Decision assurance and evidence
Tests institutional actions against the authority that applied at that moment.
AI decision assurance & regulatory evidence
QAi evaluates whether an AI-assisted decision stayed within the authority that applied at that moment, then preserves the action, named human decision, and independently observed execution outcome in one reviewable case record.
For banks, insurers & telecom operators · Beside the AI system. Never in its path.
EUR 480 · 16:42:08 UTC
Complaints L2 · limit EUR 500 · valid at 16:42
Decision owner recorded · 16:47:31 UTC
Payment cannot be established from the record
The scrutiny test
One consequential case · seven essential answers
An auditor, regulator, risk committee, or customer asks how one AI-assisted decision was reached. Most institutions can answer some of these questions—from several systems, slowly.
QAi binds the complete answer into one reviewable case record, preserving what was known, what was decided, what was executed, and where the evidence remains incomplete.
Q1What authority did the AI have at that moment?
Q2What did it recommend or do?
Q3Was the action within the approved mandate?
Q4Was the required human involved?
Q5Who made the final decision?
Q6What was actually executed?
Q7Is the evidence complete and defensible?
Seven questions. One traceable, defensible case record.
What QAi is
Decision assurance beyond model performance
Model monitoring measures signals such as accuracy, drift, bias, and technical behaviour. QAi can use those signals, then carries assurance to the institutional question: did the resulting action remain within approved authority, was the right human involved, and what was ultimately executed?
Tests institutional actions against the authority that applied at that moment.
Binds authority, action, evaluation, human decision, and execution into one reviewable record.
QAi reaches an operational finding. The institution and its accountable advisers reach the compliance conclusion.
The evidence chain
Four distinct links. One reviewable case.
QAi preserves each link separately so that approval, authority, and execution can be reviewed without collapsing them into one claim—even when source events arrive in a different chronological sequence.
The approved, versioned mandate that governed the case when the action occurred.
What the AI proposed or did, preserved with its time, inputs, and provenance.
The accountable person, role, decision, and time whenever human judgment is required.
Evidence from the executing system showing what the institution ultimately did.
Authority frames the action. Human judgment is recorded where required. Execution is established independently.
How QAi concludes
The doctrine
Model-assisted checks may surface and escalate a case. Closure remains grounded in deterministic evidence and accountable human judgment.
Every evaluation resolves to exactly one of four terminal states.
The observed action is supported by complete evidence and falls inside the authority that applied at that time.
The evidence is complete enough to show that the action crossed a declared limit, condition, or mandate.
The available record is insufficient to establish the authority, decision, or executed outcome required for a defensible conclusion.
The action or outcome required for the evaluation was not observed in the relevant source. Silence is recorded, never interpreted as success.
Human decision required determines who must decide and what decision evidence must be recorded. It never replaces the four-state evaluation result.
Evaluation dimensions
A case may carry a decision evaluation and a separate transaction-evidence evaluation. The overall state remains insufficient whenever either required dimension is unresolved.
Answers whether the decision or action was permitted by the authority that applied at that moment.
Answers whether the executed outcome can be established independently from the system that performed it.
Evidence-gap property
This axis is separate from DEC.* and TRN.*. Either evaluation can encounter either kind of gap.
A mapped source can supply the missing record through retrieval, connection, or backfill.
Reviewer action Complete the evidence connection and re-evaluate.No mapped source or future record can establish the missing fact within the current workflow.
Reviewer action Redesign the workflow or record the permanent limitation.Ordering rules
01Missing evidence outranks a failed control.
02A human decision cannot close an incomplete record.
03Approval cannot make a failure disappear.
04Model-assisted checks may escalate; they can never close.
Case interrogation
REF-0427 · illustrative synthetic data
The hero shows the evidence. Here is what happens when an auditor presses the case further.
KnownAuthority and human approval are recorded.
UnknownThe executed payment outcome.
Required nextAn independent execution receipt.
Refusing to conclude ahead of the evidence is not a gap. It is the product.
Download the five-page case pack with the seven answers, DEC.* and TRN.* findings, evidence inventory, ordering rules, and reviewer challenge prompts.
Why now
Regulatory confidence, case by case
AI regulation, operational-resilience requirements, and sector standards increasingly require institutions to demonstrate how consequential automated decisions were governed in practice.
Case-level records of the AI-supported decision, applicable authority, human involvement, and resulting outcome.
Structured evidence linking an ICT-supported workflow to controls, accountable owners, and execution.
Operational records supporting oversight, reconstruction, and management accountability across covered essential and important entities.
A consistent evidence structure that can be assessed against the institution’s selected standards and controls.
Regulatory context. QAi structures evidence relevant to these frameworks. Each institution and its advisers determine applicability and legal sufficiency.
Dates compliance teams are planning around
Selected EU AI Act dates as amended by Regulation (EU) 2026/1744 ↗
02 Aug 2026Article 50 appliesTransparency obligations apply; limited transition below. Official text ↗
02 Dec 2027Annex III routeHigh-risk obligations under Regulation (EU) 2026/1744. Official text ↗
Earlier phases began on 2 February 2025 (Chapters I–II) and 2 August 2025 (GPAI rules), subject to exceptions and transitional provisions. For synthetic-content AI systems placed on the market before 2 August 2026, providers have until 2 December 2026 to meet Article 50(2)’s marking and detection obligations. Commission guidance ↗ The Annex I high-risk product route applies from 2 August 2028. Selected planning dates only; each institution confirms applicability with its advisers based on its systems, role, sector, and jurisdiction.
Where it runs
Out-of-band by design
QAi observes records from the systems that recommend, approve, and execute. It is designed to operate outside the live decision path, keeping the operational workflow independent of QAi availability.
ObserveRead recommendation, decision, and execution records.
EvaluateResolve the authority that applied at that time.
EvidenceProduce a case record independently of the live flow.
Security & deployment
From your systems to a reviewable case
QAi connects approved records, maps the authority that applied, evaluates the case, and prepares evidence for accountable review. Source access, hosting, identity, encryption, residency, retention, isolation, and operational controls are established for the institution’s environment.
Product boundary
Clear roles · defensible accountability
Liability traceability Who authorised what, on which basis, and what was ultimately executed remains visible in the case record.
InstitutionOwns compliance
QAiProvides the evidence
Advisers & auditorsAssess and assure
Regulators & courtsDetermine legal acceptability
QAi tests each AI-assisted action against the institution’s approved authority and preserves the resulting evidence. Legal, risk, audit, and compliance functions apply the wider legal and organisational context and remain accountable for their conclusions.
Start with one workflow
Focused evidence sprint · typically 2–4 weeks
A typical sprint begins once the workflow scope and usable access to representative records are agreed. One consequential workflow and one named authority owner keep the work focused and the findings reviewable.
Agree the action, accountable owner, authority sources, decision point, execution system, and review objective.
Selected recommendations, applicable policy versions, human decisions, execution confirmations, and a secure access route.
Connect the records, preserve their provenance, apply the approved authority, and name missing or conflicting evidence.
Case findings, evidence gaps, authority map, review trail, and the agreed path to workflow integration.
Start with your workflow and goals. Share case data only through an agreed secure channel.
Review before a first conversation
Interrogate REF-0427 and see why a permitted decision can still produce an insufficient-evidence finding.
Open the PDF 02Security & deploymentFollow the out-of-band path from mapped source records and authority to a reviewable case.
Review deployment 03Reviewer pathSee the taxonomy, closure rules, observation logic, and pack-integrity questions open to challenge.
Review the scopeIndependent reviewers can challenge the taxonomy, ordering rules, observation-completeness logic, and offline verification of the evidence pack against synthetic cases.
Discuss an independent reviewTaxonomy & case states
Ordering & closure rules
Pack integrity & offline verification
Institutional sprint. Your data, findings, and results remain yours. Publication requires written consent.
Independent review. Reviewer observations remain attributable to the reviewer and are published only with written consent.