A3

Model Audit

Model Audit examines what a model is built from, what it does to its grounds, what it can support, and where representation, operational success, or predictive strength is assigned to actuality.

Abstract

Models are indispensable in research, technology, administration, and ordinary orientation. They may organise observations, express relations, enable calculation, simulate processes, and produce testable predictions. Model Audit therefore does not begin by treating the model as false or merely arbitrary. It examines the documented relation among object, data, assumptions, model structure, calculation, output, validation, and practical use.

The audit distinguishes model from actuality, representation from generative rule, measurement from modelled quantity, internal consistency from external correspondence, calibration from independent validation, interpolation from extrapolation, and operational usefulness from ontological assignment. Model capture is one possible risk pattern and may be recorded as F6 or F7 only where the model gains documented governing priority over relevant observation and correction.

1

Purpose and scope

The purpose is to test whether a model is used within the grounds, purpose, and domain of validity that can be documented. The audit may be applied to mathematical, statistical, physical, economic, legal, administrative, linguistic, and machine-learning models, but its questions and evidential requirements must be adapted to the relevant field.

Model Audit concerns the relation between model and object. It does not decide in advance whether the model is true, false, realistic, useful, or misleading. A model may be highly useful without being a complete account of its object, and an idealised model may carry genuine knowledge where its limits are visible and correspondence is tested.

2

Definitions and decisive distinctions

Model Audit becomes imprecise where model, data, representation, calculation, simulation, and actuality are treated as interchangeable. The distinctions below are functional: the same artefact may perform several roles, but those roles must then be documented separately.

That a model incorporates relations, parameters, or dynamic rules does not make it empty. But ontological content does not follow from symbols or calculation alone. Assignment to actuality requires a visible correspondence relation, traceable evidence, and testing against relevant alternatives.

Basic distinctions in Model Audit
TermWorking useMust not automatically become
Actuality / objectThe phenomenon, object, process, or relation to which the model is applied.The same as the selected model, data structure, or visualisation.
Observation, measurement, or dataRecorded traces or values produced through a documented process.Unmediated access to actuality without selection, instrument, definition, or uncertainty.
ModelA bounded arrangement of concepts, relations, rules, parameters, or procedures for a defined purpose.An exhaustive ontology or the object itself.
RepresentationA presentation of selected features of something else.The generative rule, cause, or whole behind the presentation.
CalculationA rule-governed operation upon defined quantities or symbols.Proof that the quantities or relations exist in actuality in the same way.
ProjectionA transformation from one representational space or coordinate system to another.A physical explanation of the form, cause, or ontology of what is projected.
SimulationA generated process under the model’s rules, initial conditions, and parameters.A record that the simulated process actually occurred.
PredictionA prospectively specified outcome testable against later or held-out material.Complete confirmation of every assumption or the only possible explanation.
Parameter or constantA fixed, estimated, or calibrated quantity with a defined role in the model.A neutral value without professional, measurement, or ontological content.
ValidationDocumented testing of model outputs against relevant and preferably independent grounds.A final guarantee for every situation beyond the tested domain.
3

Object and mandate

The mandate must identify the particular model, version, and use to be tested. It is not sufficient to state that the task is to ‘audit the model’ or ‘expose model capture.’

The same model may be defensible for one purpose and indefensible for another. The mandate must therefore bound objective, population, time period, decision context, and the kind of conclusion actually being assessed.

M1

Identify the model

Record name, version, owner, developer, documentation, implementation, and any derived variants.

Minimum basis
Model file, code, specification, publication, contract, technical documentation, or another identifiable source.
M2

Establish the purpose

Document what the model was created or selected to describe, explain, classify, predict, control, or decide.

Consequence
The model must not be assessed against a purpose it was never intended to serve without making that shift explicit.
M3

Bound the object

Identify the phenomenon, population, system, period, or decision to which the model is being applied.

Minimum basis
Concrete uses and claims, not only general descriptions of the model.
M4

Identify the model chain

Distinguish raw grounds, preprocessing, model structure, parameterisation, software, output, visualisation, and final claim.

Consequence
Error or uncertainty must be assigned to the stage it actually concerns.
M5

Establish decision effect

Document whether the model is advisory, explanatory, automatically decisive, or one ground among several.

Minimum basis
Actual procedures, powers, and actions—not merely formal descriptions.
M6

State what is not being audited

Exclude questions requiring separate professional, technical, ethical, or legal assessment from the mandate.

Consequence
The conclusion cannot exceed the mandate and competence actually used.
4

Model lineage and traceability

The model should be traceable from object through data selection, definitions, measurement, filtering, preprocessing, assumptions, structure, and parameters to output and final claim. Traceability does not require every stage to be simple, but it does require each stage to be identifiable and open to testing.

Inherited coordinate systems, defaults, training data, classifications, and software libraries may carry assumptions not visible in the final product. They must be registered where relevant to the finding.

  • Record the source of observations, measurements, training data, or register data.
  • Document definitions, units, coordinate systems, and selection criteria.
  • Distinguish fixed parameters from estimated, calibrated, and learned parameters.
  • Record transformations, filtering, normalisation, aggregation, and missingness.
  • Identify software version, rounding, numerical methods, and known implementation deviations.
  • Show how output is translated into text, figure, category, decision, or ontological claim.
  • Register stages that are unavailable for inspection, reproduction, or independent testing.
5

Audit questions

The questions should open the model to testing without building in that it must be false or capturing. Answers must be tied to documentation, tests, and concrete use cases.

Q1

Object

What in actuality is the model being used about, and how is that reference established?

Q2

Purpose and output

Which question is the model meant to answer, and what kind of output can it actually provide?

Q3

Inputs and selection

What material enters, what is omitted, and how does selection affect the result?

Q4

Assumptions

What is held fixed, idealised, linearised, normalised, or placed outside the model?

Q5

Generative rule

Which rule produces model evolution or output, and is a representational format being mistaken for that rule?

Q6

Parameters and identifiability

Are parameters measured, estimated, calibrated, or learned, and can different parameter sets produce the same result?

Q7

Validation

Against which independent observations, held-out data, or prospective predictions has the model been tested?

Q8

Alternatives

Are there other models or explanations that correspond equally well or better to the grounds?

Q9

Sensitivity and robustness

How much does the result change under reasonable changes in data, parameters, initial conditions, or model choice?

Q10

Domain of validity

Where is the model calibrated or validated, and is it being used for interpolation or extrapolation?

Q11

Assignment

What is claimed about actuality on the basis of the model, and is that claim stronger than the correspondence supports?

Q12

Correction

Which observation, test, or competing model could change, bound, or reject the use of the model?

6

Validation, uncertainty, and domain of validity

Internal consistency shows that the model coheres under its own rules, but not by itself that it corresponds to actuality. External correspondence is strengthened where the model meets material not merely used to construct or calibrate it.

Predictive strength is relevant evidence but must be assessed together with purpose, baseline, alternatives, uncertainty, data leakage, and whether the prediction was specified before the outcome was known. Operational success may provide strong support, but it does not automatically confirm every interpretation of the model’s parts.

Forms of testing
TestWhat it may showWhat it does not show by itself
Internal consistencyThat rules, equations, or procedures do not contradict one another within the model.That the model corresponds to its object.
CalibrationThat parameters can be fitted to known material.That the model generalises to independent cases.
BacktestingHow the model would have performed on historical material under documented conditions.That it would have been used or performed identically in real time.
Independent validationWhether outputs correspond to material not used for construction or calibration.That every assumption or mechanism is correct.
Prospective predictionWhether the model can produce testable outcomes before results are known.That the model is the only possible explanation.
Sensitivity analysisWhich parameters, data, and choices most strongly affect the result.Which values are actually correct without external grounds.
Alternative-model testingWhether the conclusion is robust across reasonable model choices.That every relevant alternative has been tested.
7

Model capture as a risk pattern

Model capture is not another name for model use, mathematics, idealisation, or professional agreement. The risk pattern becomes relevant where the model gains governing priority over its object, determines what may count as relevant grounds, and protects that priority against corrective observation or testing.

An F6 finding may be recorded where several concrete indications point in this direction but decisive conditions for F7 remain undocumented. F7 requires documentation of the complete relation among model, substitution, governing operation, resistance to correction, and consequence.

MC1

The model is identified

The particular model, version, implementation, and use exercising governing force are documented.

Minimum basis
Code, specification, report, procedure, decision, or actual use.
MC2

The substitution is identified

It is shown what the model replaces: observation, individual evidence, local variation, alternative explanation, professional judgment, or the object itself.

Minimum basis
A visible shift from model as instrument to model as exhaustive ground.
MC3

Governing priority is documented

Model outputs or internal categories determine what may count as relevant evidence, interpretation, or decision.

Minimum basis
Concrete procedures, decisions, or patterns in which model results override relevant counter-material without justification.
MC4

Relevant correction is resisted

Errors, deviations, new observations, or competing models are rejected by protecting the model frame rather than testing the grounds.

Minimum basis
Documented closure, redefinition, selective data use, or sanction against relevant examination.
MC5

The consequence is documented

It is shown how model capture affects knowledge, classification, decision, resource allocation, responsibility, safety, or corrigibility.

Consequence
Without a documented relevant consequence, the finding should not normally be elevated to F7.
8

Findings and formulation

Model Audit uses the common finding categories F1–F7. The finding must state which model, output, use, and claim were assessed, which validation exists, and which uncertainty or limitation remains.

A finding should distinguish error in data, implementation, model structure, parameter, interpretation, and use. That a model is bounded or idealised is not itself an error where the limitation is relevant, open, and kept within the domain of validity.

Examples of Model Audit findings
CategoryPossible formulationIndefensible formulation
F1The model corresponds to independent test data within the stated uncertainty and documented domain of validity.The model is reality.
F2The model captures the principal pattern in the tested domain, but systematic deviation makes it unsuitable for the relevant subgroup.The model is mostly true.
F4The claim about mechanism extends beyond what calibration and predictive fit can document.The mechanism does not exist.
F5The implementation applies the wrong unit in one transformation stage and produces systematically erroneous outputs.The whole field is false.
F6Model output is used as a final decision ground despite documented deviations, but resistance to correction is not sufficiently documented.The institution is model-captured.
F7Within the audited decision process, the model is documented as replacing individual evidence, restricting which counter-material was processed, and rejecting relevant correction with a visible consequence.They believe the model rather than reality.
9

Correction and safeguards

Correction must answer to the bounded finding. Its purpose is not to remove models or demand model-free practice, but to restore precise use, visible uncertainty, relevant counter-testing, and traceable assignment to actuality.

A model may be corrected through data, definition, structure, parameter, implementation, documentation, interface, decision rule, or validity boundary. The measure must address the stage to which the finding actually belongs.

  • Correct errors in data, units, code, parameters, or transformations and document the effect.
  • Clearly separate model output, professional interpretation, and final decision.
  • Expose assumptions, uncertainty, data coverage, and domain of validity at the point of use.
  • Add independent validation, competing models, sensitivity analysis, or human review where risk requires it.
  • Bound or suspend extrapolation without documented grounds.
  • Change the decision rule where model effect exceeds what validation supports.
  • Permit affected parties to provide relevant individual or case-specific grounds not captured by the model.
  • Define responsibility, deadline, review, rollback, and closure criteria.
10

Limitations and misuse

Model Audit may itself become model-capturing where the auditor’s own categories, competing model, or preferred ontology is made incorrigible. The audit must therefore test its own mandate, evidence selection, and language under the same requirements.

The method can expose traceability failures, inferential leaps, and validity problems, but cannot by itself settle every professional question. Claims about statistical identifiability, physical mechanism, software safety, or regulatory conformity may require specialist competence and separate standards.

V1

Avoid hostility to modelling

The audit must not treat abstraction or idealisation as error merely because the model is not identical with actuality.

V2

Avoid result worship

Good fit or prediction must not automatically become confirmation of every mechanism, parameter, or ontological interpretation.

V3

Avoid post hoc fitting

Explanations and thresholds changed after the outcome was known must not be presented as prospective prediction.

V4

Avoid total rejection from one deviation

A single deviation must not alone be used to reject a model without examining uncertainty, measurement, scope, and alternatives.

V5

Avoid concealed competence overreach

The auditor must distinguish methodological findings from professional conclusions requiring expertise the audit does not possess.

V6

Audit the audit

The auditor’s competing model, interpretation, or conceptual frame must remain equally open to traceability, validation, and correction.

11

Audit record and review

A Model Audit must be documented in the common audit record or an equivalent traceable format. The record should show mandate, model version, model chain, data sources, assumptions, tests, alternatives, findings, contradiction, correction, and planned review.

Review must examine whether correction actually improved correspondence, robustness, intelligibility, and decision quality, and whether it reduced risk without creating a new model or manual practice with the same incorrigible function.

Foundation and further work

  1. DET SOM ERThe founding work of Røyndalism and the distinction among actuality, appearance, language, model, system, and practice.
  2. Corrigible RealismThe broader philosophical placement of the model as a corrigible intermediary.
  3. Reality Audit — methodology overviewThe common methodological placement.
V

Revision history

Document version
1.0
First published
18 June 2026
1.0

First public edition.