Preparing for an AI Governance Audit: A Practical Readiness Guide
Whether it is an internal audit function adding AI to its scope, an external auditor assessing EU AI Act obligations, or an FCA supervision visit with a governance focus, the preparation for an AI governance audit is the same. The question the auditor is trying to answer is: does this organisation know what AI it is using, is it being actively governed, and can it prove it?
Audit preparation is not about making the organisation look better than it is. It is about ensuring the evidence of what the organisation actually does is organised, accessible, and in a form auditors can evaluate. The preparation reveals the gaps. The gaps are what needs fixing.
What Auditors Are Actually Assessing
Objective 1: Completeness of the AI agent inventory
The first and most fundamental objective is to confirm that the organisation has an accurate, current picture of what AI systems are operating. Auditors test completeness by comparing the inventory to an independent discovery output. If the organisation cannot produce independent discovery evidence, auditors note the completeness risk as unresolved.
Objective 2: Adequacy of governance controls
The second objective is to assess whether governance controls (human oversight, risk classification, monitoring) are designed appropriately and operating effectively. Operating effectively means there is evidence that the controls are running, not just that they are documented.
Objective 3: Quality of governance evidence
The third objective is whether the evidence of governance meets the standard required for the context: regulatory examination, insurance underwriting, or board assurance. Evidence that satisfies internal audit may not satisfy a regulatory supervisor. Audit preparation needs to account for the intended use of the evidence.
The Pre-Audit Readiness Assessment
Four to six weeks before an AI governance audit, conduct a readiness assessment across five areas:
Area 1: Inventory currency and completeness
- When was the AI agent inventory last updated?
- Was it produced through programmatic discovery or self-reporting?
- Does it cover all major platforms?
- Is there a signed, dated record verifiable under examination?
If the inventory is more than 30 days old, run a fresh discovery cycle. If it relies on self-reporting, run a programmatic discovery and compare. The gap is the finding the audit will surface. Better to find it yourself first.
Area 2: Risk classification documentation
- Is there a documented classification methodology?
- Does each agent have a classification with documented reasoning?
- Have classifications been reviewed when agent configurations changed?
The most common gap: classifications exist but reasoning is not documented. Review classifications before the audit and document the reasoning for any that lack it.
Area 3: Monitoring records
- Are there records of monitoring activities for the period under review?
- Do the records show what was monitored, what was found, and what action was taken?
- Is the monitoring cadence consistent with the documented frequency?
Gaps in monitoring cadence, months where no monitoring occurred, are significant audit findings. Missing months are not explainable by "the system was stable." They are gaps in the governance programme.
Area 4: Oversight documentation
- Are oversight responsibilities assigned to named individuals for each material system?
- Is there evidence of oversight activity (meeting records, escalation logs, intervention decisions)?
- Are the responsible individuals aware of their obligations?
Area 5: Evidence pack integrity
- Are signed evidence packs available for the period under review?
- Can the signatures be verified?
- Do the packs cover cross-platform findings, not just individual platform views?
The Gap-Fixing Priority Order
- Inventory completeness. Run programmatic discovery first. This is the foundational issue.
- Monitoring record gaps. Missing records are the most visible audit finding. Document what monitoring occurred.
- Classification reasoning. Document reasoning for any classifications that lack it. Quick to address.
- Oversight evidence. Collect and organise oversight activity records for the period under review.
- Evidence pack signatures. If packs have been generated but not signed, ensure going forward they are signed at generation.
What to Prepare for Audit Fieldwork
- The current AI agent inventory with discovery methodology documented
- Classification methodology and classifications for each agent
- Monitoring records for the full period, organised by cycle
- Oversight responsibility matrix and evidence of oversight activities
- Signed evidence packs for the period with signatures verifiable
- AETHER Pulse methodology document. Auditors will want to understand the methodology behind outputs
How AETHER Pulse Supports Audit Preparation
AETHER Pulse generates the evidence outputs the five readiness areas require. Its programmatic discovery addresses inventory completeness. Its classification framework addresses classification documentation. Its monitoring records address cadence gaps. Its signed evidence packs address integrity verification. For firms preparing for an AI governance audit, AETHER provides the evidence infrastructure that makes preparation straightforward rather than reactive.
Frequently Asked Questions
How long does AI governance audit preparation typically take?
For organisations with existing infrastructure, pre-audit preparation is primarily a gap-finding exercise completable in four to six weeks. For organisations without existing governance infrastructure, preparation is a multi-month process.
Should we engage external advisers for AI governance audit preparation?
External advisers can be valuable for gap assessment. However, the evidence itself needs to be generated by the organisation's governance programme, not manufactured for audit purposes. Auditors are experienced at distinguishing live programmes from documentation produced in response to an audit request.
Working on Article 26 readiness, deployer-side governance evidence, or AI agent risk at a regulated firm? We'd value 15 minutes of your perspective.
Start a conversation