TwinEthosRequest access

Control

AI product without the independent third-party audit a law requires of it

Where a law requires an AI product's operator to have it audited, an external, independent and competent auditor examines the operator's compliance on the required cycle (and before a risk-increasing release where the law says so), the operator gives the auditor the documents it needs and keeps them and the signed report for the required period, and it files and publishes the summaries the law requires.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI is deployed without a documented risk-management process or impact assessment · control id cond.ai-system-no-required-independent-audit

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
1more where it is enacted, not yet applying
0standards and frameworks on the same control

enacted, not yet applying in California (US-CA); next date 2029-01-01.

The guard to add

Schedule the required independent audit of the AI product, give the auditor access, keep the signed report and documents, and file and post the required summaries on time.

An audit cycle owned by the operator's governance or legal lead and tracked as calendared tasks with evidence links: the first audit by the statutory date (or before first public release if later), repeat audits on the statutory cycle, and an audit before any release whose risk assessment shows increased risk; an engagement letter recording the auditor's independence and non-contingent fee; auditor access to the documentation it needs, under security protocols for trade secrets and privacy; retention of that documentation and the unredacted signed report for the period the law sets; and, after each report, the summary and attestation filed with the regulator and the high-level public summary posted within the statutory deadlines. This is an organizational record, not a code change; the repository can hold the evidence index for each cycle and a release gate that checks it.

Where it goes: 11 CI/CD pipeline, 12 repository artifacts, 14 user-facing text.

What reviewers look for: for each audit cycle, an engagement letter with independence and fee terms, the signed report with its date, a filing receipt for the regulator summary, the public summary link and its posting date, and a retention entry; and, for releases flagged by the risk assessment as raising risk, an audit completed before the release date.

Organizational control: the evidence is a kept record, its owner and its upkeep, not code.

Example (Audit evidence index (repo record)), before:

# governance/child-safety-audit.yaml
2029: internal review done

After:

# governance/child-safety-audit.yaml
2029:
  auditor: Example Assurance LLP          # external; no financial interest either way
  engagement_letter: evidence/2029/engagement.pdf   # fee not conditioned on results
  signed_report: evidence/2029/report-signed.pdf
  report_received: 2029-03-02
  ag_summary_filed: 2029-04-10           # within 30 business days, with officer attestation
  public_summary_url: https://example.com/safety/child-safety-audit-2029  # posted within 90 days
  retention: records-vault://child-safety-audit/2029 (deployment + 5 years)
next_audit_due: 2031-03-02

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — not yet in force or stayed (1)