The Problem: AI Is Scaling Faster Than the Proof That It Is Under Control
The question landing on more and more leadership agendas is no longer "are we using AI?" but "can we show that we control it?" Board members, auditors, insurers and customers can all ask it, and an answer needs evidence, not intentions.
Grant Thornton's 2026 AI Impact Survey (950 business leaders across 10 industries, February to March 2026) found that 78% of executives lack confidence they could pass an independent AI governance audit within 90 days. The firm calls this the "AI proof gap" and sums it up as: "Most organizations are scaling AI they cannot explain, measure or defend." The same survey reports that 75% lack a fully developed AI strategy and that 73% cite competitor pressure, rather than internal ROI analysis, as the driver of AI adoption.
The gap shows up between board and security leadership too. In an Okta-sponsored survey of 306 CISOs (published July 2026), only 12% of US CISOs said they feel aligned with their board on AI risk acceptance.
A caution on these numbers: Grant Thornton and Okta both sell services in this area, and a confidence survey measures how leaders feel, not how many would actually fail an audit. We read them as a signal, not as a verdict.
The Solution: Treat AI Governance as Evidence You Can Hand Over
Governance that lives in a policy document is hard to defend. Governance that produces records is easy to defend. In the same Grant Thornton data, 74% of leaders with fully integrated AI were very confident in their audit readiness, against 7% of those still piloting. Those with fully integrated AI were also far more likely to report AI-driven revenue growth (58% against 15%). The survey shows these things moving together; it does not prove that governance causes the returns, and organizations that scale may simply have more resources. But it does suggest that the organizations getting value from AI are also the ones who can explain it.
In practice, "provable" governance rests on five things: an inventory of AI systems and their owners, a risk classification for each, controls mapped to a recognized framework, records showing those controls actually operate (approvals, logs, testing, reviews), and a named line of accountability up to the board.
The external clock matters too. Under the EU AI Act, the Article 50 transparency obligations applied from 2 August 2026, while obligations for stand-alone high-risk systems were postponed to 2 December 2027 under the omnibus agreement. In Switzerland, the Federal Council decided in February 2025 to ratify the Council of Europe AI Convention and to amend Swiss law where needed, alongside sector-specific regulation. Dates and scope can shift, so confirm the current position with your legal counsel.
One claim we could not verify: a compliance firm has argued that customers now require ISO/IEC 42001 certification from AI suppliers, but its article named no buyers and quoted no tender wording. We treat that as unproven. Our own view, which is an inference and not a finding, is that a recognized management-system standard is still useful because it gives auditors and boards a structure they already know how to read.
The Approach: A 90-Day Audit-Readiness Test
1. Inventory and owners. List every AI system, feature and agent in use, including AI embedded in software you already license. Name a business owner for each. Most organizations discover that the list is longer than expected.
2. Classify by risk and data. Sort each use by the data it touches and the decisions it influences. This is what lets you apply heavy controls where they matter and light ones elsewhere.
3. Map controls and find gaps. Compare what you do today against ISO/IEC 42001, the NIST AI Risk Management Framework and, where you have EU exposure, the EU AI Act. The output is a ranked gap list, not a long report.
4. Build the evidence pack and rehearse. Collect the records an auditor would ask for, then have someone independent of the AI team ask the questions. If the pack cannot be assembled within days, the gap is in your evidence, not your intent.
The practical test of readiness: if an independent reviewer asked tomorrow how you control AI, could you hand over the evidence within a week?
How ANG Associates Can Help
ANG Associates runs an AI audit-readiness review for mid-size and large companies. We build the AI inventory with your teams, classify each use by risk and data, assess your current controls against ISO/IEC 42001, the NIST AI RMF and, where relevant, the EU AI Act, and assemble the evidence pack with the rehearsal questions an auditor, insurer or board member is likely to ask. You receive a ranked remediation plan and a board-level summary that documents oversight.
Our Life Sciences background means we can align AI governance evidence with the validation and quality-system practices that regulated companies already run, instead of creating a parallel bureaucracy. To be clear about scope: ANG is not a certification body and cannot certify you, and we are not a law firm, so legal interpretation stays with your counsel. What we do is get you ready, and show you where you stand before someone else asks.
This is one of six services in our ANG AI Trust Compass offering.
Sources
- Grant Thornton, "2026 AI Impact Survey" (950 business leaders, 10 industries, February to March 2026; the firm sells advisory services in this area)
- Cybersecurity Insiders, report on the Okta-sponsored CISO survey (306 CISOs, published 31 July 2026; sponsor is an identity-governance vendor)
- Al Jazeera, report on what came into force under the EU AI Act (6 August 2026)
- Gibson Dunn, summary of the EU AI Act omnibus agreement (describes the provisional agreement, including postponed high-risk deadlines)
- Swiss Federal Council press release on AI regulation (12 February 2025)
- WilmerHale, client alert on board oversight and AI (January 2026) (written around Delaware law; Swiss board duties may differ)
- Bright Defense, article on ISO 42001 as a vendor requirement (the claim we could not verify; vendor content)