AIPolicyTracker
RegisterFree · sent to your work emailISO/IEC 42001NIST AI RMFEU AI Act

AI Audit Evidence Tracker

Formats: XLSX · Version v1 · Built from dataset bb068ecd9dad · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

In brief

The AI Audit Evidence Tracker is a free XLSX register for ISO/IEC 42001, NIST AI RMF and EU AI Act. Every piece of evidence the recorded controls expect, one row each, with owner, status, location and review date, so an audit or certification starts from a complete list. It is licensed CC BY 4.0 and is not legal advice.

Format
XLSX · Register
Version
v1, built 28 Sep 2026
Rows from the records
105
Written for
Deployer / user organisation, Provider / developer, Public authority / government body
Price and licence
Free · CC BY 4.0

What's inside

  • Evidence tracker: control, evidence expected, kind, owner, status, location, last reviewed
  • Status colouring for missing and available evidence
  • Controls sheet: every control on record with its duties and framework references

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Evidence tracker · 8 columns · 79 rows from the records
First rows of the Evidence tracker sheet
ControlEvidence expectedKindOwnerStatus ▾Where it is keptLast reviewedControl record
AI governance policy and accountability structureAI policypolicy documenthttps://aipolicytracker.org/controls/ai-governance-policy-and-accountability
AI governance policy and accountability structureBoard or executive approval of the AI policyapproval recordhttps://aipolicytracker.org/controls/ai-governance-policy-and-accountability
AI governance policy and accountability structureAI governance forum minutesmeeting recordhttps://aipolicytracker.org/controls/ai-governance-policy-and-accountability
AI governance policy and accountability structureAI responsibility mapregister entryhttps://aipolicytracker.org/controls/ai-governance-policy-and-accountability
AI impact and fundamental-rights impact assessmentAI impact assessmentimpact assessmenthttps://aipolicytracker.org/controls/ai-impact-assessment
AI impact and fundamental-rights impact assessmentImpact assessment approvalapproval recordhttps://aipolicytracker.org/controls/ai-impact-assessment

Every piece of evidence the controls on record expect, one row each. Fill in owner, status and location as the evidence is gathered; an auditor starts here.

Sheet: Controls · 11 columns · 26 rows from the records
First rows of the Controls sheet
ControlKindPurposeTypical ownerFrequencyDuties it satisfiesDuties it supportsEvidence it producesISO/IEC 42001NIST AI RMFRecord
AI governance policy and accountability structurePolicyGives the organisation a single approved statement of how it will develop, buy and use AI, and names the people who are answerable for it, so that every other AExecutive sponsor for AIannual97AI policy; Board or executive approval of the AI policy; AI governance forum minutes; AI responsibility mapClause 5.1, 5.2, 5.3, 9.3; Annex A.2, A.3GOVERN 1.1, 1.2, 1.3, 2.1, 3.1https://aipolicytracker.org/controls/ai-governance-policy-and-accountability
AI impact and fundamental-rights impact assessmentProcessExamines how a planned AI use will affect the people, groups and communities it touches, with particular attention to discrimination and rights, and records theAI system ownerper_system47AI impact assessment; Impact assessment approval; Impact assessment procedure and templateClause 6.1.4, 8.4; Annex A.5MAP 5.1, 5.2; MEASURE 2.11https://aipolicytracker.org/controls/ai-impact-assessment
AI incident management and regulatory reportingProcessEnsures that harm or near-harm caused by an AI system is detected, contained, investigated and, where a rule requires it, reported to the right authority and afIncident coordinatorcontinuous95AI incident response playbook; AI incident record; Incident report to an authorityClause 10.2; Annex A.8.3, A.8.4MANAGE 4.1, 4.3; GOVERN 4.3, 6.2https://aipolicytracker.org/controls/ai-incident-management-and-reporting
AI interaction and use disclosure noticesProcessTells people, in plain language and at the right moment, that they are interacting with an AI system, that AI is being used in a decision about them or that theProduct owneron_material_change153AI interaction or use notice; Notice catalogue; Notice wording approvalAnnex A.8.2, A.8.5MEASURE 2.8; GOVERN 5.1https://aipolicytracker.org/controls/ai-interaction-and-use-disclosure
AI literacy and role-based training programmeTrainingGives everyone who builds, buys, operates or is overseen by AI systems the knowledge they need for their role, from general awareness to the specific skills of Learning and development leadannual13AI training completion records; Role-to-curriculum training matrix; AI training curriculum and materialsClause 7.2, 7.3; Annex A.4.6GOVERN 2.2, 4.1https://aipolicytracker.org/controls/ai-literacy-and-role-based-training
AI risk assessment and lifecycle risk registerProcessIdentifies, rates and treats the risks that a specific AI system poses to health, safety, rights and the organisation itself, and keeps that analysis alive fromAI system ownerper_system75AI system risk assessment; Per-system AI risk register; Residual-risk acceptanceClause 6.1.2, 6.1.3, 8.2, 8.3MAP 3, MAP 4, MANAGE 1.2, 1.3, 2.1https://aipolicytracker.org/controls/ai-risk-assessment

How to use it

  1. 1Request the files. Enter your name, company and work email in the form on this page. The XLSX download links arrive by email and work for 7 days.
  2. 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
  3. 3Fill in your rows. Complete the "Evidence tracker" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
  4. 4Check the duties against your situation. The "Evidence tracker" and "Controls" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
  5. 5Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.

Duties this template covers (107)

Each is cited in the file with its source reference and a link back to the record.

See all 107 duties →

Legal basis

Version history

Versions of AI Audit Evidence Tracker
VersionBuiltDatasetWhat changed
v1bb068ecd9dadFirst version, built from dataset bb068ecd9dad.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

What is in the AI Audit Evidence Tracker?

Evidence tracker: control, evidence expected, kind, owner, status, location, last reviewed. Status colouring for missing and available evidence. Controls sheet: every control on record with its duties and framework references.

Which duties does it cite?

107 recorded duties from Australian Voluntary AI Safety Standard, California SB 53, Colorado ADMT law (SB 26-189) and EU AI Act, including Guardrails 1 and 2, Guardrails 4, 5 and 6, Guardrails 7, 8 and 9, Business and Professions Code, Chapter 25.1 (as added by SB 53), Business and Professions Code Section 22757.12 (as added by SB 53) and Labor Code Section 1107 (as added by SB 53). Each row links to the record, and the record to the official source.

Who is it for?

The duties it cites fall on deployer / user organisation, provider / developer and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.

Is it free?

Yes. Request the XLSX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

How will I know when it changes?

Version v1 was built on 28 September 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.

Does completing it make us compliant?

No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.