AAAP IN CONTEXT
130. AAAP IN CONTEXT
From Citizen Auditing to an Open Evidence Layer for AI Governance
Comparing AAAP v2.0 with NIST AI RMF, Algorithmic Impact Assessment, AI Auditing and the EU AI Act
Introduction
The development of AI governance is no longer taking place around a single framework.
Governments, standards organizations, regulators, researchers, civil society organizations, and technology companies are developing different mechanisms for managing AI risks, evaluating systems, documenting decisions, and establishing accountability.
Among the most significant examples are the NIST AI Risk Management Framework (AI RMF), the European Union AI Act, Canada's Algorithmic Impact Assessment (AIA), and the growing field of independent algorithmic auditing and AI testing, evaluation, verification and validation (TEVV).
These approaches address important parts of the AI accountability problem.
The purpose of this publication is not to replace them.
It is to ask a narrower question:
How can an observation originating outside an institution become a structured, verifiable, and traceable piece of evidence that can potentially be used by existing AI governance and accountability systems?
This is the question from which Citizen Auditing and the Algorithmic Accountability and Audit Protocol (AAAP) emerge.
1. Different Frameworks, Different Questions
AI governance frameworks do not all perform the same function.
The NIST AI RMF, for example, organizes AI risk-management activities around four functions:
Govern → Map → Measure → Manage.
NIST describes the framework as a voluntary framework intended to improve the incorporation of trustworthiness considerations into the design, development, use, and evaluation of AI systems. Its AI Resource Center also supports testing, evaluation, verification and validation (TEVV).
The European Union AI Act takes a regulatory approach, establishing obligations concerning areas such as risk management, documentation, traceability, transparency, human oversight, accuracy, cybersecurity and robustness for relevant high-risk systems.
Canada's Algorithmic Impact Assessment provides a structured assessment mechanism for automated decision systems. The current tool contains 65 risk questions and 41 mitigation questions, and was developed openly with input from public institutions, academia and civil society. It is available for sharing and reuse under an open licence.
Independent algorithmic auditing and AI evaluation approaches add another important layer by testing systems, identifying risks, measuring performance, and examining potential harms.
These approaches can therefore be understood as answering different questions:
What risks exist?
How should an organization manage them?
What obligations apply?
How should an AI system be tested?
How should compliance be demonstrated?
How should an impact be assessed?
Citizen Auditing asks a preceding question:
How does an observation become a reliable record that others can examine?
2. The Evidence Gap
Consider a simple example.
A person encounters an unexpected behavior from an algorithmic or AI-enabled system.
They may believe that something went wrong.
They may even have a screenshot.
But several questions immediately arise:
- What exactly happened?
- When did it happen?
- What was the original context?
- Is the record authentic?
- Has the observation been independently corroborated?
- Was the institution notified?
- Did the institution respond?
- Which part is directly observed?
- Which part is interpretation?
- Can another person independently reproduce or examine the record?
Without a structured process, the observation can easily become mixed with interpretation.
That creates a fundamental problem:
An allegation is not automatically evidence.
Citizen Auditing attempts to create a disciplined transition between the two.
3. Citizen Auditing
The proposed Citizen Auditing methodology is deliberately simple:
Observe → Record → Verify → Notify → Archive
The purpose is not to turn every citizen into a lawyer, auditor, engineer, or journalist.
The purpose is to establish a repeatable recording discipline.
A citizen does not have to prove everything.
The citizen must first distinguish:
What I observed
from
What I believe it means.
This distinction is fundamental.
4. The Evidence Matrix
The proposed A/B/C/D structure provides another layer of separation.
A — Primary Record
An original or direct record:
- official document;
- direct system output;
- original communication;
- timestamped record;
- direct observation preserved in an appropriate form.
B — Notice Record
A record showing that an institution or responsible party was informed:
- complaint;
- submission;
- notification;
- delivery record;
- acknowledgement;
- institutional correspondence.
C — Independent Corroboration
Evidence originating independently from the initial observation:
- independent records;
- external developments;
- separate witnesses;
- independent datasets;
- later institutional confirmation.
D — Analysis
Interpretation, hypothesis, commentary or inference.
The central rule is simple:
D-level analysis must not be presented as A-level evidence.
This distinction may appear obvious, but maintaining it consistently can significantly improve the reliability of public-interest documentation.
5. AAAP v2.0
The Algorithmic Accountability and Audit Protocol (AAAP) v2.0 builds upon this principle.
The proposal is not that AAAP should become another closed institutional compliance system.
Instead, AAAP is proposed as an open and reproducible evidence layer connecting observation, documentation, verification, auditing and institutional accountability.
Conceptually:
CITIZEN / OBSERVER
│
▼
OBSERVATION
│
▼
AAAP EVIDENCE
LAYER
│
▼
RECORD / VERIFY /
CORROBORATE
│
▼
AUDIT / TEVV
│
▼
AI GOVERNANCE
FRAMEWORKS
│
▼
INSTITUTIONAL
RESPONSE
This is not intended to replace the governance layer.
It is intended to potentially feed it.
6. AAAP and NIST AI RMF
There is an important methodological relationship between the two.
NIST's AI RMF uses:
Govern → Map → Measure → Manage
AAAP proposes:
Observe → Record → Verify → Notify → Archive
These are not competing sequences.
They operate at different levels.
NIST's framework asks organizations to manage AI risks and develop trustworthy AI systems. Its Core emphasizes continuous risk management and documented, objective, repeatable or scalable TEVV processes.
AAAP asks:
What evidence can enter such a process, and how can its provenance be preserved?
This suggests a possible complementary relationship:
Citizen observation
↓
AAAP evidence
↓
NIST Measure / TEVV
↓
NIST Manage
The important word is possible.
AAAP does not claim that NIST has adopted this approach.
It does not claim NIST endorsement.
It proposes a point of methodological compatibility that can be independently evaluated.
NIST's AI Resource Center itself is evolving as a collaborative platform containing standards, metrics, measurement methods, tools and TEVV resources, and explicitly anticipates stakeholder-produced content and case studies.
7. AAAP and Canada's Algorithmic Impact Assessment
Canada's AIA is another useful comparison.
The AIA provides a formal mechanism for evaluating the risks and impacts of automated decision systems.
Its structure includes risk assessment, mitigation, consultation, data considerations, procedural fairness, privacy, audit trails and recourse.
The difference is primarily one of perspective.
AIA asks:
What is the impact and risk profile of this automated decision system?
Citizen Auditing asks:
How can an observation concerning such a system be documented and verified?
Again, these functions can potentially complement one another.
A citizen-generated evidence record could, in principle, become an input into a broader institutional assessment process.
8. AAAP and the EU AI Act
The EU AI Act establishes important requirements around documentation, traceability, risk management, transparency and monitoring for relevant AI systems.
AAAP does not attempt to reproduce those legal requirements.
Instead, it approaches the problem from another direction:
How can evidence about a potentially relevant event be preserved before, during, or alongside an institutional compliance process?
This distinction matters.
Regulation establishes obligations.
Auditing examines systems.
Governance establishes processes.
AAAP proposes a methodology for structuring evidence that may enter those processes.
9. Independent AI Auditing and TEVV
The field of AI auditing is growing rapidly.
Auditors and researchers may examine:
- bias;
- robustness;
- security;
- privacy;
- explainability;
- reliability;
- performance;
- safety;
- discriminatory outcomes;
- system behavior.
NIST's AI Metrology Center already brings together metrics, methodologies and tools for trustworthy AI and TEVV, covering areas such as fairness, safety, privacy, security, robustness, validity and reliability.
This creates another potential point of connection.
AAAP does not attempt to become the auditor.
Instead:
AAAP can potentially help establish the provenance of the material that an auditor later examines.
That distinction is important.
10. Observation Is Not Proof
The Citizen Auditing methodology therefore deliberately rejects a dangerous shortcut:
“I observed it, therefore it is proven.”
The correct progression is closer to:
Observation
↓
Record
↓
Preservation
↓
Verification
↓
Independent corroboration
↓
Analysis
↓
Institutional review
At every stage, uncertainty can remain.
That is acceptable.
A good evidence system does not eliminate uncertainty.
It makes uncertainty visible.
11. What AAAP Does Not Claim
For the sake of methodological and intellectual honesty, AAAP does not claim:
- to replace the EU AI Act;
- to replace NIST AI RMF;
- to replace professional auditing;
- to constitute a legal evidentiary standard;
- that every citizen observation is correct;
- that every submitted record is authentic;
- that an institution receiving a notification agrees with it;
- that publication equals institutional validation;
- that submission to a government platform constitutes government endorsement.
This distinction is not a weakness.
It is part of the methodology.
12. An Open Ecosystem Rather Than a Closed Product
This leads to a broader question.
What happens if AAAP remains open?
One organization might develop software for creating AAAP records.
Another might develop verification services.
A university might test the methodology.
A civil-society organization might use it for public-interest monitoring.
A government institution might adapt elements of it.
A company might build an audit platform around it.
Another researcher might criticize it and propose AAAP v3.0.
This is not a failure of ownership.
It may be the intended outcome.
We do not need to own every implementation. We need to make the methodology good enough to be worth building upon.
13. From Product Ownership to Infrastructure
There is a fundamental strategic difference between building a company around every individual idea and developing reusable infrastructure.
A product-centered model asks:
How can we commercialize this?
An infrastructure-centered model asks:
How can others build on this?
The second model does not eliminate commercial opportunity.
It can multiply it.
One organization can develop software.
Another can provide auditing.
Another can provide training.
Another can conduct academic research.
Another can develop certification.
Another can integrate the protocol into existing governance systems.
The methodology becomes a common layer, while implementation remains distributed.
14. The Five Questions
The entire approach can therefore be reduced to five questions:
1. Who observed it?
2. What exactly was recorded?
3. How was it verified?
4. Who was notified?
5. What happened afterwards?
These questions do not automatically establish truth.
They establish something else:
traceability.
And traceability is a prerequisite for meaningful accountability.
15. Toward an Open Evidence Layer
The central proposal of this publication is therefore modest but ambitious:
AI governance may benefit from an open evidence layer capable of connecting observations made by citizens and other independent actors with existing auditing, evaluation, risk-management and institutional accountability processes.
Such a layer would not replace existing governance frameworks.
It would potentially make them more permeable to independently generated, structured and verifiable evidence.
In simplified form:
OBSERVE
↓
RECORD
↓
VERIFY
↓
CORROBORATE
↓
AUDIT / TEVV
↓
GOVERNANCE
↓
ACCOUNTABILITY
16. A Living Methodology
This publication should also be understood as an invitation to scrutiny.
If researchers identify weaknesses, we want to know.
If auditors identify missing controls, we want to know.
If engineers identify technical problems, we want to know.
If legal scholars identify limitations, we want to know.
If institutions believe that another framework already solves a particular problem better, that comparison is valuable.
The objective is not to protect the methodology from criticism.
The objective is to make the methodology better through criticism.
17. From Citizen Observation to Institutional Accountability
Citizen Auditing began with a simple principle:
Documentation is the first act of civic accountability.
AAAP extends that principle toward algorithmic and AI systems.
The proposed chain is:
Citizen observation
→ structured documentation
→ verification
→ independent corroboration
→ audit / TEVV
→ institutional review
→ accountability
The chain is not guaranteed to reach its final destination.
But without a reliable beginning, the later stages become considerably harder.
Conclusion
The AI governance ecosystem does not need another isolated framework simply for the sake of having another framework.
What may be useful is a mechanism that connects existing frameworks to evidence originating beyond the institutions that operate AI systems.
NIST provides risk-management and TEVV structures.
The EU AI Act establishes regulatory requirements.
Canada's AIA provides structured impact assessment.
Independent auditors provide examination and testing.
Researchers provide measurement and analysis.
Civil society provides observation and public-interest scrutiny.
AAAP and Citizen Auditing propose an evidence layer between observation and these institutional processes.
Not above governance.
Not instead of governance.
Beneath it — as a potential evidence layer.
And perhaps the most important principle is the simplest:
We do not ask others to trust what we say.
We document what we do, disclose what we can, distinguish facts from interpretation, preserve the record, and remain open to scrutiny.
That is the methodology.
That is the experiment.
And now, it is open for others to examine, challenge, improve, and—if they find value in it—build upon.
130. Publication — 15 August 2026
AAAP v2.0 + Citizen Auditing for AI Governance
Observe → Record → Verify → Notify → Archive
**Open methodology. Independent scrutiny. Verifiable evidence.**
Institutional Dissemination & Transparency Log
In alignment with the CMA255509 Research Protocol, the AAAP v2.0 methodology (Publication No. 130) has been officially disseminated to the following international regulatory, academic, media, and technical bodies as of August 15, 2026:
This log serves as a record of our ongoing commitment to open-source algorithmic governance and institutional accountability. We remain open to scrutiny, methodological critique, and collaborative dialogue.





Yorumlar
Yorum Gönder