California is regulating the AI auditor, not only the audit
Two signed laws create a framework for independent verification organisations and a registry for AI auditors. The hard enterprise question is how to prove competence, access and independence in practice.

What happened
California Governor Gavin Newsom signed SB 813 and AB 1405, linking third-party AI verification with a state mechanism for registering auditors.
Why it matters
Organisations buying or operating consequential AI will need to manage the assessor as part of the control system, including conflicts, evidence access and remediation boundaries.
California's latest AI laws shift attention from the existence of an audit to the institution performing it. On 9 September, Governor Gavin Newsom signed SB 813 and AB 1405. The official announcement describes two linked mechanisms: a framework for independent verification organisations that can assess AI systems and models for compliance with state law, and a state registry for AI auditors with standards for independence, transparency and integrity.
The distinction matters. A verification organisation needs access, technical methods and a defined reporting channel. A registry addresses who may present themselves as an auditor and under what professional conditions. Neither mechanism alone guarantees that the test covers the right system boundary, that an assessor has the relevant competence or that a finding leads to remediation.
The AB 1405 legislative record also describes protections against an auditor blocking or retaliating against an employee who raises concerns. That provision recognises a practical problem: an audit team can be formally independent from the developer yet still suppress information inside its own organisation. Independence has to apply to incentives and speech as well as ownership.
Build an evidence-access contract
For an employer using AI in hiring, performance, scheduling or learning, the immediate task is not to commission a generic “AI audit”. It is to define the object being tested. The contract should identify the model version, data flow, decision point, human override, affected population, deployment environment and change-control period. Without those boundaries, a clean report can describe a different system from the one affecting workers.
Access must be equally concrete. An assessor may need sampling data, model and prompt logs, policy exceptions, incident records, demographic performance slices, vendor documentation and interviews with operators. Privacy, trade-secret and security constraints remain legitimate, but they should result in recorded limitations rather than a silent narrowing of the work.
The laws do not create empirical proof that registered audits reduce harm. Independent enterprise coverage treats implementation as an emerging compliance task, not a finished standard. Agencies still have to turn statutory concepts into mechanisms, and courts may clarify disputed boundaries. Organisations should avoid marketing a registry entry as certification that a product is safe or lawful.
Preserve the objections
The Business Software Alliance argued before enactment that California should use workable, risk-based and interoperable rules and avoid duplicated obligations. BSA represents software vendors and therefore has a regulatory interest, but its objections identify real operating questions. A patchwork of incompatible audit formats can increase cost without improving evidence. Broad scope can also pull low-risk systems into processes designed for consequential uses.
Those concerns are a reason to design reusable evidence, not to abandon independent assessment. Enterprises can map California requirements to an existing control library, retain one system inventory and expose the same versioned evidence to several legitimate reviewers. They should still record where each legal test differs. “Interoperable” must not become a reason to erase a stricter local duty.
Procurement teams should now ask potential auditors for a competence matrix, conflict disclosures, quality-control process, insurance, subcontractor policy, incident escalation and sample limitation language. Product vendors should maintain an audit-ready change log and a route for workers or applicants to challenge outcomes. Boards should assign one executive who owns remediation after an adverse finding; outsourcing the assessment does not outsource the decision.
The practical value of California's move is institutional. It makes the credibility of the reviewer visible as a separate governance layer. The Skills Atlas can help identify the technical and domain capabilities an audit team needs. The organisation must still test whether those people had enough access, independence and authority to examine the deployed system.