Auditors and compliance need traceability, not just results. A result without evidence is worthless in an audit. cNode documents every statement down to its source and retains the compute path per data point — automatically, not assembled after the fact.
Context & background
Compliance functions in the mid-market and public sector face growing evidentiary pressure. Internal audit, external auditors, supervisory authorities and increasingly the EU AI Act demand not only that a statement is correct but that it is backed and traceable.
The EU AI Act makes logging (Art. 12) and transparency (Art. 13) mandatory for decision-preparing systems. At the same time the GDPR requires clear processor arrangements (Art. 28) and prohibits purpose-alien use of personal data. An AI system meant to support compliance must itself meet these requirements — otherwise it merely shifts the risk.
The problem
AI output without evidence is worthless in an audit. A language model that 'outputs' a figure or an assessment delivers no auditable artifact: neither the source nor the compute path can be reconstructed, and on the next run the result may differ.
In practice the evidence is therefore laboriously rebuilt by hand — documents are gathered, derivations reconstructed, screenshots archived. That is expensive, error-prone and exactly what the EU AI Act intends to replace with systematic logging.
Concrete failure points
- AI output without evidence is worthless in an audit.
- Proof is laboriously assembled by hand.
- Results from black-box models are not reproducible.
- The EU AI Act demands documented, traceable decisions.
The causal chain
The chain that leads to an expensive, risky audit begins long before the review:
- Result without concurrent evidenceforces after-the-fact proof reconstruction
- Manual reconstructionis patchy and not reproducible
- Patchy evidencedoes not withstand the review
- Evidence that failsproduces findings and liability risk
Where cNode breaks the chain
cNode breaks the chain at the first link: the evidence runs concurrently rather than being reconstructed afterward. For every data point the audit trail is created automatically in the very run that computes the result. There is nothing to rebuild — the proof is already there, reproducible and exportable, before the review even begins.
How cNode solves it
cNode produces the audit trail per data point automatically, as an integral part of the computation — not as a downstream report. Every statement references the source it comes from and the full compute path it arose through.
Because the computation is deterministic and reproducible via a fixed seed, the same data basis provably yields the same result. An auditor can follow the derivation step by step and repeat the run at any time — the strongest form of auditability.
The trail can be exported audit-friendly as PDF, CSV or JSON and integrated into existing audit and GRC processes. The system runs either in Frankfurt or fully on-prem up to air-gapped, without data leaving the premises.
Here too the language model serves only to verbalize: it explains the evidenced derivation in legible language but invents neither numbers nor evidence.
The deterministic process
- Audit trail per data point — automatic in the compute run, not retrofitted.
- Source and compute path for every single statement.
- Deterministic and reproducible via a fixed seed.
- Export as PDF, CSV or JSON; the LLM only verbalizes.
- Operable on-prem up to air-gapped, no training on the data.
The outcome
Audits run faster because the evidence is already there instead of having to be produced. The documentation maps to EU AI Act Art. 12/13, processing follows the data-processing agreement under GDPR Art. 28, and customer data is not used for training. A risky audit becomes a routine procedure.
Methodology & verifiability
The methodological core is the separation of computation and language: the engine computes deterministically and logs completely, the language model only phrases. As a result, no unbacked or invented statement can enter the trail.
Reproducibility via a fixed seed, source and compute-path evidence per statement, and a continuous audit trail form the basis for EU-AI-Act conformity (Art. 12/13). Processor arrangement under GDPR Art. 28, operable on-prem up to air-gapped, model-agnostic.
Sources & further reading
- EU AI Act, Art. 12 — record-keeping (logging).
- EU AI Act, Art. 13 — transparency and information.
- GDPR, Art. 28 — processor obligations.
- Related: Municipal holdings management, Public administration.