A policy document is not proof of anything
Plenty of organisations can produce an AI policy on request. Far fewer can show that a specific AI system was assessed, tested, approved with named sign-off, and monitored afterwards. The gap between having a policy and having evidence is where most AI governance programmes actually fail under scrutiny.
Borrowing from internal control thinking
The COSO Internal Control Framework offers a useful discipline here: control environment, risk assessment, control activities, information and communication, and monitoring activities. Applied to AI, this means a named control owner, a documented control design, evidence that the control actually operated, and periodic testing rather than a one-off sign-off.
Testing controls, not just describing them
Assurance work distinguishes control design effectiveness, whether the control would work if operated as described, from control operating effectiveness, whether it actually did. Testing this properly uses walkthroughs, inspection, sampling of evidence and reperformance, not just asking the team responsible whether everything is fine.
What a defensible evidence pack contains
At minimum: an AI system description, a harm and stakeholder assessment, a risk register entry, a testing and evaluation plan with a model card, a framework mapping showing how the system was assessed against the relevant standards, a risk treatment decision with named sign-off, and a monitoring plan covering what happens after launch. Each item should be specific to the system, not a generic template left unfilled.
The real test of the evidence pack
A useful check: if a regulator, auditor or senior leader asked why an AI system was approved, could the evidence pack answer that question on its own, without anyone needing to reconstruct the reasoning from memory. If it cannot, the governance work is not finished yet.
Learners build a full evidence pack across the AI Governance, Risk & Compliance Practitioner programme.