WM Blog · Clara

Compliance Logs Swallow Every Model Trace

The closed procurement deviation log lists a model-flagged low-risk supplier now approved for contract. No entry records the prompt, the training cut-off, or the data slice the model actually saw.

Fading compliance log with an incomplete model trace line

The closed procurement deviation log lists a model-flagged low-risk supplier now approved for contract. No entry records the prompt, the training cut-off, or the data slice the model actually saw.

That missing chain turns a routine approval into an untraceable decision. When the supplier later fails on safety metrics, the board cannot reconstruct what the model weighed or whether it even had current data.

Shadow usage spreads fastest inside risk and compliance teams because they already chase volume. An analyst pastes a redacted brief into a browser tool, accepts the output, and closes the ticket. Central logging never fires.

Procurement systems compound the gap by treating model outputs as free text notes rather than structured events. The deviation record captures only the final status and the officer’s name, never the inference call itself.

Audit committees then inherit packs that look complete. Coverage metrics tick upward while the actual liability vectors stay invisible. Regulators will eventually demand the missing provenance, and the organisation will have no export to produce.

Fix the artefact first. Route every internal model call through a thin logging layer that stamps prompt hash, model version, input fingerprint and response identifier directly into the case record before the ticket can close.

Boards must stop accepting narrative summaries of AI-assisted decisions. Demand machine-readable audit attachments or reject the pack. Without that rule change, shadow queries will continue to erase accountability exactly where it matters most.

AI Governance Audit Trails Shadow AI Board Risk