REVIEW 2 major objections 5 minor 111 references
Third-party compliance reviews for frontier AI safety frameworks
T0 review · 2 major / 5 minor · reviewed 2026-08-16 · deepseek-v4-flash
Pith's one-line read The paper argues that an independent external reviewer checking whether a frontier AI company follows its own safety framework is a workable and valuable mechanism, with known mitigations for the main risks.
desk verdict A genuinely useful design space for third-party compliance reviews of frontier AI safety frameworks, but the transfer argument from other industries is thinner than the structure and deserves scrutiny. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is the third-party compliance review itself—an independent external assessment of whether a company adheres to its own safety framework, as distinct from an adequacy review of whether the framework is strong enough. The argument is carried by transferring audit and assurance practices from other industries, including audit trails, segregation of reviewer duties, role-based access management, internal review liaisons, structured kick-offs, and reviewer-authored reports. These practices are the mechanism that is supposed to let a frontier AI company capture the compliance and assurance benefits without being undone by security risk or cost. The paper's design framework, with its four information-source tiers and three assessment styles, is what turns those practices into a concrete review procedure.
What would settle it
Run a two-year controlled pilot in which several frontier AI companies undergo third-party compliance reviews while matched companies do not; if reviewed companies show no fewer safety-framework violations than controls and stakeholders report no greater confidence in them, the core claim fails.
Extended reading notes
Core claim
The central claim is that compliance reviews are an effective way to close the information gap between a frontier AI company and its stakeholders, and that the obstacles to them are manageable. The paper supports this by cataloguing the benefits—greater adherence because employees anticipate scrutiny, credible assurance for governments and other companies, and assurance for boards and employees—and by pairing each challenge with a mitigation used in established auditing, such as audit trails, segregation of duties, role-based access, reviewer vetting, internal pre-reviews, and conflict-of-interest controls. It then maps the design space of a review into six questions: who reviews, what information reviewers see, how compliance is graded, what is disclosed, how findings affect development and deployment, and when reviews happen. For each question it compares options and proposes three levels of ambition, so the paper's operational claim is that a well-designed review is feasible today.
Load-bearing premise
The mitigations used in financial, cybersecurity, nuclear, and oil and gas auditing transfer to frontier AI settings without unacceptable degradation, so information-security risks, cost burdens, false results, measurability gaps, and self-censorship do not neutralise the value of reviews.
Editorial extensions
If this is right
- A frontier AI company can start with a minimalist review today: a Big Four firm, structural information sources, pass/fail grading of framework commitments, public acknowledgment only, no delayed actions, and ad-hoc timing.
- Expanding reviewer access from structural to procedural and operational information should produce more confident findings and more useful recommendations, at the price of higher security exposure.
- Tying deployment decisions to compliance findings in key areas creates stronger incentives to fix gaps, but risks shallow fixes and lower internal buy-in.
- Annual review cycles give stakeholders a firmer basis for trusting long-term compliance than ad-hoc schedules do.
- Widespread adoption of compliance reviews would let governments move from voluntary to mandatory audit regimes with a tested template already in place.
Reading between the lines
- The review machinery described here could also be applied to other voluntary AI commitments, such as disclosure or interpretability pledges, because the information tiers and grading approaches do not depend on the specific content of a safety framework.
- The paper's logic predicts that companies with weak internal safety culture will show the largest compliance gains from third-party reviews, which is testable by comparing pre- and post-review adherence across firms with different internal audit maturity.
- A thin market for qualified reviewers is the most likely place the central claim breaks: if only a few firms can do these reviews, retention pressure may swamp reputation incentives and elevate the risk of false positives the paper only mentions.
- Standardization of grading rubrics across companies is the logical precondition for regulators or insurance markets to rely on review results, even though the paper leaves that to future work.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper argues that third-party compliance reviews, in which an independent external party assesses whether a frontier AI company adheres to its own safety framework, can increase compliance and provide assurance to internal and external stakeholders. It identifies four main challenges (security risks, cost burden, false results, measurability, and self-censorship) and argues that these can be mitigated through practices borrowed from financial, cybersecurity, nuclear, and other audit domains. The paper then systematically answers six practical questions about review design (reviewer type, information sources, assessment method, external disclosure, internal response to noncompliance, and timing) by evaluating plausible options and their trade-offs. Finally, it proposes minimalist, more ambitious, and comprehensive combinations of these options, and discusses how some approaches are more compatible with each other. The paper is situated in the current policy landscape, referencing existing commitments by Anthropic and G42 and the EU General-Purpose AI Code of Practice.
Significance. The paper makes a useful contribution by filling a practical gap: while several scholars and companies have endorsed third-party compliance reviews, there was no systematic guidance on how to design and conduct them in the frontier AI context. The structured option space and explicit trade-off analysis are valuable for companies, auditors, and policymakers who are currently developing such reviews. The comparative assessment of reviewer types and the discussion of information-source granularity are particularly concrete and well organized. The paper is honest about its limitations, acknowledges the relevant literature, and stops short of overclaiming empirical proof. Its central claim is plausible but rests on analogical evidence from other industries, so the significance depends on the strength of that transferability argument.
major comments (2)
- [Section 2.2, closing paragraph] The mitigation strategies proposed for the conflict-of-interest problem (choosing a competent reviewer, avoiding reviewers who provide other services) do not address the structural selection problem inherent in voluntary, company-commissioned reviews. In a purely voluntary market, the frontier AI company selects the reviewer, defines the scope, controls the budget, can specify which findings to act on, and can credibly threaten to terminate the relationship. Without institutional scaffolding such as mandatory reviewer assignment or rotation, public reporting standards, oversight by a body analogous to the PCAOB, or legal liability for inaccurate findings, reviewers face economic incentives for leniency that the paper's process-level mitigations are unlikely to neutralize. This matters because the central claim that reviews 'provide assurance to external stakeholders' depends on the reviewer being genuinely independent and accurate; if review quality is endogenous to company selection, the assurance benefit weakens and the paper's own acknowledged 'false sense of security' becomes a systemic outcome rather than an edge case. The paper should either incorporate structural independence mechanisms into its recommended approaches or substantially qualify the assurance claim.
- [Section 2 and Section 4] The central claim of the paper is not empirically established by direct measurement in frontier AI settings, but the paper's own framing is appropriately exploratory. The concern is that the analogical evidence is used to support a stronger conclusion than the institutional differences warrant.
minor comments (5)
- [Executive summary] The table summarizing options is duplicated in the executive summary and in Section 4; the two copies should be merged or cross-referenced to avoid redundancy.
- [Section 2.2] The sentence 'the company can also be selective about what information is shared with the reviewer' is grammatically awkward; consider rephrasing to 'the company can also be selective about which information it shares with the reviewer.'
- [Section 4] The 'comprehensive' approach for review timing is identical to the 'more ambitious' approach (every 12 months), which may be intentional but could confuse readers; the text should explicitly state whether the comprehensive approach differs in any way from the more ambitious one.
- [References] Several references contain line breaks or partial URLs (e.g., Anthropic 2025, G42 2025, DSIT 2024, OpenAI 2023) that will need cleanup in the final version.
- [Section 3.5] The paper notes that the company 'could decide where they are not compliant by selecting findings from the results of the review that they agree with,' but it does not discuss this limitation in depth; a brief elaboration of how the company's ability to cherry-pick findings interacts with the assurance benefit would strengthen the analysis.
Circularity Check
No significant circularity: the paper's policy argument draws on external audit literature, and its self-citations are contextual rather than load-bearing.
full rationale
This is a policy analysis and practical guidance paper, not a derivational or predictive model. The central claims—that third-party compliance reviews can increase compliance and provide assurance, and that their challenges can be mitigated—are supported by external empirical literature on auditing and employee behavior (e.g., Neidermeyer & Neidermeyer, 2005; Cardinaels & Jia, 2012; Ewelt-Knauer et al., 2021; Tynan, 2005), not by fitting parameters, equations, or the paper's own prior results. References to work by the same research community (Alaga et al., 2024; Schuett, 2024; Mökander et al., 2023; Williams et al., 2025; Brundage et al., 2020) appear as contextual citations for definitions, existing recommendations, or supporting points; each cited work contains independent content and none is invoked to define away a research question or to force the paper's conclusions. The operationalization of a safety framework into a control or process framework is presented as one of several assessment options, with trade-offs discussed, and it is not a case where the outcome being 'predicted' is built into the input by construction. The skeptical concern that voluntary company-selected reviewers may be captured is a substantive validity objection about institutional design, not a circularity objection. Therefore no circular steps were identified.
Assumptions & free parameters
assumptions (4)
- domain assumption Safety frameworks, if followed, keep frontier AI risks at an acceptable level.
- domain assumption Anticipating external audits increases employee compliance and accountability.
- domain assumption Information asymmetry between AI companies and stakeholders is a problem that external assurance can reduce.
- domain assumption Audit and assurance practices from finance, cybersecurity, nuclear, and oil/gas industries can be adapted to frontier AI without losing their effectiveness.
Cite this review
Pith. "Pith review of Third-party compliance reviews for frontier AI safety frameworks." pith.science (2026). https://pith.science/paper/MMHTI5II
@misc{pith2026250501643,
author = {Pith},
title = {Pith review of: Third-party compliance reviews for frontier AI safety frameworks},
year = {2026},
howpublished = {\url{https://pith.science/paper/MMHTI5II}},
note = {Machine review of arXiv:2505.01643}
}
read the original abstract
Safety frameworks have emerged as a best practice for managing risks from frontier artificial intelligence (AI) systems. However, it may be difficult for stakeholders to know if companies are adhering to their frameworks. This paper explores a potential solution: third-party compliance reviews. During a third-party compliance review, an independent external party assesses whether a frontier AI company is complying with its safety framework. First, we discuss the main benefits and challenges of such reviews. On the one hand, they can increase compliance with safety frameworks and provide assurance to internal and external stakeholders. On the other hand, they can create information security risks, impose additional cost burdens, and cause reputational damage, but these challenges can be partially mitigated by drawing on best practices from other industries. Next, we answer practical questions about third-party compliance reviews, namely: (1) Who could conduct the review? (2) What information sources could the reviewer consider? (3) How could compliance with the safety framework be assessed? (4) What information about the review could be disclosed externally? (5) How could the findings guide development and deployment actions? (6) When could the reviews be conducted? For each question, we evaluate a set of plausible options. Finally, we suggest "minimalist", "more ambitious", and "comprehensive" approaches for each question that a frontier AI company could adopt.
Figures
Reference graph
Works this paper leans on
-
[1]
Abbott2012- APACrefauthors Abbott, L J. , Parker, S. \ Peters, G F. APACrefauthors \ 2012 . Internal Audit Assistance and External Audit Timeliness Internal audit assistance and external audit timeliness . Auditing: A Journal of Practice & Theory 31 4 3–20 . https://doi.org/10.2308/ajpt-10296
-
[2]
aftab2019- APACrefauthors Aftab, M U. , Qin, Z. , Hundera, N W. , Zakria, O A. , Son, N T. \ Dinh, T V. APACrefauthors \ 2019 . Permission-Based Separation of Duty in Dynamic Role-Based Access Control Model Permission-based separation of duty in dynamic role-based access control model . Symmetry 11 5 669 . https://doi.org/10.3390/sym11050669
-
[3]
AICPA2017 APACrefauthors AICPA . APACrefauthors \ 2017 . Guide: Reporting on an Entity's Cybersecurity Risk Management Program and Controls Guide: Reporting on an entity's cybersecurity risk management program and controls . Wiley . https://doi.org/10.1002/9781119449966
-
[4]
alaga2024 APACrefauthors Alaga, J. , Schuett, J. \ Anderljung, M. APACrefauthors \ 2024 . A Grading Rubric for AI Safety Frameworks A grading rubric for AI safety frameworks . arXiv preprint arXiv:2409.08751
arXiv 2024
-
[5]
Anderljung2023 APACrefauthors Anderljung, M. , Barnhart, J. , Korinek, A. , Leung, J. , O'Keefe, C. , Whittlestone, J. Wolf, K. APACrefauthors \ 2023 . Frontier AI regulation: Managing emerging risks to public safety Frontier AI regulation: Managing emerging risks to public safety . arXiv preprint arXiv:2307.03718
arXiv 2023
-
[6]
APACrefauthors \
AnthropicTrustCenter APACrefauthors Anthropic. APACrefauthors \ . Trust Center. Trust center. https://trust.anthropic.com
-
[7]
APACrefauthors \ 2023
anthropic2023-longterm APACrefauthors Anthropic . APACrefauthors \ 2023 . The Long-Term Benefit Trust . The Long-Term Benefit Trust . https://www.anthropic.com/news/the-long-term-benefit-trust
2023
-
[8]
APACrefauthors \ 2025
anthropic2025 APACrefauthors Anthropic . APACrefauthors \ 2025 . Responsible Scaling Policy . Responsible Scaling Policy . https://www-cdn.anthropic.com/17310f6d70ae5627f55313ed067afc1a762a4068.pdf
2025
Show all 111 references
-
[9]
, Ur Rehman, S
Ashfaq2021- APACrefauthors Ashfaq, K. , Ur Rehman, S. , Ul Haq, M. \ Usman, M. APACrefauthors \ 2021 . Factors influencing stakeholder’s judgment on internal audit function’s effectiveness and reliance Factors influencing stakeholder’s judgment on internal audit function’s eff...
2021 doi
-
[10]
, Belfield, H
Avin2021- APACrefauthors Avin, S. , Belfield, H. , Brundage, M. , Krueger, G. , Wang, J. , Weller, A. Zilberman, N. APACrefauthors \ 2021 . Filling gaps in trustworthy development of AI Filling gaps in trustworthy development of AI . Science 374 1327-1329 . https://doi.org/10....
2021 doi
-
[11]
, Kim, J
Badertscher2023- APACrefauthors Badertscher, B A. , Kim, J. , Kinney Jr, W R. \ Owens, E. APACrefauthors \ 2023 . Assurance level choice, CPA fees, and financial reporting benefits: Inferences from U.S. private firms Assurance level choice, CPA fees, and financial reporting be...
2023
-
[12]
, Czermak, S
Balafoutas2020- APACrefauthors Balafoutas, L. , Czermak, S. , Eulerich, M. \ Fornwagner, H. APACrefauthors \ 2020 . Incentives for dishonesty: An experimental study with internal auditors Incentives for dishonesty: An experimental study with internal auditors . Economic Inquir...
2020 doi
-
[13]
APACrefauthors \ 2010
Barton2010- APACrefauthors Barton, J. APACrefauthors \ 2010 . Who Cares about Auditor Reputation? Who cares about auditor reputation? Contemporary Accounting Research 22 3 549-586 . https://doi.org/10.1506/C27U-23K8-E1VL-20R0
2010 doi
-
[14]
, Miller, S
Bate1994- APACrefauthors Bate, R. , Miller, S. , Armitage, J. , Cusick, K. , Jones, R. , Kuhn, D. Reichner, A. APACrefauthors \ 1994 . A Systems Engineering Capability Maturity Model, Version 1.0. A systems engineering capability maturity model, version 1.0. https://insights.s...
1994
-
[15]
APACrefauthors \ 2021
Benaroch2021- APACrefauthors Benaroch, M. APACrefauthors \ 2021 . Third-party induced cyber incidents: Much ado about nothing? Third-party induced cyber incidents: Much ado about nothing? Journal of Cybersecurity 7 1 . https://doi.org/10.1093/cybsec/tyab020
2021 doi
-
[16]
APACrefauthors \ 2021
Berkowitz2021 APACrefauthors Berkowitz, P. APACrefauthors \ 2021 . Internal Disclosures from Compliance Audits: What Could Go Wrong? Internal disclosures from compliance audits: What could go wrong? https://www.littler.com/news-analysis/asap/internal-disclosures-compliance-aud...
2021
-
[17]
, Saad, M
Bley2018- APACrefauthors Bley, J. , Saad, M. \ Samet, A. APACrefauthors \ 2018 . Auditor choice and bank risk taking Auditor choice and bank risk taking . International Review of Financial Analysis 61 37-52 . https://doi.org/10.1016/j.irfa.2018.11.003
2018 doi
-
[18]
, Avin, S
Brundage2020- APACrefauthors Brundage, M. , Avin, S. , Wang, J. , Belfield, H. , Krueger, G. , Hadfield, G. Anderljung, M. APACrefauthors \ 2020 . Toward Trustworthy AI Development: Mechanisms for Supporting Verifiable Claims Toward trustworthy AI development: Mechanisms for s...
2020 arXiv
-
[19]
\ Skoglund, K
Bruno2024 APACrefauthors Bruno, M. \ Skoglund, K. APACrefauthors \ 2024 . Analyzing the themes of Artificial Intelligence as framed by the Big Four accounting firms: A Document Analysis. Analyzing the themes of artificial intelligence as framed by the Big Four accounting firms...
2024
-
[20]
APACrefauthors \ 2019
Bryce_2019 APACrefauthors Bryce, C. APACrefauthors \ 2019 . Security governance as a service on the cloud Security governance as a service on the cloud . Journal of Cloud Computing 8 1 . http://doi.org/10.1186/s13677-019-0148-5
2019 doi
-
[21]
\ Trager, R F
bucknall_2023 APACrefauthors Bucknall, B S. \ Trager, R F. APACrefauthors \ 2023 . Structured access for third-party research on frontier AI models: Investigating researchers' model access requirements. Structured access for third-party research on frontier AI models: Investig...
2023
-
[22]
, Bucknall, B
Buhl2025- APACrefauthors Buhl, M D. , Bucknall, B. \ Masterson, T. APACrefauthors \ 2025 . Emerging Practices in Frontier AI Safety Frameworks Emerging practices in frontier AI safety frameworks . arXiv preprint arXiv:2503.04746
2025 arXiv
-
[23]
, Van Arsdale, S
Bullock2024 APACrefauthors Bullock, C. , Van Arsdale, S. , Arnold, M. , Maas, M M. \ Winter, C. APACrefauthors \ 2024 . Existing Authorities for Oversight of Frontier AI Models Existing authorities for oversight of frontier AI models . SSRN . https://doi.org/10.2139/ssrn.4976362
2024 doi
-
[24]
, Papadatos, H
Campos2025- APACrefauthors Campos, S. , Papadatos, H. , Roger, F. , Touzet, C. , Quarks, O. \ Murray, M. APACrefauthors \ 2025 . A Frontier AI Risk Management Framework: Bridging the Gap Between Current AI Practices and Established Risk Management A frontier AI risk management...
2025 arXiv
-
[25]
\ Jia, Y
Cardinaels2012- APACrefauthors Cardinaels, E. \ Jia, Y. APACrefauthors \ 2012 . How Audits Moderate the Effects of Incentives and Peer Behavior on Misreporting How audits moderate the effects of incentives and peer behavior on misreporting . European Accounting Review 25 1 183...
2012
-
[26]
, Ezell, C
Casper_2024 APACrefauthors Casper, S. , Ezell, C. , Siegmann, C. , Kolt, N. , Curtis, T L. , Bucknall, B. Hadfield-Menell, D. APACrefauthors \ 2024 06 . Black-Box Access is Insufficient for Rigorous AI Audits Black-box access is insufficient for rigorous AI audits . The 2024 A...
2024
-
[27]
, Hope, O K
Che2019- APACrefauthors Che, L. , Hope, O K. \ Langli, J C. APACrefauthors \ 2019 . How Big-4 Firms Improve Audit Quality How Big-4 firms improve audit quality . Management Science 66 10 4359-4919 . https://doi.org/10.1287/mnsc.2019.3370
2019
-
[28]
APACrefauthors \ 2023
cmmi-model APACrefauthors CMMI Institute . APACrefauthors \ 2023 . CMMI Model Viewer. CMMI model viewer. https://cmmiinstitute.com/products/cmmi/cmmi-model-viewer
2023
-
[29]
\ Nash, J
coglianese2021 APACrefauthors Coglianese, C. \ Nash, J. APACrefauthors \ 2021 . Compliance Management Systems: Do They Make a Difference? Compliance management systems: Do they make a difference? B. van Rooij\ D D. Sokol\ ( ), The Cambridge Handbook of Compliance The Cambridge...
2021 doi
-
[30]
APACrefauthors \ 1997
Coppersmith1997 APACrefauthors Coppersmith, B B. APACrefauthors \ 1997 . An Internal Compliance Review Program An internal compliance review program . SPE/EPA Exploration and Production Environmental Conference . SPE/EPA Exploration and Production Environmental Conference . ht...
1997 doi
-
[31]
APACrefauthors \ 2013
COSO2013- APACrefauthors COSO . APACrefauthors \ 2013 . Internal Control: Integrated Framework. Internal control: Integrated framework. https://www.coso.org/_files/ugd/3059fc_1df7d5dd38074006bce8fdf621a942cf.pdf
2013
-
[32]
APACrefauthors \ 2019
Davis2019 APACrefauthors Davis, F T. APACrefauthors \ 2019 . American Criminal Justice: An Introduction American criminal justice: An introduction . Cambridge University Press . https://doi.org/10.1017/9781108694773.017
2019 doi
-
[33]
APACrefauthors \ 2024
dod-2024 APACrefauthors Department of Defense . APACrefauthors \ 2024 . Cybersecurity maturity model certification (CMMC) model overview. Cybersecurity maturity model certification (cmmc) model overview. https://dodcio.defense.gov/Portals/0/Documents/CMMC/ModelOverview.pdf
2024
-
[34]
, Shah, R
dragan-2025 APACrefauthors Dragan, A. , Shah, R. , Flynn, F. \ Legg, S. APACrefauthors \ 2025 . Taking a responsible path to AGI . Taking a responsible path to AGI . https://deepmind.google/discover/blog/taking-a-responsible-path-to-agi
2025
-
[35]
APACrefauthors \ 2024
dsit2024 APACrefauthors DSIT . APACrefauthors \ 2024 . Frontier AI Safety Commitments, AI Seoul Summit 2024. Frontier AI safety commitments, AI Seoul Summit 2024. APACrefURL https://perma.cc/M9NQ-GNED APACrefURL
2024
-
[36]
\ Whittington, M
Duncan2016- APACrefauthors Duncan, B. \ Whittington, M. APACrefauthors \ 2016 . Enhancing Cloud Security and Privacy: The Power and the Weakness of the Audit Trail Enhancing cloud security and privacy: The power and the weakness of the audit trail . CLOUD COMPUTING 2016: The S...
2016
-
[37]
, Wang, D
Ege2025 APACrefauthors Ege, M. , Wang, D. \ Xu, N. APACrefauthors \ 2025 . The consequences of reputation-damaging events for Big Four auditors: evidence from 110 cases with media coverage between 2007 and 2019. The consequences of reputation-damaging events for big four audit...
2025 doi
-
[38]
APACrefauthors \ 2023
EuropeanCommission2023 APACrefauthors European Commission . APACrefauthors \ 2023 . Delegated Regulation on independent audits under the Digital Services Act . Delegated Regulation on independent audits under the Digital Services Act . https://digital-strategy.ec.europa.eu/en/...
2023
-
[39]
APACrefauthors \ 2025
EuropeanCommission2025 APACrefauthors European Commission . APACrefauthors \ 2025 . Third Draft of the General-Purpose AI Code of Practice published, written by independent experts. Third draft of the General-Purpose AI Code of Practice published, written by independent expert...
2025
-
[40]
, Schwering, A
Ewelt-Knauer2021- APACrefauthors Ewelt-Knauer, C. , Schwering, A. \ Winkelmann, S. APACrefauthors \ 2021 . Probabilistic Audits and Misreporting – the Influence of Audit Process Design on Employee Behavior Probabilistic audits and misreporting – the influence of audit process ...
2021
-
[41]
, Shneiderman, B
Falco2021- APACrefauthors Falco, G. , Shneiderman, B. , Badger, J. , Carrier, R. , Dahbura, A. , Danks, D. Yeong, Z K. APACrefauthors \ 2021 . Governing AI safety through independent audits Governing AI safety through independent audits . Nature Machine Intelligence 3 566–571 ...
2021 doi
-
[42]
APACrefauthors \ 2005
FDIC2005- APACrefauthors Federal Deposit Insurance Corporation . APACrefauthors \ 2005 . Non-Public Supervisory Information Interagency Advisory on Confidentiality of CAMELS Ratings and Other Non-Public Supervisory Information. Non-public supervisory information interagency ad...
2005
-
[43]
APACrefauthors \ 2023
fdic_2023 APACrefauthors Federal Deposit Insurance Corporation . APACrefauthors \ 2023 . Interagency Guidance on Third-Party Relationships: Risk Management. Interagency guidance on third-party relationships: Risk management. Federal Reserve System
2023
-
[44]
, Kölle, T
Fochmann2020 APACrefauthors Fochmann, M. , Kölle, T. , Mohr, P. \ Rockenbach, B. APACrefauthors \ 2020 . Trust Them, Threaten Them, or Lure Them? Effective Audit Systems to Promote Compliance Trust them, threaten them, or lure them? effective audit systems to promote complianc...
2020
-
[45]
APACrefauthors \ 2024
FrontierModelForum2024 APACrefauthors Frontier Model Forum . APACrefauthors \ 2024 . Issue Brief: Components of Frontier AI Safety Frameworks. Issue brief: Components of frontier AI safety frameworks. https://www.frontiermodelforum.org/updates/issue-brief-components-of-frontie...
2024
-
[46]
APACrefauthors \ 2025
G422025 APACrefauthors G42 . APACrefauthors \ 2025 . Frontier AI Safety Framework. Frontier AI safety framework. https://www.g42.ai/resources/publications/g42-frontier-ai-safety-framework
2025
-
[47]
, Ross, S
Gipper2024- APACrefauthors Gipper, B. , Ross, S. \ Shi, S X. APACrefauthors \ 2024 . ESG assurance in the United States ESG assurance in the united states . Review of Accounting Studies 18 3 . https://doi.org/10.1007/s11142-024-09856-2
2024 doi
-
[48]
, Prawitt, D F
Glover2006 APACrefauthors Glover, S M. , Prawitt, D F. \ Wood, D A. APACrefauthors \ 2006 . Internal Audit Sourcing Arrangement and the External Auditor's Reliance Decision. Internal audit sourcing arrangement and the external auditor's reliance decision. https://doi.org/10.21...
2006 doi
-
[49]
APACrefauthors \ 2025 1
googledeepmind2025 APACrefauthors Google DeepMind . APACrefauthors \ 2025 1 . Frontier Safety Framework Version 2.0 . Frontier Safety Framework Version 2.0 . https://deepmind.google/discover/blog/updating-the-frontier-safety-framework
2025
-
[50]
APACrefauthors \ 2025 2
GoogleDeepMind2025-2 APACrefauthors Google DeepMind . APACrefauthors \ 2025 2 . Taking a responsible path to AGI . Taking a responsible path to AGI . https://deepmind.google/discover/blog/taking-a-responsible-path-to-agi
2025
-
[51]
\ Kells, S
Gow_2018 APACrefauthors Gow, I D. \ Kells, S. APACrefauthors \ 2018 . The Big Four : The Curious Past and Perilous Future of the Global Accounting Monopoly The Big Four : The curious past and perilous future of the global accounting monopoly . Berrett-Koehler
2018
-
[52]
APACrefauthors \ 2007
Hammer2017- APACrefauthors Hammer, M. APACrefauthors \ 2007 . The Process Audit. The process audit. Harvard Business Review, https://hbr.org/2007/04/the-process-audit
2007
-
[53]
, Höst, M
Helgesson2011- APACrefauthors Helgesson, Y Y L. , Höst, M. \ Weyns, K. APACrefauthors \ 2012 . A review of methods for evaluation of maturity models for process improvement A review of methods for evaluation of maturity models for process improvement . Journal of Software: Evo...
2012 doi
-
[54]
, Kijsanayothin, P
Hewitt2008- APACrefauthors Hewett, R. , Kijsanayothin, P. \ Thipse, A. APACrefauthors \ 2008 . Security Analysis of Role-based Separation of Duty with Workflows Security analysis of role-based separation of duty with workflows . 2008 Third International Conference on Availabil...
2008 doi
-
[55]
APACrefauthors \ 1998
Humphrey1998- APACrefauthors Humphrey, W S. APACrefauthors \ 1998 . Characterizing the software process: A maturity framework Characterizing the software process: A maturity framework . IEEE Software 5 2 73-79 . https://doi.org/10.1109/52.2014
1998 doi
-
[56]
\ Roberts, C
Ismael2018- APACrefauthors Ismael, H R. \ Roberts, C. APACrefauthors \ 2018 . Factors affecting the voluntary use of internal audit: evidence from the UK Factors affecting the voluntary use of internal audit: evidence from the UK . Managerial Auditing Journal 33 3 288-317 . ht...
2018 doi
-
[57]
APACrefauthors \ 2015
Iso2015- APACrefauthors ISO . APACrefauthors \ 2015 . ISO 17021-1:2015 Conformity assessment — Requirements for bodies providing audit and certification of management systems . ISO 17021-1:2015 Conformity assessment — Requirements for bodies providing audit and certification o...
2015
-
[58]
APACrefauthors \ 2018
iso_2018 APACrefauthors ISO . APACrefauthors \ 2018 . ISO 31000 Risk management — Guidelines . ISO 31000 Risk management — Guidelines . https://www.iso.org/iso-31000-risk-management.html
2018
-
[59]
APACrefauthors \ 2022
iso_2022 APACrefauthors ISO . APACrefauthors \ 2022 . ISO 27002:2022 Information security, cybersecurity and privacy protection — Information security controls. ISO 27002:2022 Information security, cybersecurity and privacy protection — Information security controls. https://w...
2022
-
[60]
, Karthi, P N
Jagadeeswari2023- APACrefauthors Jagadeeswari, M. , Karthi, P N. , Kumar, V A N. \ Ram, S L S. APACrefauthors \ 2023 . A Secure File Sharing and Audit Trail Tracking Platform with Advanced Encryption Standard for Cloud-Based Environments A secure file sharing and audit trail t...
2023
-
[61]
APACrefauthors \ 2024
Karnofsky2024 APACrefauthors Karnofsky, H. APACrefauthors \ 2024 . If-Then Commitments for AI Risk Reduction. If-then commitments for AI risk reduction. Carnegie Endowment for International Peace, https://carnegieendowment.org/research/2024/09/if-then-commitments-for-ai-risk-reduction
2024
-
[62]
APACrefauthors \ 2024
Kasirzadeh2024- APACrefauthors Kasirzadeh, A. APACrefauthors \ 2024 . Measurement challenges in AI catastrophic risk governance and safety frameworks Measurement challenges in AI catastrophic risk governance and safety frameworks . arXiv preprint arXiv:2410.00608
2024 arXiv
-
[63]
\ Massey, A
Kempe2021- APACrefauthors Kempe, E. \ Massey, A. APACrefauthors \ 2021 . Perspectives on Regulatory Compliance in Software Engineering Perspectives on regulatory compliance in software engineering . IEEE International Requirements Engineering Conference (RE) Ieee international...
2021
-
[64]
APACrefauthors \ 2014
Kovynev2014- APACrefauthors Kovynev, A. APACrefauthors \ 2014 . Inside a WANO peer review. Inside a WANO peer review. https://www.nsenergybusiness.com/analysis/featureinside-a-wano-peer-review-4294101
2014
-
[65]
APACrefauthors \ 2016
Layton2016 APACrefauthors Layton, T P. APACrefauthors \ 2016 . Information Security Information security . Auerbach Publications . https://doi.org/10.1201/9781420013412
2016 doi
-
[66]
, Ramamoorti, S
Lee2021- APACrefauthors Lee, J. , Ramamoorti, S. \ Zelazny, L. APACrefauthors \ 2021 . Whistleblowing Intentions for Internal Auditors: Why Psychological Safety Is Critically Important. Whistleblowing intentions for internal auditors: Why psychological safety is critically imp...
2021
-
[67]
\ Pittman, J A
Lennox_2008 APACrefauthors Lennox, C S. \ Pittman, J A. APACrefauthors \ 2008 . Big Five Audits and Accounting Fraud Big five audits and accounting fraud . SSRN . http://doi.org/10.2139/ssrn.1137829
2008 doi
-
[68]
, Suloway, T
Lightman_2022 APACrefauthors Lightman, S. , Suloway, T. \ Brule, J. APACrefauthors \ 2022 . Satellite ground segment: Applying the cybersecurity framework to assure satellite command and control Satellite ground segment: Applying the cybersecurity framework to assure satellite...
2022 doi
-
[69]
, Schneider, S
Lins_2018 APACrefauthors Lins, S. , Schneider, S. \ Sunyaev, A. APACrefauthors \ 2018 . Trust is Good, Control is Better: Creating Secure Clouds by Continuous Auditing Trust is good, control is better: Creating secure clouds by continuous auditing . IEEE Transactions on Cloud ...
2018
-
[70]
\ Huang, H W
Liu2020- APACrefauthors Liu, W P. \ Huang, H W. APACrefauthors \ 2020 . Auditor realignment, voluntary SOX 404 adoption, and internal control material weakness remediation: Further evidence from U.S. -listed foreign firms Auditor realignment, voluntary SOX 404 adoption, and in...
2020
-
[71]
APACrefauthors \ 2024
Liu2024- APACrefauthors Liu, Y. APACrefauthors \ 2024 . Build an Audit Framework for Data Privacy Protection in Cloud Environment Build an audit framework for data privacy protection in cloud environment . Procedia Computer Science 247 166-175 . https://doi.org/10.1016/j.procs...
2024 doi
-
[72]
\ Yang, K K
low_2019 APACrefauthors Low, J M W. \ Yang, K K. APACrefauthors \ 2019 . An exploratory study on the effects of human, technical and operating factors on aviation safety An exploratory study on the effects of human, technical and operating factors on aviation safety . Journal ...
2019
-
[73]
, Martin, S
Manheim2024- APACrefauthors Manheim, D. , Martin, S. , Bailey, M. , Samin, M. \ Greutzmacher, R. APACrefauthors \ 2024 . The Necessity of AI Audit Standards Boards The necessity of AI audit standards boards . arXiv preprint arXiv:2404.13060
2024 arXiv
-
[74]
APACrefauthors \ 2013
Martinez2013 APACrefauthors Martinez, V R. APACrefauthors \ 2013 . The Monitor-'Client' Relationship The monitor-'client' relationship . SSRN . https://ssrn.com/abstract=2309498
2013
-
[75]
APACrefauthors \ 2025
Meta2025- APACrefauthors Meta . APACrefauthors \ 2025 . Frontier AI Framework. Frontier AI framework. https://ai.meta.com/static-resource/meta-frontier-ai-framework
2025
-
[76]
APACrefauthors \ 2025
metr2025 APACrefauthors METR . APACrefauthors \ 2025 . Common elements of frontier AI safety policies. Common elements of frontier AI safety policies. https://metr.org/common-elements.pdf
2025
-
[77]
, Das, S R
Mishra_2016 APACrefauthors Mishra, A. , Das, S R. \ Murray, J J. APACrefauthors \ 2016 . Risk, Process Maturity, and Project Performance: An Empirical Analysis of US Federal Government Technology Projects Risk, process maturity, and project performance: An empirical analysis o...
2016 doi
-
[78]
\ Floridi, L
mokander_2021 APACrefauthors M\" o kander, J. \ Floridi, L. APACrefauthors \ 2021 . Ethics-Based Auditing to Develop Trustworthy AI Ethics-based auditing to develop trustworthy AI . Minds and Machines 31 2 323–327 . http://doi.org/10.1007/s11023-021-09557-8
2021 doi
-
[79]
, Schuett, J
mokander2023 APACrefauthors M\" o kander, J. , Schuett, J. , Kirk, H R. \ Floridi, L. APACrefauthors \ 2023 . Auditing large language models: A three-layered approach Auditing large language models: A three-layered approach . AI and Ethics . https://doi.org/10.1007/s43681-023-00289-2
2023 doi
-
[80]
\ Neidermeyer, P E
Neidermeyer2005- APACrefauthors Neidermeyer, A A. \ Neidermeyer, P E. APACrefauthors \ 2005 . Audit anticipation: does it impact job performance? Audit anticipation: does it impact job performance? Managerial Auditing Journal 20 1 19-29 . https://doi.org/10.1108/02686900510570669
2005 doi
-
[81]
\ Simek, J W
nelson-2013 APACrefauthors Nelson, S D. \ Simek, J W. APACrefauthors \ 2013 . Clients Demand Law Firm Cyber Audits Clients demand law firm cyber audits . Law Practice 39
2013
-
[82]
, Lahav, D
nevo2024 APACrefauthors Nevo, S. , Lahav, D. , Karpur, A. , Bar-On, Y. , Bradley, H A. \ Alstott, J. APACrefauthors \ 2024 . Securing AI Model Weights. Securing AI model weights. RAND, https://doi.org/10.7249/RRA2849-1
2024 doi
-
[83]
APACrefauthors \ 2008
ObjectManagementGroup2008- APACrefauthors Object Management Group . APACrefauthors \ 2008 . Business Process Maturity Model (BPMM) . Business process maturity model (BPMM) . http://www.omg.org/spec/BPMM/1.0/PDF
2008
-
[84]
obrien2024 APACrefauthors O'Brien, J. , Ee, S. \ Williams, Z. APACrefauthors \ 2024 . Deployment Corrections: An Incident Response Framework for Frontier AI Models Deployment corrections: An incident response framework for frontier AI models . arXiv preprint arXiv:2310.00328
2024 arXiv
-
[85]
O hman, P. , H \
Ohman2012- APACrefauthors \"O hman, P. , H \"a ckner, E. \ S \"o rbom, D. APACrefauthors \ 2012 . Client satisfaction and usefulness to external stakeholders from an audit client perspective Client satisfaction and usefulness to external stakeholders from an audit client persp...
2012 doi
-
[86]
APACrefauthors \
openai-trust-portal APACrefauthors OpenAI. APACrefauthors \ . Trust Portal. Trust portal. https://trust.openai.com
-
[87]
APACrefauthors \ 2023
OpenAI2023-tt APACrefauthors OpenAI . APACrefauthors \ 2023 . Preparedness Framework (Beta) . Preparedness Framework (Beta) . https://perma.cc/9FBB-URXF
2023
-
[88]
APACrefauthors \ 2025
OpenAI2025- APACrefauthors OpenAI . APACrefauthors \ 2025 . Preparedness Framework . Preparedness Framework . https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf
2025
-
[89]
\ Mähler, C
pang_2014 APACrefauthors Pang, J. \ Mähler, C. APACrefauthors \ 2014 . Certified Quality Certified quality . Mechanical Engineering 136 2 40-43 . https://doi.org/10.1115/1.2014-Feb-2
2014 doi
-
[90]
APACrefauthors \ 2017
Peterson_2017 APACrefauthors Peterson, J. APACrefauthors \ 2017 . Count Down: The Past, Present and Uncertain Future of the Big Four Accounting Firms Count down: The past, present and uncertain future of the big four accounting firms \ ( 2 \ ). Emerald Group Publishing
2017
-
[91]
, Doherty, N
Pilbeam2016- APACrefauthors Pilbeam, C. , Doherty, N. , Davidson, R. \ Denyer, D. APACrefauthors \ 2016 . Safety leadership practices for organizational safety compliance: Developing a research agenda from a review of the literature Safety leadership practices for organization...
2016 doi
-
[92]
APACrefauthors \ 2025
Pistillo2025- APACrefauthors Pistillo, M. APACrefauthors \ 2025 . Towards Frontier Safety Policies Plus Towards frontier safety policies plus . arXiv preprint arXiv:2501.16500
2025 arXiv
-
[93]
, Smart, A
Raji2020- APACrefauthors Raji, I D. , Smart, A. , White, R N. , Mitchell, M. , Gebru, T. , Hutchinson, B. Barnes, P. APACrefauthors \ 2020 . Closing the AI accountability gap: defining an end-to-end framework for internal algorithmic auditing Closing the AI accountability gap:...
2020
-
[94]
Raji2022-outsider APACrefauthors Raji, I D. , Xu, P. , Honigsberg, C. \ Ho, D E. APACrefauthors \ 2022 . Outsider Oversight: Designing a Third Party Audit Ecosystem for AI Governance Outsider oversight: Designing a third party audit ecosystem for AI governance . AAAI/ACM Confe...
2022
-
[95]
, Gogolin, F
Rosati2020- APACrefauthors Rosati, P. , Gogolin, F. \ Lynn, T. APACrefauthors \ 2020 . Cyber-Security Incidents and Audit Quality Cyber-security incidents and audit quality . European Accounting Review 31 3 701–728 . https://doi.org/10.1080/09638180.2020.1856162
2020
-
[96]
, Serra-Ruiz, J
sabillon_2017 APACrefauthors Sabillon, R. , Serra-Ruiz, J. , Cavaller, V. \ Cano, J. APACrefauthors \ 2017 . A Comprehensive Cybersecurity Audit Model to Improve Cybersecurity Assurance: The CyberSecurity Audit Model ( CSAM ) A comprehensive cybersecurity audit model to improv...
2017
-
[97]
APACrefauthors \ 2009
Salehi2009- APACrefauthors Salehi, M. APACrefauthors \ 2009 . In the Name of Independence: With Regard to Practicing Non-Audit Service by External Auditors In the name of independence: With regard to practicing non-audit service by external auditors . International Business Re...
2009 doi
-
[98]
Sarbanes--Oxley Act
sarbanes_oxley_2002 Sarbanes--Oxley Act . Sarbanes--Oxley Act . 2002 . Pub.\ L.\ No.\ 107-204, 116 Stat.\ 745. https://www.govinfo.gov/content/pkg/COMPS-1883/pdf/COMPS-1883.pdf
2002
-
[99]
APACrefauthors \ 2024
Schoemaker2024 APACrefauthors Schoemaker, M. APACrefauthors \ 2024 . Putting Teeth into AI Risk Management Lessons from Cybersecurity Procurement Rules and Practices. Putting teeth into AI risk management lessons from cybersecurity procurement rules and practices. Center for S...
2024
-
[100]
, Drechsler, A
schrimpf_2020 APACrefauthors Schrimpf, A. , Drechsler, A. \ Dagianis, K. APACrefauthors \ 2020 . Assessing identity and access management process maturity: first insights from the German financial sector Assessing identity and access management process maturity: first insights...
2020
-
[101]
APACrefauthors \ 2024
schuett2024-ia APACrefauthors Schuett, J. APACrefauthors \ 2024 . Frontier AI developers need an internal audit function Frontier AI developers need an internal audit function . Risk Analysis 1--21 . https://doi.org/10.1111/risa.17665
2024 doi
-
[102]
\ Toffel, M W
Short2016- APACrefauthors Short, J L. \ Toffel, M W. APACrefauthors \ 2016 . The integrity of private third-party compliance monitoring The integrity of private third-party compliance monitoring . Administrative & Regulatory Law News 42 1 22-25
2016
-
[103]
\ Lin, L
Tepalagul2015- APACrefauthors Tepalagul, N. \ Lin, L. APACrefauthors \ 2023 . Auditor Independence and Audit Quality: A Literature Review Auditor independence and audit quality: A literature review . Journal of Accounting, Auditing & Finance 30 1 101-121 . https://doi.org/10.1...
2023 doi
-
[104]
APACrefauthors \ 2013
iia-2013 APACrefauthors The Institute of Internal Auditors . APACrefauthors \ 2013 . Selecting, using, and creating maturity models: a tool for assurance and consulting engagements. Selecting, using, and creating maturity models: a tool for assurance and consulting engagements...
2013
-
[105]
APACrefauthors \ 2017
Thompson2017 APACrefauthors Thompson, E C. APACrefauthors \ 2017 . Building a HIPAA-Compliant Cybersecurity Program Building a HIPAA-Compliant cybersecurity program . Apress
2017
-
[106]
APACrefauthors \ 2017
Toy2017- APACrefauthors Toy, A. APACrefauthors \ 2017 . Generating standards for privacy audits: Theoretical bases from two disciplines Generating standards for privacy audits: Theoretical bases from two disciplines . Journal of Law, Information and Science 25 1 26-48 . https:...
2017 doi
-
[107]
APACrefauthors \ 2012
TVO2012- APACrefauthors TVO . APACrefauthors \ 2012 . WANO conducts Peer Review of annual outages. WANO conducts peer review of annual outages. https://www.tvo.fi/en/index/news/pressreleasesstockexchangereleases/2012/hqfAPEOFY.html
2012
-
[108]
APACrefauthors \ 2005
Tynan2005- APACrefauthors Tynan, R. APACrefauthors \ 2005 . The Effects of Threat Sensitivity and Face Giving on Dyadic Psychological Safety and Upward Communication The effects of threat sensitivity and face giving on dyadic psychological safety and upward communication . Jou...
2005
-
[109]
doj-2024 APACrefauthors U. S. Department of Justice . APACrefauthors \ 2024 . Evaluation of Corporate Compliance Programs. Evaluation of corporate compliance programs. https://www.justice.gov/criminal/criminal-fraud/page/file/937501/dl?inline=
2024
-
[110]
, Schuett, J
Williams2025- APACrefauthors Williams, S. , Schuett, J. \ Anderljung, M. APACrefauthors \ 2025 . On Regulating Downstream AI Developers On regulating downstream AI developers . arXiv preprint arXiv:2503.11922
2025
-
[111]
APACrefauthors \ 2025
Wills2025 APACrefauthors Wills, P. APACrefauthors \ 2025 . Regulatory Supervision of Frontier AI Developers Regulatory supervision of frontier AI developers . SSRN . https://ssrn.com/abstract=5122871
2025
Reviewed August 16, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.