On September 9, California enacted two laws that together do something no American state had done before. They begin to define, in statute, what an AI auditor is.
Governor Newsom signed SB 813, authored by Senator Jerry McNerney, which creates a framework for “independent verification organizations,” private assessors that check AI systems and models for compliance with state law. He also signed AB 1405, authored by Assemblymember Rebecca Bauer-Kahan, which sets up a state registry of AI auditors and writes standards for their independence, transparency and integrity. Neither law requires a developer to get an audit tomorrow. They set the rules for who is allowed to perform one once other California laws call for it. The registry is not due to exist until January 1, 2029, and the criteria for becoming an independent verifier are due a year before that.
Bauer-Kahan gave the reason in one sentence. “We cannot expect industry to simply grade its own homework.”
That is the oldest charge in our profession. Grading your own homework is the exact suspicion internal audit has spent decades building structures to answer: functional reporting to the audit committee, objectivity requirements, the independence the IIA’s Global Internal Audit Standards have asked of us since they took effect in January 2025.
But the independence California is writing into law is not that kind. It is third-party independence, an organization with no stake in the result, from outside the company entirely. Ours is organizational independence. It is real, and it is not the same thing. In the model these two laws describe, the internal auditor looking at their own organization’s AI is on the auditee side of the line the state just drew, not the verifier side.
Two weeks ago I wrote that internal audit is adopting AI faster than external audit partly because it has no referee. External auditors answer to an inspector who tests whether their reliance on a tool was defensible. We answer to no one outside the function. Here is a referee arriving. Not for our use of AI, and not staffed by us. It is a referee for the AI itself, and California is standing up a new registered profession to fill the role.
California is not doing this alone. Illinois passed its Artificial Intelligence Safety Measures Act in July, and by the reporting on it, that law already requires annual independent third-party audits for major frontier developers. California took the other half of the problem. It is not mandating the audit so much as standardizing who is considered credible enough to perform one. Two states, two mechanisms, one direction: outside verification of AI systems, by someone with nothing to gain from the verdict.
So what does this mean for a function sitting inside an organization, reading the news over coffee?
Here is the part I think matters, and it is not the part that stings. An independent verifier, when one eventually arrives, checks a system against a set of criteria at a point in time. That is what the SB 813 framework is built to produce. What it cannot produce is the thing that makes the check possible: the inventory of where AI is actually running, the evidence that the controls operated, the record of what the system was allowed to do and on whose authority, the name of the human answerable for its output. None of that can be manufactured by an outsider on the day they show up. It is built inside, over months, and it is internal audit’s natural work.
That readiness is the real exposure, and most functions have not measured it. I would treat the gap between “we use AI widely” and “an outsider could verify our AI against criteria tomorrow” as a potential indicator of unreadiness rather than a conclusion, and it is the first thing I would examine.
The reason to examine it now rather than in 2029 is that the verifier will not wait for the registry. California is not only regulating AI, it is buying it. The state has launched a public assistant called AskCA and has started tightening what it asks of AI vendors seeking state contracts. A buyer that large, asking whether a vendor’s AI has been independently checked, is a forcing function that arrives well before any statutory deadline. Your own customers may ask the same question before the state does.
This connects to something I keep coming back to: AI is splitting our work into the formal assurance that must stay independent and the advisory the business can now reach in minutes. California has just taken the first half, the independent-assurance half, and started hardening it into a licensed third-party role. That is the “must” side of the profession being written into law by someone other than us.
So the work between now and 2029 is not to wait for the registry, and not to argue about which side of the independence line we belong on. It is to make the organization’s AI auditable by someone who owes us nothing: an inventory that classifies what each system is allowed to do rather than only counting the systems, evidence retained rather than regenerated, controls written down against a criteria set that exists before the verifier does, and a named owner for every material AI output. Do that, and the arrival of an independent verifier is an ordinary Tuesday. Skip it, and it is the day you find out what you should have been documenting all along.
The independent AI auditor is now a profession the state is prepared to register. Internal audit’s job is to make sure that when one of them finally opens your organization’s AI, there is something there to audit.