GovernAuditx, accounted for
Run an AI audit from plan to sealed archive.
A risk-based plan, independence declared, design and operating tests, two-person review and a sealed archive anyone can verify.
Engagement · AI agents: Day 1 Plan approved (against a board minute); Day 4 Scope frozen (independence declared); Day 12 Design, then operation (samples replay identically); Day 19 Finding answered (by management); Day 26 Archive sealed (timestamped, verifiable).
In short
Audit in ColossalX runs the internal-audit lifecycle for AI systems, from a risk-based plan approved against a board minute to a sealed, timestamped archive. Engagements open only with evidence for their trigger, independence is declared, design and operation are tested on samples that replay identically, and the preparer, reviewer and signer are always different people.
An AI audit is assembled from screenshots weeks later, and the person who did the work signs it.
ColossalX samples graded evidence, refuses sign-off by anyone who touched the work, and seals the archive.
How it works
From a proven exposure to a sealed archive.
A proven exposure on an agent justifies an unplanned audit. A person opens it, the work is tested and reviewed, and the archive is sealed.
01 Opened with a reason
A proven exposure raises a candidate; a person opens the engagement.
02 Tested twice
Design is tested before operation, on samples that replay identically.
03 Finding answered
Management responds, and an action plan opens one owned issue.
04 Archive sealed
Sign-off by someone who did no work seals the archive.
What you see
An audit finding, closed only on a verified re-test.
An audit finding that became owned work, raised from the audit with its root cause recorded, and closed only when a verified re-test resolved it.
- Plan on risk
- Open with a reason
- Test, then review
- Report, sign, seal
Read the detail, step by step4
- Plan on risk. An audit universe with AI systems and third parties drives the plan. Each auditable entity carries a risk rating a person confirms in writing and a cycle from monthly to every three years. Management approves the plan against a board or audit-committee minute, and the person who drafted it cannot approve it.
- Open with a reason. Engagements open only when the evidence for their trigger exists. Triggers are scheduled, regulatory, risk-based or event-driven. Proven exposures, advisories and incidents raise candidates for an unplanned audit; a person opens one or dismisses it with a reason, and nothing opens by itself from a signal.
- Test, then review. Design before operation, samples that replay, and a second reviewer. Each person declares their own independence, with a conflict check against controls they decided or own issues on. Scope freezes when fieldwork starts. Workpapers record verdict, rationale, preparer and reviewer, and reliance on automated monitoring voids itself if the monitor stops being healthy.
- Report, sign, seal. Sign-off by someone who did no work seals a timestamped archive. The audit report carries a conformance statement generated from the gates, naming each gate that did not hold. Approval seals the engagement, workpapers, findings, decisions, report and evidence into an archive with a public timestamp anyone can verify.

3notes
- Raised from an audit
- Root cause recorded
- Closed by verified re-test
How it connectsx, accounted for
Where an audit finding goes next.
A finding is owned work and a risk, tracked until a newer test proves it fixed.
An action plan opens one issue with an owner and a due date, closed on a newer test.
Each non-conformity opens a risk entry whose rating and closure follow the finding.
Risk acceptances
An accepted finding carries a reason and an end date, and lapses back into open work.
Audit tests feed the health label each control carries in compliance.
Honest by design
What it does, and what it does not.
Sealed archive · what it proves: Record unchanged Verifiable by anyone; Timestamp From a public authority; Completeness Not proven by the seal; Checklists Starting content, for review. Re-check any time.
What it does not do
x, not measured
The sealed archive proves the record has not changed since sealing, not that it is complete.
All 4 limits
- AI-system audit checklists ship as starting content for your auditors to review.
- AI drafting of workpaper rationales is off by default and needs a passed test set first.
- Regulatory clocks are started by a person; an incident does not start one by itself.
How we know
- Separation of duties is enforced by the server: a preparer cannot sign off their own engagement.
- Samples carry a fingerprint and replay identically, so a reviewer sees what the preparer saw.
- Risk acceptances must expire within a year and lapse back into open work.
- The archive carries a public timestamp that anyone can verify.
Questions
Questions buyers ask
How do you audit an AI system?
Scope the system and the controls that govern it, test whether each control is designed well and then whether it operates, on evidence sampled from the period, and report findings with management's response. ColossalX runs that lifecycle on graded evidence from the platform itself, with AI-system checklists as starting content for your auditors.
What is an audit universe, and should it include AI systems and third parties?
An audit universe is the list of everything an internal audit function could audit, each with a risk rating and a cycle. AI systems and the third parties behind them belong in it, because they carry risk of their own. ColossalX keeps both in the universe, with ratings a person confirms in writing.
How does ColossalX keep preparer, reviewer and signer separate?
The server enforces it. The person who prepares a workpaper cannot review it, the person who raised a finding cannot confirm its rating, and management sign-off is refused for anyone who prepared, reviewed, raised a finding on or submitted the engagement, or generated the report. Each person also declares their own independence.
What is a sealed audit archive?
When management approves the report, the engagement, workpapers, findings, decisions, the report's fingerprint and its evidence are sealed into one archive and timestamped by a public authority, so anyone can verify it has not changed since. The seal proves the record is unchanged; it does not prove the audit was complete.
Do audit findings feed the risk register?
Yes. Each non-conformity opens a risk-register entry whose rating and closure follow the finding, and its action plan opens one issue with an owner and a due date. Closing it needs a newer effective test, and a finding accepted rather than fixed carries an end date and lapses back into open work.
Related
Where to look next.
-
Compliance and AI governance
Mapped frameworks, policies and evidence
-
Risk quantification
AI risk in money, as a loss range
-
ColossalX Trust Engine
A trust score that explains itself
Next step
Account for your x.
See an AI audit run from plan to sealed archive on your own controls and evidence.
- 01Tell us what you run
- 02See the four verbs on it
- 03Decide where to start