Two of the five can be inspected. That is the finding

Everyone assessing an AI portfolio inspects five things. Two of them have evidence to inspect. When a review reports confidently on all five, that is not thoroughness — it is the thing worth asking about.

The five, and what they rest on

Any serious review of what an organization is doing with AI comes down to five connected questions.

  • Capacity — is supply matched to demand, reliably, at a cost you can defend?
  • Access — who can reach which systems, models and data, and under what controls?
  • Provenance — can data, models, content and decisions be traced back to something reliable?
  • Compliance — are the obligations that apply built into how the work happens, and can that be demonstrated?
  • Attribution — can cost and operational gain be traced to business outcomes?

The first two can be examined directly. There are systems, there are settings, there are invoices, there are access lists. An assessor with the right permissions can go and look.

The last three usually cannot, and the reason is the same in each case: the evidence they depend on was never built.

Three of the five have nothing to inspect.

  • Capacity
  • Access
  • Provenance
  • Compliance
  • Attribution

Why the evidence was never built

Nobody decided against it. The evidence layer is simply not a by-product of doing the work.

Provenance requires that someone recorded where a number came from at the moment it was produced. Almost no operational system does this by default, because it costs something at write time and pays off only when somebody later asks a question nobody anticipated.

Compliance requires a map from each obligation to the specific step that satisfies it, and something that proves the step happened. Most organizations have the obligations documented and the steps happening, and nothing connecting the two.

Attribution requires that spend and outcome were instrumented against the same unit, on the same calendar, by people who agreed in advance what the unit was. Spend lives in one system owned by finance. Outcomes live in another owned by a product or operations team. Nobody has the authority to connect them, and connecting them retroactively is usually impossible rather than merely expensive.

So the honest answer to "what did this AI investment return" is very often that the evidence layer needed to answer it was never built. That is an organizational gap, not a technical one — which is why no tool has closed it. Tools are good at what is being spent. They are silent on what it bought and who is accountable for the difference.

What this means for reading any assessment

A review that reports with equal confidence across all five dimensions is making a claim about your evidence layer that is unlikely to be true.

There are three ways that happens, and they are worth being able to tell apart.

Sometimes the assessor has substituted a proxy — surveying people about whether they trust the numbers, and reporting the result as provenance. That is a measure of confidence, not of traceability, and the two diverge precisely where it matters.

Sometimes the assessor has scored a policy rather than a practice. The policy exists, so compliance scores well. Whether the work follows it was not examined, because examining it is expensive.

And sometimes attribution has been reconstructed after the fact from whatever could be joined, which produces a number with a decimal point and no defensible basis.

None of those is dishonest. All of them are what happens when a review is scoped to produce a complete answer rather than a true one.

The finding is the gap

When we assess these five and three come back unassessable, we do not treat that as a limitation of the review. We treat it as the result.

It tells leadership something specific and actionable: before the next funding decision can be defended with evidence, the evidence has to exist, and here is the smallest version of it that would answer the question actually being asked.

That is usually a much smaller programme than it sounds. It does not require instrumenting everything. It requires picking the decisions that will be asked about, and building the trail for those.

The alternative — funding the next round on conviction and describing it as evidence-based — is the position most organizations are currently in, and it holds right up until somebody on the board asks the second question.

What to do with this

If you are commissioning a review, ask the assessor in advance which of the five they expect to be able to inspect, and what they will do about the others. The answer tells you a great deal about what you are buying.

If you already have one, look at how provenance, compliance and attribution were scored, and ask what evidence was inspected. Not what was concluded — what was looked at.

We do not issue audit opinions, assurance opinions or certifications. We measure what can be measured, name what cannot, and say which of the two your next decision depends on.

Start a conversation about the decisions in front of you.

Start a conversation