A national financial regulator mandated that all AI systems in lending, fraud detection, and credit scoring must be audited annually against ISO/IEC 42001. Three years later, a review discovered that every audit was conducted by certification bodies whose methodologies derived from templates provided by the vendors being evaluated. The audit requirement was structurally incapable of detecting the conflicts. The sovereignty failure was built into the audit design, not discovered by it.
Keep Reading
Exclusive insights & inspiration
Account created. Refreshing…