← All signals

The next board-level AI question isn't 'does it work' — it's 'who audits it'

For most of the last two years, the boardroom question about AI was a question of capability: can we build it, and what will it save us? That question is largely settled. The one replacing it is harder — and it’s the one that decides whether your AI ever leaves the pilot stage: can we prove it’s safe, fair, and accountable, and who, exactly, checks?

An entire assurance ecosystem is forming to answer that. The UK’s Centre for Data Ethics and Innovation, for one, has laid out a roadmap for an effective AI assurance ecosystem — the standards, tools and professional services that let an organisation demonstrate its AI is trustworthy rather than merely assert it (CDEI assurance roadmap, 2022). This matters because, as the governance literature keeps pointing out, formal regulation is still patchy and uneven across jurisdictions; in that gap, governance runs on soft law — voluntary standards, codes of conduct and certification (Kshetri, 2024). Assurance is how soft law gets teeth.

Auditing becomes the mechanism

If assurance is the goal, algorithmic auditing is becoming the mechanism — the actual practice of examining an AI system for bias, safety and compliance. The field is maturing quickly: there are now serious proposals for a global AI auditing framework (Towards a Global AI Auditing Framework, 2024) and, at the high end, calls for rigorous third-party assessment of the safety and security practices of frontier AI companies (Frontier AI Auditing, 2026). The direction of travel is unmistakable: AI is moving toward the same audited, assured posture we already expect of financial reporting.

But here’s the uncomfortable part the research surfaces, and the one boards should sit with: who audits the auditors? A field scan of the algorithmic-auditing ecosystem found that the auditors themselves often lack shared standards, independence or accountability (Who Audits the Auditors?, 2022). An assurance stamp is only as trustworthy as the body that issued it. Outsourcing your AI conscience to a third party you haven’t vetted isn’t governance — it’s the appearance of governance, which is more dangerous than none at all.

What this means on your desk

I spent two decades building the systems that run national carriers, and the lesson that transfers most cleanly to AI is this: auditability is a design property, not a feature you bolt on later. The billing and OSS platforms that survived regulatory and partner scrutiny were the ones built from day one to answer what happened, why, and who decided — without a forensic excavation. The AI systems that will survive the coming wave of assurance requirements are exactly the same.

Concretely, that means three things, none of which require waiting for a regulator:

  • Instrument for accountability now — log inputs, decisions, model versions and the human in the loop, so the audit trail exists before anyone asks for it.
  • Document the system, not just the model — most enterprise AI never reaches production not because the model is weak, but because the governance and implementation around it is missing (AI governance framework, 2024).
  • Vet your assurers — if you lean on a third party to certify an AI system, scrutinise their independence and standards as hard as you’d scrutinise the system itself.

The organisations that win with AI won’t be the ones with the cleverest models. They’ll be the ones who can answer “who checked this, and how” — and have been able to since day one.

The capability race is mostly over; everyone has access to the same frontier models. The differentiator now is trust — and trust, increasingly, is something you have to be able to prove: to a regulator, to a customer, or to your own board. Build for the audit before the absence of one builds a reason to doubt you.


References

← All signals