ModalPoint · Decision Audit Report · Sample / Redacted

Clarity at the Point of Decision

Decision Audit Report

Sample output — redacted from a 60-day governance engagement.

A Decision Audit Report is the operator-side artifact ModalPoint produces from every Tier 1+ governance engagement. It documents which AI-influenced decisions were authorized, under what policy basis, by whom, against which regulatory framework, and what evidence chain supports defensibility. This sample is a three-decision excerpt from a 60-day window, redacted for IR and operator confidentiality.

Operator[Redacted] — Energy E&P, NYSE-listed
Audit Window2026-03-01 → 2026-04-30 (60 days)
Regulatory LensTRAIGA / EU AI Act / NIST AI RMF / ISO 42001
Engagement TierTier 2 — Cross-Border Governance Binder
Decisions in Window87 audited · 3 shown below
Audit StatusAll 87 defensible

Decision excerpt — three representative entries

Each decision in the registry includes the full schema. The excerpts below show the canonical fields a regulator, board, or counsel can query. Schema vocabulary aligns to EU AI Act risk classes (Minimal / Limited / High / Prohibited), TRAIGA substantial-compliance defense (§552.105), and NIST AI RMF Govern function.

Decision Registry / DR-2026-0312-014
decision_idDR-2026-0312-014
date2026-03-12T11:08:42Z
decision_typePermit-renewal AI-assisted EHS classification
risk_classHIGH (EU AI Act Annex III)
authorized_by[Redacted] — VP Operations, [Redacted Subsidiary]
policy_basisDIG-2.4 / TRAIGA §552.105 / EU AI Act Art. 14
modelazure-openai-gpt-4 (rev 0125)
human_reviewYes · pre-deployment + at-decision
evidence_chainPrompt + retrieval logs + classification rationale + sign-off captured
audit_statusDEFENSIBLE
Decision Registry / DR-2026-0327-039
decision_idDR-2026-0327-039
date2026-03-27T15:42:11Z
decision_typeVendor onboarding — AI-driven contract risk scoring
risk_classLIMITED
authorized_by[Redacted] — Director, Procurement
policy_basisDIG-1.2 / TRAIGA §552.105 / NIST AI RMF Govern 4.1
modelvendor-supplied-llm-v3 (third-party)
human_reviewYes · sample-based (10%)
evidence_chainVendor attestation + DPA + decision log retained 7 years
audit_statusDEFENSIBLE
Decision Registry / DR-2026-0418-061
decision_idDR-2026-0418-061
date2026-04-18T09:15:33Z
decision_typeExternal marketing claim approval — AI-generated copy
risk_classLIMITED
authorized_by[Redacted] — VP Marketing, with GC review
policy_basisDIG-3.1 (Representation Integrity) / EU AI Act Art. 50 / FTC AI Guidelines 2026
modelazure-openai-gpt-4 (rev 0125)
human_reviewYes · counsel + comms-lead double-check
evidence_chainSource attribution + factual cross-check log + AI-disclosure version captured
audit_statusDEFENSIBLE

Methodology — how the registry is built

Each AI-influenced decision in the operator’s environment is captured at the moment of authorization, not retroactively. The registry sits in the operator’s environment (no data leaves the tenant). Schema is owned by the operator and exportable on demand. Every entry pre-binds the decision to a specific policy basis and a named human accountable. For Tier 2+ engagements, the registry is mapped to the four major regulatory regimes (TRAIGA, EU AI Act, NIST AI RMF, ISO 42001) so a single export satisfies multiple audit requests.

Want one of these for your operator? Start with the $2,500 Shadow AI Exposure Assessment — surface the decisions in your environment, then plan the registry. Begin →

Frequently Asked Questions

What is a Decision Audit Report?

It is the operator side artifact ModalPoint produces from every Tier 1 and higher governance engagement. It documents which AI influenced decisions were authorized, under what policy basis, by whom, against which regulatory framework, and what evidence chain supports defensibility. The sample shown is a three decision excerpt from a sixty day window, redacted for confidentiality.

What fields does an AI decision registry capture?

Each entry pre binds a decision to a specific policy basis and a named human accountable. Canonical fields include the decision id, date, decision type, risk class, who authorized it, the policy basis, the model and version, whether human review occurred, and the evidence chain of prompt and retrieval logs, rationale, and sign off. A regulator, board, or counsel can query any of these fields.

Where does the decision registry live and who owns it?

The registry sits inside the operator’s own environment, so no data leaves the tenant. The schema is owned by the operator and is exportable on demand. Each AI influenced decision is captured at the moment of authorization, not reconstructed retroactively.

How does one registry satisfy multiple regulators?

For Tier 2 and higher engagements, the registry is mapped to the four major regulatory regimes, TRAIGA, the EU AI Act, NIST AI RMF, and ISO 42001, so a single export can satisfy multiple audit requests. The schema vocabulary aligns to EU AI Act risk classes, the TRAIGA substantial compliance defense, and the NIST AI RMF Govern function.