AI Governance7 min read

California Just Created a Licensed AI Audit Profession. Australian Organisations Should Pay Attention

California has created an AI auditor registry and independent verification framework. Here is why a formal AI audit profession matters to Australian organisations.

Shane CoetserBy Shane Coetser
AI Audit: What California's New AI Auditor Registry Means for Australian Organisations

California signed two bills this September that don't ban anything or regulate a single model directly. What they do is arguably more important over the long run: they create the infrastructure for a professional AI audit industry.

Assembly Bill 1405 sets up a state registry of AI auditors, with standards for their independence, transparency and integrity. Senate Bill 813 creates a framework for Independent Verification Organisations, expert bodies authorised to assess AI systems and models for compliance with California law. Together they mark a shift in how AI governance gets checked, from companies saying they comply to accredited third parties confirming it.

What the Two Bills Actually Do

Under AB 1405, a public registry of AI auditors must be in place by 1 January 2029. From that date, a person who isn't registered can't offer or conduct a "covered AI audit", meaning an audit of the internal controls, processes or systems an organisation relies on to comply with state law for an AI system. The bill also sets independence rules, including that an auditor can't assign someone who held a materially relevant position with the client in the previous twelve months.

SB 813 works alongside it. Rather than registering individual auditors, it provides for Independent Verification Organisations that can assess AI systems for compliance. Legal commentary suggests certification of these bodies is expected to be in place by early 2028. These dates are years away, and that's the point. California is building the profession before demanding the audits.

Why This Matters Outside California

Australian organisations aren't bound by California law unless they operate there. But the shift it represents is broader than one state. The question regulators and boards increasingly ask isn't "do you have an AI policy?" but "who has independently checked that your AI governance works?"

Australia's own direction points the same way. National AI standards are expected to go before Parliament in early 2027, and the Joint Select Committee on Artificial Intelligence is due to report by 30 November. It would be surprising if independent assurance didn't feature somewhere in what follows. Organisations that wait until it's required will be preparing for an audit at the same moment everyone else is.

Audit Readiness Is Mostly Evidence

What an auditor actually tests is evidence. Can the organisation show its AI register is complete and current? Can it show risk assessments were done before deployment, not reconstructed afterwards? Can it show human oversight actually happened, and that monitoring caught what it was meant to catch?

This is where most governance programmes are weakest. Policies exist. Proof that the policies were followed often doesn't. Existing assurance routes, such as certification against ISO/IEC 42001 for AI management systems, test much the same thing, and working toward one is a sensible way to build the evidence trail an independent auditor would expect.

What This Means for Your Organisation

What we see across the organisations we work with is that governance built for internal comfort looks very different from governance built to withstand an independent audit. The first relies on good intentions and documents. The second relies on records produced as work happens. California's move is an early signal that the second kind is where the market is heading, and building it now costs far less than rebuilding it under an audit deadline.

Key Takeaways

  • California's AB 1405 creates a registry of AI auditors, and from 1 January 2029 unregistered auditors will not be able to conduct covered AI audits.
  • SB 813 creates a framework for Independent Verification Organisations to assess AI systems for compliance with California law.
  • The laws signal a broader shift from self-declared AI compliance to independently verified assurance, a direction Australia's 2027 standards may also take.
  • Audit readiness depends on evidence produced as work happens, and frameworks such as ISO/IEC 42001 offer a practical way to build it now.

How Trusenta Can Help

AI Governance Maturity Uplift moves an existing governance programme from policy documents to the evidence an independent auditor would expect.

Compliance Management captures the records of risk assessments, oversight and monitoring as they happen, so audit evidence doesn't have to be reconstructed later.

AI Governance Enterprise supports larger organisations in preparing for independent AI assurance across multiple business units and jurisdictions.

Conclusion

California hasn't created an AI audit requirement for Australian organisations. It has created an AI audit profession, and professions tend to spread faster than laws. The organisations that start generating audit-ready evidence now will be ready for independent assurance whenever and wherever it arrives.

Shane Coetser

Written by

Shane Coetser

With over 30 years of experience delivering real technology outcomes, he combines strategic insight with deep technical expertise across enterprise, cloud and AI. At Trusenta, he helps organisations move beyond AI hype to accountable, sustainable impact.

Connect on LinkedIn

Ready to transform your AI strategy?

Partner with Australia's AI strategy and governance specialists. From adoption roadmaps to ISO 42001 audit readiness.