Governance

Every decision, with the rule it followed and the source it believed

An audit trail for automated decisions records what was decided, the rule it followed and the source it believed. Add the input it read, the tolerance applied, the confidence, whether it escalated, and who corrected it afterwards. Autonomy controls sit beside it, setting what the system may act on alone and what always waits for a person.

Last reviewed: 2026-07-31

What an automation audit trail should record

Fourteen fields. Every one of them is something a reviewer, an internal auditor or a regulator has actually asked for after an automated decision went wrong.

FieldWhy it is there
Decision idSo the decision can be referred to at all.
TimestampWhen, to the second, not to the day.
AgentWhich worker decided. Notes belong to agents.
WorkflowWhich process it was acting inside.
ScopeWhich part of the operation owns the rule.
Inputs readEach system and each record id, not just a summary.
Rule appliedLinked to the note it lives in, and that note's version.
Sources comparedAll of them, and which one was believed.
Tolerance appliedThe band, and whether it was met.
OutcomeActed, held, or escalated. Three states.
ConfidenceRecorded, and never load-bearing. See below.
Escalation destinationWhere a held decision went, and to whom.
CorrectionWho changed it afterwards, what they changed, when.
Resulting rule editThe knowledge-base change the correction produced.

The last two are the ones almost nobody keeps. A trail that records the decision but not the human correction that followed it cannot answer the only question anyone asks afterwards: did this get fixed, and by whom.

Autonomy controls: what it may act on alone

Controls: what it may act on, and what always waits for a person. Three tiers, and only three.

TierWhat it may write backWhat it may not
Act and logThe result, where the decision is inside tolerance.Anything outside the band it was given.
Act within tolerance, hold outside itResults inside the band; holds the rest for a person.Release a held item on its own.
Propose onlyNothing. It drafts and a person decides.Write to any system of record.

Three tiers is what the existing controls plus the example note's escalation rule actually support. A fourth tier, per-field permissioning or time-boxed autonomy would be product capability nobody here has stated, and inventing a governance ladder is the worst possible place to start inventing.

Why a confidence score is not an autonomy control

Anything outside tolerance goes to escalation-queue. It is never auto-approved, regardless of confidence score. An operator decides.

ops/vendor-onboarding.md

The common design is the opposite: a threshold above which the system approves silently. That is a control in name only, because the thing being trusted is the system's own estimate of itself. A tolerance is a rule someone wrote and someone can read. A confidence score is a number the system produced about its own work.

Confidence is still recorded — it is useful when reviewing what went wrong. It is just never the thing that decides.

What happens when the rule itself was wrong

ops/vendor-onboarding.mdhuman in the loop
-Match on line position.
+Match on SKU, never on line position.
A reviewer corrected the rule in the layer's knowledge base. It read the new rule on its next run — no redeploy, no model change, and the correction sits in the audit trail with the person's name on it.

Three invoices auto-approved against the wrong lines because quantities matched by position. Caught at month-end, not by the agent.

ops/vendor-onboarding.md

The correction, the corrector and the behaviour change are all in the same trail, and no redeploy happened between them. That is what makes the trail worth keeping: it records not only what the system did, but what the organisation learned. The rule itself is the plain-text note the rule actually lives in.

What the rules landing in 2026 and 2027 ask for

Public dated fact, each row linked to its source. What the rule asks a deployer to be able to show — never what we certify.

WhereInstrumentDateWhat it asks you to show
EUAI Act, high-risk obligations2 Aug 2026Automatic logging retained six months (Art. 12), documented human oversight (Art. 14), deployer duties (Art. 26).
CanadaOSFI B-10, E-23 as expandedIn forceE-23 now covers AI and ML models: explainability, audit trail and documented human oversight, alongside third-party and technology risk.
UKFCA, PRA and Bank of England resilience frameworkAnnounced 18 Mar 2026Unified cyber and operational resilience expectations. Separately, HMRC MTD digital links require an unbroken digital trail from transaction to submitted VAT figure.
USSOX, as read in 2026 audit commentaryNo AI-specific guidance issuedAgents touching financial processes are treated as SOX-relevant controls, and the common finding is that management cannot produce the evidence trail.
IndiaDPDP RulesPhasing to 13 May 2027Rules notified 13 Nov 2025, substantive obligations phasing in. Read-only at the boundary is a materially simpler story than a warehouse build.

No primary US regulator had issued AI-specific SOX 404 guidance as of mid-2026. Stating that absence plainly is more useful than implying a rule exists.

The governance gap, in someone else's numbers

EY's *AIdea of India 2026* puts Indian enterprise adoption at 80% with 74% exploring agentic use cases — against 23% with a formal AI governance framework. Those are EY's figures, not ours. The gap they describe is the gap a decision record and three autonomy tiers are for.

What this page does not claim

No certification, no accreditation, no audit opinion, and no legal advice. Whether a given deployment falls in scope of any instrument above is a question for your own counsel, not for us.

The instruments are cited as published by the sources linked. What we describe is what the controls record — a mechanism, not a compliance status.

A held decision waits in the exception queue where a held decision waits, which is where that term is defined. The tolerances behind a held invoice are on the tolerance rules behind a held invoice.

Questions

Straight answers.

The five a governance paper usually needs answered before it is written.

What should an automation audit trail record?

What was decided, the rule it followed and the source it believed — plus the inputs read with their record ids, the tolerance applied, the outcome, the confidence, where it escalated, and who corrected it afterwards. The correction and the resulting rule change matter as much as the decision.

What audit trail do AI agents need for SOX?

No primary US regulator had issued AI-specific SOX 404 guidance as of mid-2026. What 2026 audit commentary treats as relevant is evidence: agents touching financial processes are control-relevant, and the common finding is that management cannot produce the trail when asked.

How do you structure an audit trail for autonomous decisions?

One record per decision, with a stable id, and every field written at decision time rather than reconstructed. Link the rule to the note it lives in and that note's version, so the trail still resolves after the rule changes. Keep corrections in the same record.

Who is accountable when an automated system makes a wrong decision?

The people who set the tolerance and the autonomy tier — which is why both are decisions someone makes explicitly, before anything runs, rather than defaults. The trail records who set them, who corrected the rule afterwards and when, so the question has an answer.

Does this make us compliant with the EU AI Act?

No. A product and a page are not a compliance opinion, and nobody here holds a certification of any kind. What the controls do is record what the Act's Articles 12, 14 and 26 ask a deployer to be able to show. Whether you are in scope is your counsel's call.

Start here

Bring us one workflow.

Tell us the process that crosses the most systems. You get a scope, a measure and a delivery plan back — and a straight answer if we think it is not worth building.

Get in touch

+1 (512) 954-4288Gujarat, India