What an auditor, or Sekit's evidence engine, asks for.
AI transparency and external reporting plan
The map of the parties interested in the company's AI (customers, regulators, partners, affected individuals, staff) with the information about impacts, rights and recourse each one needs, plus the rules for when and how AI information is reported externally.
From the Sekit evidence catalog
In practice
External reporting means deciding upfront which AI-related facts get shared outside the company: an incident to a regulator, an impact disclosure to a customer, an explanation to a partner whose process depends on your model. A consultancy using AI to screen job applications needs a plan for what it tells candidates and regulators if that AI makes a wrong or biased call. An auditor asks for the AI transparency and external reporting plan and checks it names specific triggers, not a vague commitment to be transparent. The recurring gap is a company that reports security metrics internally but has never defined what, if anything, gets reported externally about its AI use.
Common gaps
The company tracks security metrics internally but has no defined rule for what gets reported externally about its AI systems.
A reporting plan lists generic stakeholders like customers and regulators without saying what information each group needs.
External reporting triggers are defined for security incidents generally, but nothing specific covers an AI system producing a biased or harmful decision.
Questions your auditor will ask
What AI-related information do you report externally, and to whom?
The AI transparency and external reporting plan maps each interested party, customers, regulators, partners, to the specific information they need and when it is shared.
Who decides what gets reported when something goes wrong with an AI system?
The reporting plan sets defined triggers tied to the same metrics review process leadership already uses, rather than an ad hoc call each time.
Are your AI reporting practices reviewed and kept current?
The plan is reviewed on the same schedule as security metrics reporting, so it reflects current AI systems rather than the ones in use when it was written.
How would you explain an AI decision to an affected customer?
The transparency plan defines what customers are told about impacts and their recourse, so the explanation is prepared rather than improvised.
Where regulation demands it
NIS2 art. 7.3 (Regular review and update) applies to reporting practices for AI as much as for any other security process.