Wrivio
Get Wrivio
6 min readBy Wrivio Team

How to Prepare for an AI Audit as a Small Team

You do not run a Fortune 500 compliance department. You are a small team that uses a handful of AI tools to write, summarize, and draft things faster, and you have started to notice that “AI audit” is no longer a phrase reserved for large enterprises. It is showing up in client questionnaires, in vendor contracts, and now in state law.

Two pieces of news from September 2026 make this concrete rather than hypothetical. On September 9, 2026, Governor Newsom signed AB 1405 and SB 813, which together build California’s first state framework for independently auditing AI systems: SB 813 requires a framework for designating Independent Verification Organizations by January 1, 2028, and AB 1405 stands up a registry of AI auditors by January 1, 2029 (source: gov.ca.gov, September 9, 2026). Meanwhile the EU AI Act’s enforcement powers, giving the AI Office and national authorities the ability to demand documentation, evaluate models, and fine noncompliant providers, became active in August 2026 (source: European Commission, enforcement of the AI Act).

Neither law reaches down to demand your five-person team submit to a formal audit next month. But both signal where the ground is heading, and the honest reason to prepare now is not fear of a regulator showing up. It is that the same documentation an auditor would want is exactly what a client, an insurer, or a new hire’s employer will start asking for, and scrambling to produce it after the fact is worse than keeping it as you go.

A Demonstrable Process Beats a Perfect One

Auditors, whether state-registered ones under California’s new framework or a client’s own security review, are not looking for a flawless AI program. They are looking for evidence that you know what you are doing: a repeatable process, written down, that someone else could follow and verify. A team that can show “here is what we use, here is where the data goes, here is who checks the output” passes far more reviews than a team with an elaborate policy nobody follows. Keep that principle in mind through the rest of this list, because it is the actual grading criterion.

Keep an Inventory of Every AI Tool in Use

Start with a simple, living list: every AI tool anyone on the team uses for work, not just the one the company officially adopted. Shadow AI use, someone quietly pasting client text into a public chatbot because it was faster, is the single most common finding when an actual review happens. List the tool, who uses it, and what it is used for. Update it quarterly. This alone answers the first question any audit asks: what are you actually running.

Document Where Your Data Actually Goes

For each tool on that inventory, write down what happens to the text you put into it: is it processed locally, or sent to a server. If it is sent externally, whose server, is it retained, and for how long. This is the part most teams have never actually written down, because it requires reading a privacy policy once and recording the answer rather than re-reading it every time someone asks. How to document your AI workflow for an auditor walks through a template for exactly this.

Keep Vendor Terms and Check for Published Documentation

Save the terms of service, data processing agreement, and any security documentation each vendor publishes. For frontier model providers, note whether they have signed the EU’s GPAI Code of Practice or otherwise published model documentation, since that is increasingly what regulators and enterprise clients both check first. How to audit an AI vendor in 2026 has the specific questions to ask a vendor before you rely on their tool for anything sensitive.

Record Where a Human Actually Reviews the Output

This is the single highest-value line item on the list, and the one most teams skip. For each significant use of AI, from drafting client emails to writing marketing copy, write down who reviews the output before it goes out and what they are checking for. “A person reads it before it’s sent” sounds obvious, but writing it down, and actually doing it consistently, is what separates a defensible process from an assumed one. It also happens to be the same practice that state employment rules increasingly expect; see US state AI employment rules for 2026 for how several states are now codifying human review requirements directly into law.

Write a One-Page AI Use Policy

You do not need forty pages. A single page that states which tools are approved, what kinds of data may and may not go into them, and who reviews AI-assisted work before it ships is enough to show a demonstrable, repeatable process exists. Date it, review it twice a year, and keep old versions so you can show the policy itself has a history.

A Wrivio Context can make one part of this concrete and reusable. Set up a context for documenting an AI-use decision each time you make one:

Turn these notes into a short, dated record of an AI-use decision: which tool, what data category, who approved it, and what review step applies. Keep every name, date, figure, and commitment exactly as written. Use plain, direct language a non-technical reviewer could read in under a minute.

Press Ctrl+Shift+Space, paste your rough notes in, and check the diff before you file the record.

Common Questions

Does my small team actually need to worry about California’s AI auditor registry?

Not directly yet: AB 1405’s registry does not open until January 1, 2029, and SB 813’s verification framework arrives January 1, 2028, but the documentation habits both laws assume are worth building now rather than under deadline pressure later.

What does the EU AI Act’s August 2026 enforcement actually cover?

As of September 2026 it primarily targets providers of general-purpose AI models and prohibited practices, giving the EU AI Office power to demand technical documentation and issue fines, not small teams that merely use AI tools, though vendors you rely on are now squarely in scope.

What is the single most important thing to document?

Where a human reviews AI output before it is acted on or sent, since that is the control every framework, state law, and client questionnaire asks about first.

Do I need a lawyer to write an AI use policy?

For a first version, no, a clear one-page document covering approved tools, data rules, and review steps is enough to demonstrate a real process; bring in legal review once the policy needs to satisfy a specific contract or regulation.

How often should the tool inventory be updated?

Quarterly is a reasonable baseline for a small team, with an off-cycle update any time someone adopts a new tool for client or confidential work.

Keeping a clean, reviewable record starts with the tools you actually use: Download Wrivio for Windows.