← Back to resources

From auditing data to auditing algorithms: a decade of lessons in applying technical rigor

For more than a decade we worked, across different roles, on MinTIC’s technical audit information system: first on its initial implementation, then leading its technical evolution, and today supporting its operation as expert consultants. Over that time we took part, cumulatively, in more than 750 technical audits. That number is not a vanity metric; it is the real origin of how we think about technology at BIT.

Auditing an information system, in practice, is not checking whether it “works.” It is checking whether what it produces can be trusted: whether the data that went in is what it claims to be, whether the process that transformed it is reproducible, whether the conclusions it outputs can withstand external scrutiny. It is structured skepticism, applied methodically.

After more than ten years running that exercise on traditional information systems, the arrival of artificial intelligence inside organizations did not feel, to us, like entirely new territory. It felt like the same problem with an added layer of complexity: now the system does not just process data according to rules someone wrote, it also learns patterns and makes decisions that even its own creator cannot fully explain without additional tools.

That continuity is why, while many technology companies arrive at AI governance as a compliance requirement to check off, we arrived from the opposite direction: we first understood what it means to audit with rigor, and now we apply that exact standard, formalized under ISO/IEC 42001, to the AI systems we design and to the ones we evaluate for others.

Three lessons from that decade that we still apply today, unchanged: first, a system no one can audit is a system no one should fully trust, no matter how well it appears to work. Second, traceability is not added at the end of a project; it is designed in from day one, because trying to reconstruct it afterward is almost always impossible or prohibitively expensive. Third, the person who builds a system is rarely the most objective judge of its own risks — which is why an auditor’s perspective, even one internal to the same organization, remains irreplaceable.

We are writing this not as a marketing piece about our track record, but as an invitation: if your organization is adopting AI, apply to it the same structured skepticism you would apply to any system your operation depends on. That discipline, more than any specific model, is ultimately what determines whether an AI deployment is trustworthy — or just looks like it.

Want a conversation, not just an article?