Logo
FrontierNews.ai

California Creates Nation's First AI Auditing Framework: What It Means for Your Data

California has enacted two landmark bills that establish the nation's first formal framework for independent third-party audits of artificial intelligence systems. Gov. Gavin Newsom signed SB 813 and AB 1405 on September 9, creating a mechanism to verify that AI systems and models comply with state law, much like the auditing standards that govern the financial industry.

Why Does AI Need Independent Auditors?

The new framework addresses a fundamental governance gap: companies have been essentially grading their own homework when it comes to AI safety and compliance. The two bills establish independent verification organizations (IVOs) that can assess AI systems for legal compliance and create a state registry for AI auditors with standards for their independence, transparency, and integrity.

"We cannot expect industry to simply grade its own homework; third-party auditors are essential to ensuring AI is safe for our communities and critical infrastructure," said Assemblymember Rebecca Bauer-Kahan, who authored AB 1405.

Assemblymember Rebecca Bauer-Kahan, California State Assembly

The legislation represents a response to what auditors and compliance professionals have identified as serious blind spots in how organizations currently oversee AI. A practitioner research report documented 32 specific gaps in existing audit frameworks and proposed 47 new AI-specific control objectives across nine domains. These gaps reveal that AI risks fall into areas that traditional auditing frameworks simply don't address.

What Specific AI Risks Are Auditors Missing Today?

Current audit frameworks struggle with several AI-specific challenges that don't fit neatly into traditional categories. These include:

  • Autonomous Action Accountability: When AI systems execute transactions without direct human oversight, auditors cannot attribute actions to a specific accountable person, creating a major control gap that existing frameworks don't address.
  • Model Drift and Behavioral Monitoring: AI models can degrade over time without anyone noticing until a customer-facing incident occurs. Auditors now flag the absence of behavioral monitoring as a critical control gap.
  • Shadow AI Governance: Employees adopt AI-powered tools like ChatGPT, Claude, code completion tools, and AI writing assistants without IT approval or vetting, creating audit findings that don't fit into existing categories.
  • Runtime Enforcement vs. Policy Documentation: Auditors are no longer satisfied with policies sitting in a binder. They now require evidence that governance is actively enforced in production systems, not merely documented.

Gov. Newsom emphasized the urgency of the moment in his signing statement, noting that "the scale and potential consequences of this technology demand sustained action from every level of government" and calling on the federal government to establish robust national regulations.

Newsom

How Are Organizations Currently Implementing AI Governance?

While California's framework is still being implemented, organizations across sectors are already grappling with AI governance challenges. Credit unions, for example, are adopting what some describe as "minimum viable governance" frameworks because AI technology and use cases are changing too rapidly for static policies.

Linda Bodie, CEO of Element Federal Credit Union in West Virginia, explained that effective AI governance requires knowing where AI is working, what data it touches, and who is checking its output. She noted that AI-generated work cannot simply be accepted as accurate or compliant, as the technology "does not consider compliance" and can "go off the rails".

Linda Bodie, CEO of Element Federal Credit Union in West Virginia

"It's not a manual that sits on a shelf. It is actually knowing where the AI is working, what it's touching and who's checking it," said Linda Bodie.

Linda Bodie, CEO of Element Federal Credit Union

George Estrada, Chief Technology and Innovation Officer at Rize Credit Union in California and Nevada, noted that his institution reviews its AI governance monthly and has created an AI business analyst position to monitor and calibrate policies as the technology evolves. He emphasized that the most important line organizations must draw involves member data and personally identifiable information.

What Control Gaps Exist in Current Audit Standards?

The accounting profession is debating whether to add a sixth category to the SOC 2 (System and Organization Controls 2) framework specifically for AI governance and risk management. Currently, SOC 2 consists of five categories: security, availability, processing integrity, confidentiality, and privacy. However, these categories don't adequately address AI-specific risks.

A dedicated AI governance category could explicitly address model governance and lifecycle management, bias and fairness detection, data provenance and training data quality, model performance monitoring, third-party AI services and vendor management, autonomous action accountability, and responsible AI use and guardrails.

The American Institute of Certified Public Accountants (AICPA) appears to be taking a deliberate wait-and-see approach, potentially to avoid duplicating international standards like ISO/IEC 42001 (the international standard for AI management systems) and the NIST AI Risk Management Framework released in January 2023. However, pressure is mounting as organizations encounter concrete governance gaps during audits.

Steps Organizations Should Take to Prepare for AI Auditing

Whether or not formal audit standards expand, organizations need to act now to establish AI governance. Here are key steps to consider:

  • Establish an AI System Inventory: Identify all AI systems in production, including shadow AI tools and third-party services that employees may be using without formal approval.
  • Map AI Systems to Existing Audit Frameworks: Explicitly name AI systems in your audit scope and agree on control mappings with your auditor upfront to avoid inconsistent interpretations across audit cycles.
  • Implement AI-Specific Controls: Layer AI-specific controls on top of standard controls to address drift, bias, non-determinism, and training data governance that traditional frameworks don't cover.
  • Enforce Runtime Governance Evidence: Move beyond policies to automated enforcement records, audit trails, and behavioral monitoring that demonstrate governance is actively working in production.
  • Manage Shadow AI as a Governance Priority: Approve a curated set of AI tools, evaluate them through your vendor management process, and deploy them with corporate authentication integration.

Organizations should start implementing controls at least six months before a SOC 2 Type II audit, which examines a 6 to 12-month window. Implementing controls too close to the audit date leaves insufficient evidence for auditors to evaluate.

California's new auditing framework signals that AI governance is no longer optional. As more states and the federal government develop AI regulations, organizations that establish robust governance practices now will be better positioned to demonstrate compliance and protect consumer data from the risks that auditors are only beginning to understand.