AI Evidence
by Formiti's Global DPO Team
A consolidated evidence repository for AI governance documentation, linking compliance artifacts to specific AI systems, assessments, remediation tasks, and suppliers.
Who uses this module?
AI Governance Leads, DPOs, Compliance Managers, Auditors.
What governance problem does it solve?
AI compliance evidence is often scattered across email threads, shared drives, and disparate systems. AI Evidence creates a single, indexed repository where every artifact is linked to its governance context — making audit readiness a default state rather than a scramble.
What are the key workflows?
- Upload evidence documents with structured metadata (type, owner, version)
- Link evidence to AI systems, assessments, remediation tasks, or suppliers
- Categorise by evidence type (policy, technical documentation, test results, approval records)
- Set review dates and track document currency
- Provide external links for cloud-hosted documentation
Upload evidence documents with structured metadata (type, owner, version)
Link evidence to AI systems, assessments, remediation tasks, or suppliers
Categorise by evidence type (policy, technical documentation, test results, approval records)
Set review dates and track document currency
Provide external links for cloud-hosted documentation
What evidence and reporting does it produce?
Built-in outputs for accountability and regulatory readiness
Evidence inventory by system, type, and status
Coverage analysis (systems with/without required evidence)
Review date compliance tracking
Evidence linkage map (system → assessment → task → evidence)
How does it connect to other Privacy360 modules?
- Linked to AI System Register as the anchor
- References AI Assessment findings and remediation task completions
- Supplier due diligence documents stored and linked
- Supports review workflow by demonstrating compliance readiness
- Mirrors Privacy Documents pattern for AI-specific context
What are some example use cases?
A governance lead uploads the model card and fairness testing results for a high-risk AI system, linking them to the relevant assessment and system record.
An auditor requests all evidence for a specific AI system; the evidence repository produces a complete, linked inventory within minutes.
A remediation task requires proof of updated human oversight procedures; the system owner uploads the document and links it to both the task and the system record.
Related modules
AI System Register
Structured inventory of every AI system with EU AI Act risk tier, named business and technical ownership, and AI Bill of Materials provenance.
AI Assessments
A 13-section EU AI Act and GDPR assessment wizard that scores prohibited practice, high-risk, GPAI and transparency outcomes with evidence.
AI Remediation
Turn AI assessment findings into assigned, dated remediation tasks with evidence requirements — so gaps close between assessment cycles.
Privacy Documents
A governed repository for privacy policies, notices and procedures with version control, review cycles and external reviewer access.