BlogGovernance
Governance4 min read· July 12, 2026

A Model Audit Checklist for Compliance

Carolina Fogliato

Published July 12, 2026

A model audit isn't a vibe check. Here's the checklist compliance can actually run before the model ships.

A model audit isn't a vibe check — it's a structured review that lets compliance sign off before the model ships. Here's the checklist that actually works.

A model audit is the compliance gate that, done well, lets a model ship. Done badly, it's a rubber stamp that gets everyone in trouble later. The checklist is what makes it the first.

The Diligence Frame: What Compliance Needs

Treat the model audit like diligence — the structured questions that expose whether the model is safe to ship. Compliance needs answers to specific questions, not assurances about quality. The checklist is the set of questions.

  • What does the model do, and on what data?
  • What are the known failure modes?
  • What's the audit trail — can a decision be reconstructed?
  • What's the kill switch and the escalation path?
  • Who owns the model in production?

The Checklist

  • **Intended use.** Documented, specific, and bounded.
  • **Data.** What it trained on, what it sees at inference, what's retained.
  • **Evals.** A repeatable test suite, with the results.
  • **Failure modes.** Known, documented, with mitigations.
  • **Audit trail.** Decisions logged and reconstructable.
  • **Guardrails.** Confidence thresholds, escalation, kill switch.
  • **Ownership.** A named owner in production.
  • **Review.** A cadence for re-audit.

What to Refuse

  • "We tested it" without the eval suite.
  • "It's mostly accurate" without the failure modes.
  • "We'll add the audit trail later."
  • No named owner.

How to Use the Checklist

Run the checklist before the model ships, not after. Each item is a gate — a model that fails an item doesn't ship until the item is closed. The checklist is what makes the audit a gate instead of a rubber stamp.

Conclusion

A model audit is a structured diligence review, not a vibe check. Run the checklist — intended use, data, evals, failure modes, audit trail, guardrails, ownership, review — before the model ships, and compliance can sign off without signing away the risk.

About FACTA

FACTA helps startups and growth-stage teams turn AI into production systems that keep running — not demos that impress once.

We design the architecture around the parts that actually break under real usage: tooling you own, credentials you control, failover, cost controls, observability. The boring infrastructure that keeps a system alive after launch.

Led by Matías Baglieri and Carolina Fogliato, we focus on one thing:

AI leadership that builds. Not just advises.

Run your next model against the checklist above.

Tell us which items you can't close, and we'll help you close them. See eval-driven compliance for the eval-as-audit-trail pattern.

Explore AI Strategy
Book a 30-minute call →

No pitch. No pressure. Just a look at where your AI stack is fragile — and what to fix first.

Stay Updated

Get production AI insights in your inbox

Weekly insights. No spam. Unsubscribe anytime.

Your Privacy Matters

We use cookies to enhance your experience, analyze traffic, and serve targeted ads.

By clicking "Accept All", you consent to all cookies. Cookie Policy