G1 - Your AI Policy Is a Promise. Your Regulator Wants Proof.
Most AI governance today is written, not operated: policies describe how systems should behave, while nobody can show how they actually do behave. Evidence over assertion is the shift that separates governance that holds from governance that folds.
Where this gets hard
- Policies are written at deployment, but AI behaviour keeps moving after approval — the document ends up governing a system that no longer exists.
- ‘We have a policy for that’ gets treated as equivalent to ‘we can prove that’ — right up until someone asks for the artefact.
- Assessments, registers and sign-offs live in documents; runtime behaviour lives in production. Nothing connects the two.
- When an incident lands, teams reconstruct evidence after the fact — which convinces nobody, least of all an authority.
- Governance reviews audit whether the paperwork is current, not whether the estate behaves as the paperwork claims.
Where to start
- Apply one test to every stated control: what artefact would a sceptical third party examine — and can we produce it today?
- Instrument first, write second: a monitored behaviour with a thin policy beats a thick policy with no telemetry.
- Anchor each regulatory obligation to a specific piece of runtime evidence — a log, a metric, a signed record.
- Score your governance on a three-point scale — absent, asserted, evidenced — and be honest about how much of it sits at ‘asserted’.
- Make ‘if it isn’t monitored, it isn’t governed’ the design rule for every new AI system.
The companion consulting document on our website includes the evidence-anchor test, a six-pillar governance diagnostic and the three-point scoring guide.
Part of RMAT's 12-part series on AI governance — Governing AI with Evidence. The companion consulting document — detailed checklists, a risk table, a maturity self-assessment and a 90-day action roadmap — is available on our website.