AI audit trail requirements in banking, and where logs stop being enough
Every institution deploying AI keeps logs. Few can show that the logs were not edited. That distinction is the whole difference between a record and evidence.
Supervisory expectations for AI in banking are converging on a familiar shape: know what the system does, govern it, document it, and be able to reconstruct specific decisions on request. Institutions generally handle the first three. The fourth is where examinations get uncomfortable.
What a reconstructable decision requires
- The model and version in force at the time.
- The inputs, or a cryptographic commitment to them where the inputs are sensitive.
- The output, including confidence or score where applicable.
- Human review, override, or documented absence of either.
- A timestamp that is credible to someone outside the institution.
The first four are ordinary engineering. The fifth is the hard one, and it is the one that carries evidentiary weight.
The self-attestation gap
An institution's logs are produced, stored, and maintained by the institution. In a dispute about whether a decision happened as described, that provenance is exactly the weakness opposing counsel will press. Tamper-evidence that depends on the log owner's controls is not tamper-evidence to a third party; it is a policy assurance.
Independent verifiability is what closes the gap. If the record's timestamp and integrity are witnessed by a party with no interest in the outcome, the institution's own controls stop being load-bearing.
What this looks like operationally
Rubric attests decision records at the moment they occur: the record is signed with a post-quantum key the application does not hold, and the signature is anchored to the Hedera Consensus Service, a public ledger operated by an independent council. Anyone can later verify that a record existed at a given time and has not changed, using public infrastructure.
Check it yourself
Every Rubric attestation resolves publicly, with no account and no API key, and every anchor resolves to a public ledger message you can read without our cooperation.
HCS topic 0.0.10416909 · ML-DSA-65 signatures
Where institutions usually start
Attesting every inference is rarely the right first step. The high-value scope is the set of decisions that are expensive to be unable to prove:
- Adverse actions and denials.
- Autonomous approvals above a materiality threshold.
- Model version changes and configuration edits.
- Incidents, overrides, and escalations.
Evidence quality matters more than evidence volume. A small set of independently verifiable records is worth more in an examination than terabytes of logs nobody can authenticate.
Standards posture
Evidence packages produced by Rubric carry C2PA Content Credentials, the same content provenance standard adopted across the major technology platforms, on top of the post-quantum attestation layer.
Verifiable, not asserted
Rubric Protocol is a conformant C2PA Generator Product (Content Credentials 2.4, Assurance Level 1).
Record 01a002b7-3663-7b3b-a60e-db3b99ee2d94 · Echelon Intelligence Group LLC
Related: SR 26-2 agentic AI documentation · Attestation vs SIEM logging · Financial services