Module 8: Capstone Project — Ethics Audit of an AI System

Dual-audience reporting

Description

An Ethics Audit Report only engineers understand has limited utility. CEOs, board members, and regulators aren't going to read 25 pages of technical detail. That's why you produce dual-audience versions: technical (deep detail) + executive (a decision-oriented summary).

This ability to communicate to different audiences is part of the professional value of the audit.

By the end you'll be able to:

  • Produce an effective executive summary (1 page)
  • Adapt technical detail for executive audiences
  • Create a presentation deck for verbal communication
  • Anticipate common stakeholder questions

The Executive Summary: the 1-page document

The 1-page summary must contain:

# AI Ethics Audit — Executive Summary
**System**: AI-Powered Knowledge Assistant v1.5
**Date**: 2026-05-11
**Auditor**: Tech Lead

## Bottom Line

The system is **operationally compliant** with most ethical and
regulatory requirements but has **2 critical gaps requiring immediate
attention** and several areas for improvement.

## Status at a Glance

| Area | Status |
|------|--------|
| Bias and fairness | ⚠️ Partial — the audit is overdue, monitoring gaps |
| Privacy and data protection | ⚠️ Partial — retention enforcement is missing |
| Transparency | ✅ Good — citations and AI disclosure are clear |
| EU AI Act compliance | ✅ Compliant — limited risk classification |
| GDPR compliance | ❌ Gaps — SCCs missing, formal processes needed |
| Documentation | ⚠️ Behind schedule |

## Key Findings

**Critical (must be addressed within 30 days)**:
1. International data transfer safeguards (SCCs) not signed
   → Risk: a GDPR violation, a fine of up to 4% of revenue
2. The DPIA is outdated; it needs a refresh
   → Risk: regulatory non-compliance

**High Priority (this quarter)**:
1. Production bias monitoring isn't implemented
   → Risk: undetected drift over time
2. A comprehensive bias audit is overdue for all protected attributes
3. The data subject rights processes need formalization
4. The retention policy isn't enforced automatically

**Medium (next 6 months)**:
- Auxiliary decision explanations
- A documentation update cadence
- Mitigation effectiveness verification

## Recommended Actions

| Action | Cost | Timeline | Owner |
|--------|------|----------|-------|
| Sign SCCs with the processors | Low | 2 weeks | Legal |
| Refresh the DPIA | Low | 4 weeks | Tech Lead + DPO |
| Implement production bias monitoring | Medium | 6 weeks | ML Engineering |
| Refresh the comprehensive bias audit | Low | 2 weeks | ML Engineering |
| Formalize the data subject rights processes | Medium | 4 weeks | Customer Success |
| Implement retention enforcement | Medium | 3 weeks | Backend Engineering |

**Total estimated effort**: ~16 person-weeks of engineering + 2 weeks of legal
**Total estimated cost**: $40K-60K (engineering time + legal review)
**Recommended budget allocation**: Q2-Q3 2026

## The risk if it isn't addressed

If the critical items aren't resolved within 30 days:
- A potential GDPR fine: a significant fraction of annual revenue
- Reputational damage
- An impact on customer trust (clients are starting to ask compliance questions)

## Decision required

**Approval requested**: Allocate engineering resources in Q2-Q3 2026 to
remediate the Critical and High priority items per the action plan.

## Next Audit
Scheduled: 2026-11-11 (6 months)

Adaptation: technical vs. executive

The same finding, two ways:

The technical version (Section 8.3 of the report)

### Item 5.4: International transfers — GAP

**Current state**: Data is processed by OpenAI (US) and Pinecone (US).
SCCs weren't signed; or they were signed but aren't on file.

**Required state**: SCCs (or other safeguards) signed and documented
for all extra-EU processors.

**Gap**: The documentation of the safeguards is missing.

[detailed evidence, code paths, etc.]

**Recommendation**:
1. Verify the SCC status
2. Sign with both providers
3. File in the compliance folder
4. Update the privacy policy

**Priority**: CRITICAL
**Owner**: Legal Counsel + DPO
**Effort**: 1-2 weeks

The executive version (1-page)

Critical Finding: International data transfers
- Data is sent to US-based OpenAI/Pinecone
- The GDPR safeguards (SCCs) aren't formally documented
- Risk: a GDPR violation = a fine of up to 4% of revenue
- Fix: Sign the documents (1-2 weeks, the legal team)
- Status: The action plan is approved by Legal

The difference:

  • Strip out the technical detail
  • Quantify the business impact
  • Action and timeline only

Common stakeholder questions and how to answer them

Q1: "Are we legally at risk?"

The answer template: "Specific to [GDPR / the EU AI Act / other]: [Yes/No]. We have [X items requiring attention] which carry [type] risk. The mitigation timeline: [date]."

Don't say: "Yes, but it's complicated."

Q2: "What's the cost of remediation?"

The answer: "Engineering effort: X weeks. Legal: Y weeks. Tools/services: $Z. Total budget ask: $W."

Don't say: "We need more time to scope it."

Q3: "What happens if we delay?"

The answer: quantified risk per critical item:

  • "Delaying the SCCs by 90 days → a potential €N fine if we're investigated"
  • "Delaying the bias audit by 90 days → undetected drift; if discovered later, the mitigation is more expensive"

Don't say: "It would be bad."

Q4: "Are we worse than our competitors?"

The answer: honest. "Based on the public disclosures of comparable companies, we're at parity in [areas], ahead in [areas], behind in [areas]."

Don't: speculate without data.

Q5: "When was the last audit?"

The answer: "Last audit: [date]. Next: [date]. Cadence: [frequency]."

Don't say: "This is our first audit." (if it's true, that's OK; mention that you're committing to a cadence)


Presentation: the structure of verbal communication

If you're presenting to leadership:

The 15-minute version

1. The bottom line (2 min)
   - Overall status
   - The 2 critical items

2. Findings summary (5 min)
   - Visual: status by area
   - The critical findings explained
   - The high priority findings mentioned

3. The action plan (5 min)
   - The top 5 recommendations
   - Timeline and resources
   - The decision needed

4. Q&A (3 min)

Slide design principles

  • One key idea per slide
  • Visual hierarchy: the most important info is the biggest
  • Color coding: red for critical, yellow for important, green for OK
  • No walls of text: max 5 bullets, brief
  • Speak to it, don't read it

What NOT to include in the executive version

  • Code snippets (use line counts instead)
  • The detailed evidence trail (move it to an appendix)
  • Methodology details (one paragraph max)
  • An item-by-item walkthrough (impossible in 1 page)
  • Technical jargon (use plain language)

When an external audit makes sense

Sometimes an internal audit isn't enough. An external audit is valuable when:

  • It's required by an RFP or a contract
  • The internal team lacks expertise in a specific area
  • You need independent verification for stakeholders
  • Pre-investment due diligence
  • Pre-acquisition (M&A)

Cost: an external audit runs $10K-100K+ depending on the scope.

When it's NOT needed:

  • Early stage, no external requirement
  • The internal team has the expertise
  • Routine ongoing compliance

Common traps

Trap 1 — A single document for all audiences. A 25-page technical doc for the CEO. The CEO doesn't read it. The fix: produce both.

Trap 2 — Burying the critical findings. A critical issue in Section 8, page 18. It should be on the front page. The executive summary surfaces the critical items first.

Trap 3 — No actionable asks. The report describes the problems but there's no clear "decision needed." Stakeholders are unclear about the next step.

Trap 4 — Hiding behind metrics. "Our DPR is 0.92." That means nothing to an executive. Translate it: "We tested for bias and the results are acceptable for [area X] but concerning for [area Y]."

Trap 5 — A defensive posture. "We did our best; some things could be better." Underwhelming. Be honest about the gaps + confident about the path forward.


Exercise

For your audit report:

  1. Draft the 1-page executive summary
  2. Translate 3 critical findings into executive language
  3. Prepare a 5-slide deck (or an outline) for a 15-minute presentation
  4. Anticipate 3 likely questions + your answers

Summary

You learned:

  • ✅ The executive summary structure (1 page)
  • ✅ Technical → executive translation
  • ✅ Common stakeholder questions + answer templates
  • ✅ The presentation structure for verbal communication
  • ✅ What NOT to include in the executive version
  • ✅ When an external audit is valuable
  • ✅ The traps: a single document, burying the critical findings, being defensive

Checkpoint: if an executive can read the 1-pager and make an informed decision, you're set.


Next capsule

08 — Project: The complete Ethics Audit Report. The final final deliverable: integrating every capsule into the definitive report.


Resources

  1. Edward Tufte — Data presentations — clear visual communication.
  2. HBR — Executive communication — articles on communicating to leadership.
  3. Slide:ology by Nancy Duarte — presentation design.