Auditing AI: a test checklist

22 control areas over 7 domains. Each carries the objective, a test procedure somebody can re-perform, the evidence to ask for, and what the test returned against Cadence, a consumer lending engine built first and audited afterwards, so the failures are recorded with the passes.

11 areas map to a control objective, 1 is partly covered and 10 have none. The uncovered areas are a fact about that control library rather than about the checklist. The system the results come from is at cadence-lending.vercel.app/audit.

Areas
22
With an objective
11
Partly covered
1
Uncovered
10
Failing control
1

Governance

4 areas · 1 with an objective · 3 with none

Regulatory position

4 areas · 4 with an objective

Data

3 areas · 3 with none

Model

4 areas · 4 with an objective

Security

2 areas · 2 with an objective

Third parties

2 areas · 2 with none

Operation

3 areas · 1 with an objective · 2 with none