Assurance memo · Evidence protocol · Method register

Methodology

How Guardian turns AI activity into defensible evidence.

A defensible AI evidence record is not a dashboard screenshot. It is a linked chain of signals, reviews, owners, policies, incidents, and exportable proof. Guardian's method links operational signals, human oversight, policy mapping, a traceable evidence trail, and export-ready records — configured per deployment, not as generic governance theory.

Legal compliance remains a separate human determination. ProductEU AI Act

Method principles

Evidence protocol foundations

Six principles that govern how Guardian captures, links, reviews, and exports evidence — not advisory theory.

Method principle registerREF · GRD-MTH-PRN
IDPrincipleApplication
PRN-01Evidence before opinionSignals, thresholds, and review records precede narrative claims about compliance posture.
PRN-02One record per high-risk AI systemEach in-scope system gets a governed dossier — not a portfolio-wide slide deck.
PRN-03Every signal needs contextMetrics link to source, timestamp, owner, and the policy frame they support.
PRN-04Human oversight must be traceableReviewer actions, sign-off, and escalation paths are retained artefacts — not implied.
PRN-05Custody mattersHandlers, transfers, and retention boundaries are explicit from intake to export.
PRN-06Export must be reconstructableAudit-ready packets rebuild the chain from source event to review-ready evidence — on demand.

6 principles · applied per in-scope system

What this methodology is

A documented framework for which production signals are measured, how thresholds are set, and what review and evidence records should exist when those thresholds fire — not a substitute for legal judgement or a single “compliance score” as a verdict.

Compliance, risk, legal, and AI teams get shared language: metric → threshold → owner → retained artefact, anchored on one in-scope system first so the pattern can extend without losing traceability.

Product overviewEU AI ActHiring & HR AICredit, fraud & underwriting

Evidence lifecycle

Process register

From raw signal to register-backed export — capture, normalize, link, assign, review, and package.

Lifecycle process registerREF · GRD-MTH-LFC
IDStepHandlerOutputStatus
LFC-01Capture signalIntake layerRaw event with source ID and receipt timestampCore
LFC-02Normalize payloadEvidence recordStructured artefact with metric, threshold, and system contextCore
LFC-03Link policy and obligationPolicy mappingArticle, control, or internal policy reference attachedActive
LFC-04Assign ownerCustody registryNamed reviewer, escalation path, and due dateActive
LFC-05Review and approveOversight workflowSigned review record with resolution or follow-upVerified
LFC-06Package export packetExport dossierReconstructable evidence bundle for audit or regulator reviewVerified

6 steps · continuous loop per in-scope system

Traceable evidence trail method

Guardian preserves traceability from source event to reviewable evidence packet — handlers, timestamps, and policy links intact at every transfer.

  • Source system emits signal — webhook, batch, or manual intake with receipt timestamp
  • Guardian normalizes payload and assigns a custody handler before review
  • Policy and obligation links attach while the artefact is open — not retrofitted at export
  • Human oversight actions append to the same record with reviewer identity and timestamp
  • Export packet captures a point-in-time record: source → handler → review → resolution

What makes evidence defensible

Illustrative dossier rows — every exportable artefact should answer these six fields.

SourceTimestampOwnerPolicy linkReview stateExport state
MLflow run #48212026-03-14T09:22:11ZML platformArt. 15 accuracyApprovedReady
Drift alert — cohort A2026-03-14T11:04:33ZRisk & complianceArt. 10 data governanceIn reviewPending
Incident #INC-2042026-03-15T08:17:02ZAI governanceArt. 62 serious incidentEscalatedOpen

What Guardian measures

Illustrative signal families configured per deployment — not a universal legal mapping of your obligations. Your counsel sets legal context; the table shows how we typically relate inputs to EU AI Act themes for review and evidence.

MetricWhat it showsRegulatory link
Demographic parityFairness across cohortsArticle 10 / Article 14
Equalised oddsError-rate equity across groupsArticle 10
Model driftPerformance change over timeArticle 72
Data qualityInput distribution and anomaly signalsArticle 10
Human oversight actionsReview and intervention recordsArticle 14
Incident frequencyRate and nature of flagged eventsArticle 62
Documentation completenessCoverage of required technical recordsArticle 11

How signals connect to operational review

Guardian maps each monitoring signal to the operational and regulatory context it supports. When a threshold is crossed, the output should not sit in isolation. It should help teams understand what changed, why it matters, who should review it, and what record should be maintained next.

This does not replace legal interpretation. It connects measurement to action in a governed record. A typical path is the 4-week Readiness Sprint, then day-to-day use in Guardian with EU AI Act context as needed.

Why open methodology matters

For high-risk AI systems, monitoring outputs need to be explainable. If a signal, alert, or score cannot be traced to a documented method, it is difficult to defend in front of a regulator, auditor, internal governance committee, or legal review.

Guardian's approach keeps that logic visible — what is measured, why it matters, which threshold fired, and what follow-up record is expected — so outputs stay useful in operations and defensible in review.

What becomes easier with a documented methodology

The same clarity lands in Guardian as timestamps, owners, and retained artefacts — not only in monitoring charts.

  • Explaining why a signal or alert was generated
  • Showing which metric, threshold, and reference support an output
  • Making monitoring outputs easier for compliance, legal, and risk teams to review
  • Building a monitoring and evidence baseline that can be expanded over time

Scope boundaries

What Guardian does not do

  • Does not replace MLOps tools — Guardian sits above them, linking outputs into evidence
  • Does not replace legal counsel — obligations and determinations remain human-led
  • Does not certify compliance automatically — scores and signals support review, not verdicts
  • Does not require moving model weights — metrics, signals, and records only
  • Does not create fake evidence after the fact — export rebuilds what was captured in real time

Academic and regulatory grounding

Guardian's methodology is developed with academic oversight from Dr. OJ Akintande of DTU Compute, bringing statistical rigor to fairness, drift, and model-risk monitoring.

Metrics and threshold logic are grounded in published statistical methods and relevant regulatory frameworks, including the EU AI Act, NIST AI RMF, ISO 42001, and peer-reviewed fairness research.

The goal is not to make legal determinations automatically. It is to make monitoring outputs more explicit, reviewable, and defensible.

Team

Nordic AI Integrity

NameRoleAffiliation
Thomas NobaCo-founder & CEONordic AI Integrity ApS.
Joris CappaCo-founder & COONordic AI Integrity ApS.
Dr. OJ AkintandeTechnical AdvisorDTU Compute (Technical University of Denmark). ML fairness and model risk specialist.

Common questions

Method essentials

What is Guardian's methodology?
A practical evidence method: capture operational signals, normalize them, link policy and owners, run review workflows, preserve custody, and export reconstructable proof.
What makes AI evidence defensible?
A linked chain of source, timestamp, owner, policy reference, review state, and export state — not a dashboard screenshot or narrative slide.
Does Guardian certify compliance?
No. Guardian maintains traceable evidence and review records. Legal compliance remains a separate human determination in context.
How does Guardian preserve a traceable evidence trail?
Every artefact records source lineage, custody handlers, oversight actions, and export metadata — reconstructable from intake to audit packet.

Frequently asked questions

Is Guardian's compliance score a legal determination?
No. Guardian does not treat a score as a legal verdict. A score is only one monitoring signal among others, used to help teams prioritise review and maintain a defensible evidence record.
Why publish the methodology openly?
Because monitoring outputs are more useful when teams can understand and explain them. Open methodology makes it easier to trace outputs back to documented metrics, thresholds, and references.
How are thresholds set?
Thresholds are based on documented statistical methods and calibrated to the monitoring context. The goal is to make review triggers explicit rather than opaque.
Does methodology replace legal review?
No. The methodology supports monitoring and evidence maintenance. Legal interpretation and compliance determinations still require human review in context.

Put the methodology to work on one system

Pilot discussion to align signal scope; security policy for how we handle data in production.

Evidence lifecycleFAQ