An AI governance audit is a structured review of how an organisation selects, uses, oversees and evidences AI. It identifies unmanaged risk, unclear ownership, control gaps and worthwhile opportunities, then records what should happen next and why.
We look at three things
Risk
Where current or proposed AI use creates data, compliance, operational or reputational exposure.
Opportunity
Where repeatable work may be a sensible candidate for AI, based on how the work actually happens.
Leave alone
Where automation would add fragility, obscure accountability or solve a problem that is not worth solving.
What the review covers
The precise scope is agreed before work begins. Depending on the organisation and the questions it needs answered, the review may consider:
- Known and informal use of generative AI and other AI-enabled tools.
- Ownership, approval routes and escalation responsibilities.
- Data handling, privacy, retention and supplier dependencies.
- Human oversight, review and the consequences of incorrect output.
- Policies, registers, risk assessments and existing evidence.
- Operational work that appears suitable for automation, and work that does not.
- Relevant regulatory, contractual, funder or board expectations.
What you receive
- An executive summary written for accountable decision-makers.
- A map of observed AI use, risks, opportunities and control gaps within the agreed scope.
- Findings that distinguish evidence, estimates and our professional judgement.
- Prioritised actions with reasoning, dependencies and an accountable owner where one can be identified.
- Questions that remain open because the evidence was unavailable or inconclusive.
See the structure of an illustrative report. It is deliberately marked as an example and is not presented as client work.
What this service is not
Mise provides independent advisory services. We are not an ISO certification body, do not provide accredited certification and do not present an advisory review as proof of legal compliance. Where legal interpretation or accredited certification is required, that work needs the appropriate qualified provider.
Why independence matters
BSI has warned of a potential “wild west” of unchecked AI-audit providers and differing levels of assessment. A credible review needs clear scope, competent people, traceable evidence and conclusions that are not predetermined by a product sale. Read the BSI announcement.
Who it is for
The audit is intended for organisations accountable to a board, regulator, funder, membership or client base, including charities and nonprofits, member organisations, regulated SMEs and professional-services firms.
Frequently asked questions
Do we need to be using advanced AI already?
No. The useful question may be how informal tools are already being used, whether a proposed use is sensible, or whether the organisation should establish basic ownership before it expands adoption.
Does an audit always recommend more AI?
No. A finding may recommend a control, a change to a process, a specialist provider, further evidence or no AI intervention at all.
Is this ISO/IEC 42001 certification?
No. Mise is not an ISO certification body and does not provide accredited certification.
How are scope, timing and cost decided?
They are agreed after an initial conversation and confirmed before the engagement begins. Mise does not publish a universal figure because the evidence surface and accountability questions differ by organisation.