
AI assurance under ISAE 3000: the evidence object the engagement is missing
System notes
ISAE 3000 (Revised) requires the practitioner to obtain sufficient appropriate evidence and to document the work so that an experienced practitioner with no prior connection to the engagement can understand the basis for the conclusion.
For assurance over an AI system's operating effectiveness there is no established evidence object of record: the system under review emits answers, not inspectable records of how each answer was reached.
A governed decision here emits a candidate evidence object: the rule set pinned to a content hash, each seat's clause-by-clause derivation in machine-comparable form, the deterministic gate's disposition, and a permanent receipt.
The gate refuses to authorise a unanimous verdict when the underlying derivations diverge, and the refusal is itself a permanent record.
The gate's first version passed a false convergence (clause numbers matched, meanings did not); the defect, the retraction, and the repaired seal are all public receipts.
In 72 controlled calls, auditable structure (declared-absent records, flip conditions, rejected alternatives) appeared in zero of 48 ungoverned calls and only under the governing constitution.
A calibration study of 30 oracle-labelled synthetic cases through the production gate recorded zero wrongful authorisations across 30 sealed panels; seat accuracy was 30/30 (glm-5.2) and 29/30 (kimi-k2.7), and the weak seat's transport failures blocked every NEGATE seal.
Every sealed record must declare the evidence it did not receive, and a panel that cannot conclude seals an abstention naming the absence — logic that maps to ISA 705's inability-to-obtain-sufficient-appropriate-evidence basis for a modified opinion.
A governed call costs $0.0006 to $0.0024 and a three-seat sealed decision about half a cent, so per-decision evidence is cheaper than the working paper it would support.
No claim of ISAE 3000 conformance is established: the calibration evidence covers 30 synthetic determinate fixtures in one task class, criteria suitability is untested against real engagement subject matter, and the mapping to the standards is a candidate mapping, not an accepted one.
Evidence ledger 10 · tier-ranked · API
5 more ranked claims
Ask this article · 8 suggested prompts
Text the build (+14245134626) or WhatsApp — slug|question creates a question node. Paste evidence with ingest slug|q:NODE_ID|your paste.