# Run an AI audit from plan to sealed archive.

> Audit in ColossalX runs the internal-audit lifecycle for AI systems, from a risk-based plan approved against a board minute to a sealed, timestamped archive. Engagements open only with evidence for their trigger, independence is declared, design and operation are tested on samples that replay identically, and the preparer, reviewer and signer are always different people.

A risk-based plan, independence declared, design and operating tests, two-person review and a sealed archive anyone can verify.

Canonical page: https://colossalx.tech/platform/audit · Last reviewed: 6 Oct 2026

*Illustration:* Engagement · AI agents: Day 1 Plan approved (against a board minute); Day 4 Scope frozen (independence declared); Day 12 Design, then operation (samples replay identically); Day 19 Finding answered (by management); Day 26 Archive sealed (timestamped, verifiable).

## The threat and the control

- **The threat:** An AI audit is assembled from screenshots weeks later, and the person who did the work signs it.
- **The control:** ColossalX samples graded evidence, refuses sign-off by anyone who touched the work, and seals the archive.

## How it works: From a proven exposure to a sealed archive.

A proven exposure on an agent justifies an unplanned audit. A person opens it, the work is tested and reviewed, and the archive is sealed.

### Workflow: an unplanned audit, sealed (illustrative)

1. **Opened with a reason.** A proven exposure raises a candidate; a person opens the engagement.
   Trigger: proven exposure on support-bot; Basis: generated from the records; Opened by: Head of internal audit
2. **Tested twice.** Design is tested before operation, on samples that replay identically.
   Test of design (done); Test of operating effectiveness (failed: lapse found); Sample replayed (done: identical)
3. **Finding answered.** Management responds, and an action plan opens one owned issue.
   Head of IT: Agree: guardrail change by month end | Issue: owner and due date; Risk entry: follows the finding
4. **Archive sealed.** Sign-off by someone who did no work seals the archive.
   Signer never preparer · Timestamped · Verify any time | x, accounted for

## What you see: An audit finding, closed only on a verified re-test.

An audit finding that became owned work, raised from the audit with its root cause recorded, and closed only when a verified re-test resolved it.

1. **Plan on risk.** An audit universe with AI systems and third parties drives the plan. Each auditable entity carries a risk rating a person confirms in writing and a cycle from monthly to every three years. Management approves the plan against a board or audit-committee minute, and the person who drafted it cannot approve it.
2. **Open with a reason.** Engagements open only when the evidence for their trigger exists. Triggers are scheduled, regulatory, risk-based or event-driven. Proven exposures, advisories and incidents raise candidates for an unplanned audit; a person opens one or dismisses it with a reason, and nothing opens by itself from a signal.
3. **Test, then review.** Design before operation, samples that replay, and a second reviewer. Each person declares their own independence, with a conflict check against controls they decided or own issues on. Scope freezes when fieldwork starts. Workpapers record verdict, rationale, preparer and reviewer, and reliance on automated monitoring voids itself if the monitor stops being healthy.
4. **Report, sign, seal.** Sign-off by someone who did no work seals a timestamped archive. The audit report carries a conformance statement generated from the gates, naming each gate that did not hold. Approval seals the engagement, workpapers, findings, decisions, report and evidence into an archive with a public timestamp anyone can verify.

*Screen, from a demo workspace:* A closed issue in a demo workspace: an audit finding that the AI system impact assessment control was deficient by design, its root cause recorded as a design gap, resolved by a verified re-test. Callouts: 1. Raised from an audit 2. Root cause recorded 3. Closed by verified re-test

## How we know

- Separation of duties is enforced by the server: a preparer cannot sign off their own engagement.
- Samples carry a fingerprint and replay identically, so a reviewer sees what the preparer saw.
- Risk acceptances must expire within a year and lapse back into open work.
- The archive carries a public timestamp that anyone can verify.

## Where an audit finding goes next.

A finding is owned work and a risk, tracked until a newer test proves it fixed.

- **Owned work.** An action plan opens one issue with an owner and a due date, closed on a newer test.
- **The risk register.** Each non-conformity opens a risk entry whose rating and closure follow the finding.
- **Risk acceptances.** An accepted finding carries a reason and an end date, and lapses back into open work.
- **Control health.** Audit tests feed the health label each control carries in compliance.

Where an x ends up: x, accounted for.

## Specs: delivery and data

- **Delivery:** SaaS, from one login.
- **Isolation:** Each customer runs in an isolated workspace with its own database.
- **Certifications:** None held. Frameworks are mapped to and assessed against.

## Frameworks

- Mapped to ISO/IEC 42001: AI-system audit checklist, as starting content.
- Mapped to EU AI Act: AI-system audit checklist, as starting content.
- Mapped to NIST AI RMF: Checklist items covered by controls.

## What it does not do

- The sealed archive proves the record has not changed since sealing, not that it is complete.
- AI-system audit checklists ship as starting content for your auditors to review.
- AI drafting of workpaper rationales is off by default and needs a passed test set first.
- Regulatory clocks are started by a person; an incident does not start one by itself.

*Illustration:* Sealed archive · what it proves: Record unchanged Verifiable by anyone; Timestamp From a public authority; Completeness Not proven by the seal; Checklists Starting content, for review. Re-check any time.

## Questions

### How do you audit an AI system?

Scope the system and the controls that govern it, test whether each control is designed well and then whether it operates, on evidence sampled from the period, and report findings with management's response. ColossalX runs that lifecycle on graded evidence from the platform itself, with AI-system checklists as starting content for your auditors.

### What is an audit universe, and should it include AI systems and third parties?

An audit universe is the list of everything an internal audit function could audit, each with a risk rating and a cycle. AI systems and the third parties behind them belong in it, because they carry risk of their own. ColossalX keeps both in the universe, with ratings a person confirms in writing.

### How does ColossalX keep preparer, reviewer and signer separate?

The server enforces it. The person who prepares a workpaper cannot review it, the person who raised a finding cannot confirm its rating, and management sign-off is refused for anyone who prepared, reviewed, raised a finding on or submitted the engagement, or generated the report. Each person also declares their own independence.

### What is a sealed audit archive?

When management approves the report, the engagement, workpapers, findings, decisions, the report's fingerprint and its evidence are sealed into one archive and timestamped by a public authority, so anyone can verify it has not changed since. The seal proves the record is unchanged; it does not prove the audit was complete.

### Do audit findings feed the risk register?

Yes. Each non-conformity opens a risk-register entry whose rating and closure follow the finding, and its action plan opens one issue with an owner and a due date. Closing it needs a newer effective test, and a finding accepted rather than fixed carries an end date and lapses back into open work.

## Related

- [Compliance and AI governance](https://colossalx.tech/platform/compliance)
- [Risk quantification](https://colossalx.tech/platform/risk-quantification)
- [ColossalX Trust Engine](https://colossalx.tech/platform/trust-engine)

---

ColossalX is an AI security and governance platform from Quantexra Labs LLP, delivered as SaaS. Book a walkthrough: https://colossalx.tech/demo · client.success@quantexra.tech
