2, 1.3, 2.1, 3.1 | https://aipolicytracker.org/controls/ai-governance-policy-and-accountability |
| AI impact and fundamental-rights impact assessment | Process | Examines how a planned AI use will affect the people, groups and communities it touches, with particular attention to discrimination and rights, and records the | AI system owner | per_system | 4 | 7 | AI impact assessment; Impact assessment approval; Impact assessment procedure and template | Clause 6.1.4, 8.4; Annex A.5 | MAP 5.1, 5.2; MEASURE 2.11 | https://aipolicytracker.org/controls/ai-impact-assessment |
| AI incident management and regulatory reporting | Process | Ensures that harm or near-harm caused by an AI system is detected, contained, investigated and, where a rule requires it, reported to the right authority and af | Incident coordinator | continuous | 9 | 5 | AI incident response playbook; AI incident record; Incident report to an authority | Clause 10.2; Annex A.8.3, A.8.4 | MANAGE 4.1, 4.3; GOVERN 4.3, 6.2 | https://aipolicytracker.org/controls/ai-incident-management-and-reporting |
| AI interaction and use disclosure notices | Process | Tells people, in plain language and at the right moment, that they are interacting with an AI system, that AI is being used in a decision about them or that the | Product owner | on_material_change | 15 | 3 | AI interaction or use notice; Notice catalogue; Notice wording approval | Annex A.8.2, A.8.5 | MEASURE 2.8; GOVERN 5.1 | https://aipolicytracker.org/controls/ai-interaction-and-use-disclosure |
| AI literacy and role-based training programme | Training | Gives everyone who builds, buys, operates or is overseen by AI systems the knowledge they need for their role, from general awareness to the specific skills of | Learning and development lead | annual | 1 | 3 | AI training completion records; Role-to-curriculum training matrix; AI training curriculum and materials | Clause 7.2, 7.3; Annex A.4.6 | GOVERN 2.2, 4.1 | https://aipolicytracker.org/controls/ai-literacy-and-role-based-training |
| AI risk assessment and lifecycle risk register | Process | Identifies, rates and treats the risks that a specific AI system poses to health, safety, rights and the organisation itself, and keeps that analysis alive from | AI system owner | per_system | 7 | 5 | AI system risk assessment; Per-system AI risk register; Residual-risk acceptance | Clause 6.1.2, 6.1.3, 8.2, 8.3 | MAP 3, MAP 4, MANAGE 1.2, 1.3, 2.1 | https://aipolicytracker.org/controls/ai-risk-assessment |
How to use it
- 1Request the files. Enter your name, company and work email in the form on this page. The XLSX download links arrive by email and work for 7 days.
- 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
- 3Fill in your rows. Complete the "Evidence tracker" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
- 4Check the duties against your situation. The "Evidence tracker" and "Controls" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
- 5Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.
Duties this template covers (107)
Each is cited in the file with its source reference and a link back to the record.
- Establish accountability processes and a risk-management process (guardrails 1 and 2)
- Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6)
- Provide contestability, supply-chain transparency and records (guardrails 7 to 9)
- Large frontier developers must publish a frontier AI framework
- Report critical safety incidents to the Office of Emergency Services
- Frontier developers must publish a transparency report before deploying a new frontier model
- Large frontier developers must send periodic summaries of catastrophic-risk assessments to the state
- Frontier developers must protect employees who report catastrophic-risk concerns
- Notify consumers before automated decision-making technology influences a consequential decision
- Disclose the use of the technology and the principal reasons after an adverse consequential decision
- Offer meaningful human review of an adverse consequential decision
- Keep records of consequential decisions influenced by the technology for three years
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | bb068ecd9dad | First version, built from dataset bb068ecd9dad. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
What is in the AI Audit Evidence Tracker?
Evidence tracker: control, evidence expected, kind, owner, status, location, last reviewed. Status colouring for missing and available evidence. Controls sheet: every control on record with its duties and framework references.
Which duties does it cite?
107 recorded duties from Australian Voluntary AI Safety Standard, California SB 53, Colorado ADMT law (SB 26-189) and EU AI Act, including Guardrails 1 and 2, Guardrails 4, 5 and 6, Guardrails 7, 8 and 9, Business and Professions Code, Chapter 25.1 (as added by SB 53), Business and Professions Code Section 22757.12 (as added by SB 53) and Labor Code Section 1107 (as added by SB 53). Each row links to the record, and the record to the official source.
Who is it for?
The duties it cites fall on deployer / user organisation, provider / developer and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.
Is it free?
Yes. Request the XLSX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
How will I know when it changes?
Version v1 was built on 28 September 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.