All insights

Governance & Audit

Explaining an Agent's Decision to a CAG Auditor

· 14 minute read

A CAG party will not grade your model card. They will pick one rejected scholarship and ask who approved the agent, what it retrieved, what it proposed, and what the officer signed. If those four sentences are not on the file, you do not have an auditable system.

The audit party arrived on a Tuesday in a state scholarship directorate. They did not ask the brand of the model. They asked for file 2025/SCH/4418. A clerk produced a printout of a chatbot conversation. The senior audit officer turned the page, looking for a signature. There was a thumbs-up emoji from a section officer's personal phone, forwarded into the official WhatsApp group. That was the approval.

The agent had recommended rejection because the income certificate 'appeared stale'. The retrieval set was gone. The prompt version was gone. The officer who clicked send could not remember whether she had opened the PDF. The minutes of the purchase committee said the platform was fully auditable. The file in the room was not.

This is not a story about a hostile Comptroller and Auditor General. CAG's constitutional job, under Articles 148 to 151, is to audit government receipts and expenditure and to report. When a department lets an agent draft, retrieve or recommend, CAG does not need a special AI statute to ask ordinary questions: who spent, who decided, on what record, under whose authority. Those questions predate language models. Agents make them sharper because the machine can act at a speed no noting sheet ever did.

This article is a field guide for DPOs, CIOs and officers who will sit across from a CAG party. It is written on 16 August 2026. It is not legal advice and it is not an official CAG manual. It is the reconstructable file we wish every agent workflow already produced. Prcept AI builds on-prem and air-gapped agents for Indian institutions, is DPIIT recognised, and does not train on customer data. None of that replaces your file.

There is no CAG AI circular to hide behind

Vendors will tell a committee that their product is CAG-ready or aligned to CAG's AI framework. Pause. As of this writing we have not located a CAG circular that imposes a new, department-facing duty to document agentic systems in a prescribed form. What exists in public is CAG using AI for its own work — press notes and an Artificial Intelligence Strategy Framework in 2025 about how the audit institution itself might mine records, detect anomalies and shorten cycles. That is interesting. It is not your control.

Do not invent a CAG AI circular in a bid or a standing order. If a later circular arrives, file it and obey it. Until then, say the accurate sentence: CAG applies existing audit standards to new systems. Regularity, propriety, authority, completeness of the voucher, and the ability of a later officer to reconstruct the decision. MeitY's India AI Governance Guidelines, released on 5 November 2025, speak of accountability as a principle. They are guidelines, not a CAG manual and not a substitute for the Comptroller's mandate.

The practical effect is almost harder than a circular would have been. A circular at least names the annexure. Existing standards mean the auditor can pick any case and walk backwards until the story breaks. Your job is to make sure the story does not break at the agent.

The four sentences of a reconstructable file

Every citizen-affecting or money-affecting agent action should leave four sentences that a stranger can read in 2029.

  1. Who approved: the competent authority who authorised this workflow, this model version, and this officer to accept or reject the machine's proposal, with the instrument of delegation cited.
  2. What the agent retrieved: corpus name, document identifiers, retrieval timestamp, and whether any personal or classified class was in the set.
  3. What it proposed: the exact draft, score, or recommendation, hashed, with the prompt and policy version that produced it.
  4. What the officer signed: accept, reject, or modify, with a reason if the machine was overruled, on an official identity, not a personal chat.

Those four sentences are the whole product. Everything else — dashboards, token graphs, 'explainability' heat maps — is optional colour. If the vendor cannot export those four sentences as a packet the department owns, the platform is not auditable. It is conversational.

What a CAG party can reconstruct versus what a vendor demo usually shows.
Question on the fileDemo artefactFile artefact that survives
Who approved the workflow?Steer-co minutes saying AI is approvedStanding order naming workflow, model version, competent authority, sunset
What did the agent read?We use RAG on your circularsRetrieval log with document IDs, hashes, time, data class
What did it propose?Screenshot of a helpful answerImmutable output object with prompt/policy version
Who signed?Officer was in the loopeOffice / digital signature / system-of-record act by a named post
Was money moved?The agent only draftsProof the payment tool is refused without a DFPR-competent click
Can we see last year's case?Vendor console, if the tenant still existsDepartment-owned export, retention-mapped, CERT-In 180-day floor

What is not evidence

A model card is not evidence of a case. It is useful. It tells intended use, training-data class at a high level, and known limits. Keep one. Do not hand it to the auditor as if it were file 4418.

A vendor SOC 2 or an ISO/IEC 42001 certificate is not evidence of a case. Those documents, when genuine, say something about a management system at a point in time. They do not say why this widow's pension was held. Third-party assurance is a later article in this cluster. It does not reconstruct a decision.

A blockchain of logs is usually theatre. Signed, append-only logs shipped to a SIEM the department controls will answer the four sentences. A permissioned chain that the vendor operates, whose keys the department cannot use, is a more expensive diary. Honest teardown belongs in the companion piece. For CAG day, ask who can export last March without the vendor's tenant being alive.

Human-in-the-loop as a slogan is not evidence. The loop is a named officer, a named action, a timestamp, and a record in the system that already holds legal effect — the bill, the sanction, the speaking order, the eOffice noting. A thumbs-up on a phone is not a loop. It is a rumour with a screenshot.

Logs that match CERT-In and still fail CAG

The Indian Computer Emergency Response Team's directions dated 28 April 2022 require covered entities to enable logs of ICT systems and maintain them for a rolling 180 days, available within Indian jurisdiction, and to report specified incidents on a short clock. That duty is real. It is also the wrong shape for an administrative audit if you only keep firewall and authentication events.

An agent action log needs a different grain: actor (human or service account), time, tool called, data class touched, purpose tag, approval state, output identifier, override if any. CERT-In gives you a floor and a residency hint. CAG gives you a case. Design for the case. The 180-day floor is not a licence to delete the administrative file at day 181. Departmental record-retention schedules and purpose limitation still apply. Conversation logs are often personal data under the Digital Personal Data Protection Act, 2023. Treat them as such.

Two rooms the auditor can enter

Objections you will hear in the pre-audit meeting

The vendor says we are aligned to CAG's AI strategy. Answer: CAG's strategy is about CAG's own tools. Ask for the four-sentence export the department will own after the contract dies. If they cannot show it on a dark VM, they are aligned to a press note.

The CIO says logging everything will create personal-data risk. Answer: that is true, and it is an argument for purpose tags, access control and a retention map, not for silence. A system that affects rights and leaves no trace is not a privacy design. It is an unaccountable design.

The section officer says she is in the loop because she glances at the screen. Answer: glancing is not signing. Put the accept control in the system of record. If the agent cannot write there, the officer writes there. The agent remains a clerk.

Finance says we will write the reconstruction note when CAG lands. Answer: reconstruction after the retrieval set has aged out is fiction. Design the packet now. CAG day is too late to invent hashes.

A four-week playbook before the audit intimation arrives

  • Week 1: list every live agent workflow. For each, write the four sentences as they would look for one real case. If you cannot, mark the workflow amber and stop new citizen-facing use.
  • Week 2: pick three closed cases per amber or green workflow. Export the packet to a store the department owns. Time the export. If it needs a vendor engineer, it is not your packet.
  • Week 3: map logs to CERT-In 180 days and to the departmental record schedule. Decide which conversation fields are personal data. Write who may open a packet without a ticket.
  • Week 4: run a tabletop with internal audit. One officer plays CAG and names a file number. The DPO has thirty minutes. Whatever is missing becomes a change ticket, not a slide.

File note you can paste

Subject: Reconstructable records for agent-assisted decisions — preparation for audit.

This department has not located a CAG circular that prescribes a special form for artificial-intelligence agents. Existing standards of regularity, authority and completeness continue to apply. Each citizen-facing or money-facing workflow shall therefore leave a department-owned packet stating: (1) the approving authority and instrument of delegation; (2) the retrieval set with identifiers and time; (3) the agent's proposal with prompt and policy version; and (4) the competent officer's accept, reject or modify action in the system of record.

Vendor consoles, model cards and third-party certificates are supporting papers. They are not the packet. Logs will meet the CERT-In 180-day floor and the departmental retention schedule. Conversation logs will be treated as personal data where they identify a person.

Internal audit will test three cases before any external party is received. This note is an internal aid. It is not legal advice.

What we will put on the packet

Prcept AI will not sell you a CAG certificate. We will run the agent on your rack or in your air gap, refuse payment-adjacent tools unless a DFPR-competent officer acts, and give you an export of the four sentences that still works if our company is gone. We do not train on your cases. If a competitor can show a better packet, compete us. The auditor will not be grading our logo.

What the party will actually open, in order

Do not prepare a theatre of dashboards. Prepare a walk. The senior audit officer will name a file. You will produce the speaking order from the system of record. You will produce the packet that sits behind it. You will produce the standing order that authorised the workflow on that date, including the model hash and the prompt ID. You will produce the delegation that made the officer competent. If money moved, you will produce the DFPR serial and the human click. That is the morning. The afternoon is whatever broke.

Have a spare walk ready. Parties sample. If 4418 is perfect and 4419 is a WhatsApp thumb, they will write 4419. Internal audit should have already burned you on 4419. If they have not, you are using CAG as your first rehearsal, which is how paras become public.

Keep a paper or eOffice copy of the standing order in the same volume as the purchase file. Auditors still think in volumes. A packet that lives only in a GPU node's disk is a packet that will be 'down for maintenance' on the day. Export weekly to the official file store. Dull copies survive transfers, power cuts and vendor exits.

If the party asks whether you followed 'the CAG AI circular', say the accurate sentence: we have not found one that binds this department; we applied existing standards of regularity and reconstructability; here is the packet. Offering a fabricated circular number is worse than offering nothing. Officers who invent citations become the story.

  • Print the four-sentence header on a half-folio and clip it to the first sampled file the night before.
  • Name the officer who will sit in the room. It should be someone who has opened a packet with their own hands, not only the vendor CSM.
  • Disable the demo tenant. Parties have been shown staging before. Staging is not the file.
  • If a log store is on legal hold, say so. Do not improvise a deletion story in the room.

This article is informational field guidance for Indian public institutions, not legal, audit or procurement advice. Confirm against the live CAG mandate, your audit manual, CERT-In directions, DPDP commencement, and counsel before you file it.

Questions this usually raises

Has CAG issued a circular that tells departments how to document AI agents?
As of 16 August 2026 we have not found a CAG circular that creates a new departmental duty titled for AI agents. CAG has spoken publicly about using AI inside its own audit work, including an Artificial Intelligence Strategy Framework in 2025. That is CAG as a user of AI. It is not a licence for you to invent a CAG AI circular. Existing audit standards still apply to new systems.
What four facts must a reconstructable agent file contain?
Who approved the workflow and the model version. What the agent retrieved, with corpus and document identifiers. What it proposed, as a draft or recommendation. What the competent officer signed, including any override. If any of those four is missing, the file is a conversation, not a decision.
Does a model card replace the audit file?
No. A model card is useful documentation of intended use, data and limits. It is not a legal safe harbour and it is not a substitute for the transaction log of a particular case. Auditors reconstruct cases. Brochures describe products.
Are conversation logs enough for CAG?
A chat transcript without identity, purpose, data class, retrieval set, approval and output hash is a diary. CERT-In's 28 April 2022 directions already expect specified ICT logs to be retained for 180 days in Indian jurisdiction. That floor is necessary and not sufficient for a reconstructable administrative file.

Sources