Building the Colorado Evidence File for Each High Risk System

Building the Colorado Evidence File for Each High Risk System is the final step in ensuring compliance with the Colorado AI Act. This process involves gathering, documenting, and maintaining detailed records that demonstrate adherence to the Act’s requirements. The evidence file must be sufficient to support claims of compliance, including data on risk assessment, testing, monitoring, and governance. The file must be accessible, complete, and up to date, reflecting the system’s lifecycle from design through deployment and eventual decommissioning.

Lesson concept diagram

Content Requirements for the Evidence File

The evidence file must contain documentation that reflects the AI system’s design, development, and deployment phases. This includes records of risk assessments, data quality checks, testing outcomes, and any corrective actions taken. For example, if an AI system is used for credit scoring, the file must include data on how bias was identified, tested, and mitigated. The file must also contain records of training data sources, including any data governance or anonymisation processes applied. Where applicable, the file must show that the system meets the transparency obligations under Article 50 of the EU AI Act, such as machine-readable marking for generative AI systems placed on the market before 2 August 2026.

  • Records of risk assessments must detail identified risks, their likelihood, and impact.
  • Testing documentation must include validation and verification outcomes, including edge-case testing.
  • Training data records must show data sources, quality checks, and any bias mitigation efforts.
  • Monitoring logs must capture system performance, including any anomalies or drifts detected.
Building the Colorado Evidence File for Each High Risk System

Organisation of the File

The structure of the evidence file must align with the AI system’s lifecycle and the requirements of the Act. The file should be divided into clearly defined sections such as system overview, risk management, data governance, testing, monitoring, and incident reporting. Within these sections, documents must be tagged and indexed for quick retrieval. For example, a file for an AI-based hiring tool must have a section dedicated to candidate data protection, including records of data minimisation, consent, and access controls. The file must also include records of staff training, as required by Article 4 of the EU AI Act, which applies since 2 February 2025.

Each section must be reviewed and updated regularly, particularly after any system changes or incidents. The file must also reflect any updates to the AI system’s operational environment, such as new data sources or integration with other systems. Where systems are subject to the GPAI model obligations, which apply since August 2025, the file must include documentation of model governance, including access controls, audit logs, and data lineage. The file must be stored securely, with access limited to authorised personnel, and must be available for inspection by regulators or auditors.

Organisations must ensure that the evidence file is not static but evolves with the AI system. Regular audits of the file should be conducted to confirm that it remains accurate and complete. Where systems are classified as high risk, the file must also include records of any third-party assessments or certifications, such as those provided by ISO/IEC 42001:2023. The first UKAS-accredited certification body, BSI, was granted accreditation on 15 January 2026, and certification bodies must adhere to ISO/IEC 42006:2025. These records must be maintained alongside other compliance documentation to support claims of adherence to AI governance frameworks.

By maintaining a detailed and accessible evidence file, organisations can demonstrate their commitment to responsible AI deployment. The file serves as a central repository of compliance efforts, enabling quick responses to regulatory inquiries or internal audits. It also supports continuous improvement by providing data on system performance, identified risks, and mitigation strategies. The file must be reviewed at least annually or after any significant change to the AI system. In the event of a regulatory investigation, the evidence file must be ready for immediate access, ensuring that compliance efforts are not only documented but also verifiable.