Lighthouse AdvisorySLED AI Adoption Intelligence
← Back to results

From the State Government edition of September 9, 2026

Government auditCautionaryNewly relevant · Apr 2025

New York audit documents the gap between AI policy and verifiable operating procedures

New York State Office of the State Comptroller · State government · New York, United States

Publisher
Office of the New York State Comptroller
Original publication
April 3, 2025
Source retrieved
2026-09-10
Read original source

What happened

The auditor found inconsistent governance and insufficient evidence of testing procedures across a judgmental agency sample.

Why it matters

State shared-service oversight and agency accountability are central. Use-case examples support that governance analysis; no policing or education cross-tags are added.

Evidence and measured results

Audit period: January 2019–November 2024. Methods included policy review, interviews, vendor demonstrations and documentation checks for four judgmentally selected agencies and one selected use case each. DMV disputed testing-related findings; the auditor said supplied documentation did not establish the requested procedures.

Limitations and uncertainty

Non-statistical sample cannot be projected to all agencies. Historical audit is not a September 2026 compliance assessment. It identifies assurance gaps rather than quantifying population harm; auditee disagreement is preserved.

Put this evidence to work

Lighthouse Advisory interpretation, grounded in this source. Enriched 2026-09-10; this does not change the original publication date. Labels below come from the analysis itself.

Sales

Role takeaway

Qualify the assurance workload with central IT, agency program owners, procurement and internal audit. Ask whether a reviewer can trace policy requirements to executed tests, who settles classification disputes, and which supplier terms constrain evidence access. A bounded engagement could reconcile one agency's inventory and inspect a sample of approval and monitoring records. The credible value hypothesis is clearer accountability and less effort assembling defensible evidence. Do not claim that this older audit describes the customer's present posture or proves actual discrimination. Establish current remediation status independently and include the agency's explanation when documenting any disputed control gap.

Pre-sales engineering

Role takeaway

Fit is evidence integration across inventory, configuration, contracts and test records. Prerequisites include named system owners, an agreed AI definition and access to supplier documentation. Build a trace from each material risk to its test, result and approval, including exceptions. Validate output accuracy and subgroup behavior using use-case-specific criteria; generic security reviews cannot establish these properties. Test whether a model or vendor change triggers renewed review. A proposed proof of value should reconstruct one complete approval history and repeat the relevant evaluation. Deployment may span cloud, on-premises and hybrid environments; the audit supports a governance approach, not selection of a hosting model.

Delivery

Role takeaway

Reconcile existing systems, document required procedures and assign recurring review to operational owners. Central IT supplies common definitions and templates, while agency leaders accept residual risks. Dependencies include procurement cooperation, specialist evaluation skills and access to legacy records. Train staff on how to identify AI features and report uncertain classifications.

Proposed acceptance criteria
every sampled system has a named owner, documented data terms, retained test evidence and an approved disposition for exceptions. Exercise a supplier change and verify that review occurs. Risks include stale inventories and treating a policy document as operational proof; report disputed findings and remediation evidence separately.

Implementation considerations

Lighthouse Advisory interpretation across the operating dimensions a public-sector buyer must settle before this evidence becomes a design. Each note answers the question under its heading for this specific source.

Architecture and integration

What must connect, and where does the AI sit in the workflow?

Trace inventories to actual configurations and retained evaluation artifacts across hosted and internally managed systems. This governance audit supplies no model or hardware benchmark.

Governance

Who approves, reviews and stays accountable for outcomes?

Resolve AI-definition disputes and require evidence that agency review responsibilities operate in practice.

Security and privacy

What data, permissions and controls need testing?

Map data ownership, vendor reuse and retention to enforceable terms and system behavior.

Accessibility and workforce

Who is affected, and what skills or accommodations follow?

Distinguish tool-use training from the skills needed to detect bias and inaccurate outputs; include affected users in validation.

Procurement

What should contracts, pricing and exit terms secure?

Make supplier testing access and data-use obligations explicit, with accountable exception approval.

Operating model

Which teams own the service once it runs?

Central IT provides usable procedures; agency owners retain risk acceptance and regular performance review.

What changed

Full archive contains separate NYC and SUNY audits, but not this statewide 2023-S-50 report. Historical source newly included for the policy-to-procedure distinction and documented auditee disagreement, not as a fresh audit.

Publication history

  1. 2026-09-09State Government · Issue 043 resources
Read preserved resource versions (JSON)

Stable resource ID: ny-state-ai-governance-audit-2023-s-50