Also known as: AI Audit Β· Audit Β· Artificial Intelligence Audit
An AI Audit is a structured evaluation of an AI system, model, or governance process against defined criteria. It may examine performance, compliance, risk controls, documentation, or trustworthiness claims and is most valuable when conducted with sufficient independence and transparency.
An AI audit is, with respect to an AI system or model, an evaluation of performance and/or process against transparent criteria. An audit is broader than a 'conformity assessment' which is 'the demonstration that specified requirements relating to a product, process, system, person or body are fulfilled.' As noted in the RFC, entities can audit their own systems or models, be audited by a contracted second party, or be audited by a third party. To distinguish audits from other evaluations, we use the term audit to refer only to independent evaluations. An audit can be structured merely to verify the claims made about AI. Alternatively, it can be scoped more broadly to evaluate AI system or model performance vis a vis attributes of trustworthy AI, regardless of claims made. Simply put, an audit is an assurance tool, characterized by precision and providing an independent evaluation of an AI system, claims made about that system, and/or the degree to which that system is trustworthy. For ease of reading, we include audits in the umbrella term 'evaluations.'
A comprehensive assessment of conformance to standards, policies or legal requirements for data gathering, storage and/or usage.
A side-by-side comparison of AI Risk Assessment and AI Audit. Understand how a risk process supports decisions before and during deployment, while an audit evaluates systems or governance against defined criteria.
A side-by-side comparison of AI Assurance and AI Audit. Understand how assurance is a broader evidence-generating confidence practice, while audit is a structured evaluation against defined criteria.
A side-by-side comparison of Red Teaming and AI Audit. Understand how the terms differ, when each applies, and what the distinction means for AI governance, system design, or assurance evidence.