An AI governance audit looks at how an organisation chooses, uses and controls AI, and what evidence it keeps. It compares day-to-day practice with the organisation’s responsibilities and stated approach, then records the findings, gaps and priorities.
Why an organisation might need one
AI use often spreads through features embedded in existing software, individual subscriptions and supplier products before ownership is clear. A board, regulator, funder, customer or leadership team may then ask, “How is AI governed here?” One policy will not usually answer that question.
An audit creates an evidence-based view of the current position. It may be prompted by a proposed deployment, a contractual request, an incident, growing informal use or a desire to improve governance before external pressure arrives.
What should be in scope?
There is no universal scope. A review may cover the whole organisation, a business unit, a defined process or a particular AI use. The scope should state the systems, teams, time period, evidence and obligations included, plus what has not been examined.
What evidence might be reviewed?
- AI or software inventories and approved-tool lists.
- Policies, risk registers, DPIAs and supplier assessments.
- Governance papers, approvals and assigned responsibilities.
- Data flows, retention practices and access controls.
- Evaluation results, sample outputs, logs and monitoring.
- Interviews with people who operate and oversee the work.
- Incidents, complaints, overrides and lessons learned.
What should a finding contain?
A useful finding states what was observed, the evidence supporting it, why it matters, the confidence or uncertainty, and a proportionate next step. It should distinguish a documented fact from an estimate or professional judgement.
A polished rating is not a substitute for traceable evidence and a clear explanation of what should happen next.
Audit, assessment and certification are not interchangeable
These terms are sometimes used loosely. A risk assessment normally examines a defined use or decision. A governance audit examines a wider control and accountability environment. Accredited certification is a separate conformity-assessment process carried out by an appropriately accredited certification body against a defined standard.
How to assess an audit provider
- Ask what standard, framework or stated criteria shape the review.
- Ask how evidence, estimates and judgement are distinguished.
- Confirm the scope and limitations in writing.
- Understand the provider’s competencies and any conflicts of interest.
- Check whether “audit” is being confused with accredited certification.
- Ask to see the proposed finding and report structure.
BSI published BS ISO/IEC 42006:2025 to establish requirements for bodies auditing and certifying AI management systems, while warning about inconsistent assessment in a growing market. That certification context is not the same as every advisory audit, but it reinforces why competence, consistency and independence matter. Read BSI’s announcement.
What happens after the report?
Actions should be assigned, evidence gaps closed and higher-risk uses monitored. Some findings need legal, technical, security or sector expertise beyond the original audit. Governance is an operating practice, so a one-off report should not be treated as a permanent statement about a changing organisation.
Next step
Use the AI governance checklist to identify obvious gaps, or read how Mise conducts an audit.