The European Union's Artificial Intelligence Act (Regulation (EU) 2024/1689) represents one of the most significant shifts in how technology systems are audited and assured. For the first time in decades, a major jurisdiction is actively reversing the modern trend of superficial, interview-heavy audits and restoring the original, rigorous, evidence-based approach that defined auditing for most of its history.
This is not an innovation. It is a reset.
Auditing was originally conceived as a verification discipline - not a confirmation exercise. The core principle was simple: assurance is based on verified objective evidence. Auditors were expected to examine program code, test transactions, inspect records, and independently corroborate management's claims. The burden of proof rested firmly on the auditee to demonstrate compliance through verifiable artefacts.
Over the past 10-20 years, however, this fundamental principle has been progressively eroded in many areas of IT and systems auditing. Several factors contributed to this decline:
- Knowledge gap: Many auditors lacked deep technical understanding of complex computer systems, algorithms, data pipelines, and emerging technologies such as AI and machine learning. As systems grew more sophisticated, auditors increasingly relied on management explanations rather than independent verification.
- Commercial time pressure: Audit firms, operating under tight deadlines and fee competition, often prioritised efficiency and client satisfaction over depth. The goal shifted from "prove it" to "get the audit done and signed off." This led to an over-reliance on interviews, walkthroughs, and management representations - methods that are quicker and less confrontational but far less reliable.
- Documentation fatigue: As regulatory and compliance requirements multiplied, many organisations produced voluminous policy documents that looked impressive on paper but had little connection to actual operational practice. Auditors, facing time constraints, often accepted these documents at face value rather than testing whether the documented controls were genuinely operating as described.
The result has been a gradual drift toward superficial auditing, where the appearance of control is accepted more readily than the substance. This degradation has been particularly pronounced in technology and information audits, where the complexity of systems meant evidence-based verification required skill and time.
The Current Audit Approach vs. the New Reality
Before the EU AI Act, auditing an AI or complex IT system typically followed a familiar pattern:
- Interviewing key personnel (developers, data scientists, compliance officers, and senior management).
- Reviewing high-level policies, procedures, and governance frameworks.
- Accepting management representations and assertions about how the system functioned in practice.
- Conducting limited spot-checks or sample testing of outputs and processes.
This "interview-heavy" model worked reasonably well for conventional software systems. Outcomes were largely deterministic, decision logic was relatively transparent, and human oversight was clearly documented. Auditors could reasonably rely on explanations provided during interviews, supported by policy documents.
Under the EU AI Act, this approach is fundamentally inadequate - especially for high-risk AI systems listed in Annex III (e.g., those used in employment, credit scoring, law enforcement, critical infrastructure, or biometric identification). Regulators, notified bodies, and market surveillance authorities now require verifiable, documented, and often immutable evidence that the system meets the Act's strict requirements across its entire lifecycle - from design and development through deployment, monitoring, and eventual decommissioning.
The EU AI Act: Forcing a Return to First Principles
The EU AI Act is now forcing a decisive correction. For high-risk AI systems, the Act explicitly rejects the modern, interview-centric model and reinstates the original evidence-based standard.
Regulators and notified bodies are no longer willing to accept verbal assurances, high-level policy statements, or management representations as primary evidence. Instead, they require verifiable, documented, and often immutable evidence that demonstrates compliance across the entire lifecycle of the AI system.
This shift is not creating something new - it is restoring what auditing was always intended to be: an independent, evidence-driven process that places the burden of proof on the organisation claiming compliance.
The Act achieves this through several interlocking requirements:
Technical Documentation (Article 11 & Annex IV)
Providers must prepare and maintain highly detailed technical documentation before placing a high-risk AI system on the market or putting it into service. This documentation must be kept up to date and must contain sufficient detail for notified bodies and national authorities to independently assess compliance. It covers the system's intended purpose, design specifications, data governance processes, risk management measures, testing and validation results, human oversight mechanisms, and more. These documents must be kept for 10 years.
Immutable Logging and Traceability (Article 12)
High-risk AI systems must automatically record events (logs) in a way that enables traceability of the system's outputs and decisions. Critically, these logs must be immutable - meaning they are generated and stored in a tamper-proof manner that prevents alteration, deletion, or manipulation after the fact. This ensures a reliable, chronological audit trail that regulators can trust. Without immutable records, it becomes impossible to demonstrate that the system operated as documented or to investigate incidents effectively.
Quality Management System - The Only Pathway to Compliance (Article 17 & prEN 18286)
The implementation and maintenance of a formal Quality Management System (QMS) is not merely recommended - it is the only structured and recognised pathway to demonstrating compliance for high-risk AI systems under Annex VII. The QMS must integrate all key obligations: risk management (Article 9), data quality and governance (Article 10), technical documentation, human oversight (Article 14), accuracy and robustness (Article 15), cybersecurity, and post-market monitoring (Article 72).
The emerging harmonised standard prEN 18286 translates Article 17 into an auditable QMS framework specifically designed for EU AI Act purposes. Conformity assessment under Annex VII requires notified bodies to evaluate both the QMS and the supporting technical documentation. This is a fundamental departure from traditional audits: the focus shifts from "what people say the system does" to "what the documented processes, records, and logs demonstrably show."
Conformity Assessment and Notified Body Scrutiny (Article 43 & Annex VII)
For many high-risk systems, conformity assessment must involve a notified body. These bodies are empowered to examine technical documentation in detail, request additional evidence or conduct their own tests if the submitted materials are insufficient, review the effectiveness of the QMS through periodic audits, and - in limited cases - request access to training data or models (subject to intellectual property and trade secret protections).
This level of scrutiny makes it impossible to rely primarily on interviews. In essence, the AI Act is saying: "We no longer accept 'trust us' as a substitute for proof."
What This Means for Companies
The move to evidence-based auditing has far-reaching implications across multiple dimensions:
1. Documentation Becomes a Strategic and Operational Priority
Technical documentation, immutable logs, validation reports, bias testing records, risk assessments, and decision logs are no longer internal working documents - they are regulatory deliverables. Every claim about fairness, accuracy, robustness, or risk mitigation must be supported by contemporaneous, verifiable evidence. Companies that treated documentation as an afterthought during development will face significant remediation costs.
2. Audits Become Significantly More Technical and Forensic
Auditors and notified bodies will increasingly scrutinise code-level decisions, dataset provenance and quality, model cards, training and validation protocols, post-market monitoring logs, and the effectiveness of human oversight mechanisms. Traditional "management interview" days will be replaced by deep dives into data pipelines, test harnesses, and audit trails.
3. The Quality Management System Is Mandatory - Not Optional
Organisations can no longer approach AI compliance as a collection of standalone activities. They must implement and maintain a formal, auditable QMS that demonstrably addresses all Article 17 requirements. This has major implications for organisational structure, process design, tooling, and internal governance. For many companies, this will require substantial investment in new systems and capabilities.
4. Substantially Higher Costs and Resource Demands
The shift demands significant upfront and ongoing investment in technical documentation infrastructure, immutable logging and audit trail capabilities, QMS implementation and certification readiness, and skilled personnel (or external expertise) capable of producing regulator-grade evidence. Non-EU companies face additional complexity because they must satisfy these requirements to access the European market - often without the benefit of local notified bodies or established compliance ecosystems.
5. Increased Scrutiny on Changes and Lifecycle Management
Any "substantial modification" to a high-risk AI system (as defined in the Act) may trigger a new conformity assessment. This means companies must maintain continuous evidence of compliance, not just a one-time snapshot. Post-market monitoring (Article 72) and serious incident reporting (Article 73) further extend the evidentiary burden throughout the system's operational life.
6. Competitive Differentiation Opportunity
While the requirements are demanding, organisations that build robust evidence-based compliance programmes early will gain a significant advantage. They will be able to demonstrate trustworthiness to regulators, customers, and partners more effectively than competitors still relying on traditional audit approaches.
The Bottom Line
The EU AI Act has moved AI auditing from a trust-based model (interviews, assertions, and high-level policy reviews) to a proof-based model centred on verifiable evidence, immutable records, and a formal Quality Management System.
For any company developing or deploying AI systems that fall within the scope of the Act - especially high-risk systems - the implications are profound. Documentation, logging, and QMS implementation are no longer optional overhead; they are core to market access and legal operation in Europe.
Organisations that continue relying primarily on traditional interview-led audit practices for high-risk AI systems face a high risk of non-compliance findings, delayed market entry, costly remediation, and potential enforcement action. The era of "trust us, it works" in AI auditing is over. Those that embrace the new evidence-based paradigm early - treating technical documentation, immutable audit trails, and robust quality management as strategic assets - will be best positioned to succeed in the European market and beyond.