// AI governance · Core distinction

Audit trails versus replayability

An audit trail tells you what happened. Replayability tells you whether it was what the institution authorised.

An audit trail is a record of events: this happened, at this time, by this identity. Replayability is a governance standard: can the institution reconstruct what it authorised, which data and rules were in force, where judgement entered, what executed, and where any material divergence occurred — while action is still possible.

// 01

Three different records

Audit trail

Establishes which events occurred, and when.

Monitoring

Establishes what a system did while it was doing it.

Replayability

Establishes whether the decision authorised is the decision executed.

// 02

A concrete example

Archegos, 25 March 2021: five institutions faced the same counterparty default, the same instrument and the same initial error. Every one of them held audit trails. The Paul, Weiss review of 29 July 2021 records that Credit Suisse had seen numerous warning signals, including large and persistent limit breaches. The events were logged. What differed between a near-zero impact at Goldman Sachs and US$5.5 billion at Credit Suisse was how quickly each institution could reconstruct its own position and act while acting still changed the result.

The records existed. The reconstruction did not. That distance is the whole of the difference.

// 03

Why the distinction matters to a board

An audit trail answers a forensic question after the fact: what occurred. A board is accountable for a different question: was the decision we authorised the decision that was carried out. Those are not the same enquiry, and the first does not produce the second. Most institutions already hold much of the underlying evidence — approvals, logs, configuration history, records of action. What is usually missing is the connection between them.

Read the canonical definitions →

// Questions people ask

Common questions

Is an audit trail enough to satisfy a regulator?

It satisfies the requirement to evidence activity. It does not evidence control. A regulator asking whether an institution retained authority over an automated decision is asking a replayability question, not a logging question.

Does replayability mean storing more data?

Usually not. It means connecting evidence the institution already holds — authorised intent, authority boundaries, the data and rules in force, the point of judgement, the executed action and the feedback path.

Where do audit trails typically fall short?

At the joins. Each component logs its own activity correctly. Nothing records the relationship between the decision that was authorised and the action that was executed.

// The practical test

Test one institutional decision

The ten-day Decision Drift Audit™ maps one material decision across all eight layers, assesses replayability and authority boundaries, and delivers one prioritised board finding.

Test one decision →Canonical definitions →Decision Integrity Chain™ →

Related questions

Further reading: The Irrecoverable Institution.