Product chapter · Evidence dossier

The evidence layer for high-risk AI systems.

Guardian turns operational AI activity — monitoring signals, incidents, reviews, model changes, and oversight workflows — into one defensible evidence record your team can export when scrutiny arrives.

This page explains how Guardian works — the operating model, modules, and teams behind the dossier. Not another dashboard: a governance layer above the stack you already run.

4-week readiness sprint — fixed scope, first baseline.EU AI Act overview

RecordCustodyPolicy
Record live

Guardian · Evidence record

EU AI Act evidence dossier

dcs_01842
Audit-readySourcesPolicyIntegrityExport

Owner

Risk & compliance

Reviewer

Risk committee

Integrity

Record linked

Evidence trail

4 events linked

SeqSource eventHandlerStatus
01model.eventguardian-ingestlinked
02review.noterisk-committeelinked
03incident.openedoversight-queuelinked
04oversight.logcompliance-desklinked
evidence-pack-dcs_01842.zip

Settled product view — one in-scope system with ownership, integrity, and export state visible at a glance.

Product operating model

How Guardian links day-to-day AI activity to an audit-ready dossier — without replacing your monitoring stack.

  1. 01

    Capture activity

    Ingest production signals, model events, review notes, incidents, and oversight actions from the systems you already run.

  2. 02

    Link to policy and custody

    Attach each signal to the applicable policy frame, custody handler, and reviewer context inside one governed record.

  3. 03

    Review and assign ownership

    Route open items to risk, compliance, legal, and ML owners with timestamps, status, and resolution history intact.

  4. 04

    Export audit-ready dossier

    Package the living record for internal review, regulator questions, or board scrutiny — without reconstructing the story after the fact.

Product register

Product modules

Six modules compose the governed record — each answers a distinct evidence question auditors and reviewers ask when scrutiny arrives.

Guardian product registerREF · GRD-PRD-MOD
Module IDModuleEvidence functionStatus
MOD-01Evidence recordSingle traceable ledger for in-scope systems, runs, and review stateCore
MOD-02Traceable evidence trailSource lineage, handler assignment, and custody trail per artefactCore
MOD-03Policy mappingLink activity to EU AI Act articles, internal controls, and annex contextCore
MOD-04Incident evidenceOpen items, escalation, resolution history, and linked artefactsActive
MOD-05Human oversight traceReviewer actions, sign-off, and oversight procedure evidenceActive
MOD-06Export dossierAudit-ready packages generated from the live record on demandVerified

6 modules · one governed record · exports trace to live operating events

Illustrative register — module availability follows deployment scope and configured review rules.

Common questions

Product essentials

What is Guardian?
The evidence and auditability layer above monitoring, incidents, reviews, and oversight workflows — not another dashboard.
What does the product capture?
Production signals, thresholds, incidents, review notes, ownership, and exportable artefacts in one defensible record.
Who uses Guardian?
Risk, compliance, AI governance, ML platform, legal, and product teams accountable for high-risk AI systems.
Does Guardian replace existing tools?
No. Guardian sits above MLOps, monitoring, and ticketing — linking their outputs into audit-ready evidence.

What teams can do with Guardian

Capabilities map directly to the modules above — documented as a checklist, not a separate product story.

  • Document in-scope AI systems and maintain a clear governance record
  • Track drift, robustness, data quality, and performance signals over time
  • Set thresholds and flag changes that need review
  • Log incidents, assign follow-up, and maintain resolution history
  • Maintain oversight records and supporting evidence in one traceable path
  • Prepare exportable evidence packs for internal and external review
  • Give compliance, legal, risk, and AI teams role-appropriate visibility

What becomes easier with Guardian

Outcomes once the operating record replaces one-off reconstruction.

  • Answering regulator, auditor, or board questions faster
  • Keeping compliance, legal, risk, and ML teams aligned on the same system
  • Showing what changed, when it changed, and how the team responded
  • Moving from scattered documentation to a continuous evidence trail
  • Starting with one system first instead of launching a broad transformation programme

What evidence Guardian helps maintain

  • Risk management documentation
  • Data governance records
  • Technical documentation
  • Human oversight procedures and actions
  • Post-deployment operational review records
  • Incident logs with follow-up and resolution trails

Each item maps to owners, timestamps, and artefacts in the same governed record — prioritise one system first, then widen coverage.

EU AI ActMethodologyIntegrations

Who uses Guardian

Guardian is shared infrastructure — each team touches a different part of the same dossier, not a separate tool.

TeamIn practice
Risk & complianceReadiness tracking, evidence bundles, regulator-facing preparation
AI governancePolicy mapping, oversight records, cross-system accountability
ML platformProduction signals, drift visibility, incident input from pipelines
Product ownersWorkflow visibility, follow-up coordination, in-scope system context
LegalIncident documentation, defensible records, review support

Frequently asked questions

Is Guardian a compliance certification tool?
No. Guardian is a governance and evidence layer. It helps teams maintain production signals, records, and traceable review artefacts that support EU AI Act readiness. Legal compliance remains a separate determination.
Does Guardian process raw personal data?
Guardian is designed around metrics, signals, and operational records rather than raw personal data. The focus is on configured monitoring inputs, incidents, and evidence maintenance.
Can Guardian integrate with existing monitoring tools?
Yes. Guardian is designed to sit above existing models and monitoring infrastructure. It helps turn existing signals into a structured governance record—not a replacement observability stack.
How do teams usually get started?
Most teams start with one in-scope production system in the 4-week Readiness Sprint. That creates a first evidence baseline and review posture before expanding further.

Next step: talk through one system

Start with one in-scope production system. Map your evidence sources, then expand the same dossier pattern.

4-week readiness sprint — fixed scope, first baseline.