← All briefings
Briefing 27 · The Assurance Profession

California just made AI auditing a registered profession.

On September 9, 2026, Governor Newsom signed two bills that regulate the people who check AI rather than the people who build it. SB 813 (Chapter 179) tells a state agency to build a framework for designating “independent verification organizations.” AB 1405 (Chapter 178) goes further: from January 1, 2029, nobody may offer, sell or conduct a “covered AI audit” in California without registering with the state. We read both chaptered texts the morning after signing; some of what circulated while the bills were moving is no longer true of the law.

Who carries the duty. Neither law requires a company that builds or deploys AI to get an audit. Both put their obligations on the auditor. If you buy AI audits, your side of this is simpler but real: from 2029, the person selling you one must be registered, and the report they hand you must contain specific things. If you sell them, this is your new licensing floor.

AB 1405: registration, independence rules and a required report format

AB 1405 adds Government Code sections 11549.80 to 11549.86. A “covered AI audit” is an audit of the internal controls, processes or systems put in place for an AI system or model that are necessary for compliance with state law. That is narrower than “any AI assessment”: a bias test run for your own comfort is not covered; a review done to show you meet a California statute is.

The Government Operations Agency must have an AI Auditor Registry, a fee schedule and a public misconduct-report channel live no later than January 1, 2029. From that same date the prohibition bites: “a person shall not offer, sell, or conduct a covered AI audit unless the person is registered.” Offering alone is enough to trigger it.

Registration is not a rubber stamp. An auditor files the standards it audits against, its accreditations, and a standard operating procedure that states the basis for any claims about the accuracy of its own methods. Its registration number must appear on every piece of advertising that offers audit services.

The independence rules are the part most buyers should read. A registered auditor may not audit where it has a financial, business or employment interest that would reasonably impair its objectivity (a normal fee is fine). It may not audit its own work: any system, process or control it materially designed, built, implemented or operated for you. Its staff may not negotiate a job with you during the audit, and anyone who worked for you on the audited subject in the prior 12 months is off the engagement. Auditor employees who report non-compliance to the state are protected from retaliation.

The report itself now has a statutory minimum: scope and objectives; results with the documentation behind them; for each deficiency, the measures that would reasonably address it; whether you actually followed your own internal safety standards; a limitations section naming anything in scope that was not assessed and any material gaps in evidence or access; and a signed, dated statement that the audit followed the chapter. Working papers are kept ten years. Licensed CPA firms meet the report and independence rules through the AICPA attestation standards they already work under.

SB 813: a designation tier above registration, and no safe harbor

SB 813 adds Government Code sections 8898 to 8898.4. It tells the same agency to develop, by January 1, 2028, application requirements, designation criteria and suspension procedures for “independent verification organizations,” meaning auditors the state recognizes as competent to assess the risks of an AI system and to identify the metrics and methods behind that assessment. The criteria must at least cover risk methodology, technical staffing, conflict-of-interest management (payment at market rates is fine; payment conditioned on the result is not) and structural independence. The agency is told to align with existing audit and assurance standards rather than invent new ones. Designated IVOs report annually to the agency and the Legislature.

Two things the chaptered text does not do, despite what earlier versions and some summaries said. It does not require anyone to hire an IVO or undergo an audit as a condition of deploying AI in California; section 8898.4 says so in terms. And it does not create a liability safe harbor. In a lawsuit alleging that an AI system caused harm, an audit performed under a chapter standard is “relevant to, but not conclusive of” the case. That is evidence, not immunity. Anyone still describing SB 813 as a safe-harbor law is working from a superseded draft.

Read together: AB 1405 registration is the floor for anyone selling state-law compliance audits from 2029. SB 813 designation is an optional tier above it, and no IVO can exist before the criteria do in 2028.

What changes if you buy AI audits

Nothing about your own compliance duties changed on September 9. What changed is the quality bar on the evidence you will rely on. From 2029, an audit report offered to a California regulator, a customer or a court should come from a registered auditor and carry the six required elements. A report without a limitations section, or from a firm that also built the thing it is reviewing, will look thin next to one that meets the statute. The self-review bar is the first California statute to say plainly that the vendor who built your AI controls cannot audit them for state-law compliance; Illinois drew the same line for frontier developers in SB 315. If your assurance plan depends on a build-and-bless arrangement, it now has a date on it.

What this means for Sentinel

We are the regulated party here, and we would rather say so. Sentinel will need to register under AB 1405 before offering a covered AI audit to any California auditee from January 1, 2029, and we are gap-checking our report format against the statute now. We will not describe ourselves as an IVO, or as designated or state-recognized, until the state actually designates anyone, which cannot happen before the 2028 criteria exist. Both instruments were mapped into our Deployment Gate method the day this briefing was written, including a new evidence-acceptance check for third-party audit reports dated on or after January 1, 2029.

What to do now

1. Ask any AI auditor for its standards and its SOP today. Under AB 1405 these become public filings in 2029; a firm that cannot show them now is telling you something. 2. Put the six report elements in your next audit contract, especially the limitations section. You will want them whether or not the statute reaches that engagement. 3. Separate build from check. The self-review bar is now in statute; unwind any arrangement where one vendor does both. 4. Do not accept “IVO” or “state-recognized” claims before 2028. No designation exists yet. 5. Watch the rulemaking. The agency may adopt regulations at any time, and the California nexus for “covered AI audit” is not defined in the text.

An honest limitation

Both chapters are signed but not yet operative; as non-urgency 2026 statutes they take effect January 1, 2027, and the working deadlines are 2028 (SB 813 criteria) and 2029 (AB 1405 registry and prohibition). No registry exists, no fees are set, and the agency has not said how far “covered AI audit” reaches outside California. Read the chaptered texts, not the bill analyses: SB 813 and AB 1405.

This briefing is general information from Sentinel Assurance Group, not legal advice. Regulatory dates and requirements change; we maintain these briefings, but verify against primary sources and counsel before acting. Prepared with AI assistance and reviewed by the firm. Last reviewed September 10, 2026.

See how a Gap Assessment maps your exposure →

Buying an AI audit before 2029?
Know what the report has to contain.

The free AI Risk Exposure call walks through what California will expect of your auditor and your evidence, and where your current arrangements fall short.

Book the call →