Skip to main content

AI accountability checklist: 12 questions an assessor will ask

Zander Wilken, AIC. Checked against its sources on , 8 minute read

How do you check whether your AI decisions are accountable?

Ask whether you can name every AI system that decides things about people, the person accountable for each, and show that their override works and is used. Then test whether each decision gives a true reason, whether people can contest it and get an answer, and whether they were told AI was involved before it affected them.

Each question below maps to requirements in the published AIC standard. They are written as an assessor would ask them: what you can show, not what your policy says.

Who is accountable

  1. Can you list every AI system that makes or shapes a consequential decision?Including bought-in tools and AI inside software you already use. A register that misses shadow AI fails the rest of the list. (HU-3, HU-10)
  2. Is a person, not a role, named for each one, and have they accepted it?A named individual who has signed to say so. (HU-1, HU-2)
  3. Can that person describe how the system works today without checking with someone?Needing to ask is itself a finding. (HU-11)

Whether oversight is real

  1. Does the override work in production, and does it ask for a reason?Demonstrated live, with the reason stored. (HU-4, HU-5, HU-6)
  2. Has it been used?Zero overrides across a large volume of decisions is not a pass; it means nobody is really looking. (HU-7)

Whether reasons are true

  1. Is there a plain-language explanation for each decision, kept and retrievable?One a person can be given on request. (EX-1 to EX-4)
  2. Does the stated reason match what actually drove the decision?A reason that differs from the dominant feature is post-hoc rationalisation, a critical finding. (EX-5)

Whether outcomes are fair

  1. Has disparate impact been tested recently, including across combinations of attributes?With a ratio of at least 0.8 across tested characteristics, and proxies identified. (EM-6 to EM-8, EM-10)

Whether people can contest it

  1. Can an ordinary person find the route to contest a decision?Not just someone who already knows it exists. (CO-1, CO-2)
  2. Do you meet your own response time, and do upheld challenges change the outcome?Measured, logged and traceable, with a named person responsible. (CO-3 to CO-5, CO-8, CO-9)

Whether people were told

  1. Were people told AI was involved, specifically and before it affected them?A generic clause in terms and conditions accepted at sign-up generally fails for a decision made later. (TR-2 to TR-5)

AIC Aware asks a short version of these questions and gives you a free result in about ten minutes.

Questions people also ask

How often should AI accountability be checked?

Continuously where possible. Point-in-time audits miss drift; a record kept over time shows whether oversight held between audits.

What is a good disparate impact ratio?

The AIC standard uses at least 0.8 across tested protected characteristics, the widely used four-fifths rule, and expects intersectional analysis too.

Sources

  1. The AIC standard, published in full
  2. Protection of Personal Information Act 4 of 2013 (POPIA), section 71
  3. IBM Cost of a Data Breach Report 2025 (summary)

This guide explains the law and standards in general terms. It is not legal advice about your organisation. AI Integrity Certification is a certification body and does not consult on the systems it certifies.

Check your own organisation

AIC Aware is a free self-assessment against the AIC standard. It takes about ten minutes and shows where accountability for automated decisions is missing.