Assurance memo · Evidence protocol · Method register
How Guardian turns AI activity into defensible evidence.
A defensible AI evidence record is not a dashboard screenshot. It is a linked chain of signals, reviews, owners, policies, incidents, and exportable proof. Guardian's method links operational signals, human oversight, policy mapping, a traceable evidence trail, and export-ready records — configured per deployment, not as generic governance theory.
Method principles
Six principles that govern how Guardian captures, links, reviews, and exports evidence — not advisory theory.
| ID | Principle | Application |
|---|---|---|
| PRN-01 | Evidence before opinion | Signals, thresholds, and review records precede narrative claims about compliance posture. |
| PRN-02 | One record per high-risk AI system | Each in-scope system gets a governed dossier — not a portfolio-wide slide deck. |
| PRN-03 | Every signal needs context | Metrics link to source, timestamp, owner, and the policy frame they support. |
| PRN-04 | Human oversight must be traceable | Reviewer actions, sign-off, and escalation paths are retained artefacts — not implied. |
| PRN-05 | Custody matters | Handlers, transfers, and retention boundaries are explicit from intake to export. |
| PRN-06 | Export must be reconstructable | Audit-ready packets rebuild the chain from source event to review-ready evidence — on demand. |
6 principles · applied per in-scope system
A documented framework for which production signals are measured, how thresholds are set, and what review and evidence records should exist when those thresholds fire — not a substitute for legal judgement or a single “compliance score” as a verdict.
Compliance, risk, legal, and AI teams get shared language: metric → threshold → owner → retained artefact, anchored on one in-scope system first so the pattern can extend without losing traceability.
Evidence lifecycle
From raw signal to register-backed export — capture, normalize, link, assign, review, and package.
| ID | Step | Handler | Output | Status |
|---|---|---|---|---|
| LFC-01 | Capture signal | Intake layer | Raw event with source ID and receipt timestamp | Core |
| LFC-02 | Normalize payload | Evidence record | Structured artefact with metric, threshold, and system context | Core |
| LFC-03 | Link policy and obligation | Policy mapping | Article, control, or internal policy reference attached | Active |
| LFC-04 | Assign owner | Custody registry | Named reviewer, escalation path, and due date | Active |
| LFC-05 | Review and approve | Oversight workflow | Signed review record with resolution or follow-up | Verified |
| LFC-06 | Package export packet | Export dossier | Reconstructable evidence bundle for audit or regulator review | Verified |
6 steps · continuous loop per in-scope system
Guardian preserves traceability from source event to reviewable evidence packet — handlers, timestamps, and policy links intact at every transfer.
Illustrative dossier rows — every exportable artefact should answer these six fields.
| Source | Timestamp | Owner | Policy link | Review state | Export state |
|---|---|---|---|---|---|
| MLflow run #4821 | 2026-03-14T09:22:11Z | ML platform | Art. 15 accuracy | Approved | Ready |
| Drift alert — cohort A | 2026-03-14T11:04:33Z | Risk & compliance | Art. 10 data governance | In review | Pending |
| Incident #INC-204 | 2026-03-15T08:17:02Z | AI governance | Art. 62 serious incident | Escalated | Open |
Illustrative signal families configured per deployment — not a universal legal mapping of your obligations. Your counsel sets legal context; the table shows how we typically relate inputs to EU AI Act themes for review and evidence.
| Metric | What it shows | Regulatory link |
|---|---|---|
| Demographic parity | Fairness across cohorts | Article 10 / Article 14 |
| Equalised odds | Error-rate equity across groups | Article 10 |
| Model drift | Performance change over time | Article 72 |
| Data quality | Input distribution and anomaly signals | Article 10 |
| Human oversight actions | Review and intervention records | Article 14 |
| Incident frequency | Rate and nature of flagged events | Article 62 |
| Documentation completeness | Coverage of required technical records | Article 11 |
Guardian maps each monitoring signal to the operational and regulatory context it supports. When a threshold is crossed, the output should not sit in isolation. It should help teams understand what changed, why it matters, who should review it, and what record should be maintained next.
This does not replace legal interpretation. It connects measurement to action in a governed record. A typical path is the 4-week Readiness Sprint, then day-to-day use in Guardian with EU AI Act context as needed.
For high-risk AI systems, monitoring outputs need to be explainable. If a signal, alert, or score cannot be traced to a documented method, it is difficult to defend in front of a regulator, auditor, internal governance committee, or legal review.
Guardian's approach keeps that logic visible — what is measured, why it matters, which threshold fired, and what follow-up record is expected — so outputs stay useful in operations and defensible in review.
The same clarity lands in Guardian as timestamps, owners, and retained artefacts — not only in monitoring charts.
Scope boundaries
Guardian's methodology is developed with academic oversight from Dr. OJ Akintande of DTU Compute, bringing statistical rigor to fairness, drift, and model-risk monitoring.
Metrics and threshold logic are grounded in published statistical methods and relevant regulatory frameworks, including the EU AI Act, NIST AI RMF, ISO 42001, and peer-reviewed fairness research.
The goal is not to make legal determinations automatically. It is to make monitoring outputs more explicit, reviewable, and defensible.
Team
| Name | Role | Affiliation |
|---|---|---|
| Thomas Noba | Co-founder & CEO | Nordic AI Integrity ApS. |
| Joris Cappa | Co-founder & COO | Nordic AI Integrity ApS. |
| Dr. OJ Akintande | Technical Advisor | DTU Compute (Technical University of Denmark). ML fairness and model risk specialist. |
Common questions
Pilot discussion to align signal scope; security policy for how we handle data in production.