When One Person Is Your Audit Trail

RedHub AI Editorialupdated September 2, 20265 min read

One person works through a folder at a desk while the second chair beside her sits still wrapped in factory plastic.
Jump to a section8

If one person is the only one who can assemble your evidence, the ability to answer belongs to that person and not to your company. Two things fix it: a written procedure somebody else has followed, or a second person who has actually produced the pack. Either one is enough. Neither counts if it exists only in principle.

TL;DR: Teams treat this as a documentation gap and it is a continuity risk. A well-organized archive that only one person can navigate scores well on every records checklist and fails the moment they are on leave. This is the "people" axis of the AI audit trail guide.

The Shape of the Problem

Somebody on your team can produce the evidence pack. They know which export to run, which table joins to which, which of the three date fields is the real one, and which caveat to attach so the numbers reconcile. They have done it four times. It takes them an afternoon.

None of that is written down, and nobody else has ever done it.

On paper you look fine. The records exist. Retention is configured. Somebody is accountable. Every box a checklist can test is ticked, and the whole capability is one resignation, one illness or one holiday away from being unavailable for as long as it takes somebody else to reverse-engineer it.

Worth measuring: if the person who assembled your last evidence pack left tomorrow, how long would the next one take? That number is the real metric here, and almost nobody tracks it.

Why It Survives Every Review

This gap is invisible to the checks people normally run, for a specific reason: every question a records review asks is answerable by the person who holds the knowledge.

Do you keep decision records? Yes. Can you retrieve one from March? Yes — watch. Is there an owner? Yes, me. Each answer is true. The review is satisfied. And the thing being demonstrated in every case is that this individual can do it, which is precisely the thing in question and precisely what the review cannot see, because they are the one being asked.

The only question that surfaces it is asked in the negative: has anybody else ever done this? Not could they. Have they.

The Two Routes, and Why "In Principle" Fails

A written procedure somebody has followed

Not a document describing where things are. A procedure another person has executed end to end, without the author in the room, producing a correct pack.

The distinction is the whole point. Documentation written by the expert is almost always incomplete in exactly the places the expert stopped noticing, and those are the places a newcomer stalls. A procedure only becomes evidence of transferability once somebody has transferred along it.

The cheap way to get there: have the expert write the steps, then have a colleague run them while the expert stays silent and takes notes on every point the colleague gets stuck. The notes are the real document. Expect this to take two attempts.

A second person who has produced it

The alternative route, and often the faster one. No document required. Somebody else has assembled a real pack, at least once, and it was correct.

This is weaker in one way — it lives in a second head, not on paper — and stronger in another, because it is demonstrated rather than described. For a small team it is usually the realistic option, and it is sufficient. Two people who have both done it is not a documentation gap worth agonizing over.

What Does Not Count

Three things teams offer as the fix that do not close it:

  • A folder everyone can access. Access is not capability. Knowing where the files are does not tell you which export to run or which date field is authoritative.
  • A wiki page written by the expert, unread. Until somebody has followed it, it is a description of what the author believes they do, which is reliably not what they do.
  • A deputy who was shown once. Being walked through it is not producing it. The gap between watching and doing is where every undocumented step hides.

The Order to Fix It In

  1. Name the packs. List the evidence requests your business receives — customer security reviews, board reporting, an incident account, a diligence list. Usually three to five.
  2. Mark the bus factor of each. How many people have produced this one? The honest answer is often one, and sometimes zero, because the last one was assembled by somebody who has since left.
  3. Take the most-requested one first. Not the hardest. The one most likely to be asked for while its single owner is unavailable.
  4. Run the silent handover. Second person produces it, first person watches and writes down every stall.
  5. Stop there for now. One pack with two routes beats five packs with a document nobody has tested.

Where This Gets Graded

The Audit Evidence Pack Assay ($119) grades the joins between a decision record and the context, policy and authorization behind it — 24 questions returning ANSWERABLE, NEEDS A WITNESS or NO RECORD. The middle verdict is this article's subject: an account that can be given, by one particular person, if they are available. It grades what you describe and inspects nothing, and every input is an answer you supply about your own wiring.

The free AI Compliance Assurance assessment makes this its dispositive gate: if nothing is written down that somebody else could follow, and nobody else has ever produced the pack, it returns UNREPRODUCIBLE at any score — 93 out of 100 included — because everything else in the file is describing what one person can do. Either route releases it, as long as it has actually happened. Self-declared, and it measures durability rather than adequacy.

Pairs well with

Turn each single-owner pack into a tracked item with a named second in the AI Risk Register & Treatment-Tracking System ($99), or take the accountability instruments together in the AI Audit & Accountability Bundle ($269).

This is general operational guidance, not legal advice. Nothing here states what any law requires — ask a qualified lawyer about that.

More in this guide

What is a bus factor for audit evidence?

The number of people who could assemble a given evidence pack correctly. When it is one, the ability to answer belongs to that individual rather than to the organization, however well organized the underlying records are.

Isn't good documentation the answer?

Only once somebody has followed it. Documentation written by the expert is incomplete in exactly the places the expert stopped noticing, and those are where a newcomer stalls. A procedure becomes evidence of transferability when somebody has transferred along it.

Is a second trained person enough on its own?

Yes, if they have produced a pack rather than been shown one. It lives in a second head instead of on paper, which is weaker in one way and stronger in another, because it has been demonstrated rather than described.

Why does this survive normal reviews?

Because every question a review asks is answerable by the person holding the knowledge, and each answer is true. The only question that surfaces it is whether anybody else has ever done it — not whether they could.

Where should a small team start?

With the pack most likely to be requested while its single owner is unavailable. Have a second person produce it while the owner stays silent and notes every stall. Those notes are the document.

How it decides
Diagram of the AI Risk Register: six weighted governance fields, an accepted-high-residual gate, and entry R-03 scoring 78 that still reads UNGOVERNED.

The gate this post refers to, drawn from the tool’s own logic. See the tool.