What an auditor, or Sekit's evidence engine, asks for.
AI system documentation for users
The material the company gives to the people who use the AI system: what it is for, what it cannot do, its known limitations, how to interpret and challenge its outputs, and how the person is told they are dealing with AI.
From the Sekit evidence catalog
In practice
This is the material given to the people using an AI system: what it does, what it does not do, its known limitations, how to challenge or question its output, and a clear signal that they are dealing with AI rather than a person. A firm rolling out an AI drafting tool to staff needs a short, plain-language guide, not the vendor's technical manual. An auditor asks to see the AI system documentation for users and checks it against what staff received: was it handed out, is it current, do people know it exists. The common gap is a policy document written for the file that was never shared with the people using the tool.
Common gaps
Users are pointed to the vendor's technical manual instead of a plain-language guide covering what the tool cannot do and how to challenge its output.
Documentation for an AI tool exists in a policy folder but was never distributed to the staff who use the tool daily.
Nobody tells users they are interacting with an AI system rather than a person, so there is no record they were informed.
Questions your auditor will ask
What do users of this AI system know about its limitations?
The AI system documentation for users names known limitations in plain language and is distributed before the tool goes into use, not buried in a policy folder.
How does a user know they are dealing with AI, not a person?
User documentation includes a clear statement that the interaction involves an AI system, part of the same package covering intended use and limitations.
Can users challenge or question an AI output they disagree with?
The documentation explains how to interpret and challenge outputs, giving users a defined path rather than leaving them to guess.
How do you know this documentation reached the people using the tool?
Distribution is treated as evidence to retain, so there is a dated record of who received the current version and when.
Where regulation demands it
GDPR accountability (5.2) means being able to show, not only state, that users were informed about how an AI system works and what it cannot do.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.