A3
Model Audit
Model Audit examines what a model is built from, what it does to its grounds, what it can support, and where representation, operational success, or predictive strength is assigned to actuality.
Abstract
Models are indispensable in research, technology, administration, and ordinary orientation. They may organise observations, express relations, enable calculation, simulate processes, and produce testable predictions. Model Audit therefore does not begin by treating the model as false or merely arbitrary. It examines the documented relation among object, data, assumptions, model structure, calculation, output, validation, and practical use.
The audit distinguishes model from actuality, representation from generative rule, measurement from modelled quantity, internal consistency from external correspondence, calibration from independent validation, interpolation from extrapolation, and operational usefulness from ontological assignment. Model capture is one possible risk pattern and may be recorded as F6 or F7 only where the model gains documented governing priority over relevant observation and correction.
Purpose and scope
The purpose is to test whether a model is used within the grounds, purpose, and domain of validity that can be documented. The audit may be applied to mathematical, statistical, physical, economic, legal, administrative, linguistic, and machine-learning models, but its questions and evidential requirements must be adapted to the relevant field.
Model Audit concerns the relation between model and object. It does not decide in advance whether the model is true, false, realistic, useful, or misleading. A model may be highly useful without being a complete account of its object, and an idealised model may carry genuine knowledge where its limits are visible and correspondence is tested.
Definitions and decisive distinctions
Model Audit becomes imprecise where model, data, representation, calculation, simulation, and actuality are treated as interchangeable. The distinctions below are functional: the same artefact may perform several roles, but those roles must then be documented separately.
That a model incorporates relations, parameters, or dynamic rules does not make it empty. But ontological content does not follow from symbols or calculation alone. Assignment to actuality requires a visible correspondence relation, traceable evidence, and testing against relevant alternatives.
| Term | Working use | Must not automatically become |
|---|---|---|
| Actuality / object | The phenomenon, object, process, or relation to which the model is applied. | The same as the selected model, data structure, or visualisation. |
| Observation, measurement, or data | Recorded traces or values produced through a documented process. | Unmediated access to actuality without selection, instrument, definition, or uncertainty. |
| Model | A bounded arrangement of concepts, relations, rules, parameters, or procedures for a defined purpose. | An exhaustive ontology or the object itself. |
| Representation | A presentation of selected features of something else. | The generative rule, cause, or whole behind the presentation. |
| Calculation | A rule-governed operation upon defined quantities or symbols. | Proof that the quantities or relations exist in actuality in the same way. |
| Projection | A transformation from one representational space or coordinate system to another. | A physical explanation of the form, cause, or ontology of what is projected. |
| Simulation | A generated process under the model’s rules, initial conditions, and parameters. | A record that the simulated process actually occurred. |
| Prediction | A prospectively specified outcome testable against later or held-out material. | Complete confirmation of every assumption or the only possible explanation. |
| Parameter or constant | A fixed, estimated, or calibrated quantity with a defined role in the model. | A neutral value without professional, measurement, or ontological content. |
| Validation | Documented testing of model outputs against relevant and preferably independent grounds. | A final guarantee for every situation beyond the tested domain. |
Object and mandate
The mandate must identify the particular model, version, and use to be tested. It is not sufficient to state that the task is to ‘audit the model’ or ‘expose model capture.’
The same model may be defensible for one purpose and indefensible for another. The mandate must therefore bound objective, population, time period, decision context, and the kind of conclusion actually being assessed.
Identify the model
Record name, version, owner, developer, documentation, implementation, and any derived variants.
- Minimum basis
- Model file, code, specification, publication, contract, technical documentation, or another identifiable source.
Establish the purpose
Document what the model was created or selected to describe, explain, classify, predict, control, or decide.
- Consequence
- The model must not be assessed against a purpose it was never intended to serve without making that shift explicit.
Bound the object
Identify the phenomenon, population, system, period, or decision to which the model is being applied.
- Minimum basis
- Concrete uses and claims, not only general descriptions of the model.
Identify the model chain
Distinguish raw grounds, preprocessing, model structure, parameterisation, software, output, visualisation, and final claim.
- Consequence
- Error or uncertainty must be assigned to the stage it actually concerns.
Establish decision effect
Document whether the model is advisory, explanatory, automatically decisive, or one ground among several.
- Minimum basis
- Actual procedures, powers, and actions—not merely formal descriptions.
State what is not being audited
Exclude questions requiring separate professional, technical, ethical, or legal assessment from the mandate.
- Consequence
- The conclusion cannot exceed the mandate and competence actually used.
Model lineage and traceability
The model should be traceable from object through data selection, definitions, measurement, filtering, preprocessing, assumptions, structure, and parameters to output and final claim. Traceability does not require every stage to be simple, but it does require each stage to be identifiable and open to testing.
Inherited coordinate systems, defaults, training data, classifications, and software libraries may carry assumptions not visible in the final product. They must be registered where relevant to the finding.
- Record the source of observations, measurements, training data, or register data.
- Document definitions, units, coordinate systems, and selection criteria.
- Distinguish fixed parameters from estimated, calibrated, and learned parameters.
- Record transformations, filtering, normalisation, aggregation, and missingness.
- Identify software version, rounding, numerical methods, and known implementation deviations.
- Show how output is translated into text, figure, category, decision, or ontological claim.
- Register stages that are unavailable for inspection, reproduction, or independent testing.
Audit questions
The questions should open the model to testing without building in that it must be false or capturing. Answers must be tied to documentation, tests, and concrete use cases.
Object
What in actuality is the model being used about, and how is that reference established?
Purpose and output
Which question is the model meant to answer, and what kind of output can it actually provide?
Inputs and selection
What material enters, what is omitted, and how does selection affect the result?
Assumptions
What is held fixed, idealised, linearised, normalised, or placed outside the model?
Generative rule
Which rule produces model evolution or output, and is a representational format being mistaken for that rule?
Parameters and identifiability
Are parameters measured, estimated, calibrated, or learned, and can different parameter sets produce the same result?
Validation
Against which independent observations, held-out data, or prospective predictions has the model been tested?
Alternatives
Are there other models or explanations that correspond equally well or better to the grounds?
Sensitivity and robustness
How much does the result change under reasonable changes in data, parameters, initial conditions, or model choice?
Domain of validity
Where is the model calibrated or validated, and is it being used for interpolation or extrapolation?
Assignment
What is claimed about actuality on the basis of the model, and is that claim stronger than the correspondence supports?
Correction
Which observation, test, or competing model could change, bound, or reject the use of the model?
Validation, uncertainty, and domain of validity
Internal consistency shows that the model coheres under its own rules, but not by itself that it corresponds to actuality. External correspondence is strengthened where the model meets material not merely used to construct or calibrate it.
Predictive strength is relevant evidence but must be assessed together with purpose, baseline, alternatives, uncertainty, data leakage, and whether the prediction was specified before the outcome was known. Operational success may provide strong support, but it does not automatically confirm every interpretation of the model’s parts.
| Test | What it may show | What it does not show by itself |
|---|---|---|
| Internal consistency | That rules, equations, or procedures do not contradict one another within the model. | That the model corresponds to its object. |
| Calibration | That parameters can be fitted to known material. | That the model generalises to independent cases. |
| Backtesting | How the model would have performed on historical material under documented conditions. | That it would have been used or performed identically in real time. |
| Independent validation | Whether outputs correspond to material not used for construction or calibration. | That every assumption or mechanism is correct. |
| Prospective prediction | Whether the model can produce testable outcomes before results are known. | That the model is the only possible explanation. |
| Sensitivity analysis | Which parameters, data, and choices most strongly affect the result. | Which values are actually correct without external grounds. |
| Alternative-model testing | Whether the conclusion is robust across reasonable model choices. | That every relevant alternative has been tested. |
Model capture as a risk pattern
Model capture is not another name for model use, mathematics, idealisation, or professional agreement. The risk pattern becomes relevant where the model gains governing priority over its object, determines what may count as relevant grounds, and protects that priority against corrective observation or testing.
An F6 finding may be recorded where several concrete indications point in this direction but decisive conditions for F7 remain undocumented. F7 requires documentation of the complete relation among model, substitution, governing operation, resistance to correction, and consequence.
The model is identified
The particular model, version, implementation, and use exercising governing force are documented.
- Minimum basis
- Code, specification, report, procedure, decision, or actual use.
The substitution is identified
It is shown what the model replaces: observation, individual evidence, local variation, alternative explanation, professional judgment, or the object itself.
- Minimum basis
- A visible shift from model as instrument to model as exhaustive ground.
Governing priority is documented
Model outputs or internal categories determine what may count as relevant evidence, interpretation, or decision.
- Minimum basis
- Concrete procedures, decisions, or patterns in which model results override relevant counter-material without justification.
Relevant correction is resisted
Errors, deviations, new observations, or competing models are rejected by protecting the model frame rather than testing the grounds.
- Minimum basis
- Documented closure, redefinition, selective data use, or sanction against relevant examination.
The consequence is documented
It is shown how model capture affects knowledge, classification, decision, resource allocation, responsibility, safety, or corrigibility.
- Consequence
- Without a documented relevant consequence, the finding should not normally be elevated to F7.
Findings and formulation
Model Audit uses the common finding categories F1–F7. The finding must state which model, output, use, and claim were assessed, which validation exists, and which uncertainty or limitation remains.
A finding should distinguish error in data, implementation, model structure, parameter, interpretation, and use. That a model is bounded or idealised is not itself an error where the limitation is relevant, open, and kept within the domain of validity.
| Category | Possible formulation | Indefensible formulation |
|---|---|---|
| F1 | The model corresponds to independent test data within the stated uncertainty and documented domain of validity. | The model is reality. |
| F2 | The model captures the principal pattern in the tested domain, but systematic deviation makes it unsuitable for the relevant subgroup. | The model is mostly true. |
| F4 | The claim about mechanism extends beyond what calibration and predictive fit can document. | The mechanism does not exist. |
| F5 | The implementation applies the wrong unit in one transformation stage and produces systematically erroneous outputs. | The whole field is false. |
| F6 | Model output is used as a final decision ground despite documented deviations, but resistance to correction is not sufficiently documented. | The institution is model-captured. |
| F7 | Within the audited decision process, the model is documented as replacing individual evidence, restricting which counter-material was processed, and rejecting relevant correction with a visible consequence. | They believe the model rather than reality. |
Correction and safeguards
Correction must answer to the bounded finding. Its purpose is not to remove models or demand model-free practice, but to restore precise use, visible uncertainty, relevant counter-testing, and traceable assignment to actuality.
A model may be corrected through data, definition, structure, parameter, implementation, documentation, interface, decision rule, or validity boundary. The measure must address the stage to which the finding actually belongs.
- Correct errors in data, units, code, parameters, or transformations and document the effect.
- Clearly separate model output, professional interpretation, and final decision.
- Expose assumptions, uncertainty, data coverage, and domain of validity at the point of use.
- Add independent validation, competing models, sensitivity analysis, or human review where risk requires it.
- Bound or suspend extrapolation without documented grounds.
- Change the decision rule where model effect exceeds what validation supports.
- Permit affected parties to provide relevant individual or case-specific grounds not captured by the model.
- Define responsibility, deadline, review, rollback, and closure criteria.
Limitations and misuse
Model Audit may itself become model-capturing where the auditor’s own categories, competing model, or preferred ontology is made incorrigible. The audit must therefore test its own mandate, evidence selection, and language under the same requirements.
The method can expose traceability failures, inferential leaps, and validity problems, but cannot by itself settle every professional question. Claims about statistical identifiability, physical mechanism, software safety, or regulatory conformity may require specialist competence and separate standards.
Avoid hostility to modelling
The audit must not treat abstraction or idealisation as error merely because the model is not identical with actuality.
Avoid result worship
Good fit or prediction must not automatically become confirmation of every mechanism, parameter, or ontological interpretation.
Avoid post hoc fitting
Explanations and thresholds changed after the outcome was known must not be presented as prospective prediction.
Avoid total rejection from one deviation
A single deviation must not alone be used to reject a model without examining uncertainty, measurement, scope, and alternatives.
Avoid concealed competence overreach
The auditor must distinguish methodological findings from professional conclusions requiring expertise the audit does not possess.
Audit the audit
The auditor’s competing model, interpretation, or conceptual frame must remain equally open to traceability, validation, and correction.
Audit record and review
A Model Audit must be documented in the common audit record or an equivalent traceable format. The record should show mandate, model version, model chain, data sources, assumptions, tests, alternatives, findings, contradiction, correction, and planned review.
Review must examine whether correction actually improved correspondence, robustness, intelligibility, and decision quality, and whether it reduced risk without creating a new model or manual practice with the same incorrigible function.
Foundation and further work
- DET SOM ERThe founding work of Røyndalism and the distinction among actuality, appearance, language, model, system, and practice.
- Corrigible RealismThe broader philosophical placement of the model as a corrigible intermediary.
- Reality Audit — methodology overviewThe common methodological placement.
Revision history
- Document version
- 1.0
- First published
- 18 June 2026
First public edition.