M.A.I. Consulting
AnalysisAdvanced9 October 20266 min read

The audit trail for an AI-influenced decision: what to record and for how long

When AI helped shape a decision and a funder asks how it was reached, "we have the chat history" is not an answer. The Decision Ledger: four lines, five minutes, one named owner.

A funder's programme officer emails on a Tuesday. Two years ago your organisation reallocated a regional budget line, and the decision memo now under review leaned on an analysis that an AI assistant helped produce. The question is short: how was that conclusion reached, and who was responsible for it? Nobody on your team can say which version of the analysis was used, what the assistant was asked, or who checked it.

Most mission-driven organisations are one such email away from this scenario. The gap is rarely bad faith. It is that AI became part of how decisions get made faster than anyone decided what evidence that involvement should leave behind. Our view is that the answer is neither an elaborate compliance system nor nothing at all. It is a small, disciplined record, kept at the point of decision.

An audit trail is not a record of everything the AI did. It is a record of what a named person relied on, and why they were entitled to.

Why "we keep the chat history" is not an audit trail

Many teams assume that an AI tool's conversation history is their record. It is not, for three reasons. Histories are tied to individual accounts, so they vanish when a colleague leaves. They capture what was said to the tool, but not which output was actually used, or what was changed before it reached the memo. And they say nothing about the human judgement that turned a draft into a decision.

An auditor, a funder or a board asking about a past decision is rarely interested in the transcript. They want to know whether the organisation had control: whether someone competent looked at the material, whether the sensitive parts were handled properly, and whether the person who signed could explain what they signed.

The Decision Ledger: four lines, kept at the point of decision

We use a deliberately small structure that we call the Decision Ledger. It has four lines, and it can be completed in under five minutes by the person making the decision.

None of this requires new software. A shared template attached to the decision memo, or a short section at its end, is enough. What matters is that the ledger lives with the decision, not in a separate system that nobody opens.

Proportionality: not every AI use needs a ledger

A common reason audit trails fail is that they are designed for the exceptional case and then imposed on the routine one. Nobody keeps a ledger for a polished email. The rule we recommend is tied to consequence, not to tool use.

A ledger is warranted when the output influences one of four things: money committed or reallocated, a commitment made to a funder or regulator, a decision about a named individual or group, or a public statement made on the organisation's behalf. Everything below that threshold is covered by the general permitted-use policy and the person's own diligence.

The question is never "did we use AI?" It is "would we be able to explain, calmly and without searching, how this conclusion was reached?"

This threshold has a useful side effect. It gives staff a clear line, which reduces both under-recording (nothing is kept) and over-recording (everything is kept, and nothing can be found).

How long to keep it, and where

Retention is the question executives ask last and should ask first. We suggest three principles rather than a fixed number of years, because obligations differ by jurisdiction, funder and contract.

First, keep the ledger for as long as you must keep the decision it supports. If grant records must be retained for a set period under a funding agreement, the ledger follows the same clock. Second, store it where the decision record itself is stored, under the same access controls, so that it survives staff turnover. Third, confirm the schedule with your data protection lead or legal adviser, because a ledger that refers to personal data categories is itself part of your records.

If you cannot state the retention rule for the decision, you cannot state it for the ledger. Fix the first problem first.

Common failure modes

Three patterns recur when organisations try this for the first time.

The first is retrospective reconstruction: ledgers completed weeks later from memory. They are quickly recognised for what they are. The discipline is to complete the four lines when the decision is signed, or not at all.

The second is treating the ledger as a confession. If staff fear that recording AI use will count against them, they will stop recording it, or stop using approved tools. The ledger must be presented as evidence of good practice, and leaders must be seen to complete it themselves.

The third is recording the tool but not the judgement. A ledger that says "used an AI assistant to draft the paper" and nothing else demonstrates that AI was involved and that no one can say what happened next. That is worse than silence.

Questions for your next leadership meeting

The bottom line

An audit trail for AI-influenced decisions is a four-line record of input, influence, judgement and owner, kept at the point of decision and proportionate to the consequence. Organisations that can produce it calmly are not more cautious than others. They are simply the ones who decided, before the email arrived, what accountability would look like.

Series · AI Consulting: leadership briefings · part 11 of 11
02 ยท AI Use Policy

What are our people allowed to do, and how?

If this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.