Evidence-quality problemNIST, PCAOB, and The IIA converge on a useful idea: assurance depends on evidence that's fit for an objective, reliable enough to support a conclusion, and sufficient for the decision being made. That's the conceptual foundation for distinguishing proof from merely related paperwork.
AI-in-domain rationaleCybersecurity and audit research show active use of AI and NLP for analysis and document-oriented support, while also documenting reliability, explainability, governance, and overreliance concerns. ControlSift therefore studies assistive classification rather than autonomous audit.
Technical designLoRA and QLoRA ground parameter-efficient adaptation; Gemma documentation grounds the lightweight model choice. None of those sources are treated as evidence that fine-tuning must improve performance.
Responsible useNIST AI RMF and EU human-oversight requirements support explicit scope, documented limitations, monitoring, meaningful override authority, and resistance to automation bias. ControlSift keeps human judgment authoritative.
Outcome evidenceOnly ControlSift's sealed experiment files support statements such as “TF-IDF reaches 0.5327 macro F1 on v1.1” or “few-shot is strongest within the Gemma v1.0 ladder.” External literature never substitutes for experiment evidence.