CSA, Audits, and AI
The letter arrived on a Tuesday. The FMCSA (Federal Motor Carrier Safety Administration) compliance review notice gave the carrier 30 days to prepare documentation. The safety manager, who had been using an AI-assisted dispatch tool for eight months, realized in that moment that she had no idea whether the AI's decisions were documented in a format that would survive a compliance review. The tool had made hundreds of recommendations. She had committed most of them. The audit trail was whatever the TMS (transportation management system) had automatically logged, which was less than she needed.
How CSA Works: The System That Watches Every Carrier
CSA stands for Compliance, Safety, Accountability, the FMCSA program that uses data from roadside inspections, crash reports, and investigations to create a rolling profile of every carrier's safety and compliance performance. Understanding CSA is not optional for any fleet professional; it is the foundation of the regulatory accountability that applies to every dispatch decision, every maintenance call, and every safety action a carrier takes.
The CSA Safety Measurement System (SMS) aggregates compliance data across seven categories called Behavior Analysis and Safety Improvement Categories, or BASICs. Each BASIC measures a different dimension of carrier behavior:
Unsafe Driving: Speeding, reckless driving, improper lane changes, seatbelt violations, and other moving violations recorded at roadside inspections.
Hours of Service Compliance: HOS (hours of service) violations discovered at roadside inspections and in ELD (electronic logging device) audits. If a driver is found to have exceeded driving or on-duty limits, that violation scores against this BASIC.
Driver Fitness: Invalid CDL (commercial driver's license), improper CDL class for the vehicle being operated, or driving while disqualified.
Controlled Substances and Alcohol: Drug and alcohol violations recorded at inspections or reported through the Drug and Alcohol Clearinghouse.
Vehicle Maintenance: Out-of-service vehicle violations, brake defects, lighting defects, tire issues, and other mechanical violations found during roadside inspections or DVIR (driver vehicle inspection report) audits.
Hazardous Materials Compliance: Violations related to hazmat placarding, handling, and documentation requirements.
Crash Indicator: Crash involvement data adjusted for mileage, which tracks the frequency and severity of crashes the carrier is involved in.
Each BASIC is scored on a percentile basis relative to other carriers with similar mileage exposure. A score at the 90th percentile means the carrier performs worse than 90 percent of comparable carriers in that category. FMCSA publishes alert thresholds (which vary by BASIC), and carriers whose scores exceed those thresholds appear on the public-facing CSA interface, visible to shippers, insurers, and brokers who use that data when selecting carrier partners.
The CSA scores are time-weighted, meaning more recent violations are weighted more heavily than older ones. A single bad inspection month followed by consistent clean inspections will improve the score over time. A pattern of violations that accumulates over months will push the score progressively higher, eventually triggering FMCSA intervention. Understanding this time-weighting is important for a fleet that has adopted AI tools and wants to assess whether the tools are helping or hurting its compliance trajectory.
What Triggers an Audit
FMCSA uses CSA data as the primary trigger for compliance investigations and audits, though not all audits result from poor CSA scores. There are several pathways to an audit.
Intervention based on CSA scores: Carriers whose scores in one or more BASICs exceed FMCSA alert thresholds receive Warning Letters (the first level of intervention), followed by Targeted Roadside Inspections if improvement is not demonstrated, followed if necessary by a Request for Corrective Action or an Onsite Investigation. The Onsite Investigation (what most people mean when they say "an audit") involves FMCSA investigators reviewing carrier records at the carrier's place of business.
Crash-triggered investigations: A serious crash involving a carrier's vehicle can trigger an investigation regardless of the carrier's CSA profile. If a crash results in fatalities or serious injuries, FMCSA may initiate a Compliance Review (the formal name for the onsite audit) to examine whether the carrier's safety management practices contributed to the crash.
New entrant safety audits: Carriers that have recently obtained a USDOT number and operating authority are subject to a safety audit within 12 months of beginning operations. This is a scheduled review that all new carriers should prepare for.
Consumer complaints: Complaints filed against a carrier with FMCSA can, if they describe a pattern of safety or compliance concern, trigger investigatory attention.
Random selection: FMCSA reserves the right to audit carriers randomly, though in practice the limited investigative resources are concentrated on carriers with elevated CSA scores or crash involvement.
For a carrier using AI tools in dispatch, maintenance, or safety functions, the most important audit trigger to understand and manage is the CSA score trajectory. If AI-assisted dispatch is producing HOS violations that accumulate in the SMS, or if AI-assisted maintenance recommendations are leading to deferred repairs that show up as Vehicle Maintenance violations at roadside inspections, the CSA score is the early warning signal. A safety manager who monitors CSA scores and can connect trends to specific operational practices (including AI tool outputs) has the best chance of catching a trajectory problem before it triggers an audit.
The Audit Documentation That AI Tools Affect
During a Compliance Review, FMCSA investigators examine several categories of records. Each of these has implications for a carrier that uses AI tools in operations.
Driver qualification files: Records confirming each driver's CDL status, medical certificate, and driving history. AI tools generally do not affect these directly, though an AI-assisted onboarding or compliance tracking tool that misfields a record could create gaps.
HOS and ELD records: The ELD data for the review period, along with the dispatch records that describe what each driver was assigned, by whom, and on what timeline. If AI dispatch tools generated the plans that drivers executed, and those plans produced HOS violations, the investigator will compare the dispatch records with the ELD records. The dispatcher's commit of each AI-generated plan needs to be documentable as a separate act, not just a software output that automatically propagated to the driver.
Vehicle maintenance records: Pre-trip inspection records (DVIRs), maintenance schedules, and repair orders. AI-assisted maintenance scheduling that recommended but failed to document scheduled servicing, or that generated preventive maintenance alerts that were dismissed without record, creates gaps in the maintenance file that an investigator will note.
Accident records: Documentation of crashes including post-crash drug and alcohol testing, driver statements, and accident register entries.
Safety management practices: Evidence that the carrier has systems in place to monitor driver performance, manage HOS compliance, and respond to safety issues. For a carrier using AI tools, the investigator may ask about those tools: what they are, how they work, how their recommendations are reviewed, and who has accountability for the decisions they inform.
This last point is where AI tools create a documentation obligation that many carriers have not fully thought through. When an AI dispatcher tool recommends a load assignment and a human dispatcher commits it, what is in the record? If the TMS logs only the final assignment without a trace of how it was generated, there is no audit trail that documents the human's review of the AI recommendation. If the AI tool flagged a potential HOS concern that the dispatcher overrode, is that flag and that override in the record? If the AI maintenance tool recommended a brake inspection and the shop manager declined it for scheduling reasons, is that decline documented?
The answer at most carriers using AI tools in 2026 is: inconsistently. Some platforms log AI recommendations alongside human decisions. Many do not. A carrier that cannot demonstrate, during a Compliance Review, that human review occurred between an AI recommendation and a dispatch or maintenance action has a governance gap that an investigator may characterize as an inadequate safety management system.
Keeping AI in the Loop Without Risking Operating Authority
Operating authority is the authorization from FMCSA that allows a carrier to legally operate commercial vehicles in interstate commerce. A carrier that fails a Compliance Review faces the possibility of a Conditional or Unsatisfactory safety rating, which affects operating authority and triggers additional scrutiny and requirements. The most serious outcome, an Unsatisfactory rating, can result in the loss of operating authority if not remediated.
For a fleet that is integrating AI tools, the risk of losing or compromising operating authority is not hypothetical. It is a concrete possibility if the carrier cannot demonstrate adequate safety management during a Compliance Review. The AI tools themselves are not the problem; an AI optimizer that helps dispatchers avoid HOS violations is genuinely good for safety compliance. The problem is governance: whether the carrier has built the accountability structures, documentation practices, and human oversight that allow it to demonstrate responsible AI use.
The practical principles that protect operating authority when AI is in the loop:
Human commit documentation: Every AI-generated dispatch plan, maintenance recommendation, or safety alert that results in a carrier action needs a documented human commit. The record should show who reviewed the AI recommendation, what they decided, and when. This does not have to be elaborate; a timestamp of the dispatcher's acceptance and name in the TMS, a shop manager's signature on an AI-generated work order, a safety manager's notation on a flagged ELD exception, are all sufficient if consistently applied.
Override and exception logging: When a human overrides an AI recommendation (accepts a load the AI flagged as HOS-marginal, declines a maintenance recommendation the AI generated, dismisses a safety alert), that override needs to be documented. The log of what the AI recommended versus what the human decided is exactly the kind of evidence that demonstrates a functioning human-in-the-loop governance structure during a Compliance Review.
Source-of-truth verification: Any AI-generated plan that touches HOS compliance needs to be verified against the live ELD record before dispatch, and that verification needs to be documented. This is both a compliance safeguard and an audit trail item: if the verification happened and was logged, the carrier can demonstrate it during a review. If the verification happened but was not logged, it cannot be demonstrated.
Periodic review of AI tool output against CSA data: A safety manager who regularly cross-references the AI tool's dispatch outputs with the resulting CSA violations can identify whether the tool is improving or worsening compliance patterns. This review is itself a governance practice that demonstrates responsible AI management, and documentation of these reviews is evidence a carrier can show during an audit.
Vendor documentation: If the AI tool is a third-party product (a TMS AI module, a telematics-based dispatch optimizer, or a predictive maintenance platform), the carrier should have documentation of what the tool does, how its recommendations are generated, and what its known limitations are. A carrier that cannot explain what its AI tools do, during a compliance investigation, has a governance gap that an investigator may treat as evidence of inadequate safety management oversight.
CSA Scores and the AI-Assisted Carrier
A carrier that uses AI tools well should, over time, have a CSA profile that reflects the improvement. AI dispatch that reliably avoids HOS violations will show a declining Hours of Service Compliance BASIC score. AI-assisted maintenance that catches brake and tire issues before roadside inspection will show a declining Vehicle Maintenance BASIC score. AI safety monitoring that identifies and coaches on Unsafe Driving behaviors will improve the Unsafe Driving BASIC. These are the tangible outcomes that justify AI investment and that demonstrate to shippers, insurers, and FMCSA that the AI tools are serving safety and compliance purposes rather than just efficiency ones.
But a carrier that uses AI tools poorly, committing AI-generated plans without verification, dismissing AI maintenance alerts without documentation, or relying on AI safety recommendations without human review, will have a CSA profile that reflects the opposite. The Hours of Service Compliance BASIC will rise as stale-data plans produce HOS violations. The Vehicle Maintenance BASIC will rise as deferred repairs show up at roadside. The Unsafe Driving BASIC may rise if AI routing recommendations push drivers into aggressive schedules that produce speeding violations. And when the audit comes, the carrier will have difficulty explaining its safety management practices to an investigator.
The safety manager in the lesson's opening story got a Compliance Review notice because FMCSA noticed something in her carrier's CSA data that warranted a closer look. The question that letter forced her to confront is the question every carrier deploying AI tools should be asking proactively: if FMCSA reviewed my records today, could I demonstrate that human review occurred between every AI recommendation and every dispatch, maintenance, or safety action? If the answer is "mostly" or "I think so," that is an accountability gap that needs to be closed before an auditor asks.
The 90-Day Compliance Hygiene Plan
For a carrier that has already deployed AI tools but has not built the governance around them, there is a practical path to closing the documentation and accountability gaps within 90 days. This is not a compliance overhaul; it is a set of targeted, achievable habits.
Days 1 to 30: Audit the current documentation. Pull one month of AI-generated dispatch plans and compare them against the TMS log. For each plan, can you identify who committed it, when, and whether a live ELD verification was performed? If not, what would need to change in the workflow or the TMS configuration to create that record? Identify the gap specifically before trying to fill it.
Days 31 to 60: Implement the logging habit. Establish a standard practice for how dispatchers document their review of AI recommendations: a named commit in the TMS, a verification timestamp, a notation when an override occurs. Train the safety manager to review AI maintenance alerts and document their disposition. This does not require new software; it requires new habits applied consistently within existing platforms.
Days 61 to 90: Review CSA trends against AI tool activity. Pull the CSA data for the same period and look for correlations between AI tool usage and compliance outcomes. Is the Hours of Service Compliance BASIC improving since the AI dispatch tool was implemented, or is it rising? This review is both a governance checkpoint and preparation for a Compliance Review: if CSA data is trending well, you have evidence that the AI tools are working as intended. If it is trending poorly, you have 30 days to identify and fix the specific AI workflow producing the violations before they accumulate further.
The 90-day plan is not a one-time project. It is the start of an ongoing practice. A carrier that reviews AI tool output against CSA data quarterly, maintains consistent human-commit documentation, and keeps records of AI override decisions will be in a fundamentally better position for any audit than one that relies on the AI tool to "handle compliance" without human documentation.
Key Takeaways
- CSA (Compliance, Safety, Accountability) measures carrier performance across seven BASICs using data from roadside inspections, crash reports, and investigations; scores above alert thresholds trigger FMCSA intervention that can escalate to an Onsite Investigation (Compliance Review).
- The primary audit triggers are elevated CSA scores, crash involvement, new entrant review, complaints, and random selection; carriers using AI tools that produce HOS or Vehicle Maintenance violations will see those violations accumulate in CSA scores.
- During a Compliance Review, investigators examine HOS and ELD records, maintenance files, driver qualification records, and evidence of the carrier's safety management practices, including the human oversight structures around any AI tools in use.
- AI tools create a documentation obligation: every AI recommendation that results in a carrier action needs a documented human commit showing who reviewed it, what they decided, and when; override and exception decisions also need to be logged.
- Operating authority, the FMCSA authorization that allows a carrier to operate commercially, can be jeopardized by a poor Compliance Review outcome; carriers that cannot demonstrate adequate human oversight of AI tools face a governance gap that investigators may treat as an inadequate safety management system.
- AI tools used correctly should produce improving CSA scores over time: better HOS compliance from AI dispatch, better Vehicle Maintenance scores from AI predictive maintenance, better Unsafe Driving scores from AI driver coaching; these improvements are the evidence that justifies AI investment.
- A 90-day compliance hygiene plan that audits current documentation gaps, implements consistent human-commit logging, and reviews CSA trends against AI tool activity is a practical starting point for any carrier that has deployed AI tools without building governance around them.
- The cardinal rule applies to CSA and audit readiness: the dispatcher, fleet manager, or safety professional who commits the decision owns it, and that ownership must be documentable; "the AI said so" is not a defensible answer in a FMCSA Compliance Review.
Skill.re