AI audit reporting
An audit only creates value if its results are communicated to the right audiences and, where the
public interest is at stake, released. Reporting is also where the auditor's own credibility is
established or lost.
Produce results in multiple formats (dual-audience)
Present results in multiple formats to meet the needs of all relevant audiences. At minimum:
- A precise, comprehensive technical report for review by testing professionals — detailed
enough that another competent professional could evaluate and, ideally, reproduce the audit's
reasoning. Mirror the structure of a
technical-validation-report, but
organized around the 12 components and the claims evaluated.
- A layperson-friendly summary for whomever the audit's predictions will directly affect
(e.g., candidates) — clear, accurate, non-technical, addressing the fairness concerns in the terms
those audiences actually use (justice/transparency — see
ai-fairness-lenses).
One format cannot serve both audiences; write both.
Suggested technical-report structure
- Claims evaluated — each developer claim as an explicit statement, classified as
validity / utility / lack-of-bias (from
ai-audit-planning).
- Fairness standard(s) — the lens(es) and precise definitions used (
ai-fairness-lenses), stated
so conclusions are interpretable across disciplines.
- Findings by component (1–12) — model (1–6), information & perceptions (7–9), meta (10–12), each
with evidence, gaps, and access limitations encountered.
- Auditor credibility statement (see below).
- Recommended corrective actions — to remove or minimize adverse effects, and (for formative
audits) to improve the model.
- Limitations — what could not be evaluated, and why (NDA, missing documentation, small
intersectional subgroups, etc.).
Establish credibility in the report
No auditor or audit is automatically credible. "This system has been audited and is therefore
credible" deserves skepticism. So the report must let readers judge the audit itself by disclosing:
- the measurement standards and definitions of bias/fairness applied, and that they were applied
in due course across the components;
- the auditor's type and relationship to the developer (internal / external / independent);
- the terms of access and nondisclosure — including what could be withheld at the company's
discretion (the existence and scope of withholding should itself be disclosed).
Access and documentation vary even within auditor type, so transparency about access is essential to
interpreting the findings.
Decide on release — default to disclosure in the public interest
Unless there is a compelling, transparently stated reason not to, an audit whose results are in
the public interest should be released. Organizations may choose otherwise, but doing so risks the
credibility of the audit, the company that built the algorithm, and the auditors. Public-facing,
transparent, open audits are especially warranted when a system has outsized societal impact.
Normalize routine auditing. Treat regular internal and external auditing as a public good
that raises the probability algorithmic systems in general are valid, valuable, and fair — and that
builds public trust. Formative auditing folded into development, with complete documentation, can
diminish or even preclude the need for post-hoc audits.
Pitfalls
- Shipping only a technical report (affected people can't use it) or only a summary (professionals
can't evaluate it).
- Implying "audited = trustworthy" without exposing standards and access terms.
- Hiding what was withheld under NDA instead of disclosing that it was withheld.
- Suppressing a public-interest audit, harming everyone's credibility.
- Reporting findings without actionable corrective recommendations.
Checklist
See also
ai-audit-planning (audience & release policy set up front) · ai-fairness-lenses ·
all model/stakeholder/meta audit skills · technical-validation-report
(structure parallel)
Source: Landers & Behrend (2023), "Designing an Effective Psychological Audit" — multiple-format
reporting, releasing results in the public interest, normalizing routine auditing, and auditor
credibility.
1---2name: ai-audit-reporting3description: Use when writing up and releasing the results of a psychological audit of an AI/ML personnel assessment — producing a precise, comprehensive technical report for testing professionals AND a layperson-friendly summary for those the predictions affect, establishing the auditor's standards and credibility in the report, and deciding on public release. Triggers: "write the AI audit report", "release the bias audit results", "dual-audience audit report", "should we publish the audit", "auditor credibility statement", "communicate algorithm audit findings".4license: MIT5---67# AI audit reporting89An audit only creates value if its results are **communicated to the right audiences** and, where the10public interest is at stake, **released.** Reporting is also where the auditor's own **credibility** is11established or lost.1213## Produce results in multiple formats (dual-audience)1415Present results in **multiple formats to meet the needs of all relevant audiences.** At minimum:16171. **A precise, comprehensive technical report** for review by **testing professionals** — detailed18 enough that another competent professional could evaluate and, ideally, reproduce the audit's19 reasoning. Mirror the structure of a `technical-validation-report`, but20 organized around the **12 components** and the **claims evaluated**.212. **A layperson-friendly summary** for **whomever the audit's predictions will directly affect**22 (e.g., candidates) — clear, accurate, non-technical, addressing the fairness concerns in the terms23 those audiences actually use (justice/transparency — see `ai-fairness-lenses`).2425One format cannot serve both audiences; write both.2627## Suggested technical-report structure2829- **Claims evaluated** — each developer claim as an explicit statement, classified as30 validity / utility / lack-of-bias (from `ai-audit-planning`).31- **Fairness standard(s)** — the lens(es) and precise definitions used (`ai-fairness-lenses`), stated32 so conclusions are interpretable across disciplines.33- **Findings by component (1–12)** — model (1–6), information & perceptions (7–9), meta (10–12), each34 with evidence, gaps, and access limitations encountered.35- **Auditor credibility statement** (see below).36- **Recommended corrective actions** — to remove or minimize adverse effects, and (for formative37 audits) to improve the model.38- **Limitations** — what could not be evaluated, and why (NDA, missing documentation, small39 intersectional subgroups, etc.).4041## Establish credibility *in* the report4243**No auditor or audit is automatically credible.** "This system has been audited and is therefore44credible" deserves **skepticism.** So the report must let readers judge the audit itself by disclosing:4546- the **measurement standards and definitions of bias/fairness** applied, and that they were applied47 in **due course** across the components;48- the auditor's **type and relationship** to the developer (internal / external / independent);49- the **terms of access and nondisclosure** — including **what could be withheld at the company's50 discretion** (the existence and scope of withholding should itself be disclosed).5152Access and documentation vary even within auditor type, so transparency about access is essential to53interpreting the findings.5455## Decide on release — default to disclosure in the public interest5657**Unless there is a compelling, transparently stated reason not to,** an audit whose results are **in58the public interest should be released.** Organizations may choose otherwise, but doing so **risks the59credibility** of the audit, the company that built the algorithm, and the auditors. Public-facing,60transparent, open audits are especially warranted when a system has **outsized societal impact.**6162**Normalize routine auditing.** Treat regular internal *and* external auditing as a **public good**63that raises the probability algorithmic systems in general are valid, valuable, and fair — and that64builds public trust. Formative auditing folded into development, with complete documentation, can65**diminish or even preclude** the need for post-hoc audits.6667## Pitfalls6869- Shipping only a technical report (affected people can't use it) or only a summary (professionals70 can't evaluate it).71- Implying "audited = trustworthy" without exposing standards and access terms.72- Hiding what was withheld under NDA instead of disclosing that it was withheld.73- Suppressing a public-interest audit, harming everyone's credibility.74- Reporting findings without **actionable corrective recommendations**.7576## Checklist7778- [ ] Technical report (component- and claim-structured) produced for professionals79- [ ] Layperson summary produced for affected audiences, in their fairness terms80- [ ] Fairness lens(es) and precise standards stated for interpretability81- [ ] Auditor type, relationship, and access/NDA terms disclosed (incl. what was withheld)82- [ ] Findings, gaps, and limitations reported honestly per component83- [ ] Corrective actions recommended (and, if formative, improvement guidance)84- [ ] Release decision made; public-interest default to disclosure applied and any non-release justified8586## See also8788`ai-audit-planning` (audience & release policy set up front) · `ai-fairness-lenses` ·89all model/stakeholder/meta audit skills · `technical-validation-report`90(structure parallel)9192*Source: Landers & Behrend (2023), "Designing an Effective Psychological Audit" — multiple-format93reporting, releasing results in the public interest, normalizing routine auditing, and auditor94credibility.*