The Big Picture Starts With Cybersecurity Audits

California's audit story did not begin with these two AI laws. The California Privacy Protection Agency's CCPA regulations became effective January 1, 2026 and require certain businesses whose processing presents significant cybersecurity risk to complete annual cybersecurity audits. The first audit reports are phased in beginning April 1, 2028, based on revenue thresholds.

The cybersecurity rules already make independence part of the compliance architecture. A covered business must use a qualified, objective, independent professional and accepted auditing procedures and standards. The regulation also addresses the auditor's knowledge, independence, scope, evidence, reporting, and annual certification.

Now California is building another layer around AI assurance. On September 9, 2026, the Governor signed AB 1405 and SB 813. Together, the laws establish a registry for AI auditors and a framework for more specialized independent verification organizations.

This matters beyond one state or one compliance program. AI governance increasingly affects privacy, cybersecurity, risk management, product governance, and the controls organizations use to demonstrate compliance. California is giving those changes a concrete audit and assurance structure.

That is one reason AuditDIFF is using California as a live case study. The state is not only adding obligations around AI and data. It is also defining expectations for the people and organizations that may independently evaluate whether those obligations are being met.

Two New AI Audit Laws, Two Different Jobs

AB 1405: The AI Auditor Registry

AB 1405 defines an AI auditor as a person, partnership, or corporation that assesses an AI system or model on behalf of a third party. A covered AI audit is narrower: the law defines the term as an audit of internal controls, processes, or systems implemented for an AI system or model that are necessary for compliance with California law.

No later than January 1, 2029, the Government Operations Agency must establish the AI Auditor Registry. Beginning that same day, a person may not offer, sell, or conduct a covered AI audit without registration.

Registration is not a state endorsement. The registry must expressly disclose that registration does not mean California recommends the auditor.

SB 813: Independent Verification Organizations

SB 813 creates a more specialized designation called an Independent Verification Organization (IVO). An IVO is an AI auditor designated by the Government Operations Agency as having demonstrated expertise in assessing AI risks and identifying the metrics and methodologies used for that assessment.

By January 1, 2028, the agency must develop application requirements, designation criteria, and procedures for suspension or termination. The criteria must consider technical expertise, risk-assessment capability, conflicts of interest, and independence from the party being assessed.

SB 813 also requires stakeholder working groups and directs the agency, where practicable, to align its approach with existing professional and regulatory audit and assurance standards. That alignment matters because AI assurance does not need an entirely separate universe of audit concepts. Independence, competence, evidence, documentation, comparability, and professional judgment already have long histories in assurance.

What Registered AI Auditors Will Have to Do

AB 1405 does more than create a list of auditors. The statute establishes baseline expectations for how covered AI audits are performed and documented.

  • Register before performing covered AI audits. Beginning January 1, 2029, covered AI audit services cannot be offered, sold, or conducted without registration.
  • Disclose qualifications and methods. Registration information includes relevant certifications or accreditations, the California laws or regulations under which the auditor performs covered audits, and a standard operating procedure identifying applicable standards and the basis for claims about the auditor's protocols.
  • Use recognized standards. Covered audits must follow widely recognized industry standards appropriate to the system or model when appropriate standards are available.
  • Produce a meaningful report. Reports must address scope and objectives, results and supporting documentation, deficiencies and reasonable measures where appropriate, relevant internal safety standards, audit limitations, material evidence gaps, and a signed statement of compliance with the chapter.
  • Retain audit evidence. Auditors must retain information provided to the auditee and documentation supporting audit results for at least 10 years.
  • Maintain independence. An auditor cannot perform a covered audit when financial, business, employment, or other relationships would reasonably impair independence or objectivity.
  • Do not audit your own work. The auditor cannot evaluate a system, process, control, assessment, or other subject matter that the auditor materially designed, developed, implemented, or operated for the auditee.
  • Manage employment conflicts. An individual participating in an audit cannot seek or accept employment with the auditee during the engagement. An auditor also cannot assign someone who, during the prior 12 months, held material responsibility for the audit subject at the auditee.
  • Use competent teams. The people assigned to an audit must collectively have the knowledge, skills, abilities, and specialized expertise needed for the scope.
  • Protect whistleblowers. Registered auditors cannot prevent or retaliate against employees who make specified reports about suspected noncompliance.

SB 813 adds another set of expectations for designated IVOs. The designation framework must address technical competence, risk-assessment methods, conflicts, independence, documentation, integrity, and cybersecurity. Designated IVOs must also submit annual information about standards, methodologies, governance changes, funding relevant to independence, and changes to application information. When an IVO redacts protected information from those reports, the unredacted information must be retained for five years.

Why This Matters to Companies

You may not be an AI auditor, so why should your business care about rules governing auditors? Because these laws provide an early view of the assurance expectations California is building around AI. They tell companies what an independent reviewer may be expected to look like, how independence is protected, how audit work is documented, and how long supporting evidence may need to remain available.

The immediate distinction is important. AB 1405 regulates auditors that perform covered AI audits. The law does not independently require every business using AI to commission one.

SB 813 is even more explicit. The statute says the chapter does not require a person or organization that develops, deploys, or operates an AI system or model to engage an IVO or undergo a covered AI audit as a condition of operating in California.

Other California requirements can still create audit obligations in specific contexts. CCPA cybersecurity audits are already an example of California requiring independent audit work for covered businesses, although those audits are cybersecurity audits rather than a general AI audit. California also has other sector- or use-specific AI requirements that should be evaluated separately.

Could broader AI audit requirements follow? That is possible, especially as California develops requirements around consequential AI and automated decisionmaking, but describing a broader mandate as inevitable would go beyond the current law. The Governor's September 18 executive order directed the Government Operations Agency to accelerate implementation of SB 813 and AB 1405 and to develop recommendations that could strengthen independent verification, including possible verification of certain frontier-AI safety frameworks, transparency reports, and risk assessments. Those directions may inform future policy. They are not a current general AI-audit mandate.

For companies, the practical takeaway is readiness rather than panic. Understanding which AI systems are in use, which systems affect consequential decisions or regulated processing, and what records support those systems will make it easier to respond if independent assurance becomes applicable later.

What Organizations Can Prepare Now

An organization does not need to pretend that a future audit requirement already exists. A more useful starting point is understanding the AI systems already in use and identifying which systems create the greatest regulatory and assurance exposure.

Preparation can begin with a small set of questions:

  • What AI systems and models are being developed, purchased, or deployed?
  • Which systems influence decisions about people, employment, access to services, safety, security, or other consequential outcomes?
  • Which systems process personal or sensitive information?
  • Which systems fall within California ADMT requirements or other existing risk-assessment obligations?
  • What evidence shows how those systems were approved, tested, monitored, changed, and governed?
  • Could an independent reviewer reconstruct the organization's decision from the available records?

That inventory does not answer every legal question. The inventory does something more basic: it tells an organization where to look before a regulator, customer, auditor, or incident forces the question.

Why This Fits the AuditDIFF Mission

AuditDIFF exists to make governance requirements easier to understand and implement while strengthening assurance. California's current changes give us a practical place to examine that mission.

Cybersecurity audits are becoming a defined regulatory obligation for covered CCPA businesses. Risk assessments and ADMT rules are creating more structured records around consequential processing. California has now enacted laws governing who may perform certain AI audits and what credible AI-audit practice should include.

For now, the legal development is the important part: California is establishing who can perform covered AI audits and what credible independence, competence, documentation, and retention should look like. That gives organizations a clearer signal about the direction of AI assurance even before a general AI-audit mandate exists.

AuditDIFF will return to the engineering question separately. Future work will examine how traceability, change detection, evidence provenance, repeatable testing, and carefully used automation could help assurance keep pace with AI systems without replacing auditor judgment. This article stays focused on the rules taking shape now and what organizations should understand about them.

Primary sources

Check the Source

California AB 1405, Chapter 178: Artificial intelligence auditors registration

California SB 813, Chapter 179: Independent verification organizations

CalPrivacy: CCPA cybersecurity audits, risk assessments, ADMT, and insurance regulations

CCPA statute and regulations effective January 1, 2026

Governor's September 9, 2026 announcement on AB 1405 and SB 813

Governor's September 18, 2026 executive order on independent AI oversight