Skip to content

AI decision assurance & regulatory evidence

Regulatory confidence for consequential AI decisions.

QAi evaluates whether an AI-assisted decision stayed within the authority that applied at that moment, then preserves the action, named human decision, and independently observed execution outcome in one reviewable case record.

For banks, insurers & telecom operators · Beside the AI system. Never in its path.

CASE / REF-0427Synthetic banking case
01
AI recommendationApprove complaint refund

EUR 480 · 16:42:08 UTC

02
Authority at action timeREFUND-POLICY / v3.4

Complaints L2 · limit EUR 500 · valid at 16:42

03
Named human decisionApproved · Complaints L2

Decision owner recorded · 16:47:31 UTC

04
Execution receiptNo receipt observed

Payment cannot be established from the record

QAi findingInsufficient evidence
05

One consequential case · seven essential answers

When a decision is challenged, these are the questions that follow.

An auditor, regulator, risk committee, or customer asks how one AI-assisted decision was reached. Most institutions can answer some of these questions—from several systems, slowly.

QAi binds the complete answer into one reviewable case record, preserving what was known, what was decided, what was executed, and where the evidence remains incomplete.

Q1What authority did the AI have at that moment?

Q2What did it recommend or do?

Q3Was the action within the approved mandate?

Q4Was the required human involved?

Q5Who made the final decision?

Q6What was actually executed?

Q7Is the evidence complete and defensible?

Seven questions. One traceable, defensible case record.

Decision assurance beyond model performance

The regulatory evidence layer for consequential AI decisions.

Model monitoring measures signals such as accuracy, drift, bias, and technical behaviour. QAi can use those signals, then carries assurance to the institutional question: did the resulting action remain within approved authority, was the right human involved, and what was ultimately executed?

Core product

Decision assurance and evidence

Tests institutional actions against the authority that applied at that moment.

What it creates

Independently reviewable case records

Binds authority, action, evaluation, human decision, and execution into one reviewable record.

Clear boundary

Evidence for accountable functions

QAi reaches an operational finding. The institution and its accountable advisers reach the compliance conclusion.

Four distinct links. One reviewable case.

The case is only as defensible as the chain behind it.

QAi preserves each link separately so that approval, authority, and execution can be reviewed without collapsing them into one claim—even when source events arrive in a different chronological sequence.

01

Authority at that moment

The approved, versioned mandate that governed the case when the action occurred.

02

AI recommendation or action

What the AI proposed or did, preserved with its time, inputs, and provenance.

03

Named human decision

The accountable person, role, decision, and time whenever human judgment is required.

04

Independent execution receipt

Evidence from the executing system showing what the institution ultimately did.

Authority frames the action. Human judgment is recorded where required. Execution is established independently.

The doctrine

AI must not autonomously audit AI.

Model-assisted checks may surface and escalate a case. Closure remains grounded in deterministic evidence and accountable human judgment.

Every evaluation resolves to exactly one of four terminal states.

WITHIN_BOUNDARY

Within boundary

The observed action is supported by complete evidence and falls inside the authority that applied at that time.

OUTSIDE_BOUNDARY

Outside boundary

The evidence is complete enough to show that the action crossed a declared limit, condition, or mandate.

INSUFFICIENT_EVIDENCE

Insufficient evidence

The available record is insufficient to establish the authority, decision, or executed outcome required for a defensible conclusion.

UNOBSERVED

Unobserved

The action or outcome required for the evaluation was not observed in the relevant source. Silence is recorded, never interpreted as success.

Routing condition · not a resolution state

Human decision required determines who must decide and what decision evidence must be recorded. It never replaces the four-state evaluation result.

Evaluation dimensions

Two evaluations feed one overall case state.

A case may carry a decision evaluation and a separate transaction-evidence evaluation. The overall state remains insufficient whenever either required dimension is unresolved.

DEC.*

Decision evaluation

Answers whether the decision or action was permitted by the authority that applied at that moment.

Reviewer reads this as Was the institutional decision within mandate?
TRN.*

Transaction evidence

Answers whether the executed outcome can be established independently from the system that performed it.

Reviewer reads this as Can we establish what actually happened?

Evidence-gap property

A missing fact has one of two remediation paths.

This axis is separate from DEC.* and TRN.*. Either evaluation can encounter either kind of gap.

Obtainable

Absent, but producible

A mapped source can supply the missing record through retrieval, connection, or backfill.

Reviewer action Complete the evidence connection and re-evaluate.
Structural

Unobservable by design

No mapped source or future record can establish the missing fact within the current workflow.

Reviewer action Redesign the workflow or record the permanent limitation.

Ordering rules

Evidence discipline is enforced in the product.

01Missing evidence outranks a failed control.

02A human decision cannot close an incomplete record.

03Approval cannot make a failure disappear.

04Model-assisted checks may escalate; they can never close.

REF-0427 · illustrative synthetic data

The recommendation was permitted. The payment remains unproven.

The hero shows the evidence. Here is what happens when an auditor presses the case further.

Auditor asksThe record answersFinding
Was the decision permitted?Refund Policy v3.4; EUR 500 limit; valid at 16:42DEC.* · Within boundary
Was the required human involved?Named Complaints L2 owner approved at 16:47Recorded
Was the refund executed?The connected workflow provides no independent payment receiptTRN.* · Unobserved
What is the overall case state?Decision permitted; human recorded; execution unresolvedInsufficient evidence

KnownAuthority and human approval are recorded.

UnknownThe executed payment outcome.

Required nextAn independent execution receipt.

Refusing to conclude ahead of the evidence is not a gap. It is the product.
Synthetic review material

Take REF-0427 into the review room.

Download the five-page case pack with the seven answers, DEC.* and TRN.* findings, evidence inventory, ordering rules, and reviewer challenge prompts.

Download the pack

Regulatory confidence, case by case

The regulatory question is moving from “what is your policy?” to “show us what happened.”

AI regulation, operational-resilience requirements, and sector standards increasingly require institutions to demonstrate how consequential automated decisions were governed in practice.

NIS2 · Directive (EU) 2022/2555 ↗

Governance evidence

Operational records supporting oversight, reconstruction, and management accountability across covered essential and important entities.

ISO · NIST · ETSI

Assurance criteria

A consistent evidence structure that can be assessed against the institution’s selected standards and controls.

Regulatory context. QAi structures evidence relevant to these frameworks. Each institution and its advisers determine applicability and legal sufficiency.

Dates compliance teams are planning around

The timetable has moved. The evidence obligation has not.

Selected EU AI Act dates as amended by Regulation (EU) 2026/1744 ↗

02 Aug 2026Article 50 appliesTransparency obligations apply; limited transition below. Official text ↗

02 Dec 2027Annex III routeHigh-risk obligations under Regulation (EU) 2026/1744. Official text ↗

Earlier phases began on 2 February 2025 (Chapters I–II) and 2 August 2025 (GPAI rules), subject to exceptions and transitional provisions. For synthetic-content AI systems placed on the market before 2 August 2026, providers have until 2 December 2026 to meet Article 50(2)’s marking and detection obligations. Commission guidance ↗ The Annex I high-risk product route applies from 2 August 2028. Selected planning dates only; each institution confirms applicability with its advisers based on its systems, role, sector, and jurisdiction.

Out-of-band by design

Beside the AI system. Never in its path.

QAi observes records from the systems that recommend, approve, and execute. It is designed to operate outside the live decision path, keeping the operational workflow independent of QAi availability.

ObserveRead recommendation, decision, and execution records.

EvaluateResolve the authority that applied at that time.

EvidenceProduce a case record independently of the live flow.

Customer outcomesComplaints & refundsBanks · insurers · telecom
ClaimsClaims decisionsInsurers
Financial decisionsCredit adjudicationBanks
Risk operationsFraud triageCross-sector
Customer accessKYC & onboardingBanks · telecom

From your systems to a reviewable case

A defined evidence path. An operating profile agreed with the institution.

QAi connects approved records, maps the authority that applied, evaluates the case, and prepares evidence for accountable review. Source access, hosting, identity, encryption, residency, retention, isolation, and operational controls are established for the institution’s environment.

Clear roles · defensible accountability

The institution owns compliance. QAi makes it demonstrable.

QAi

Establishes the record

  • Records the AI recommendation or action
  • Resolves authority as it stood at that moment
  • Captures the named human decision
  • Treats execution as unproven absent an independent receipt
Institution

Governs and acts

  • Allows, blocks, releases, or executes
  • Owns approvals and case management
  • Determines legal and compliance conclusions
  • Decides whether evidence is sufficient for assurance

Liability traceability Who authorised what, on which basis, and what was ultimately executed remains visible in the case record.

InstitutionOwns compliance

QAiProvides the evidence

Advisers & auditorsAssess and assure

Regulators & courtsDetermine legal acceptability

QAi tests each AI-assisted action against the institution’s approved authority and preserves the resulting evidence. Legal, risk, audit, and compliance functions apply the wider legal and organisational context and remain accountable for their conclusions.

Shared scope

Define the decision

Agree the action, accountable owner, authority sources, decision point, execution system, and review objective.

Institution provides

Representative records

Selected recommendations, applicable policy versions, human decisions, execution confirmations, and a secure access route.

QAi configures

The case and authority map

Connect the records, preserve their provenance, apply the approved authority, and name missing or conflicting evidence.

Institution receives

A reviewable evidence pack

Case findings, evidence gaps, authority map, review trail, and the agreed path to workflow integration.

Discuss a workflow
hello@qai-global.com

Start with your workflow and goals. Share case data only through an agreed secure channel.

Independent validation path

Try to break the evidence model.

Independent reviewers can challenge the taxonomy, ordering rules, observation-completeness logic, and offline verification of the evidence pack against synthetic cases.

Taxonomy & case states

Ordering & closure rules

Pack integrity & offline verification