Deloitte Finance Webcast Frames ISO 42001 and EU AI Act as Audit Evidence Anchors
What happened
Deloitte published AI compliance and governance frameworks for finance leaders, a practitioner-focused webcast directed at finance and risk executives. The session covers how organizations should structure oversight programs, assign governance accountability, and build the evidence trail auditors will expect. Deloitte explicitly cites three primary reference frameworks: ISO/IEC 42001:2023 - Artificial Intelligence Management System, the NIST AI Risk Management Framework (AI RMF 1.0) and Playbook, and the EU AI Act (Regulation (EU) 2024/1689). The webcast follows a period of growing scrutiny on finance-sector AI governance. Relevant publications include those from BIS, interagency model risk management guidance, and the Financial Stability Board. All signal that point-in-time compliance will not satisfy regulators.
Why it matters
- ·Regulators examining financial institutions are increasingly asking for documented governance programs, not just policy statements. Deloitte's framing of ISO/IEC 42001:2023 - Artificial Intelligence Management System as an audit-evidence anchor means finance teams without a certified or equivalent management system now carry heightened examination risk.
- ·The webcast explicitly addresses agentic processes, signaling that governance programs limited to traditional model risk management will be considered incomplete. Finance organizations deploying AI agents need documented control boundaries and human oversight rationales, not just model inventories.
- ·The EU AI Act (Regulation (EU) 2024/1689) obligations cited by Deloitte apply to any financial institution serving EU markets, regardless of where the institution is headquartered. US-based finance teams that have not yet mapped EU requirements to their existing controls face a cross-border compliance gap that Deloitte's framing makes harder to ignore.
Governance controls affected
What to do now
- ☐Ask your AI governance lead whether your current program can produce documented evidence of control design, testing, and review cadence, not just a policy document, if an examiner asked today.
- ☐Confirm whether your AI inventory distinguishes between traditional models and agentic processes, and whether each category has separately documented oversight controls and human approval requirements.
- ☐Map your existing model risk management program against ISO 42001 clause requirements and identify which clauses lack documented procedures or audit evidence.
- ☐Identify every AI system your finance function uses that falls within EU AI Act scope, including vendor-hosted tools, and confirm whether conformity documentation exists for each.
- ☐Schedule a cross-functional review with legal, risk, and internal audit to agree on what constitutes sufficient audit evidence for AI governance, before an external auditor or regulator defines it for you.
What to watch next
Finance regulators in the US and EU are moving toward expecting AI governance programs to meet model risk management evidence standards. This includes documented testing, version control, and board-level escalation. The interagency model risk guidance updated in 2026 will sharpen examiner expectations. Ongoing EU AI Act (Regulation (EU) 2024/1689) enforcement activity, including EU AI Office inspections targeting credit and financial services AI, will do the same. Teams should monitor whether ISO 42001 certification becomes an explicit examiner expectation in banking supervisory letters or examination handbooks over the next 12 months.
Stay ahead of stories like this
Get every US AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
- A vulnerability that bypasses approved-plugin controls, new criminal liability for executives, and a landmark safety-disclosure framework all point to one conclusion: AI systems are outpacing the controls organizations have built around them.23 Sept
Free every Thursday. Unsubscribe anytime.
