Statements for those auditing AI systems and the evidence behind them: engagement scoping, independence, evidence sufficiency and reporting obligations.
11 statements published at v1.29
What this overlay covers
INScoping an engagement so that what was and was not examined is unambiguous.
INMaintaining and demonstrating independence from the system being examined.
INJudging whether the evidence presented is sufficient to support the conclusion sought.
INReporting findings, including reporting that no conclusion can be reached.
INHandling pressure to soften or withdraw a finding.
OUTProducing the assurance evidence, which is D6. The overlay covers the obligations of the person examining it.
OUTStatutory audit competence outside AI systems.
OUTCertification decisions, which belong to the certifying body rather than the auditor.
How it combines with core statements
An audit credential is assembled from D6 evaluation and assurance statements at L3 or L4, plus O3 statements covering engagement, independence and reporting. D6 produces the evidence; O3 governs the person examining it.
Assembly shape
Core
Domain statements at the level the practitioner must hold themselves
Overlay
O3 statements covering the obligations of this function
An overlay adds statements. It never modifies or replaces a core statement.
Statements by level
Every identifier is a permanent address. Indicators are normative; they state what would be observed in a person who meets the statement.