Clarity at the Point of Decision
Decision Audit Report
Sample output — redacted from a 60-day governance engagement.
A Decision Audit Report is the operator-side artifact ModalPoint produces from every Tier 1+ governance engagement. It documents which AI-influenced decisions were authorized, under what policy basis, by whom, against which regulatory framework, and what evidence chain supports defensibility. This sample is a three-decision excerpt from a 60-day window, redacted for IR and operator confidentiality.
Decision excerpt — three representative entries
Each decision in the registry includes the full schema. The excerpts below show the canonical fields a regulator, board, or counsel can query.
Schema vocabulary aligns to EU AI Act risk classes (Minimal / Limited / High / Prohibited), TRAIGA substantial-compliance defense (§552.105), and NIST AI RMF Govern function.
Methodology — how the registry is built
Each AI-influenced decision in the operator’s environment is captured at the moment of authorization, not retroactively. The registry sits in the operator’s environment (no data leaves the tenant). Schema is owned by the operator and exportable on demand. Every entry pre-binds the decision to a specific policy basis and a named human accountable. For Tier 2+ engagements, the registry is mapped to the four major regulatory regimes (TRAIGA, EU AI Act, NIST AI RMF, ISO 42001) so a single export satisfies multiple audit requests.
Frequently Asked Questions
What is a Decision Audit Report?
It is the operator side artifact ModalPoint produces from every Tier 1 and higher governance engagement. It documents which AI influenced decisions were authorized, under what policy basis, by whom, against which regulatory framework, and what evidence chain supports defensibility. The sample shown is a three decision excerpt from a sixty day window, redacted for confidentiality.
What fields does an AI decision registry capture?
Each entry pre binds a decision to a specific policy basis and a named human accountable. Canonical fields include the decision id, date, decision type, risk class, who authorized it, the policy basis, the model and version, whether human review occurred, and the evidence chain of prompt and retrieval logs, rationale, and sign off. A regulator, board, or counsel can query any of these fields.
Where does the decision registry live and who owns it?
The registry sits inside the operator’s own environment, so no data leaves the tenant. The schema is owned by the operator and is exportable on demand. Each AI influenced decision is captured at the moment of authorization, not reconstructed retroactively.
How does one registry satisfy multiple regulators?
For Tier 2 and higher engagements, the registry is mapped to the four major regulatory regimes, TRAIGA, the EU AI Act, NIST AI RMF, and ISO 42001, so a single export can satisfy multiple audit requests. The schema vocabulary aligns to EU AI Act risk classes, the TRAIGA substantial compliance defense, and the NIST AI RMF Govern function.

