Five different things get called an "AI audit," and they differ by a factor of ten in cost and by a great deal in what they prove. This guide sorts them out, explains what a governance audit actually examines, and tells you how to read a score and spot a badge that means nothing.
An AI audit is an independent examination of how an organization uses and governs artificial intelligence, against a stated standard, producing a documented result someone else can rely on. The word "independent" is doing most of the work in that sentence, and the word "standard" is doing the rest.
The confusion comes from the fact that the same two words describe a bias test on a hiring algorithm, a certification of an AI management system, a CPA firm's report on a software vendor's controls, and a review of whether a 40-person law firm has a policy and checks its citations. Those are different services for different buyers. If you run a firm that uses AI rather than one that builds it, only one of them is written for you.
The question here is not "is the model accurate?" but "does this firm know what AI it uses, on what data, with what human oversight, by trained people, disclosed to the right parties?" Evidence is documentary: policies, inventories, vendor terms, review sign-offs, training records, engagement clauses. The result is a score or a rating against a published rubric, renewed on a cycle. This is what AboveBoard does, under a private, voluntary standard mapped to the NIST AI Risk Management Framework and cross-walked to ISO/IEC 42001. It is also what the SEC's FY2026 exam priorities, the NAIC's AI bulletin and most client questionnaires are actually asking about.
A technical examination of a specific system: does the résumé screener disadvantage a protected group, does the underwriting model drift, does the chatbot leak data under adversarial prompts. New York City's Local Law 144 requires an annual bias audit of automated employment decision tools by an independent auditor; a New York State Comptroller review found that enforcement had been ineffective and the city committed to tightening it (DLA Piper, Jan 2026). Firms such as BABL AI and the nonprofit ForHumanity work in this space. You need one of these if you build or materially configure a model that makes consequential decisions. Most professional-services firms do not, and a governance audit will tell you whether you are the exception.
ISO/IEC 42001:2023 is the international standard for an AI management system. Certification is issued by an accredited certification body (Schellman became the first ANAB-accredited body in September 2024; A-LIGN followed in October 2024) after a documented, multi-stage audit, with annual surveillance and a three-year cycle. It is rigorous, it is recognized, and it is expensive: roughly $73,000 all-in in year one for a 30-person AI-using company, $185,000 for 120 people, and six to twelve months of effort (certbetter, Jun 2026). Approximately 350 organizations worldwide held the certificate by spring 2026, compiled from announcements since no official register exists (Atoro, Jul 2026). Almost none of them are 50-person accounting or law firms.
A SOC 2 report is a CPA firm's attestation on a service organization's controls against the AICPA Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. It is not AI-specific, although auditors increasingly ask about AI within the security and confidentiality criteria, and compliance-automation platforms now sell ISO 42001 frameworks alongside it. Type 1 audits run $5,000 to $25,000, Type 2 $7,000 to $50,000 and up, and all-in programs $30,000 to $150,000 (Bright Defense, May 2026). You need one if you are a technology vendor whose customers demand it. A CPA firm or an RIA generally does not.
Big Four and mid-tier accounting firms now offer "AI assurance": model validation, control testing and attestation-style reports against SOC, HITRUST or bespoke criteria (CPA Practice Advisor, Sept 2025; Deloitte UK AI Assurance service page). These are performed by licensed CPAs under professional attestation standards, priced for enterprises, and not published. They are the right answer when an investor, a regulator or a large customer specifically requires an attestation report. Note that AboveBoard is not one of these and does not use the word: we issue a score and a verification, not an opinion.
| You are | You probably need | Why |
|---|---|---|
| A professional-services firm of 10–1,000 people that uses AI tools (CPA, law, insurance, advisory, healthcare, consulting) | A governance audit | Your regulators, carriers and clients ask about policy, data handling, human review, training and disclosure, not about model weights. |
| An employer using AI to screen, rank or evaluate people in NYC, California, Illinois or Colorado | A governance audit plus, where the law requires it, a bias audit of the specific tool | NYC Local Law 144 mandates a bias audit; California, Illinois and Colorado (from 2027) require notice, records and explanations that a governance audit evidences. |
| A software or AI vendor selling to enterprises | SOC 2, and increasingly ISO/IEC 42001 | Procurement demands attestation reports and, for AI products, a management-system certificate. |
| A company that builds or trains AI models used in consequential decisions | ISO/IEC 42001 and model audits | The full management-system standard and technical testing are built for developers. |
| A public company or an enterprise facing investor or regulator demands for assurance | A CPA attestation engagement | When the word "attestation" is required, only a licensed CPA firm can supply it. |
The AboveBoard Standard organizes forty controls into five domains, each worth 20 points. They are the same five areas the NIST AI RMF, ISO 42001, the NAIC bulletin, ABA Formal Opinion 512 and the Joint Commission's responsible-AI guidance keep returning to, in different vocabulary.
The full rubric, with four maturity levels for every control and the evidence that proves each one, is published in full. A printable version is in the 40-point checklist.
The Federal Trade Commission's rules on seals and certifications are specific. Under 16 CFR 260.6 it is deceptive to represent, directly or by implication, that a product or service has been certified by an independent third party when it has not, and a seal must convey the basis for the certification. Two enforcement actions define the failure modes. In 2014 the FTC settled with TRUSTe for $200,000 after the seal provider promised annual recertification and failed to recertify in more than 1,000 instances. The same year it ordered Made in USA Brand, which sold certification marks on self-certification with no evaluation and had never rejected or revoked one, to stop or to disclose that its seal was self-certified.
Management-system certification standards go further. ISO/IEC 17021-1 bars a certifier from consulting for the organization it certifies and imposes a two-year cooling-off period; ISO/IEC 17065 requires an impartiality mechanism, a complaints and appeals process, surveillance, and rules for suspending and withdrawing a mark.
So when a provider says "independent," ask five questions. Is the standard published, so you can see what was verified? Is a human reviewer, not a form, doing the verifying? Is the reviewer walled off from anyone selling you remediation or training? Are badges dated, renewed and revoked when they lapse? Does the provider reject firms, and say so? AboveBoard's answers are on our independence page and in our impartiality, revocation and complaints rules: published rubric, human review, a certification officer with no role in sales, year-stamped badges that link to a registry entry, and a scoring threshold below which a firm is simply not listed.
An AboveBoard Score runs 0 to 100: five domains, 20 points each, eight controls per domain scored 0 to 3 and scaled. Three levels are listed publicly: Verified 60–74, Advanced 75–89 and Leading 90–100. Below 60 is "not yet verified," which stays private and comes with a gap plan.
Four things to know when you see one. First, a provisional score comes from a firm's self-assessment; a verified score is what an independent reviewer confirmed from evidence. Only the second appears in the registry. Second, three gating controls override the total: no firm is listed at any level with a zero on the written policy, vendor-terms review or human-review controls. Third, a score is point-in-time: it reflects evidence as of the review date, which is why badges carry a year and expire. Fourth, a score verifies practices, not outcomes. A firm scoring 92 has strong governance; it has not been certified error-free, and no honest provider would say otherwise.
An AI audit is an independent examination of how an organization uses and governs artificial intelligence, against a stated standard, producing a documented result. The phrase covers five different things: a governance audit of an organization that uses AI, a technical or bias audit of a specific model, ISO/IEC 42001 certification of an AI management system, a SOC 2 report on a service provider's controls, and a CPA attestation engagement. For a firm that uses AI rather than builds it, the relevant one is the governance audit.
A governance audit works from evidence. The firm answers a structured set of questions across governance, data, operations, workforce and transparency, uploads the documents that prove each answer (policy, inventory, vendor terms, review sign-offs, training records, engagement clauses), and an independent reviewer samples that evidence against a published rubric, asks clarifying questions and confirms a score. A model audit, by contrast, tests the system itself for accuracy, bias and robustness. See how AboveBoard works.
It depends on which kind. ISO/IEC 42001 certification runs about $73,000 all-in in year one for a 30-person firm (certbetter, Jun 2026); SOC 2 Type 2 runs $30,000 to $150,000 all-in (Bright Defense, May 2026); enterprise AI governance platforms start around $50,000 a year and are quote-only (SecurePrivacy, Jun 2026). AboveBoardAI is $7,500 to $75,000 a year by headcount, everything included. The full comparison is in How much does an AI audit cost?
It is not a law, a regulation or a standard. The phrase circulates online as a rule of thumb that a meaningful share of any AI-assisted process, often quoted as 30 percent, should stay under human judgment rather than automation. No AI law or framework that AboveBoard maps to contains a 30 percent rule. What they do require is documented human oversight, which is what a governance audit verifies.
No. ISO/IEC 42001 certifies that an organization has built an AI management system meeting the standard's clauses, issued by an accredited certification body after a multi-stage audit. Roughly 350 organizations worldwide held it as of mid-2026 (Atoro, Jul 2026). A governance audit like AboveBoard covers similar ground, mapped to NIST AI RMF and cross-walked to ISO 42001, under a private, voluntary standard, at a fraction of the cost and time. It is not an ISO certification and does not claim to be. See NIST AI RMF vs ISO 42001.