Home
AI Evidence Gap Notes
Implementation Note
Awesome GRC Workflows
Signals
About
Home
AI Evidence Gap Notes
Implementation Note
Awesome GRC Workflows
Signals
About
Subscribe
Sign in
AI Evidence Gap
Latest
Top
Discussions
A Policy Is Not Evidence That an AI Agent Obeys It
Why documented AI controls still need execution evidence before they can be relied upon.
Aug 31
•
CodeYourCompliance
1
How to Build a Claim-Evidence Matrix for AI Procurement
A practical way to map AI vendor claims to sources, scope, evidence gaps, buyer questions, and usage boundaries.
Aug 25
•
CodeYourCompliance
1
Vendor Questionnaires Fail When Claims Are Not Mapped to Sources
A completed AI vendor questionnaire may collect the right answers while leaving the buyer without the sources, scope, exceptions, and evidence needed to…
Aug 13
•
CodeYourCompliance
1
Data Residency Claims Are Useless Without Scope
A hosting country is evidence, but it does not establish where the rest of the AI data path is stored, processed, accessed, or backed up.
Aug 4
•
CodeYourCompliance
1
AI Audit Logs: What Events Are Missing?
Audit logs may exist without recording the AI-specific events needed for incident reconstruction, accountability, or review.
Aug 4
•
CodeYourCompliance
1
1
1
Prompt Retention Is a Control, Not a Preference
“Zero retention” may sound sufficient, but buyers still need evidence for data-type coverage, storage layers, deletion timing, exceptions…
Jul 16
•
CodeYourCompliance
1
Subprocessor Lists Do Not Show the Actual AI Data Path
A subprocessor list shows who may process data. It does not show which subprocessors touch which data, feature, region, workflow, or support path.
Jul 10
•
CodeYourCompliance
1
Human Review Is a Data Exposure Path Unless It Is Bounded
Human review may support safety and support workflows, but buyers still need evidence for scope, trigger, access roles, retention, opt-out, and contract…
Jul 3
•
CodeYourCompliance
Why SOC 2 Does Not Prove the AI Vendor Data Path Is Covered
SOC 2 is useful evidence, but buyers still need to map scope, product, plan, data path, support access, retention, and contract boundary.
Jun 30
•
CodeYourCompliance
A Trust Center Is Not an AI Vendor Risk Assessment
A trust center can help locate evidence, but buyers still need claim-to-source mapping, scope checks, and usage boundaries.
Jun 26
•
CodeYourCompliance
Vendor Says It Does Not Train on Your Data. What Evidence Should You Ask For?
A no-training claim may be true. It may be useful. It is still not evidence-complete.
Jun 4
•
CodeYourCompliance
AI Vendor Risk Assessment: Vendor Claim Is Not Evidence
A practical evidence gap guide for reviewing AI vendors before procurement, renewal, or audit preparation.
May 12
•
CodeYourCompliance
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts