What can your AI system evidence today?
Compliance scores cannot be audited. The question that can be is narrower, harder and far more useful: what is on the record for this system, right now, and where does the record run out?
The short answer
- An AI system is governed only as far as its weakest link, so the useful unit of measurement is a chain of records, not a score.
- Nine links, from registered to release gate. Each one either has a record behind it or it does not.
- Nearly every portfolio breaks in the same place: between controls scoped and controls effective.
The wrong question, asked confidently
Ask most AI governance tooling whether you are compliant with a framework and it will answer with a number. Seventy-three per cent. Amber. Three of five stars. The number is arithmetic performed on judgements that are not commensurable: a missing model card and an unreviewed adverse decision do not belong on the same axis, and the weights that put them there are a vendor's opinion rather than a regulator's.
The deeper problem is that a score cannot be audited. No auditor accepts a percentage in place of a record. They ask what you did, when, who decided it, and what you can show them. A governance programme built to move a number will optimise for the number, and then discover during its first real audit that the number was never the deliverable.
A system is only as governed as its weakest link, and a score is designed to hide exactly that.
The nine links
Replace the score with a chain. Each link is a record that either exists or does not, and the sequence matters because the later links depend on the earlier ones being true.
Where the chain breaks first
In practice the break is almost always between link three and link four: controls scoped, but not evidenced as effective. The reason is structural rather than cultural. Scoping is a one-off modelling exercise that a small team can complete in weeks. Effectiveness requires evidence from control owners and independent testing on a recurring cadence, which is a standing obligation on people who do not report to the governance function.
This is why the portfolio view matters more than any single system's page. Thirty-one of forty-eight systems clearing link three and only fourteen clearing link four is not a data quality problem to be cleaned up before the board sees it. It is the finding.
A test worth running
Pick your most business-critical AI system. Without asking its owner, try to produce: the current risk assessment, the list of controls scoped to it, the last independent test result, and the approval that let it into production. Time yourself. That duration is your real governance posture, and no score will improve it.
Five honest states, and no sixth
If a score is out, something has to take its place at the top of a report. Five states are enough, and each is defensible in a room with an auditor in it.
Notice what is absent. There is no state that means compliant. Compliance is a legal conclusion drawn by a qualified person against a specific regulation and a specific set of facts, and a platform that asserts it is taking a judgement it is not entitled to make, on behalf of someone who will be asked to defend it.
What to do on Monday
None of this requires a platform to begin. It requires deciding that the chain, not the score, is what you report.
- Write the nine links down and agree them with internal audit before you instrument anything. If audit will not accept the chain, the tooling cannot save it.
- Register every AI system, including the ones built in a business unit without telling anyone. An inventory that excludes the uncomfortable entries is not an inventory.
- Pick one internal control library and map frameworks onto it. Adopting a second standard should add a view, never a second backlog.
- Make effectiveness depend on independent testing rather than self-attestation, and accept that your first honest report will look worse than your last dishonest one.
Questions we get asked
Published 2 September 2026 by ENGARP AI Engineering