Guide · Proof of Decision

How to prove AI decisions to auditors.

Published July 26, 2026 · OmniStrat AI

To prove AI decisions to auditors and regulators, sign every consequential AI decision to a tamper-evident, hash-chained ledger with independent timestamps. So anyone can verify what was decided, when, and that nothing was altered, without seeing the private content. That is what OmniStrat does by default.

Why your logs are not proof

Logs you control are not evidence. An auditor’s first question is whether a record could have been altered after the fact, and for a database or log file your own team administers, the honest answer is yes. Proof requires records that neither you nor your vendor could rewrite: cryptographic hash chains anchored publicly, with external RFC 3161 timestamps.

What regulators actually require

FINRA has been explicit (Regulatory Notice 24-09) that existing books-and-records and supervision rules apply fully to AI, there is no carve-out for new technology. The industry has already paid over $625 million in penalties for communications records it could not produce. AI decisioning is the next unrecorded surface: when a firm’s AI screens, scores, recommends, or executes, the firm must be able to produce what the AI decided and on what basis.

How Proof of Decision works

OmniStrat Foundry is an AI gateway across 17 providers. Every call routed through it is logged, explainable, and signed into a hash-chained ledger: the decision, its inputs’ fingerprints, the model, and the timestamp become a receipt. The receipt is publicly verifiable. A regulator can check integrity independently, without OmniStrat’s cooperation, while the underlying content stays sealed with keys you hold.

Proving AI hiring decisions (Illinois, NYC, Colorado)

AI-hiring laws demand the same evidence: the Illinois AI Video Interview Act requires notice, explanation, and consent; NYC Local Law 144 requires bias audits of automated hiring tools; Colorado’s ADMT law requires notice and explanation for consequential automated decisions. OmniStrat pairs the consent record (Agora) with the per-decision record (Foundry), so the evidence these laws assume exists actually does. It does not perform the bias audit LL144 separately requires. See the FAQ for specifics.

What to do this quarter

Route one AI workflow through a proof-producing gateway and hand your compliance team the first audit artifact. If the artifact would satisfy a regulator, expand; if not, you have lost thirty days, not a budget cycle.

Proof without disclosure

The objection every compliance team raises first: our AI decisions contain client data, strategy, sometimes privilege — we cannot publish them to prove them. The mechanism does not ask you to. What is written to the public chain is the hash of the decision record, not the record. The content stays in your custody; the chain holds only a commitment to it. When production is required, you produce the record to the party entitled to it, they hash it themselves, and the chain confirms that exactly this content existed at exactly that position in time. Anyone can verify the commitment; only you can reveal what was committed.

That split — public verifiability, private content — is what makes the approach usable in regulated environments rather than a transparency stunt.

The questions an auditor stops asking

A verifiable decision record retires a whole class of examination questions before they are asked. Whether logs were altered after the incident: checkable. Whether the timeline was reconstructed to flatter the outcome: the chain position fixes the order. Whether the model output being shown is the one the decision actually used: the hash either matches or it does not. What remains is the conversation you actually want to have — whether the decision was right — instead of the one about whether your records can be believed.

See a Proof of Decision receipt.

A 30-day pilot on one workflow produces an audit artifact your compliance team can judge directly.

Join the list →