AI Dictionary › Regolamentazione
AI Audit
AI audit is the process of systematically verifying an artificial intelligence system to confirm it meets declared technical, legal or ethical requirements: from regulatory compliance, to data quality, to the absence of discriminatory bias, to the accuracy of stated performance. It can be conducted internally by a dedicated team within the organization or externally by an independent third party.
AI audit is the process of systematically verifying an artificial intelligence system to confirm it meets declared technical, legal or ethical requirements: from regulatory compliance, to data quality, to the absence of discriminatory bias, to the accuracy of stated performance. It can be conducted internally by a dedicated team within the organization or externally by an independent third party.
A typical audit involves examining the system's technical documentation, analyzing training data and validation processes, testing model performance including on specific population subgroups, checking human oversight mechanisms, and verifying consistency between what the provider declares and the system's actual behavior. The outcome is typically formalized in a report that can feed into the compliance documentation required by regulation.
For companies developing or adopting high-risk AI systems, undergoing regular audits is often an integral part of the risk management obligations set out in the EU AI Act and frameworks such as the NIST AI RMF. It is also an increasingly common contractual requirement from enterprise clients before integrating an AI provider into their supply chain.
The practice of algorithmic auditing emerged from extending established internal audit and financial audit methodologies to AI, adapted from the mid-2010s onward in response to documented cases of algorithmic discrimination and the growing demand for independent verifiability of automated systems.
L'AI audit è il processo di verifica sistematica di un sistema di intelligenza artificiale per accertare che rispetti requisiti tecnici, legali o etici dichiarati: dalla conformità normativa, alla qualità dei dati, all'assenza di bias discriminatori, fino all'accuratezza delle prestazioni dichiarate. Può essere condotto internamente da un team dedicato dell'organizzazione o esternamente da un soggetto terzo indipendente.
Un audit tipico prevede l'esame della documentazione tecnica del sistema, l'analisi dei dati di addestramento e dei processi di validazione, test sulle prestazioni del modello anche su sottogruppi specifici della popolazione, verifica dei meccanismi di sorveglianza umana e controllo della coerenza tra quanto dichiarato dal fornitore e il comportamento effettivo del sistema. L'esito viene tipicamente formalizzato in un report che può alimentare la documentazione di conformità richiesta dalla normativa.
Per le aziende che sviluppano o adottano sistemi AI ad alto rischio, sottoporsi ad audit regolari è spesso parte integrante degli obblighi di gestione del rischio previsti dall'EU AI Act e da framework come il NIST AI RMF. È anche una pratica sempre più richiesta contrattualmente da clienti enterprise prima di integrare un fornitore di AI nella propria catena di fornitura.
La pratica dell'audit algoritmico nasce dall'estensione all'AI delle metodologie di internal audit e financial audit già consolidate in ambito aziendale, adattate a partire dalla metà degli anni 2010 per rispondere a casi documentati di discriminazione algoritmica e alla crescente richiesta di verificabilità indipendente dei sistemi automatizzati.
From our network
Kaimaki Web — Websites That Win Customers
Custom websites, web apps and digital marketing for growing businesses.
Visit kaimakiweb.com →From the Agora Intelligence blog
📱 Download the Android app (beta) iOS coming soon
Say what you mean. Get what you need.
Grace Certified — the AI coach that trains and certifies your prompt engineering — by Agora Intelligence.