Registers, DPIAs, audit responses and insurer forms all ask versions of the same three questions: what was in use, what did the vendor's terms say at the time, and was it approved then. This page shows how a log-based audit supplies all three links, dated.
Whatever the framework, the questions decompose the same way. Each link is a report field, not a reconstruction.
The tool table: every AI hostname observed in the window, with category, per-user attribution and usage volume. Observed, not remembered.
Each tool's training verdict carries the date the vendor's terms were reviewed. "As of" statements replace impressions, and changed verdicts between runs are findings.
The sanctioned split records your approved list against reality, per run. A year later you can still show what the policy state was in any given quarter.
Your triage minutes plus the next report's deltas close the loop: found, decided, verified. That is the sentence auditors and regulators want to read.
The chain's strength is temporal: every link is dated, so the file answers "what did you know and when" without reconstruction. Reconstruction is where compliance stories fall apart.
| Your document | What it needs | Report field that supplies it |
|---|---|---|
| Processing register | Third parties actually touching data | Tool table reconciled against recorded processors |
| DPIA queue | Which assessments to run first | Training verdicts x user counts x department attribution |
| Vendor register | Suppliers in use without agreements | Unsanctioned tools with real usage, sorted by volume |
| Risk register | Quantified, dated exposure entries | High-risk and abusive counts per period, CSV import |
| Audit and certification responses | "How do you know?" answers | The PDF filed unedited, method statement included |
| Insurer questionnaires | AI usage controls, evidenced | Cadence plus the last two reports as attachments |
Three working situations, before and after the chain.
Before: "we believe staff mostly use approved tools." After: "31 tools observed, 6 sanctioned, here is the migration queue with dates." The second version wins budget and respect.
Before: interviews and hope. After: a targeted window export answers which tools and identities in hours, and the standing baseline shows whether this was new behavior.
Before: a scramble to reconstruct. After: quarterly PDFs on file, each with scope lines and dated verdicts, plus minutes showing decisions. The response drafts itself.
The evidence process itself stays defensible: hostnames, identities and timestamps only, uploads discarded after each run, reports deletable, operated by an EU company.
Compliance owns the chain; IT owns the mechanics. The interface is deliberately thin.
One export per quarter, same window, identity column in. Twenty minutes of their time; the IT manager page is written to be forwarded as the request.
The upload or the reading, the triage minutes, the filing, and the delta narrative. No console access needed, no dependency on security headcount.
A 45-minute quarterly read with IT and the affected department heads: verdict changes, new tools, sanctioned-share delta. Minutes from that meeting are link four of the chain.
Abusive flags and high-sovereignty findings route to legal and HR through the same minutes. The report's flags mean escalations arrive pre-triaged, not as surprises.
Page three of the sample report carries the control evidence statement, written to be filed as-is. If that paragraph fits your files, everything upstream of it will too.
Evidence value is mostly maintained, not created. The habits, in the order they get skipped:
Excerpting reintroduces the assertion problem. The report's scope line and statement are written to stand alone; let them.
Same 30 days every quarter. Method consistency is half of what makes trend claims defensible.
One page: findings acknowledged, decisions made, owners named. The report shows facts; minutes show governance.
Machine-readable copies let internal audit resample without new requests, which is the cheapest credibility you will ever buy.
"Logged network only; off-network use governed by policy" in every filing. Stated boundaries survive scrutiny; silent ones do not.
Four quarters of this and your AI file answers auditors, insurers and regulators from the shelf. That is the whole point of a chain.
You need one log export from IT per period; the upload and reading need no technical background. Many officers run the whole loop after the first walkthrough.
They are dated observations from an ongoing review of 13,000+ vendor terms, built for triage and citation. Final legal weight is always your counsel's call.
It prioritizes them: tools with heavy use, sensitive departments and adverse verdicts float to the top. The GDPR page details the mapping.
The delta is itself a finding: it triggers a vendor review and shows your process catches drift, which is exactly what examiners look for.
Minimal by design: hostnames, identities, timestamps; no prompt content; uploads discarded; reports deletable within 90 days. The description fits one register row.
Quarterly reports from $60 to $99 each depending on packs, or plan allowances for monthly cadence. Details on pricing.
Link one is a free upload away. Every document you owe someone gets easier from there.
Run the free audit