What audit standards already say about evidence.
The standards ask an auditor to weigh where evidence comes from and how reliable it is. Each is quoted from its source, beside what the record gives.
Evidence from outside the company counts for more.
“Evidence obtained from a knowledgeable source that is independent of the company is more reliable than evidence obtained only from internal company sources.”
The entries are still the lab's account. What changes is that their integrity no longer rests on the lab: a change to any committed entry shows, whoever made it.
“When using information produced by the company as audit evidence, the auditor should evaluate whether the information is sufficient and appropriate”
The record is information the company produced. The check tells you it's unchanged since it was committed, and when each entry was committed. Whether it's sufficient stays your judgment.
“The reliability of audit evidence is increased when it is obtained from independent sources outside the entity.”
The record's integrity is checked outside the entity, on your own computer if you like, without its systems or its cooperation.
“A greater susceptibility to management bias may exist when information is generated from internal sources.”
Committing the record doesn't take the bias out of what was written. It takes away the chance to revise it afterward.
Independent assessment of AI systems.
“Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates.”
An independent assessor can check from the record directly, instead of from what the developer compiles for them.
“It supplements ISO/IEC 17021-1 with AI-specific requirements for auditing and certification processes.”
It governs the bodies that certify AI management systems. What an agent actually did is a different question, and a committed record is one way an auditor can check it.
“Partner with an independent external auditor or evaluator to carry out independent assessments of whether the controls, monitoring, and detection are operating as intended.”
The accord is voluntary today. An assessment of whether controls are operating needs evidence of what they saw, and the record is evidence the auditor can check without the lab's systems in between.
The judgment stays yours.
PacSpace is not an auditor. It gives the auditor or evaluator something to check, and whether that evidence is sufficient and appropriate for an engagement is their judgment under the standards they work to.
The record's entries are still the lab's account, and the lab chooses what to write. What changes is that their integrity no longer rests on the lab. The IAASB has proposed revisions to ISA 500, with comments due December 15, 2026.7
Sources
- PCAOB, AS 1105, Audit Evidence, paragraphs .08 and .10.
- IAASB, ISA 500, Audit Evidence, application material, in the English text as published by the IBR.
- AICPA, SAS No. 142, Audit Evidence (AU-C 500), paragraph A32, July 2020.
- NIST, AI Risk Management Framework 1.0, MEASURE 1.3.
- ISO, ISO/IEC 42006:2025, requirements for bodies providing audit and certification of AI management systems.
- The American Presidency Project, “White House Accord on Super Intelligence”, Sept 29, 2026.
- IAASB, “Proposed Revisions for Audit Evidence & Risk Response: ISA 330, ISA 500 & ISA 520”, Aug 5, 2026.
Bring the case you think breaks it.
We would rather be evaluated by use than by description. Talk to us and we'll put you in a live environment: commit a record, do your best to change it, then check it yourself, with us out of the loop. The change shows.
The record must exist.