DataQubeDataQube

The Auditability Gap · A DataQube report

2026 · PDF · 45 pages

Can your AI prove how it got there?

A DataQube report on what regulated institutions must preserve when AI joins the analytical process — the five layers of evidence behind an answer, and the four-stage model for closing the gap.

  • The five layers of AI auditability: source, transformation, context, reasoning, reproducibility
  • Why retrieval citations, chat histories and technical logs stop short of an analytical record
  • Six design principles for auditable analysis, and the evidence layer they point to
  • A four-stage model of analytical auditability, from Output to Institutional Memory
The Auditability Gap — Can your AI prove how it got there?
Written forHeads of risk, data and analytics in regulated institutions, and the model-risk, audit and compliance functions that review what AI produces.

Get the report

Leave your details and the PDF is available immediately.

By requesting the report you agree that DataQube may contact you about it and related research. No automated drip campaigns; unsubscribe at any time. The report is in English. Privacy policy

01Inside the report

The five layers of an auditable answer

An institution that wants to rely on a conclusion needs a chain of evidence. Each layer is argued in full in the report, with what breaks when it is missing.

  1. 01
    Source. Where did the information come from?Giving an AI access to 50,000 documents does not establish which documents influenced its answer, and connecting ten databases does not establish which records produced a metric. Auditability begins by retaining that relationship.
  2. 02
    Transformation. What happened to the information?“Liquidity risk increased by 18%” is a result, not a record. Which securities were included, how missing observations were treated, which methodology applied and which calculation produced the figure all have to survive the workflow.
  3. 03Context. Which definitions and assumptions shaped the analysis?
  4. 04Reasoning. What observable steps connected the evidence to the conclusion?
  5. 05Reproducibility. Can the material analysis be reconstructed later?

The regulatory backdrop, the architectural reasons the trail breaks, and the six principles for preserving it are in the report. Get the report

  • 75%of responding UK financial-services firms were already using AIBank of England and FCA, 2024 · cited in the report
  • 1 in 3reported AI use cases used third-party implementations, up from 17%Bank of England and FCA, 2024 · cited in the report
  • 13 yearssince BCBS 239 — and data lineage was still a challenge for banks in January 2026Basel Committee on Banking Supervision · cited in the report

Definition

What is the Auditability Gap?

The distance between what an AI system can tell an organization and what the organization can establish about how that conclusion was reached. It opens when sources cannot be identified, when transformations disappear inside a workflow, when important definitions are implicit, when generated claims become detached from their supporting calculations, and when a final presentation survives but the work behind it does not.

Isn't this what citations and conversation history already solve?
A citation shows that a document was retrieved; it does not establish the role that document played in the result. A conversation preserves the interaction, not the queries, the records returned, the calculation logic, the business definitions, the intermediate results or the assumptions applied. Enterprise analysis should not depend on reconstructing a process from the final chat.
How is auditability different from explainability?
Explainability asks whether a result can be described. Auditability asks whether the evidence behind the result can be inspected. A language model can explain an answer fluently after the fact, and fluency is not evidence. What matters is the observable analytical process — not a model's internal chain of thought.
Doesn't logging everything solve it?
Auditability is not a data-retention contest. Logging records events; lineage preserves the meaningful relationships between them — this query produced this metric, this methodology defined this calculation, this calculation supports this claim, this reviewer changed this conclusion. An auditor does not need four million system events; they need the chain that matters.

02What's inside

Six chapters, from the broken chain to the auditable enterprise

  1. 01
    When the Answer Is Right but You Still Can't Use ItCorrectness and auditability are not the same thing — and the regulatory direction is already visible.
  2. 02
    The Chain of EvidenceFive questions that separate an answer from an auditable answer.
  3. 03
    The Lineage Problem Was Already HardBCBS 239, more than a decade on: AI inherits the organization's data debt.
  4. 04
    Why Modern AI Architecture Loses the Evidence TrailRetrieval is not provenance, a conversation is not an analytical record, and agents make the path conditional.
  1. 05
    What Auditable AI Looks LikeSix design principles, and the evidence layer they point to.
  2. 06
    The Auditable EnterpriseFour stages of analytical auditability, and where auditability and institutional memory converge.
  3. +
    Conclusion and sourcesTen primary sources: Basel, the ECB, the Bank of England and FCA, the EU AI Act, US model-risk guidance and NIST.

Who it's for

Heads of risk, data and analytics in regulated institutions, model-risk and validation teams, internal audit and compliance, and the AI leads accountable for what the technology produces.

How to read it

Chapters 1–2 set out the gap and the five layers of evidence. Chapters 3–4 explain why the trail breaks, first in the technology estate and then in the architecture. Chapters 5–6 are the design principles and the four-stage model. Statistics and regulatory findings are attributed to their originating institutions; the Auditability Gap, analytical lineage and the evidence layer are DataQube's own interpretation, not regulatory requirements.

Format
PDF · 45 pages
Language
English
Published
2026

Read the full report

Forty-five pages: the five layers of evidence, why the trail breaks, six design principles and the four-stage model. Prefer to discuss it with us?