AI Governance Institute
← News
Research2026-09-12

ISACA: Point-in-Time AI Compliance Cannot Survive Legal Scrutiny

What happened

ISACA published Legally Defensible AI: Governance That Can Stand Up to Scrutiny on September 4, 2026, setting out a practitioner framework for AI governance programs that can withstand regulatory inquiry, litigation, and audit. The guidance distinguishes sharply between compliance as a periodic exercise and governance as a continuous evidentiary function, arguing that defensibility depends on documented proof at every stage of the pre- and post-deployment lifecycle. Key requirements identified include a live, maintained AI system inventory, named accountability for each system, a documented legal basis for deployment, and a traceable risk assessment record that is updated as systems and operating contexts change. The publication arrives as EU AI Act enforcement has formally begun and as regulators and courts in multiple jurisdictions are demonstrating that documentation gaps, not just technical failures, attract enforcement consequences. It reinforces concerns raised by Collibra and others that static AI compliance documentation is no longer sufficient in a landscape where continuous oversight expectations are hardening across frameworks including ISO/IEC 42001:2023.

Why it matters

  • ·Regulators and courts are increasingly treating documentation gaps as independent governance failures. The EU AI Act enforcement apparatus and active litigation trends mean that an AI governance program that cannot produce timestamped, ownership-attributed evidence across the full model lifecycle is exposed, regardless of the underlying model's technical performance.
  • ·Named accountability is now a baseline defensibility requirement, not an organizational preference. If compliance teams cannot identify who is responsible for each AI system and demonstrate that the responsible party actively maintained oversight throughout the deployment period, the organization has no credible answer to a regulator or plaintiff who asks who was in charge when something went wrong.
  • ·A static AI inventory is functionally a liability. ISACA's guidance implies that any organization running an annual or quarterly inventory refresh, rather than a continuously maintained register, cannot produce the evidence required to show that its governance program was operational at the moment of an incident or audit inspection.

Governance controls affected

What to do now

  • Audit your current AI inventory process to determine whether it is continuously maintained or periodically refreshed, and assign a named owner accountable for real-time accuracy.
  • Review each AI system record to confirm it includes a documented legal basis for deployment and a risk assessment that has been updated since the system last changed in scope, data inputs, or operating context.
  • Map ownership assignments across your AI system portfolio and confirm that named owners have documented their oversight activities, not just their title designations.
  • Test whether your existing audit trail infrastructure can produce a chronological evidence record for a specific system spanning pre-deployment approval through current operation, and identify gaps before a regulator or court requests it.
  • Align your AI lifecycle governance documentation standards with ISO/IEC 42001:2023 clause requirements and cross-check against any EU AI Act conformity assessment obligations applicable to your system portfolio.

What to watch next

Compliance teams should monitor EU AI Office enforcement actions closely over the coming months, as early cases are likely to test exactly the documentation and accountability standards ISACA describes. Guidance from national market surveillance authorities on what constitutes adequate lifecycle evidence will shape how the bar is set in practice. Teams operating under financial services model risk frameworks should also track any supervisory updates that extend SR 26-2 logic into AI-specific documentation requirements, since the evidentiary standard ISACA outlines maps closely onto the model validation and governance expectations that banking regulators are already articulating. The NIST AI documentation guidance draft is also worth monitoring for alignment, as it may become a reference standard in U.S. enforcement and procurement contexts.

Stay ahead of stories like this

Get every UK AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-01

SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight

The OCC and Federal Reserve's revised model risk management guidance, SR 26-2, resets supervisory expectations for U.S. banks by shifting to a materiality-based approach that covers both traditional statistical models and AI systems, replacing the SR 11-7 framework that had governed bank model governance since 2011. Practitioner analysis from CRA identifies four areas banks must redesign: inventory scope, model tiering, validation independence, and governance alignment up to the board. A companion implementation guide from Lumenova AI adds concrete steps, including inventory rationalization and a distinct governance lane for agentic and generative AI, while a proposed academic framework maps a six-layer control architecture for bringing GenAI systems into SR 26-2 scope. Banks that still run AI governance and model risk management as separate programs face the most immediate pressure to harmonize them.

Research2026-09-03

ISO 42001 Implementation Gap Exposed: Clause-by-Clause Guide Sets Audit Baseline

enz.ai has published a detailed implementation guide for ISO/IEC 42001:2023, covering each clause of the standard from scoping and leadership through internal audit and Annex A control mapping. The guide gives compliance teams a structured path for standing up a conformant AI management system before pursuing formal certification. Organizations facing regulatory expectations of structured AI governance can use the guidance to assess and close readiness gaps.

Research2026-09-09

Credo AI Survey of 371 Leaders Maps Where Mature AI Governance Programs Pull Ahead

Credo AI released The State of AI Governance Report 2026, drawing on survey data from 371 senior leaders to benchmark where enterprise AI governance programs are advancing and where common gaps persist. The report identifies AI inventories, accountability structures, and review workflows as the controls that most differentiate mature programs from lagging ones. Compliance teams can use the findings to compare their operating models against peer practice and prioritize remediation.