Recording How AI Was Used, What Was Verified, and Who Approved
Introduction
You will learn what to document when using AI in your professional work--creating a clear record of how you used AI, what you verified, and who approved the work--so that your AI-assisted work is defensible and transparent.
At the Assisted Use level, you are moving from understanding concepts to applying them with guidance. You will begin using AI tools under supervision, learning to evaluate their outputs critically and document your verification processes. This is where theory meets practice -- with appropriate guardrails in place.
This lesson is designed to be accessible to professionals at all experience levels while providing the depth needed for practical application. Whether you are encountering these concepts for the first time or building on existing knowledge, the material ahead will strengthen your ability to navigate AI governance challenges with confidence and competence.
Core Concepts
Anti-Patterns / Misuse Risks
Anti-Pattern 1: No Documentation "I used AI, reviewed the output, and sent it along. I didn't keep any records of the process."
Risk: If questioned later, you can't show what AI produced, what you verified, or who approved it. This undermines credibility and raises questions about diligence.
Safeguard: Always keep records of AI use: prompts, output, verification steps, approvals.
Anti-Pattern 2: Minimal Documentation "I wrote down that I 'verified the content' but didn't specify what I verified or how."
Risk: "I verified it" is vague. An auditor won't accept this as evidence of rigor. Specific documentation shows what was actually checked.
Safeguard: Document specifically: What claims were verified? Against what sources? What was confirmed?
Anti-Pattern 3: No Approval Trail "I made changes to the AI output and distributed it. I didn't get explicit approval from anyone."
Risk: Without approval documentation, it's unclear if the work was properly authorized. This is a control weakness.
Safeguard: Obtain and document approval from appropriate authority before distributing final work.
Anti-Pattern 4: Hiding AI Use "I used AI to draft the policy, but I didn't mention this in the documentation. It looks like I wrote it myself."
Risk: Misrepresenting the work process is deceptive and undermines trust. If discovered, it damages credibility.
Safeguard: Be transparent: document that AI was used, what AI produced, and what you verified.
Anti-Pattern 5: Documentation Scattered Across Tools "I kept notes in email, comments in the document, and approval in a different system. It's all over the place."
Risk: Scattered documentation is hard to find, incomplete, and difficult to present to auditors.
Safeguard: Consolidate documentation in a single place or organized record.
Human Judgment Checkpoints
Before finalizing AI-assisted work, ask yourself:
- Use Documented: Have I recorded what AI was used for and what prompt I gave?
- Output Documented: Have I saved the AI output so I can show what was generated?
- Verification Documented: Have I recorded what I verified and how I verified it?
- Changes Documented: Have I tracked changes made to AI output?
- Review Documented: Have I recorded who reviewed the work and what feedback they gave?
- Approval Documented: Do I have documented approval from appropriate authority?
- Transparency: Have I been clear about AI use, or have I misrepresented the work?
- Completeness: If I needed to explain this work to an auditor, would my documentation be sufficient?
[Practical Tip]
As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.
Traceability / Defensibility Considerations
Documentation creates the audit trail that shows your diligence:
What to Record (Minimum): 1. Date and time of AI use 2. AI tool used 3. Prompt given to AI (or description of what was asked) 4. Description of AI output 5. Verification steps taken (spot-check, source check, expert review) 6. Changes made (describe revisions) 7. Who reviewed (stakeholder names, dates) 8. Who approved (authority, signature, date)
What to Record (Comprehensive): All of the above, plus: - Original source materials used - Specific sources verified - Review feedback and how it was addressed - Version control (draft versions, final version) - Distribution record (who received final work) - Implementation or use (how the work was used in decisions) - Approval conditions (any caveats or limitations on approval)
Responsible AI and Control Considerations
Responsible Documentation: 1. Transparency: Be honest about AI use; don't hide or minimize it 2. Specificity: Document what you did, not just that you did something 3. Completeness: Record enough detail so someone else could understand your process 4. Organization: Keep documentation organized and accessible 5. Retention: Maintain documentation per organizational retention policies
Control Considerations: - Documentation of AI use should be part of your control environment - For material work, documented verification and approval are standard practice - Audit and compliance teams should have access to AI use documentation - Documentation practices should be consistent across the organization
[Practical Tip]
As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.
Practice / Reflection Prompts
- Create a documentation template for AI-assisted work in your role. What would you want to record every time you used AI?
- Document one AI-assisted project from start to finish. Include: AI use, verification, review, approval. Review your documentation: Is it complete? Clear? Would an auditor accept it?
- Review documentation practices from colleagues who use AI. What do they document? What gaps do you see? What best practices could you adopt?
- Imagine an audit. An auditor asks: "Show me how you used AI to create this work, what you verified, and who approved it." Could you provide complete documentation? What's missing?
- Build a documentation library. Create templates or examples for different types of AI-assisted work (summaries, drafts, analyses). What should always be documented for each type?
Practical Application
Understanding concepts in the abstract is valuable, but the real test is whether you can apply them in professional practice. This section bridges the gap between theory and application with concrete scenarios drawn from oversight work.
Use Case 1: Policy Documentation You created a new data governance policy with AI assistance. You need to document the process so that leadership understands it was developed thoughtfully, verified carefully, and properly approved.
Documentation needed: 1. Policy objective and scope 2. AI instructions/prompts used 3. AI-generated draft (saved version) 4. Verification steps (what policy requirements were verified, how) 5. Review feedback from stakeholders (Compliance, Legal, Operations) 6. Revision history (what changed based on feedback) 7. Final approved version 8. Approval sign-off (who approved, when) 9. Distribution record (who received the policy, confirmation of understanding)
Use Case 2: Risk Assessment Summary You summarized emerging cybersecurity risks using AI. The summary will inform risk committee discussion. You need to document how the summary was developed so the committee understands the rigor behind it.
Documentation needed: 1. Risk assessment scope (what timeframe, what risk categories) 2. AI instructions (what did you ask AI to do?) 3. AI-generated summary (the output) 4. Source verification (which sources did you check? What did you verify?) 5. Risk owner feedback (did you discuss with the CISO? What did they confirm?) 6. Revisions made (any corrections or additions after review) 7. Final summary used for committee briefing 8. Approval by Chief Risk Officer or appropriate authority
Use Case 3: Audit Finding Summary You synthesized findings from multiple audits using AI. These findings will inform your risk assessment and remediation planning. You need to document the synthesis process so auditors understand that findings were accurately captured and properly categorized.
Documentation needed: 1. Audit reports reviewed (source documents) 2. AI instructions (what did you ask AI to synthesize?) 3. AI-generated synthesis (the output) 4. Verification steps (which findings were spot-checked against originals, what was confirmed) 5. Gaps identified (what findings were in originals but not in AI summary) 6. Corrections made (any status updates, severity adjustments) 7. Final corrected synthesis 8. Approval by Audit Lead or CFO
Detailed Examples
The following examples illustrate how the concepts from this lesson play out in real-world oversight scenarios. Each example is designed to help you recognize similar situations in your own work and respond with appropriate professional judgment.
Example 1: Policy Development Documentation Package
Documentation Record for New Data Governance Policy:
``` POLICY DEVELOPMENT DOCUMENTATION
Policy: Data Governance Policy v1.0 Date Initiated: 2026-02-15 Owner: Chief Data Officer Status: Approved and Distributed
- OBJECTIVE AND SCOPE
- Objective: Establish governance for organizational data including classification, use approval, encryption, and retention
- Scope: Applies to all personal data, sensitive data, and restricted data held by the organization
- AI ASSISTANCE RECORD
- AI Tool Used: Claude AI (via Compliance Portal)
- Date AI Used: 2026-02-18
- AI Prompt: "Draft a comprehensive data governance policy for a financial services organization. Include sections on: data classification, use approval, encryption requirements, data owner responsibilities, retention timelines, breach notification, and enforcement. Audience: all employees. Include examples."
- AI Output Generated: [Draft policy saved as "DataGovPolicy_Draft_20260218.docx"]
- VERIFICATION STEPS
- Verification Date: 2026-02-20
- Verification Method: Subject matter expert review and source alignment check
- Steps Taken:
- Compared AI draft against GDPR requirements (verified that AI covered key GDPR principles)
- Compared AI draft against NIST data governance framework (verified that AI addressed NIST categories)
- Checked that policy language was clear and unambiguous (read policy aloud, tested for clarity)
- Verified that data classification categories aligned with organizational risk levels
- Confirmed that enforcement provisions were appropriate
Verification Results: - AI policy captured major governance principles accurately - Policy language was clear and appropriate for employee audience - One gap identified: Policy didn't address international data transfers; added section on this topic - One correction: Encryption requirement language needed clarification (distinguished between different data types)
Verified By: Jane Smith, Compliance Analyst
- STAKEHOLDER REVIEW AND FEEDBACK
- Review Period: 2026-02-20 to 2026-02-27
- Reviewers:
- Compliance Officer (reviews for compliance and risk alignment)
- Legal Counsel (reviews for legal risk and enforceability)
- Data Security Manager (reviews for technical feasibility)
- Operations Manager (reviews for practicality)
Review Feedback Summary: - Compliance Officer: Approved with note on CCPA alignment (we added this) - Legal Counsel: Requested clarification on enforcement section; recommended adding disclaimer about legal hold exceptions - Data Security Manager: Noted that encryption requirements were feasible; asked if exemptions existed for disaster recovery - Operations Manager: Noted that data owner identification would require data inventory first; recommended phased implementation
- REVISIONS MADE
- Based on feedback:
- Added CCPA alignment section (per Compliance Officer)
- Added legal hold exception language (per Legal Counsel)
- Added disaster recovery exception to encryption requirement (per Security Manager)
- Added phased implementation timeline with data inventory step (per Operations Manager)
- Clarified international data transfer rules (from verification step)
Revised Draft Saved: "DataGovPolicy_Draft_20260227_Revised.docx"
- FINAL REVIEW AND APPROVAL
- Final Review Date: 2026-02-28
- Final Review Conducted By: Chief Data Officer and Chief Compliance Officer
- Final Approval: Yes
- Approval Signature: [CDO signature], [CCO signature]
- Approval Date: 2026-02-28
- Notes: "Policy is comprehensive, well-written, and incorporates stakeholder feedback appropriately. Approved for distribution and implementation."
- DISTRIBUTION AND IMPLEMENTATION
- Distribution Date: 2026-03-01
- Distribution Method: Email to all staff with linked one-pager summary
- Training Scheduled: 2026-03-15 and 2026-03-22 (two sessions)
- Implementation Date: 2026-03-01 (policy effective immediately; compliance expected after training)
- Acknowledgment Required: Yes (staff required to acknowledge receipt and understanding)
- DOCUMENTATION SUMMARY
- This policy was developed with AI assistance (initial drafting) combined with expert review (verification and stakeholder feedback). Multiple subject matter experts reviewed the draft and provided feedback. Revisions were made based on their input. Final policy was approved by CDO and CCO before distribution. Policy is comprehensive, legally compliant, and operationally feasible.
AI Role: Initial drafting, structure, and clear language Human Role: Verification against standards, stakeholder coordination, revision, approval Status: Complete and in effect ```
Use of This Documentation: - If an auditor asks "How was this policy developed?" -> Show this documentation package - If someone questions a policy decision -> Can point to the review feedback and approval - If policy needs revision later -> This documentation provides the baseline and change history
Example 2: Risk Assessment Documentation
Documentation Record for Emerging Risk Summary:
``` EMERGING RISK ASSESSMENT DOCUMENTATION
Assessment Date: 2026-03-01 Assessment Scope: Emerging cybersecurity, regulatory, and operational risks (2026 outlook) Owner: Chief Risk Officer Use: Board Risk Committee briefing (March 10, 2026)
- AI ASSISTANCE RECORD
- AI Tool Used: Claude AI (via Risk Management Portal)
- Date AI Used: 2026-02-25
- AI Prompt: "Summarize emerging risks facing a mid-sized financial services company in 2026. Focus on: cybersecurity threats, regulatory changes, and operational risks. For each risk, assess likelihood (high/medium/low) and impact (high/medium/low). Include credible sources that support each risk assessment. Format: table with risk, category, source, likelihood, impact."
AI Output Generated: [Risk summary draft saved as "EmergingRisks_Draft_20260225.xlsx"]
- SOURCE VERIFICATION AND FACT-CHECKING
- Verification Date: 2026-02-28
- Verification Method: Primary source checking and risk authority validation
- Sources Checked:
- CISA Cybersecurity Advisories (for cyber threats) -> Verified AI-identified threats against current CISA alerts
- SEC Recent Guidance (for regulatory changes) -> Verified AI-identified regulatory timeline against SEC website
- Federal Reserve Guidance (for regulatory changes) -> Verified Fed guidance on emerging requirements
- Industry Reports (Gartner, Forrester) -> Spot-checked industry risk assessments
Verification Results: - AI-identified cyber risks (social engineering, ransomware, supply chain): All verified against CISA alerts - AI-identified regulatory risks (AI governance): Timeline verified against SEC (2026-2027 timeline) - One risk AI listed (quantum computing threat): Verified against NIST post-quantum cryptography initiative - One gap identified: AI didn't mention recent enforcement trend on third-party risk management; added this risk
Fact-Check Results: - Likelihood and impact assessments: Reviewed with CISO and Chief Compliance Officer; generally agreed with AI assessments, with one adjustment (AI rated operational staffing risk as low; revised to medium based on hiring market analysis) - All sources cited: Verified as authoritative and current
Verified By: Risk Analysis Team Lead
- INTERNAL REVIEW AND FEEDBACK
- Review Period: 2026-02-28 to 2026-03-01
- Review Conducted By: CISO, Chief Compliance Officer, Chief Operations Officer, CFO
Review Feedback: - CISO: Concurred with cyber risk assessment; emphasized that social engineering attacks are actively targeting our industry - Chief Compliance Officer: Noted that AI regulatory timeline is accurate; concerned that third-party risk changes may require contract updates (added to remediation section) - Chief Operations Officer: Agreed with operational risk assessment; noted that legacy system reliability is critical and should be higher priority - CFO: Noted that resource implications are material; wants to ensure risk committee understands budget implications
- REVISIONS AND ADDITIONS
- Based on feedback:
- Added threat intelligence source (CISA alerts) for cyber risks
- Added note on contract review implications for third-party risk
- Increased operational risk priority and emphasis
- Added budget impact summary for resource-intensive risks
- Added CISO perspective quote on social engineering threat urgency
Revised Draft Saved: "EmergingRisks_Draft_20260301_Revised.xlsx"
- FINAL APPROVAL
- Final Review Date: 2026-03-01
- Final Review Conducted By: Chief Risk Officer
- Final Approval: Yes
- Approval Signature: [CRO signature]
- Approval Date: 2026-03-01
- Notes: "Risk assessment is comprehensive, well-sourced, and appropriately prioritized. Use for Board Risk Committee briefing approved."
- BOARD COMMITTEE BRIEFING
- Briefing Date: 2026-03-10
- Attendees: Board Risk Committee (5 members), Chief Risk Officer, Chief Compliance Officer, CISO
- Materials Provided: Risk summary with source citations, recent threat intelligence (CISA alerts), regulatory timeline, budget impact analysis
- Discussion Points: Which risks are material for strategic planning? What resource allocation is needed?
- Outcome: Risk committee approved risk mitigation planning; allocated budget for cyber risk and regulatory response initiatives
- DOCUMENTATION SUMMARY
- This risk assessment was developed with AI assistance (initial research and summary) combined with source verification and internal expert review. AI sources were checked against primary authorities (CISA, SEC, Fed). Internal subject matter experts reviewed and validated assessments. One gap (third-party risk trend) was identified during verification and added. Final assessment was approved by CRO and presented to board. Assessment was comprehensive and well-sourced.
AI Role: Initial risk identification, research summary, likelihood/impact assessment framework Human Role: Source verification, expert validation, gap identification, contextual adjustment, approval Status: Complete and presented to Board ```
Use of This Documentation: - If Board asks "How did you identify these risks?" -> Show verification and sources - If regulator questions risk management -> Demonstrate systematic approach to risk identification - If risk assessment accuracy is questioned later -> Can show sources and validation steps
Example 3: Audit Finding Synthesis Documentation
Documentation Record for Finding Synthesis:
``` AUDIT FINDING SYNTHESIS DOCUMENTATION
Synthesis Date: 2026-03-05 Scope: Consolidate findings from 2023, 2024, 2025 audits; identify patterns and repeat findings Purpose: Support risk assessment and remediation planning Owner: Chief Audit Executive
- SOURCE DOCUMENTS
- Audit Reports Included:
- 2023 Financial Reporting Audit ("2023_Audit_FY22.pdf")
- 2024 Compliance Audit ("2024_Audit_FY23.pdf")
- 2025 IT Controls Audit ("2025_Audit_FY24.pdf")
Total Findings Across Reports: 13 findings (5 from 2023, 4 from 2024, 4 from 2025)
- AI ASSISTANCE RECORD
- AI Tool Used: Claude AI (via Audit Management Portal)
- Date AI Used: 2026-03-02
- AI Prompt: "I'm providing three internal audit reports from 2023, 2024, and 2025. Synthesize the findings from all three reports. For each finding, identify: (1) Finding title and year, (2) Current status (remediated, in progress, not started), (3) Root cause, (4) Current remediation owner. Group findings by control area (Access Controls, Financial Reporting, Data Governance, Change Management, Vendor Management). Identify any findings that appear in multiple years (these are repeat findings). Create a summary matrix."
AI Output Generated: [Finding synthesis matrix saved as "AuditFindings_Synthesis_Draft_20260302.xlsx"]
- VERIFICATION PROCESS
- Verification Date: 2026-03-03 to 2026-03-04
- Verification Method: Spot-check against original audit reports; status validation with control owners
Verification Steps: Step 1: Spot-check findings for accurate description - Selected 5 of 13 findings for detailed verification - Compared AI description to original audit report narrative - Result: 4 of 5 descriptions were accurate; 1 description was over-simplified (added detail)
Step 2: Verify status information - Contacted each remediation owner to confirm current status - Findings status: 4 completed, 5 in progress, 4 not started - AI status assessment had 2 errors (Finding A marked "In Progress" but actually completed; Finding B marked "Not Started" but actually in progress)
Step 3: Identify missing findings - Reviewed original audit reports to identify any findings AI might have missed - Result: AI missed 1 finding from 2023 audit (vendor management control gap); added to synthesis
Step 4: Verify repeat finding assessment - AI identified 1 finding appearing in 2023 and 2025 (access review issue) - Confirmed that both years' findings addressed the same issue with same root cause; this is a true repeat - However, 2025 audit found that remediation was completed (status updated to completed, not repeat issue)
Step 5: Validate root cause assessments - Discussed root causes with remediation owners - AI root causes were generally accurate but sometimes superficial - Added more detailed root cause information for complex findings
Verification Results: - Findings captured: 12 of 13 (1 added during verification) - Descriptions: 4 of 5 spot-checked were accurate (1 simplified) - Status accuracy: 2 errors corrected during verification - Repeat findings: 1 confirmed; note that it was actually remediated (not a repeat now) - Root causes: Generally accurate; enriched with owner input
Verified By: Senior Audit Manager and Control Owners (by function)
- CORRECTED SYNTHESIS
- Based on verification:
- Corrected status for 2 findings
- Added missing finding from 2023
- Clarified repeat finding status (remediated, not repeat)
- Enriched root cause descriptions with control owner input
- Confirmed accuracy with CAE
Corrected Synthesis Saved: "AuditFindings_Synthesis_Final_20260305.xlsx"
- APPROVAL AND USE
- Final Review Date: 2026-03-05
- Final Approval: Chief Audit Executive (approved)
- Approval Date: 2026-03-05
- Approval Signature: [CAE signature]
Use: Finding synthesis provided to Chief Risk Officer for risk assessment; control owners received their specific finding details for remediation planning
- DOCUMENTATION SUMMARY
- Audit findings from three years were consolidated using AI assistance. AI synthesis accurately captured most findings but had status errors and missed one finding. Verification identified and corrected these issues. Control owners validated root causes and remediation plans. Final synthesis is accurate and complete.
AI Role: Synthesis, organization, categorization of findings Human Role: Spot-check verification, status validation with control owners, gap identification, root cause enrichment Accuracy: 12 of 13 findings verified; 2 status corrections; 1 finding added Status: Complete and in use for risk assessment
Finding Summary: - Completed: 4 - In Progress: 5 - Not Started: 4 - Total: 13
Control Areas Represented: Access Controls (3), Financial Reporting (3), Data Governance (2), Change Management (2), Vendor Management (3) ```
Use of This Documentation: - If audit committee asks about findings -> Can show complete, verified synthesis - If questioned about missing findings -> Can demonstrate that verification specifically checked for gaps - If control owners challenge status -> Can show confirmation from their input - If auditors review the finding process -> Can demonstrate rigor and care in consolidation
Putting It Into Practice
At the Assisted Use level, implementation means beginning to incorporate these concepts into your supervised AI work:
- Practice with guidance: Use AI tools for low-stakes tasks with a mentor or supervisor available for review. Build confidence gradually before taking on more complex scenarios.
- Verify systematically: Develop a personal checklist for reviewing AI outputs. Even a simple three-point check (accuracy, completeness, appropriateness) dramatically improves output quality.
- Document your process: Record what AI tool you used, what prompt or input you provided, what output you received, and what verification steps you performed. This documentation habit is essential.
- Seek feedback: Share your AI-assisted work products with experienced colleagues. Their input helps calibrate your judgment about when AI outputs are reliable and when they require additional scrutiny.
Key Takeaways
Review the core concepts from this lesson and consider how each one applies to your professional practice.
As you continue through this credential program, you will build on the foundation established in this lesson. Each subsequent lesson adds new dimensions to your understanding and expands your capability to work effectively with AI in oversight roles.
Skill.re