{"resourceId":"maricopa-ai-governance-public-audit-2025","versions":[{"version":"external-053748c761ca039e89a29db2b329349493ba1c4740bd5959d84040dc2339742f","resource":{"id":"maricopa-ai-governance-public-audit-2025","title":"Maricopa audit identifies AI control improvements but withholds sensitive details","organization":"Maricopa County Internal Audit","sector":"County technology oversight","geography":"Maricopa County, Arizona, United States","publishedAt":"October 15, 2025, release date on official audit index","publicationDate":"2025-10-15","eventDate":null,"sourceName":"Maricopa County","sourceLabel":"Two-page public internal-audit report","sourceUrl":"https://www.maricopa.gov/DocumentCenter/View/111482/Artificial-Intelligence-Governance-Report-PDF","evidenceClass":"government-audit","outcomeClass":"mixed","topics":["knowledge-work","data-security","governance-procurement","accessibility-workforce","operating-model"],"finding":"The audit records existing governance measures and opportunities to strengthen controls, with corrective plans in place.","sledRelevance":"Historical county oversight evidence adds a U.S. audit perspective; it does not establish present-day remediation status.","evidence":"Auditors interviewed ETI staff, examined configurations and reviewed documents. They noted a usage policy, training and AI subcommittee. Sensitive observations were withheld; nothing warranted Board consideration. Public material provides no system sample size, maturity scores or measured service benefit.","architectureImplications":"Interpretation: Maintain testable configuration evidence across purchased and internally built tools, including logging and access controls.","governanceImplications":"Interpretation: Track corrective actions to verified closure and distinguish confidential evidence from publishable assurance.","securityPrivacyImplications":"Interpretation: Protect detailed findings while preserving enough non-sensitive information to explain accountability.","caveats":"A limited public summary cannot establish specific vulnerabilities, severity, comprehensive safety or completion of corrective actions.","streamIds":["local-government"],"roles":{"sales":"Interpretation: Engage the county CIO, internal audit, security and department owners around evidence gaps in ongoing AI assurance. Ask which actions are still open, who verifies closure and what reviewers can inspect without publishing sensitive details. A bounded engagement can reconcile an action register with operational evidence for a few approved tools. The hypothesis is more reliable remediation decisions, not certification or guaranteed risk reduction. This report is not evidence of a particular exploitable defect. Smaller governments may need shared specialist support; confirm funding and access before proposing an audit-like service.","engineering":"Interpretation: Treat the report as a prompt for local verification, not a technical specification. Establish inventory, data flows, privileged roles and monitoring coverage for the chosen application. Prerequisites include approved read access and a defined evidence-handling process. Test a material configuration change and show that controls and review records remain aligned. For developer-built copilots or agents, include credentials and action permissions. Use synthetic error events to test detection and escalation without exposing resident data. No hosting topology is validated by this public report; architecture choices require local availability, security and support analysis.","delivery":"Interpretation: Internal audit should retain independent closure review while IT and service owners implement corrections. Define an evidence register, access restrictions and review calendar; train staff on incident reporting and residual uncertainty. Dependencies include time from technical owners and authority to pause a tool when evidence is inadequate. Proposed acceptance: all sampled corrective actions have a named owner and verifiable closure evidence, and an injected test event reaches the accountable responder. These criteria are proposed, not observed. Avoid closing actions on policy publication alone or interpreting the absence of public details as proof that controls are effective."},"retrievedAt":"2026-09-13T03:00:59Z","enrichedAt":"2026-09-13T03:03:31Z","enrichmentBasis":"retrieved source","accessibilityWorkforceImplications":"Interpretation: Test staff ability to recognize and escalate errors; training attendance is insufficient acceptance evidence.","procurementImplications":"Interpretation: Agree on supplier access to configuration and assessment evidence before committing to assurance duties.","operatingModelImplications":"Interpretation: Give every corrective action a funded owner, deadline and independent closure check.","updateExplanation":"Absent from all 247 archive resources checked at offsets 0, 100 and 200, plus targeted related-finding search. Historical source newly added; no substantive update or post-last-run development is claimed.","sourceVerification":{"openedUrl":"https://www.maricopa.gov/DocumentCenter/View/111482/Artificial-Intelligence-Governance-Report-PDF","referenceExcerpt":"Corrective action plans are in place","promptVersion":"sled-research-v3.1","model":null,"basis":"agent-reported inspection"}}}]}