What Would You Show a Regulator Tomorrow?
Imagine your phone rings at 9am. It is your FCA supervision contact. They want to understand your AI governance programme. They would like to see your documentation. They are available Thursday.
What do you send them?
For most compliance and risk functions at regulated firms, the honest answer to that question is uncomfortable. There is a policy. There may be a risk framework. There is probably a spreadsheet. But the question the FCA supervisor will actually ask, can you show me evidence that your AI governance programme is operating in practice and not just documented on paper, is a question most firms cannot currently answer with confidence.
This article is structured around the five categories of evidence a regulator is most likely to request in an AI governance review. For each, it describes what they will ask, what adequate evidence looks like, and what the most common gap is.
Regulators do not want to read your AI governance policy. They want to see evidence that it is operating. The gap between having a policy and having evidence that the policy is working is where most firms are currently exposed.
The Regulator's Opening Questions
Before getting into specific evidence categories, it is worth being clear about the framing regulators bring to AI governance reviews. FCA and ICO supervisors approaching this topic are not running a checkbox exercise. They are trying to answer three questions:
- Does this firm know what AI systems it is using? Not what it approved. What is actually running.
- Is there genuine human oversight of those systems, or is "oversight" a label applied to a passive monitoring function that has never actually intervened?
- If something went wrong (an AI system produced harmful outputs, a data exposure occurred, a customer was adversely affected) would this firm be able to show us what the system was doing, when, and what governance was in place?
The evidence categories below correspond to these three questions. Inventory evidence addresses the first. Approval and monitoring evidence addresses the second. Audit trail and signed evidence addresses the third.
Category 1: Inventory Evidence
The first thing a supervisor will ask for is a list of AI systems the firm is using. The question sounds simple. The adequate answer is not.
What adequate inventory evidence looks like: a current, dated register of AI systems operating in the environment, covering both formally approved tools and tools discovered through programmatic admin-level discovery. Each entry should include the system name, vendor or builder, data access scope, whether it operates on personal data, and the risk classification assigned to it. The register should show when it was last updated and how.
The most common gap: the inventory only covers what IT approved. Programmatic discovery (querying workspace admin APIs to find OAuth grants, service identities, and connected applications) is absent. The inventory is therefore materially incomplete, and a supervisor who asks "how did you identify these systems?" will expose the gap immediately.
What makes it evidence rather than a record: the inventory needs to be dated and signed. Not in the sense of a wet signature, but in the sense that it can be verified as the inventory that existed on a specific date, unaltered since generation. A spreadsheet cannot provide this. A cryptographically signed evidence pack can.
Category 2: Approval Evidence
The second question is: who approved these AI systems, under what process, and with what assessment?
What adequate approval evidence looks like: for each material AI system, a record of the approval decision (who approved it, what risk assessment was conducted, what conditions were attached, and when the approval was granted). For AI systems that were discovered through programmatic discovery rather than formal approval, a record of the retrospective assessment and the decision made about each.
The most common gap: approval records exist for formally procured tools but not for the long tail of AI systems that employees deployed without formal IT involvement. When a supervisor asks about an OAuth grant visible in the admin console that does not appear in the approval records, the firm cannot explain the gap.
A secondary gap: approval decisions are treated as one-time events. AI systems change. Vendors add features, permission scopes expand, the system's usage evolves. Approval evidence needs to reflect ongoing review, not just initial sign-off.
Category 3: Monitoring Evidence
This is where most firms' governance programmes are most exposed. Monitoring is the obligation that moves AI governance from policy to practice, and it is the obligation that requires the most ongoing operational effort.
What adequate monitoring evidence looks like: records showing that each material AI system is being actively monitored, at a documented cadence, against defined criteria. Not "we have a monitoring policy." Records that monitoring occurred, what it found, and what action was taken as a result.
For Article 26 deployers, the monitoring obligation is explicit: firms must monitor AI system operation and report serious incidents or malfunctions. For Consumer Duty purposes, monitoring must demonstrate that the AI system is delivering good outcomes for customers. For SYSC 8, monitoring must show that the firm can identify failures in its material third-party AI arrangements and respond appropriately.
The most common gap: monitoring exists at the vendor relationship level (SLAs, uptime metrics, support tickets) but not at the governance level. Whether the AI system is operating within its risk classification, whether its outputs are consistent with its intended use, whether cross-platform patterns are creating risks not visible at the platform level. These are not being monitored. The monitoring evidence that exists does not answer the questions a regulator is asking.
Monitoring evidence is not about whether the AI system is working. It is about whether your governance of the AI system is working. The distinction matters under regulatory examination.
Further reading: The AI Inventory Crisis Nobody Is Talking About covers the cross-platform patterns the inventory layer surfaces.
Category 4: Audit Trail Evidence
If the regulator asks what a specific AI system was doing on a specific date (what data it accessed, what outputs it produced, what human oversight was in place) what can you show them?
What adequate audit trail evidence looks like: for each material AI system, records of its operation at a sufficient level of granularity to answer the specific questions a supervisor might ask. This includes what data the system accessed, what outputs it produced, whether human review of those outputs occurred, and what the risk status of the system was at the relevant time.
The most common gap: audit trails exist within individual platforms (Google Workspace logs, Microsoft 365 audit logs, Salesforce activity logs) but they are not combined into a unified picture of what the AI system did across platforms. A supervisor asking about an AI agent that operated across Google and Microsoft simultaneously cannot get an answer from either platform's logs individually.
The secondary gap: audit logs are mutable. Without cryptographic signing, there is no way to verify that the logs presented to a supervisor are identical to the logs that existed at the time of the events they record. This is a fundamental limitation of conventional audit trails as regulatory evidence.
Category 5: Signed Evidence Packs
The fifth category is the one that most firms are missing entirely, because it does not exist as a concept in most governance frameworks: signed, reproducible evidence of the governance state of AI systems at a specific point in time.
What this looks like: a document generated programmatically from live discovery data, that captures the AI agent inventory, risk classifications, cross-platform findings, human oversight status, and monitoring cadence at a specific date, cryptographically signed so that its integrity can be verified under examination at any future point.
Why this matters: a supervisor who receives a signed evidence pack can verify that what they are reading is identical to what was generated on the stated date. They do not need to trust that the firm has not modified the document since generation. The signature is the verification.
This is what distinguishes governance evidence from governance records. Records can be modified. Signed evidence cannot be modified without invalidating the signature. Under regulatory examination, the difference is material.
An Evidence Readiness Framework
The following framework gives compliance and risk teams a practical self-assessment tool. Score each category honestly. The gaps it reveals are the priorities for the next 60 days.
Inventory readiness
- Do we have a current inventory of AI systems? (Y/N)
- Does the inventory include systems discovered through programmatic admin-level discovery, not just IT-approved tools? (Y/N)
- Is the inventory signed and dated such that we can verify its state at a specific past date? (Y/N)
Approval readiness
- Do we have approval records for each material AI system? (Y/N)
- Do the approval records cover AI systems found through discovery as well as formally procured tools? (Y/N)
- Are approval records reviewed and updated when AI systems change materially? (Y/N)
Monitoring readiness
- Do we have records of monitoring activity for each material AI system? (Y/N)
- Does monitoring cover governance-level questions (risk classification adherence, cross-platform patterns) not just operational uptime? (Y/N)
- Can we show evidence of what action was taken as a result of monitoring findings? (Y/N)
Audit trail readiness
- Can we produce a unified record of what a specific AI system did on a specific past date across all platforms it operates on? (Y/N)
- Are our audit records signed or otherwise verifiable as unaltered? (Y/N)
Evidence pack readiness
- Do we generate signed evidence packs at regular cadences? (Y/N)
- Can we verify the integrity of those packs under examination? (Y/N)
A score of fewer than eight "yes" answers identifies material gaps that need to be addressed before a supervision visit. Fewer than four identifies a governance programme that is policy-only and not yet operational.
How AETHER Pulse Addresses the Evidence Gap
AETHER Pulse is designed specifically around the evidence readiness framework above. Its cross-platform discovery addresses inventory readiness. Its five-dimensional classification framework produces documented risk assessments with reasoning. Its monitoring cadence (configurable, with records of each cycle) produces monitoring evidence. Its HMAC-SHA256 signed evidence packs address the signed evidence category directly.
For firms facing a supervision visit, or preparing for one, AETHER Pulse produces the evidence that the framework above requires. Not as a documentation exercise, but as the output of a live, programmatic governance programme.
Published methodology: aetherpulse.app/methodology
Frequently Asked Questions
How much notice do regulators typically give before an AI governance review?
The FCA and ICO can conduct supervisory reviews with relatively short notice. Building evidence readiness in advance, rather than in response to a supervision request, is significantly more effective than attempting to reconstruct evidence retrospectively.
What if we discover gaps during the self-assessment?
Identifying gaps is the purpose of the self-assessment. Documented gap identification, followed by a credible remediation plan with milestones, is a significantly stronger regulatory position than undiscovered gaps. Regulators respond better to firms that know where they are exposed and are doing something about it.
Do we need to retain AI governance evidence permanently?
Article 26 requires records of AI system operation to be retained for the period specified in the regulation and any applicable national law. The FCA and ICO have their own record-keeping requirements. A minimum of 24 months is a reasonable baseline for most regulated firms, but specific legal advice should be sought for retention periods in your regulatory context.
Is a monthly evidence pack sufficient?
Monthly is a defensible minimum for most regulated firms. The key is that the cadence is documented, consistently followed, and that each cycle produces a signed evidence pack. Gaps in the cadence undermine the monitoring evidence category. A six-month gap in evidence pack generation is a monitoring gap, not just a documentation gap.
Book an Evidence Readiness Review with the AETHER Pulse team →
Working on Article 26 readiness, deployer-side governance evidence, or AI agent risk at a regulated firm? We'd value 15 minutes of your perspective.
Start a conversation