The Unlearning School

How do you demonstrate AI Act compliance at an enterprise client audit?

What to show when an enterprise client audits your AI use - the evidence file that answers supplier questionnaires and EU AI Act Article 4 questions.

For companies that already have access to AI, but need rules, real tasks, verification and adoption evidence.

Start by separating two questions. Article 4 requires providers and deployers to take measures that support sufficient AI literacy. A client audit may ask for additional governance material under its own supplier, security or contractual process. An evidence file can help answer both questions, but it is a practical recommendation, not a certificate or a guarantee of legal compliance.

Questions an evidence file can answer

The exact questions depend on the client and contract. A useful preparation file can answer questions such as:

Article 4 does not create a mandatory certification. It requires proportionate AI literacy measures. The European Commission says organisations may keep internal records of training and guidance, while making clear that no specific certificate is required. Those records are evidence of action, not proof that every AI Act or contractual obligation has been met.

The evidence file, item by item

  1. Tool inventory. A dated list of AI tools in use, account types (enterprise vs personal), and which teams use them for what.
  2. AI use policy. Two to four pages covering approved tools, data boundaries, verification duties and responsibilities. Structure in our policy template.
  3. Training records. Who was trained, when, on what content, and how the content reflects role and context.
  4. Verification standard. The written rule for how AI output is checked before use, and who signs off on client-facing work.
  5. Incident path. A short procedure: what counts as an AI incident (data pasted where it should not be, unverified output sent), who is told, what happens next.

What this file does not prove

This file does not by itself prove compliance with the AI Act, data protection law, a client contract or a security standard. It organises facts that a company can review internally and provide when a client asks. Legal, privacy and security specialists should assess the obligations that apply to the specific systems, data and contract.

Frequently asked questions

Is there an official EU AI Act certification we can buy?

No. Article 4 does not create a general mandatory certification. The Commission says organisations can keep internal records of training and guidance, but no specific certificate is required.

We are a small supplier. Does proportionality help us?

Yes. Article 4 explicitly makes context relevant, including people's technical knowledge, experience, education and training, the context in which AI is used and the people affected. The practical file should match that context.

What if employees use AI informally and we say so?

Record the actual tools and tasks, decide which uses are approved, and define the rules and training needed for those uses. Do not claim zero use unless it has been checked.

How does training connect to passing an audit?

Training records can show who received guidance, when and on what topics. They are one part of the practical file, alongside the tool inventory, policy, verification rules and incident path.

Sources

Next step

Start the evidence file with the AI use policy template, or measure your current position with the free AI Adoption Score.

Next step

Take the free 7-minute AI Adoption Gap Score to see exactly where adoption is stuck in your company before any sales conversation.

Get your AI Adoption Gap Score →