AI Governance Institute
← News
Research2026-10-08

Deloitte Finance Webcast Frames ISO 42001 and EU AI Act as Audit Evidence Anchors

What happened

Deloitte published AI compliance and governance frameworks for finance leaders, a practitioner-focused webcast directed at finance and risk executives. The session covers how organizations should structure oversight programs, assign governance accountability, and build the evidence trail auditors will expect. Deloitte explicitly cites three primary reference frameworks: ISO/IEC 42001:2023 - Artificial Intelligence Management System, the NIST AI Risk Management Framework (AI RMF 1.0) and Playbook, and the EU AI Act (Regulation (EU) 2024/1689). The webcast follows a period of growing scrutiny on finance-sector AI governance. Relevant publications include those from BIS, interagency model risk management guidance, and the Financial Stability Board. All signal that point-in-time compliance will not satisfy regulators.

Why it matters

  • ·Regulators examining financial institutions are increasingly asking for documented governance programs, not just policy statements. Deloitte's framing of ISO/IEC 42001:2023 - Artificial Intelligence Management System as an audit-evidence anchor means finance teams without a certified or equivalent management system now carry heightened examination risk.
  • ·The webcast explicitly addresses agentic processes, signaling that governance programs limited to traditional model risk management will be considered incomplete. Finance organizations deploying AI agents need documented control boundaries and human oversight rationales, not just model inventories.
  • ·The EU AI Act (Regulation (EU) 2024/1689) obligations cited by Deloitte apply to any financial institution serving EU markets, regardless of where the institution is headquartered. US-based finance teams that have not yet mapped EU requirements to their existing controls face a cross-border compliance gap that Deloitte's framing makes harder to ignore.

Governance controls affected

What to do now

  • ☐Ask your AI governance lead whether your current program can produce documented evidence of control design, testing, and review cadence, not just a policy document, if an examiner asked today.
  • ☐Confirm whether your AI inventory distinguishes between traditional models and agentic processes, and whether each category has separately documented oversight controls and human approval requirements.
  • ☐Map your existing model risk management program against ISO 42001 clause requirements and identify which clauses lack documented procedures or audit evidence.
  • ☐Identify every AI system your finance function uses that falls within EU AI Act scope, including vendor-hosted tools, and confirm whether conformity documentation exists for each.
  • ☐Schedule a cross-functional review with legal, risk, and internal audit to agree on what constitutes sufficient audit evidence for AI governance, before an external auditor or regulator defines it for you.

What to watch next

Finance regulators in the US and EU are moving toward expecting AI governance programs to meet model risk management evidence standards. This includes documented testing, version control, and board-level escalation. The interagency model risk guidance updated in 2026 will sharpen examiner expectations. Ongoing EU AI Act (Regulation (EU) 2024/1689) enforcement activity, including EU AI Office inspections targeting credit and financial services AI, will do the same. Teams should monitor whether ISO 42001 certification becomes an explicit examiner expectation in banking supervisory letters or examination handbooks over the next 12 months.

Related Coverage

Research2026-10-03

CSA's ISO 42001 Certification Guide Sets the Audit Evidence Bar

The Cloud Security Alliance published a practical guide to achieving certification under ISO/IEC 42001:2023, the international standard for AI management systems. The guide specifies the concrete documentation an auditor will expect. Required artifacts include an AI policy, a scope statement, a risk and impact assessment method, a Statement of Applicability, role definitions, an AI inventory, provenance records, and incident logs. Organizations pursuing certification or requiring it from vendors now have a clearer benchmark against which their current programs will be measured.

Enforcement2026-09-28

EU AI Office Inspections Target Hiring, Credit, and Healthcare AI

The European AI Office and national market surveillance authorities launched coordinated compliance inspections of high-risk AI systems in September 2026. The inspections focus on resume-screening tools, credit-assessment systems, and healthcare triage applications. Organizations lacking documentation, audit trails, and rapid remediation plans are the primary targets.

Corporate Policy2026-10-05

Chakra's 500,000 Interviews Make AI Hiring Compliance Obligations Concrete

HackerRank has made Chakra, an AI agent that conducts and scores technical job interviews, generally available after completing more than 500,000 beta interviews. The system evaluates candidates on process and judgment, placing it directly within AI hiring regulations that require independent bias audits and candidate disclosure. HackerRank's CEO publicly acknowledged that AI hiring tools can inherit bias from underlying data, raising the due diligence bar for deploying organizations.