AI Governance

Glossary

AI Audit

A systematic examination of an AI system, its data, governance or outcomes against defined criteria.

Last reviewed 2026-08-22

In plain language

Audits may be internal, third-party, regulatory or journalistic. They can inspect models, documentation, socio-technical processes or real-world effects. There is no single global AI-audit standard; quality depends on access, independence, expertise and follow-up. Audit reports can support accountability but can also be confidential or captured by the audited organization. A concrete public-sector example is the U.S. Government Accountability Office's AI Accountability Framework (GAO-21-519SP), which structures audits of federal agency AI use around four areas—governance, data, performance and monitoring—so that GAO auditors and agency inspectors general have a repeatable basis for review, rather than an ad hoc checklist invented for each engagement. That structure illustrates the difference between an audit and the broader concept of AI assurance: the audit is the bounded act of checking a system against stated criteria at a point in time, while assurance is the ongoing, cumulative claim that results from audits plus monitoring plus documentation. An audit without published findings, a named responsible party and a route to remedy functions closer to a compliance exercise than to algorithmic accountability in the fuller sense civil-society advocates use the word—the existence of an audit report does not by itself establish that anyone can act on what it finds.

Why it matters for AI governance

Calls for “AI audits” appear in regulation, procurement and civil-society campaigns. Specifying the audit type and the public’s right to results is as important as commissioning the audit.

Authoritative sources