Shane O’Donnell, Centric Consulting’s Vice President of Cybersecurity, has two decades of experience in audit and cyber risk management.

Seventy-eight percent of senior business leaders say they lack confidence that their organization could pass an independent AI governance audit within 90 days, according to a 2026 cross-industry survey of nearly 1,000 executives spanning financial services, insurance, technology and manufacturing.

Many organizations have invested in technology, built capable teams and deployed AI across business functions. They’re not running weak AI programs, but they struggle to demonstrate it’s governed well enough to hold up under audit.

In the assessments our team conducts, this pattern consistently comes up. A technically sophisticated company undertakes an AI governance review with rigorous development practices and a team that deeply understands the technology. When we work through the controls, most are in place, but almost nothing is documented in a way an auditor, a customer or a regulator can evaluate. They’ve built the capability; they just can’t prove it.

Why Documentation Is The Real Audit Risk

Companies tend to frame AI risk as a technology problem, focused on model outputs, potential for bias or security vulnerabilities in the system itself, but that is rarely where assessments break down.

ISO 42001, the international standard for AI management systems, contains 38 controls. The majority require documented evidence; not just processes that exist in practice, but records that demonstrate those processes were followed, reviewed and maintained over time. This standard measures whether someone outside your organization can assess how you govern it.

Documentation feels redundant when the people who built the system and understand how it works are all in the room. That logic holds until an auditor asks for evidence, an enterprise client sends a compliance questionnaire or a key team member leaves and the institutional knowledge goes with them.

Governance policies that live in people’s heads will not withstand external review, and external review is no longer an outlying possibility for organizations that use AI at scale. This documentation gap shows up whether an organization is building AI products, selling AI-powered services or deploying AI internally.

Why AI Governance Certification Is Becoming A Procurement Requirement

Vendors selling into financial services, healthcare and critical infrastructure are finding that ISO 42001 certification is appearing in procurement requirements and contract terms.

What used to be a security questionnaire asking about general data practices now includes specific questions about AI governance documentation, model oversight procedures and evidence that controls are operating as described. Vendors that cannot produce that evidence are losing ground in sales cycles before they get to a conversation about capability or price.

AWS, Anthropic, OpenAI, Snowflake, Salesforce and ServiceNow have all publicly announced or disclosed ISO 42001 certification, a signal that the largest AI vendors in the world are treating it as a baseline rather than a differentiator. For mid-market organizations, that window is closing faster than most realize.

What To Do Before An AI Governance Audit

​Fortunately, this is a gap that most organizations can address systematically before an audit ever begins.​

Get ahead of the assessment.

Organizations that get certified use the process as a planning tool. They commission a gap analysis before anyone requires it, find out where they stand on their own timeline and address gaps deliberately rather than under deadline pressure.

In practice, a gap analysis rarely surfaces surprising issues. More often, the controls exist and the processes are real, but the records needed to prove them are missing. Addressing that documentation gap proactively is far less costly than trying to close it under a deadline set by a customer, auditor or regulator.

Know what auditors are evaluating.

Documentation discipline matters more than technical sophistication in a certification context. An auditor cannot evaluate a control that exists only in practice. The standard of evidence is whether there is a record showing a process was followed, reviewed and maintained over time, not whether the people in the room can describe how it works.

Start with documentation.

In my experience, the controls are often already in place and the work is formalizing what already exists rather than building from scratch. This is achievable on a reasonable timeline if the process starts before external pressure sets the deadline. A gap analysis will quickly show where processes exist, but records don’t, and that is almost always where the work is concentrated.

​Conclusion

A strong AI program that cannot be demonstrated is a liability in a procurement conversation. The organizations most exposed right now are the ones that assumed their operational maturity would speak for itself. ​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Share.
Leave A Reply

Exit mobile version