Your ISMS says AI tool usage is controlled. The auditor's follow-up is always the same question, and "we asked the department heads" is the answer that turns a checkmark into a finding. This page is about producing the other kind of answer.
Produce the evidence freeBoth look like an AI inventory in the ISMS. Under audit questioning they behave very differently.
The distinction auditors care about is not effort, it is evidentiary class: assertion versus observation. Log-derived inventories are observations with dates on them.
Generic-safe mapping: your ISMS scoping decides the exact control references. These are the conversations where the report keeps appearing.
| ISMS conversation | The auditor's angle | What the report supplies |
|---|---|---|
| Asset and service inventory | Are cloud services in use identified and owned? | The observed AI service list, per period, with per-team attribution. |
| Supplier relationships | Are third parties handling data assessed? | Dated training verdicts and sovereignty flags per vendor found in use. |
| Acceptable use and awareness | Is the policy real or decorative? | The sanctioned split: policy versus observed behavior, quantified. |
| Data leakage prevention | What stops data leaving through unapproved channels? | Detection cadence plus blocked-attempt evidence from the filter, verified by re-runs. |
| Change and continual improvement | Does the ISMS learn? | Quarter-over-quarter deltas: tools found, blocked, sanctioned, drifted verdicts. |
A composite of how the interview actually goes when the evidence exists. Sample dialogue, real structure.
"How do you identify AI services in use?"
"Quarterly log-based audit: network exports matched against a daily-maintained register of classified AI domains. Here are the last four reports."
"How current is the reference data?"
"The register updates daily, roughly 300,000 domains screened per day, and each report states the register size at run time."
"How do you assess these vendors?"
"Each found tool carries a training verdict with the date the vendor's terms were checked, drawn from an ongoing review of 13,000+ terms documents. High-tier findings feed our supplier process."
"What happens with findings?"
"Triage into sanction, control or block, minuted in this decision table, with the block list verified by the following quarter's run."
"Who sees personal data during this?"
"The audit consumes hostnames, identities and timestamps. Uploads are discarded after each run and reports are deletable; here is the data-handling note."
"Can you demonstrate it now?"
"Yes, the free preview runs in minutes on any export. Would you like to pick the window?"
Auditors reward systems that survive the "show me now" question. This one is designed to be demonstrated live.
The document is built for filing; four habits keep the chain tidy.
The PDF's scope line and evidence statement are worded to stand alone. Editing or excerpting reintroduces the assertion problem you were solving.
Same 30-day window each quarter, noted in the ISMS procedure. Consistent method is half of what "repeatable" means to an auditor.
The report shows findings; a one-page decision table shows governance. Together they close the plan-do-check-act loop on paper.
The machine-readable table lets internal audit re-sort and sample without new requests. Auditors notice when checking is easy.
Retention detail for the ISMS note: reports live 90 days in the account and can be deleted earlier; the filed PDFs and CSVs are your permanent record, under your control.
Generic-safe composites of where AI-related findings actually come from in certification cycles.
An AI inventory last touched before the audit announcement. The quarterly cadence with dated PDFs makes staleness structurally impossible to hide and easy to avoid.
A tool in heavy use with no vendor assessment on file. Training verdicts per found tool mean the assessment queue is generated, not remembered.
An acceptable-use clause about AI with no measurement behind it. The sanctioned split is the measurement, and its trend is the improvement story.
Scope line, findings, per-user attribution, control evidence statement: the sample report shows the whole evidentiary shape on sample data.
Four reports a year, same window, filed with minutes. Plans with monthly allowances cover organizations that want tighter cadence; see pricing.
Before the certification or surveillance visit, re-read the last two reports and the decision tables. The interview script above is your rehearsal sheet.
If a visit does produce an AI-related finding, the corrective action is often literally "adopt the cadence": measurable, dated, and closable at the next surveillance.
Internal audit can run the whole loop themselves: export, upload, read. No vendor meeting required, which is why this control survives budget seasons.
It requires that your ISMS controls match your risks, and unmanaged AI services are a risk most scoping now includes. The evidence question follows automatically.
Dated, repeatable, method-stated observations are the strongest class of operational evidence an ISMS produces. That is precisely the report's construction.
Start now and you have one period now; certification conversations improve with every quarter filed. Four consecutive reports read as a functioning control.
Yes: re-run the same window and compare, or sample the CSV against raw logs. Repeatability is the design goal.
State the scope honestly: the audit covers the logged network. Off-network use is a policy and awareness matter, and auditors respect stated boundaries far more than silent ones.
No, it queues and prioritizes them. Verdicts identify which vendors need the full assessment first; the assessment itself stays your process.
"How do you know?" deserves a PDF, not a pause. The first one takes an afternoon.
Run the free audit