What an auditor, or Sekit's evidence engine, asks for.
AI acceptable use and human oversight procedure
The operating rules for each AI system: what it is for, who may use it, valid inputs and outputs, prohibited uses, and how humans stay in control (trained users, review before decisions, restricted access, and a way to stop or override it).
From the Sekit evidence catalog
In practice
This is the operating rulebook for each AI system in daily use: who is allowed to use it, what inputs and outputs are valid, what uses are off limits, and how a human stays able to review, override or stop it. A firm using AI to draft client reports needs a rule that a human reviews the draft before it goes out, not a tool running unsupervised. An auditor asks for the AI acceptable use and human oversight procedure per system and checks whether staff using it completed the training tied to that role. The common gap is a general acceptable-use policy that mentions AI in passing but never specifies who can override an output or how.
Common gaps
A general acceptable-use policy mentions AI once but never says who is allowed to override an output or how to stop the system.
Staff use an AI drafting tool daily but never completed any training specific to that tool's risks or limits.
Human oversight is described as a principle but no procedure says at what point a person must review an AI output before it is acted on.
Questions your auditor will ask
Who is allowed to use this AI system, and for what?
The acceptable use procedure names permitted users, valid inputs and outputs, and prohibited uses per AI system, not a blanket rule across all tools.
How does a human stay in control of this AI system's output?
The procedure defines the review point before a decision is acted on and how a person can override or stop the system, per system.
Did the people using this AI system complete relevant training?
Completion is tracked and chased through the awareness training cycle, extended to cover role-specific AI use where relevant.
Do people with elevated AI-related responsibilities get extra training?
Roles carrying elevated responsibility get defined additional training delivered and verified on schedule, covering AI-specific duties where they apply.
Where regulation demands it
NIS2 art. 8.1 (Awareness raising and basic cyber hygiene) and art. 8.2 (Security training) cover how staff use AI tools day to day, not only how IT configures them.
GDPR's controller responsibility (24.1) means demonstrating appropriate measures for automated processing, which includes proof that human oversight of an AI system happens in practice.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.