An annual audit can accurately describe an AI system and, months later, leave out material changes to models, data or providers. This alert, with an evidence cut-off of May 2026, examines that gap from the perspective of audit practice. The formal cycle retains its value; the problem arises when the organisation uses the calendar as its only control frequency for an operation that changes before the next visit.


The operational data · verify it yourself

The update cadence varies by provider and by quarter; this alert does not replace it with an unrelated average. It proposes a check that any board can perform: count the material changes reported by its providers during the last quarter and compare them with the internal reviews documented over the same period. The ratio does not demonstrate conformity, but makes visible the difference between the technical pace and the actual capacity for review. That difference defines where additional control is needed.

The three documented pathologies

01

The valid certificate covering obsolete operations

The certificate issued in January retains its applicable validity and scope. If the base model, data or a critical provider have changed by October without an equivalent review, the document is no longer sufficient to describe current operations.

02

The audit-as-event that freezes operations

Some organisations restrict changes before the visit and resume their usual pace afterwards. The audited sample may be consistent and still not represent the full operational cycle. This observation does not imply deception: it points to an audit design that rewards temporary stability even though the risk lies in change.

03

The technical team operating without real auditing

Between audits, the technical team implements changes. Some are recorded; others are not. When the next audit arrives, only what can be recorded is documented. What was not recorded remains outside the audit scope — until it causes the incident that makes it visible.

The calendar sets the formal cycle. Material change determines when another look is needed.

The metric · audit debt

Criterion 09 proposes a working metric. Ask the person responsible for the system how many material changes have occurred since the last external audit and how many were recorded with the actor, date, criterion, scope and validity. The difference is the continuous auditing debt accumulated. It does not, on its own, measure the effectiveness of controls; it does identify changes that do not yet have a traceable review.

What continuous auditing adds

Continuous auditing complements the formal cycle. It can combine auditable telemetry, reviews triggered by relevant changes and verification of the version actually in operation. Each mechanism leaves different evidence.

ComponentWhat it addsEvidence it generates
Auditable telemetryObservation of the system in operation, in addition to its documentationStructured records — access, versions, configurations, automated decisions — readable by an independent auditor, with protected integrity
Variable-frequency reviewsIndependent verification triggered by a relevant change, in addition to the fixed cycleEvent-driven review record, with the trigger, reviewed scope and signatory documented
Trigger-based verificationEvaluation of the system version when the base model, training dataset, system prompt or a provider changesRecord of the technical event with the actor, date, criterion, scope and validity

Professional framework and limitation

ISO/IEC 42001 requires monitoring, measurement, analysis and evaluation of the management system; it does not prescribe an approach called «continuous auditing». The IIA's Global Internal Audit Standards are mandatory for professional internal audit practice, while its guidance on continuous auditing and monitoring, effective since September 2025, presents this approach as recommended practice. Standards and guidance serve different functions.

This report does not estimate adoption of the method or turn guidance into a normative requirement. It proposes a risk-based decision: document which changes require a review, who can trigger the review and what evidence demonstrates that the version in production remains within the governed scope.

Audit debt identifies material changes that do not yet have a traceable review.