Signato signato.ai

Your evidence trail: what auditors and DPAs actually want to see

Edition 07. A reading time of about 5 minutes.

The hook

When the question finally comes, from a regulator, a rejected candidate, or your own legal team, the right answer is not an explanation. It is a file. "How was this decision made?" is answered well only by something you can hand over, dated and complete. The evidence trail is what turns "we complied" into "we can show we complied," and most of it is built from things you should be keeping anyway.

What this means

Part of the trail is required by name. As a deployer, you must keep the logs the system generates automatically, for a period appropriate to its purpose and in any case at least six months, unless other law sets a different term (AI Act, Article 26(6)). And because you also have to monitor the system in use and act if a risk appears (AI Act, Article 26(5)), the record of what you saw and what you did is itself evidence.

The useful trail is wider than the legal minimum, and you have already been building it if you followed the last few editions. The inventory names what is in scope. The vendor answers show your due diligence, and rest on the provider's own duty to supply documentation (AI Act, Article 13). The oversight notes show that a human with authority actually reviewed. Stitched together, those are not paperwork for its own sake; they are the answer to the question that matters most when hiring AI is challenged, and hiring AI is high-risk by classification (Annex III, point 4).

The trap is treating this as a year-end project. Evidence assembled after the fact looks exactly like what it is. Evidence captured as you go is the cheap and credible kind.

What to do with this

Make the trail a habit, not an event. Four moves.

  1. One place per tool. A single folder holding its inventory entry, the vendor answers, the provider documentation, the oversight notes, and the exported logs. Findable in a minute, not reconstructed in a week.
  2. Keep the logs, and check you can export them. The duty runs to at least six months (Article 26(6)). Confirm the system actually generates logs and that you can get them out, before the day you need them.
  3. Capture oversight as it happens. The one-line review note from the oversight guide goes in the same folder, with a date attached.
  4. Date everything. A trail without dates is a story without proof. Timestamps are what let the file stand on its own when you are not in the room to narrate it.

None of this needs a platform or a budget. It needs a folder, a habit, and dates. Done as you go, the day someone asks to see your file, the file already exists.


This is educational material and a starting point, not legal advice. The EU AI Act is still being amended, and the high-risk timeline rests on an agreement that is not yet final law. For how the record-keeping and monitoring duties apply to your specific tools, consult a qualified lawyer. Signato is not a law firm and does not certify compliance.


AI that drafts at scale can also send the wrong thing at scale. See the Signato chamber block a forbidden send before it happens: run the free local trial, no card, nothing leaves your machine.

Every claim here is traced to the primary regulation and checked by a person before it goes out. We tell you what is settled, what is still open, and what to do next. How we work.

Know someone who hires in the EU? Forward this to them.

AI hiring law, made operational. Free, weekly.

Plain-language, sourced intelligence for HR and legal teams. Start with the free Starter Kit.

No spam. Unsubscribe in one click. See our Privacy Policy.

Run a newsletter on Beehiiv? Add Signato to your recommendations in one click, and send your readers a clear, sourced read on AI compliance.

Add Signato to your recommendations →