TwinEthosRequest access

Control

Large frontier developer without an independent third-party compliance audit

A large frontier developer has an independent, conflict-free third party audit its compliance with its frontier-AI safety obligations every year, gives the auditor the access it needs, and publishes and reports the audit results.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI is deployed without a documented risk-management process or impact assessment · control id cond.frontier-developer-no-independent-compliance-audit

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
1more where it is enacted, not yet applying
0standards and frameworks on the same control

enacted, not yet applying in Illinois (US-IL); next date 2028-01-01.

The guard to add

Engage an independent auditor on non-contingent fees each year to audit frontier-safety obligations, then publish, transmit, and retain the signed report.

A yearly audit cycle owned by the developer's governance or legal lead and tracked as a calendared task with evidence links. It covers: an engagement letter recording the auditor's independence (no financial interest either way) and a fee that does not depend on findings; auditor access to the materials it needs, including unredacted versions, under security protocols; a signed report on obligations met, material deviations with recommendations, internal controls and accountable senior staff, audit personnel, conflicts, and methodology; publication of a summary and redacted report; transmittal to the regulators; and retention of the unredacted copy. This is an organizational record, not a code change; the repository can hold the evidence index for each year.

Where it goes: 12 repository artifacts, 14 user-facing text.

What reviewers look for: for each audit year, an engagement letter with independence and fee terms, the signed report, a public summary and redacted report link, transmittal receipts, and a retention entry for the unredacted report.

Organizational control: the evidence is a kept record, its owner and its upkeep, not code.

Example (Audit evidence index (repo record)), before:

# governance/frontier-audit.yaml
2028: internal self-assessment done

After:

# governance/frontier-audit.yaml
2028:
  auditor: Example Assurance LLP
  engagement_letter: evidence/2028/engagement.pdf   # independence + non-contingent fee clauses
  signed_report: evidence/2028/report-signed.pdf
  report_date: 2028-11-20
  public_summary_url: https://example.ai/safety/audit-2028
  redacted_report_url: https://example.ai/safety/audit-2028-redacted.pdf
  transmittal_receipts: [evidence/2028/receipt-agency.pdf, evidence/2028/receipt-ag.pdf]
  unredacted_retention: records-vault://frontier-audit/2028 (retain_until set by legal)

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — not yet in force or stayed (1)