Auditors Don't Read Your PDFs. They Audit Your Evidence.
A folder full of downloaded compliance templates is not an AI Management System — it is a costume. Certification bodies have gotten very good at spotting the difference in the first hour.
There is a well-worn path to failing an audit. Someone senior decides the organisation should get certified. A template pack is purchased. Policies are populated, logos swapped, names inserted. The documentation set looks complete. Then the auditor arrives and asks the question the documents cannot answer: "Show me the last time this happened."
The gap between policy and practice
Your AI risk policy says risk assessments are reviewed quarterly. The auditor asks for the minutes of the last four meetings — there are two, both from last year. Your incident procedure describes a 24-hour escalation path. The auditor asks how many AI incidents were logged in the past year. The answer is zero — which means incidents happened and were never classified as such.
What "evidence-first" actually means
Instead of writing the policy and hoping practice catches up, start from operational reality. For every clause and control, ask three questions before a word of policy is written:
- Who does this today? If nobody does, you are designing a process, not documenting one.
- What does doing it leave behind? A ticket, an approval, a signed record. If the activity leaves no trace, it is invisible to an auditor.
- Where does that trace live, and for how long? Evidence scattered across personal drives is evidence you cannot produce on demand.
The Statement of Applicability is the honesty test
If you want to know whether a management system is real, read its Statement of Applicability. Template-driven organisations mark almost everything applicable, because excluding something feels risky. That is a tell. A mature SoA has exclusions — and the exclusions have reasons. That tells an auditor more about your governance maturity than fifty pages of policy prose.
Template packs are cheap and fast. Failed certification attempts are neither — a failed Stage 2 audit costs the audit fee, the remediation programme, the re-audit, and months of delay.