DEV Community

lizer yang for SmartGate

Posted on

AI Compliance: The Evidence Trail an Auditor Expects

Originally published at AI Compliance: The Evidence Trail an Auditor Expects on smartgate.network.

A shorter version of "AI Compliance: The Evidence Trail an Auditor Expects" — the full piece lives at smartgate.network.

What the full piece covers

  • ai compliance: the four questions an evidence review asks — A requirement gets easier once it is translated into a mechanical question: can you produce the record?
  • ai governance compliance: the frameworks, and the artefact each one names — Frameworks read as competing checklists, but they name a small number of artefacts and mostly agree on them.
  • ai audit trail: the fields one row must carry — An audit trail is a schema before it is a system.
  • ai agent audit: attributing a call to an agent, not an account — A single request can pass through a session, an orchestration run, several steps and a tool call before anything leaves your network, and every hop has a natural identity.
  • mcp logging: what the protocol gave you, and what changed — An MCP deployment once had a protocol-native answer here.
  • ai agent monitoring: from an event stream to a decision — Monitoring is what you do with the rows, and it is where teams spend the most effort for the least evidence.
  • agent observability: the minimum signal set that survives scrutiny — Agent observability has converged on one shape: a span per model call and a span per tool call, nested under the request that caused them, with attributes rather than prose in the span name.
  • mcp monitoring: health, limits and drift at the tool boundary — Where a tool boundary exists, it sees what no client sees, and several of those things are control events rather than performance metrics.
  • How to export evidence for an auditor — An export is the point at which the record becomes someone else's data.
  • What you may claim, and what you may not — Most compliance problems in tooling documentation are claim problems rather than engineering problems.
  • Limitations — This page describes what a record must contain, how a retention period is chosen and how an export is produced.

Read the full piece: AI Compliance: The Evidence Trail an Auditor Expects on smartgate.network.

Top comments (0)