What an auditor, or Sekit's evidence engine, asks for.
Responsible AI development procedure and objectives
The internal standard for developing or adopting AI systems responsibly: the measurable objectives each initiative must meet (accuracy, fairness, robustness, transparency) and the review stages, such as risk, data, human oversight and testing, that make those objectives real in practice.
From the Sekit evidence catalog
In practice
Before writing a line of code or configuring a vendor model, the team should agree what "responsible" means for this specific AI initiative: an accuracy floor, a fairness check, a human review step. The responsible AI development procedure and objectives record captures those measurable targets and the review stages meant to hit them. Auditors probe whether the objectives are measurable, accuracy above what threshold, tested how, or whether they are aspirational language copied from a policy template with no acceptance criteria attached to any real project.
Common gaps
Objectives like fairness or robustness are stated but have no measurable threshold or acceptance test attached.
The procedure exists for internally built AI but was never applied to a purchased or configured vendor AI tool.
Objectives were set once at project kickoff and never checked against what was ultimately delivered.
Questions your auditor will ask
What measurable objectives does this AI initiative have?
Documented targets, for example an accuracy floor or a required human review step, recorded in the responsible AI development procedure.
Do these objectives apply to purchased AI tools, not only internally built ones?
Yes, adopting a vendor tool triggers the same objective-setting step before it is approved for use.
Who checks whether an objective was met before release?
The review stage named in the procedure, for example a risk or testing reviewer, confirms the acceptance criteria before go-live.
How is this different from a general secure development policy?
It adds AI-specific criteria, such as fairness or transparency targets, on top of the existing security requirements already built into development.
Where regulation demands it
NIS2 art. 6.2 (Secure development life cycle) requires exactly this, extended for an AI initiative to responsible-AI objectives set before build begins.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.