//The signed document

The Signed AI Evidence Audit

A signed document a firm can hand its insurer: how AI is used in the firm's work, what is recorded, who checks the output, and how it is disclosed, reviewed against the Evidence-Grade AI Standard, signed by Matt Aubin, and renewed every year.

By Matt Aubin, Founder, Southern Recon Agency and E3 Legacy Intel. CDFE, FBCI. Investigating since 2009. Updated .

When anyone asks how your firm uses AI, this is the document you hand over.

It answers the question in writing, dated, with a named and credentialed person's signature on it, instead of leaving the firm to answer from memory under pressure. It is built on the Evidence-Grade AI Standard.

//The question counsel and carriers ask

Who can validate an AI assisted investigation?

Matt Aubin, AI investigation expert and cybercrime specialist, certified forensic examiner, and builder of the AI his own firms run on, validates AI assisted investigations. The validation checks four things: every finding traces to a source, a supervision log records the prompts and the human review, the records are verified against their databases, and the confidence and error rates are stated.

Those four checks are the Evidence-Grade AI Standard in practice: traceability is the provenance pillar, the supervision log is the audit trail and the human verification gate, database verification is sourced inputs, and stated confidence and error rates are calibrated disclosure. The audit runs them across a firm's whole workflow. When the question is a single matter and the work has to stay behind the attorney, the same checks are done as a consulting expert on AI evidence, with a written analysis for counsel.

//The audit steps

The six steps of an AI evidence audit.

Step 01

Map where AI touches the work

Matt sits with the people who do the work and lists every point where AI reads, writes, sorts or drafts anything in a case or a security operation, including the chatbots nobody put in a policy.

Step 02

Check the method

Is the way AI is used written down, repeatable and explainable? Which systems and versions? A method the firm cannot describe is a method nobody can defend.

Step 03

Check the record

Can the firm show, for any finding, what went in, what came out, and who checked it? Prompts, outputs and the human review are read against the supervision log.

Step 04

Check the human gate

Who reviews AI output before it leaves the building, and is that gate enforced or hoped for? A qualified person is accountable for every finding, never the machine.

Step 05

Check the sources and the disclosure

Records are verified against the databases they came from, error rates and limits are stated, and the firm's disclosure of AI use to clients and courts is read as written.

Step 06

Write, sign and hand over

The findings, the gaps ranked by risk, and the fixes are written up as one signed document, with a remediation plan the firm can act on and a date for the next review.

Ask about the audit.

Tell me what your firm runs and who is asking for the document. The scope comes back in writing.

//What the signed document contains

Nine things the signed audit always states.

  1. 01The firm's name, the date of the review, and the period it covers.
  2. 02Every point where AI touches the firm's work, and which systems and versions are in use.
  3. 03The written rules the firm follows for AI on case and security data.
  4. 04How findings are checked before they leave the building, and who is accountable for them.
  5. 05What is recorded: inputs, outputs, human review, and chain of custody.
  6. 06How AI use is disclosed to clients and, where it applies, to courts.
  7. 07Each gap found, ranked by risk, with the fix for each and a timetable.
  8. 08The standard the review was run against, the Evidence-Grade AI Standard, pillar by pillar.
  9. 09Matt Aubin's signature, his credentials, and the date the next review is due.

//Who signs it

Matt Aubin signs every audit himself.

AI investigation expert and cybercrime specialist. Founder, Southern Recon Agency and E3 Legacy Intel. Investigating since 2009. Founded his first firm in 2010 and built it into Southern Recon Agency in 2014. Certified Digital Forensics Examiner and Florida Board Certified Investigator. He built a proprietary AI investigation platform his own firms run on live cases. The signature means a person who builds and runs this kind of system has read your AI use and put his name to the findings.

//Renewal

Renewed every year, dated on the document.

AI models change, the tools change, and the rules of evidence are moving, so every signed audit carries the date of its next review and is renewed on an annual basis. Firms that hold a monthly advisory seat have the review folded into the seat, so the document stays current instead of being rebuilt each year.

//Questions people ask

Questions firms ask before they commission the audit.

What is a signed AI evidence audit?

A signed AI evidence audit is an independent review of how a firm uses AI in its investigations or its security operation, written up as one signed document the firm can hand its insurer, its clients, or a court. It states where AI touches the work, what is recorded, who checks the output, and how AI use is disclosed, measured against the Evidence-Grade AI Standard, and it ranks every gap by risk with a fix for each.

Who signs the audit?

Matt Aubin signs it personally. He is an AI investigation expert and cybercrime specialist, a Certified Digital Forensics Examiner, a Florida Board Certified Investigator, the founder of Southern Recon Agency and E3 Legacy Intel, and the builder of the AI his own firms run on. The signature means a named, credentialed person who builds and runs this kind of system has read the firm's AI use and put his name to the findings.

What do I get to hand over when someone asks how we use AI?

One signed, dated document. It states where AI is used in the firm's work, what data it touches, who checks its output before anything leaves the building, what record is kept of that check, and what is disclosed. It says what was found and what was fixed, and it carries the name and credentials of the person who reviewed it. What any particular insurer, client or court does with it is theirs to decide, and this page does not speculate about that. It is renewed every year.

Who needs one?

Investigation firms, security operations, corporate security teams, law firms with an investigations practice, and insurance special investigations units that already use AI in their work. If AI touches findings that could reach a client, a court, a regulator, or a claim, the firm needs to know the workflow survives being read by a stranger. Auditing before a challenge costs a fraction of scrambling after one.

Who signs off if our insurer asks for a name?

A named, credentialed person, not a firm logo. Matt Aubin is a Certified Digital Forensics Examiner and a Florida Board Certified Investigator, and he reads your AI use himself before his name goes on the findings. The signature is the part a carrier can check.

How does pricing work?

Every audit is scoped to the firm's actual workflows, so there is no one size price and no figure on this page. Tell Matt what you are running and how many people touch it, and you get a scope in writing before any work begins. The retainer is paid in full before the work starts.

How often is it renewed?

Every year, and the next review date is printed on the document itself.

The audit checks a firm against Evidence-Grade AI, the category page that explains why any of this matters, and against the Standard itself.

Get the document before the carrier asks for it.

Tell me what your firm is running and how many people touch it. You get a scope in writing before any work begins.