Evidence, testing & findings
Evidence model
Section titled “Evidence model”Use three connected evidence layers:
- Authority evidence — official source, status, provision, effective date and applicability.
- Control evidence — policy, procedure, contract, configuration, record and accountable owner.
- Outcome evidence — test, monitoring, complaint, incident, decision sample and affected-party result.
A legal source proves the obligation, not compliance. A policy proves design intent, not operation.
Common evidence by route
Section titled “Common evidence by route”| Route | Useful evidence |
|---|---|
| Data protection | Processing record, lawful-basis analysis, notices, rights handling, impact assessment, security and processor records |
| Automated decisions | Decision logic, significance analysis, human review, explanations, challenge and outcome monitoring |
| Children/vulnerability | Age and vulnerability analysis, safeguarding, consent where applicable, accessible redress |
| Public sector | Procurement, approval, project clearance, architecture, records and public-law review |
| Identity/biometrics | Identity authority, necessity, data protection, matching evaluation, security and redress |
| Finance/insurance/pensions | Licence and product scope, suitability, decisions, overrides, complaints, model validation and regulator records |
| Telecoms/critical service | Licence context, resilience, service quality, incident and continuity evidence |
| Health | Clinical purpose, SaMD status, validation, safety, professional oversight and patient rights |
| Content/election/IP | Rights clearance, consent, provenance, labelling, moderation, complaints and escalation |
Bounded tests
Section titled “Bounded tests”Tests should establish whether the specific obligation or control works. Examples:
- Trace a data-subject request through an AI system’s data and downstream processors.
- Reperform a significant automated decision and test human review and explanation.
- Compare model outcomes across relevant populations or languages.
- Trace a procurement from applicability decision through approval and acceptance.
- Sample regulated advice, underwriting, claims or credit decisions.
- Test incident-route selection against actual facts and notification triggers.
- Trace synthetic content through rights, provenance, label and complaint handling.
Obtain authorisation and avoid live harm.
Findings
Section titled “Findings”Raise a finding where:
- Applicable law or sector route was missed.
- Source status is wrong or unverified.
- A proposed obligation is reported as current law.
- A compliant claim lacks objective evidence.
- An item has failed outcome testing.
- A significant decision lacks meaningful review or redress.
- Affected populations show material disparity.
- A supplier prevents required access, evidence or control.
- An N/A decision lacks a specific basis.
- A regulator-status change invalidates the conclusion.
Severity
Section titled “Severity”Consider:
- Binding status and enforcement exposure.
- Scale and vulnerability of affected people.
- Significance and reversibility of the outcome.
- Data sensitivity.
- Licence or critical-service implications.
- Detectability and ability to provide redress.
- Recurrence and systemic scope.
Do not assign severity from the framework section alone.
Evidence checklist
Section titled “Evidence checklist”- Official source and status verified.
- Evidence belongs to the selected system.
- Regulated role and activity match.
- Current operation, not only design, sampled.
- Nigerian population, language and access context considered.
- Contrary evidence retained.
- Findings link to a legal or readiness lane.
- Remediation has an owner and verification method.