Why we audited ourselves
We sell one thing: the ability to show — not just say — how your processes work and where AI enters them. It would be strange to ask organisations to submit to that scrutiny while exempting ourselves.
So we ran our own Transparency Readiness Review on Vedomia, using the same five steps, the same four pillars and the same report structure a paying client gets. Two rules governed this document:
- No self-congratulation. A gap report that finds no gaps is marketing, not a review. We scored ourselves the way we would score a client — and some of the findings below are uncomfortable.
- Nothing invented. Every piece of evidence cited here exists and is dated. Where our practice is only days old, we say so.
This document doubles as a worked example: if you commission a Readiness Review, this is the shape, depth and honesty of what you will receive — a Gap Report, one audit-ready process map, an AI Transparency Statement, and a prioritised 30–90 day plan.
Practical readiness support, not legal advice. This review supports readiness and helps document practice; it does not constitute legal advice, certification or a conformity assessment.
Part 1 — Transparency Gap Report
We assess against Vedomia's four pillars, scored 1–5. A score of 5 means the pillar would withstand an external audit tomorrow; 3 means the core mechanism works but has documented weaknesses; 1 means the pillar exists only as intention.
Pillar 1: Visibility4/5
Is it clear what happens, who is involved, and whether AI is used?
What works
- A public AI transparency statement is live at vedomia.com/how-we-use-ai, stating in plain language where AI is used (drafting website copy, blog articles, translations, tool wording) and — equally important — where it is not used (no decisions about people, no screening, scoring or profiling; assessment logic in our free tools is human-written).
- AI-assisted outputs that leave the company carry a plain-language disclosure naming the human responsible ("Prepared with the help of an AI assistant, reviewed by Sandra Fedáková").
- The statement carries a "Last reviewed" date (July 2026), so a reader can judge its currency.
Gaps
- No formal AI tool inventory. We can name where AI enters our work, but there is no single internal document listing which AI assistants and models we use, for what purpose, and what data passes through them. A client in our position would be told to fix this — so are we.
- The public statement describes editorial AI use well, but our operational AI use (daily monitoring routines, drafting of outreach) is visible mainly through the internal AI log rather than the public page.
Pillar 2: Sequence3/5
Is it clear what happens next, in what order, and who does what?
What works
- The editorial workflow is published step by step on the public statement page: Draft → Review → Approve or revise → Label → Log. This is a genuine sequence with a named human decision point, not a policy sentence.
- Automated routines (daily monitoring, weekly reviews) run to a defined schedule, and their outputs land in defined locations before any human decision.
- Nothing is sent or published without an explicit founder instruction — the sequence has a hard stop built in.
Gaps
- Single point of failure. Every review, approval and send decision runs through one person, the founder. There is no documented fallback if she is unavailable — no deputy, no written continuity note, no access list for the systems that would need to be operated (website hosting, email sending, payments). For a solo company this is expected; it is still a real sequence risk and we record it as one.
- Follow-up cadence on outreach (currently "+4–5 days") is a working habit, not a documented rule with an owner.
Pillar 3: Justification3/5
Can each decision be explained — by what rule, on what basis, approved by whom?
What works
- Every published or sent AI-assisted item has a named approver, and the approval is recorded in the internal AI log alongside what was generated and where it lives.
- The public statement sets out the review criteria actually applied: factual accuracy against sources, tone, completeness, and whether the text stays within what we can honestly claim (no legal guarantees, ever).
- A binding internal strategy document constrains claims (no "AI Act compliant", no guarantees of legal conformity), so there is a written rule the review can be checked against.
Gaps
- Approvals are conversational, not structured. The founder approves by replying in a working session (e.g. "send it"); the log records that approval happened, but the approval itself leaves no independent artefact. An auditor would see the log entry and the sent email, and would have to take the link between them partly on trust.
- Rejections and revisions are under-recorded. When a draft is changed or discarded, the reason usually is not written down — so the justification trail is strong for what went out and weak for what did not.
Pillar 4: Auditability3/5
Does a findable record exist — evidence, history, responsibility, the ability to check back?
What works
- An AI log (audit trail) exists and is in daily use: one line per significant AI output or automated routine — date, what was generated, which files, who approved. It currently holds 35+ entries covering everything from website deployments to a 21-email outreach wave.
- Independent evidence outside our own notes: every outreach email sent from contact@vedomia.com carries a BCC back to the same inbox (a third-party-held copy with timestamp), and the sending platform records a message ID, which we log. A contact register (CSV) tracks who was contacted, when, and status.
- Website changes are deployed through a host that keeps deployment history with one-click rollback, and deploy IDs are recorded in the log.
Gaps — and these are the biggest in the review
- The audit trail lives on one laptop. The AI log and the contact register are local files. There is no automated backup, no version history, no off-device copy. A single hardware failure would destroy the primary evidence register while leaving only the scattered secondary evidence (BCC copies, platform records). For a company that sells auditability, this is the finding we are least proud of — and the first item on our own 30-day plan.
- No formal retention policy. We keep everything, indefinitely, by default. There is no written statement of what records we retain, where, for how long, or when they are reviewed or disposed of. "We keep everything" is a habit, not a policy, and it would not satisfy a funder's document-management question.
- Inconsistent log format. The AI log began as a structured table; under daily pressure, some entries were appended as free-text lines in a different format. All the information is there, but the register is no longer uniformly machine-readable or scannable — exactly the kind of drift we warn clients about.
- The practice is young. The log started on 13 July 2026. Three days of disciplined evidence is a start, not a track record. We note this because a review that hides the age of its own controls is not honest.
Part 2 — Audit-ready process map
Process: How an outreach email is produced, approved and sent at Vedomia
Purpose: contact a potential partner or client with a relevant, honest offer.
Start: a monitoring routine or a human idea identifies an opportunity.
End: the email is sent, evidenced and logged; a follow-up date exists.
AI involvement: drafting and monitoring only. AI never selects final recipients, never approves and never sends on its own initiative.
| # | Step | Owner | Where AI enters | Decision point | Evidence that the step happened |
|---|---|---|---|---|---|
| 1 | Monitoring & opportunity identification — a scheduled morning routine scans relevant news, funding calls and sector activity; findings are written into a dated briefing | AI routine, under founder's standing instruction | AI performs the scan and drafts the briefing | None — no external action possible at this step | Dated briefing file in the internal briefings folder |
| 2 | AI drafts the email — a draft with named recipient, subject and full text is written to a dedicated for-approval folder | AI assistant | AI writes the entire first draft | None — drafts cannot leave the folder without step 3 | Draft file with date-stamped filename in the for-approval folder |
| 3 | Human review — the founder reads the draft; checks facts, tone, and that no legal claims exceed what we can honestly say | Sandra Fedáková (founder) | None — human-only step | Approve / revise / reject. Revisions loop back to step 2 | Edited draft file; founder's instruction in the working session |
| 4 | Approval to send — explicit instruction from the founder (nothing is ever sent on schedule or by default) | Sandra Fedáková | None | Hard gate: no instruction, no send | Approval recorded verbatim in the AI log entry for the send |
| 5 | Send via the email platform (Brevo) — sent from contact@vedomia.com with an automatic BCC to the same address | AI assistant executes; founder's authority | AI operates the sending step as instructed | None — executes the approved decision only | Platform message ID (logged); BCC copy in the inbox — an independent, timestamped record of exactly what was sent |
| 6 | Logging — one line added to the AI log (date, what, files, approver); recipient added or updated in the contact register | AI assistant | AI writes the records | None | AI log entry; contact register row (name, date, status) |
| 7 | Follow-up — after 4–5 days without reply, a follow-up draft is prepared and re-enters this same process at step 2 | AI drafts; founder decides | AI drafts the follow-up | Founder approves or drops the follow-up | Register status updated; follow-up file and its own log line |
Known weaknesses in this process (carried into the Gap Report above): the approval at step 4 is conversational rather than a structured artefact; step 6's records are stored locally with no backup; the whole chain depends on one person's availability.
Part 3 — AI Transparency Statement
Vedomia's full statement is public and maintained at vedomia.com/how-we-use-ai. In summary:
- Where we use AI: drafting and refining website copy, blog articles, Slovak/English translations, the wording inside our free tools, and (operationally) monitoring and first drafts of outreach.
- Where we do not: AI makes no decisions about people; nothing is published or sent without a named human reading and approving it first; the assessment logic in our free tools is human-written — AI does not decide anyone's result.
- Human responsibility: every AI-assisted text published under the Vedomia name is reviewed and approved by Sandra Ahmidat Fedáková, who holds editorial responsibility for published content.
- Process, not promise: the statement publishes the actual five-step editorial sequence (draft → review → approve → label → log) and commits to an internal AI log so the audit trail exists before anyone asks for it.
- Data: our free tools run in the visitor's browser; answers are not sent to us during use.
The statement is dated ("Last reviewed: July 2026") and will be updated as our use of AI changes.
Part 4 — Prioritised 30–90 day plan
The same format a client receives: few items, ordered by risk, each one achievable by the people who actually exist in the organisation — in our case, one founder.
Days 0–30 — protect the evidence
- Back up the audit trail. Move the AI log and contact register into a versioned, off-device location (automatic cloud sync or a version-controlled repository) so no single laptop failure can erase the primary evidence. Highest-risk finding in this review.
- Restore one log format. Reconcile the AI log to a single table schema and add a two-line "how to write an entry" note at the top so the format survives busy days.
- Write the AI tool inventory. One page: which AI assistants/models are in use, for what purpose, what data they touch, and who oversees each use.
Days 30–60 — close the justification gaps
- Make approvals citable. Record the founder's approval wording verbatim (or a screenshot/quote reference) in each log entry for sent or published items, so the approval is an artefact, not an inference.
- Write a one-page retention policy. What records we keep (AI log, sent-mail BCC copies, contact register, deploy history), where, for how long, and the annual review date. Short beats perfect.
- Write the continuity note. A single document listing critical systems (hosting, email platform, payments, domain) and how a designated person could access them if the founder were unavailable.
Days 60–90 — prove it holds
- Schedule the statement review. Set a fixed quarterly date to re-review vedomia.com/how-we-use-ai and the tool inventory, and log each review as its own audit-trail entry.
- Invite one external pair of eyes. Ask a client, peer or adviser to spend 30 minutes trying to follow the audit trail from a sent email back to its approval. Where they get lost, fix the trail.
- Re-score. Repeat this four-pillar assessment and publish the delta. A readiness review that is never repeated is a snapshot; repeated, it becomes evidence of improvement.
What this means if you are considering the Readiness Review
This document is what €650 buys, applied to your organisation instead of ours: one priority process mapped end-to-end with owners, decision points and evidence; an honest four-pillar gap report; documented AI use with draft transparency wording; and a 30–90 day plan sized to your real capacity.
We found genuine weaknesses in our own practice and published them, because a transparency company that cannot survive its own method has no business selling it. The Review begins with a free 45-minute Clarity Call — details at vedomia.com/readiness-review.