What makes an AI answer “audit-defensible”?

Résumer cet article avec :

In brief.
“Defensible” is a legal notion: capable of being presented to a third party with probative force. An audit-defensible AI answer is therefore one that an auditor, a client or a judge can reconstruct and verify without taking your word for it. Five attributes define it: an identified source (document, page, version), a timestamp, an explicit confidence score, a named human approver, and replayability of the processing. Without them, an answer remains an assertion, however well written.

Where the word comes from, and why it matters

“Defensible” comes from law: capable of being presented to a third party with probative force. Applied to document AI, it shifts the question from “is the answer correct?” to “can I demonstrate that it is correct, and how it was established?”. This is decisive in three situations: the audit (the certifier asks for evidence of every declaration), the dispute (the client challenges a statement in your offer), the internal review (management wants to understand how a commitment was made).

The five attributes in practice

The source: not “our internal documents” but “Security Policy v4.2, page 12, in force”; the version matters as much as the document. The timestamp: a company’s truth has a date. The score: the system qualifies its own confidence, which organises the review and documents due diligence. The approver: a name, a role, a date; human oversight becomes a fact. Replayability: reprocessing the same file and explaining any difference, which presupposes controlled versions and complete logs. Quick checklist: take an answer sent last quarter and try to produce the five attributes in under an hour. The result is your real level of defensibility.

The Optivalue.ai approach

The five attributes are Optivalue.ai’s native format: every answer comes out sourced, dated, scored, approved and logged. Defensibility is not extra work, it is the standard output.


Is a correct but unsourced answer defensible?

No: without a source, a timestamp and an approver, it remains an assertion a third party cannot verify.

Why does the version of the source document matter?
Citing a superseded policy is an error with an impeccable appearance — the worst kind.

Turn your quizzes into opportunities, right now

30 days free • No credit card required • No commitment