From the State Government edition of September 9, 2026
New York audit documents the gap between AI policy and verifiable operating procedures
New York State Office of the State Comptroller · State government · New York, United States
- Publisher
- Office of the New York State Comptroller
- Original publication
- April 3, 2025
- Source retrieved
- 2026-09-10
What happened
The auditor found inconsistent governance and insufficient evidence of testing procedures across a judgmental agency sample.
Why it matters
State shared-service oversight and agency accountability are central. Use-case examples support that governance analysis; no policing or education cross-tags are added.
Evidence and measured results
Audit period: January 2019–November 2024. Methods included policy review, interviews, vendor demonstrations and documentation checks for four judgmentally selected agencies and one selected use case each. DMV disputed testing-related findings; the auditor said supplied documentation did not establish the requested procedures.
Limitations and uncertainty
Non-statistical sample cannot be projected to all agencies. Historical audit is not a September 2026 compliance assessment. It identifies assurance gaps rather than quantifying population harm; auditee disagreement is preserved.
Put this evidence to work
Lighthouse Advisory interpretation, grounded in this source. Enriched 2026-09-10; this does not change the original publication date. Labels below come from the analysis itself.
Sales
Role takeaway
Qualify the assurance workload with central IT, agency program owners, procurement and internal audit. Ask whether a reviewer can trace policy requirements to executed tests, who settles classification disputes, and which supplier terms constrain evidence access. A bounded engagement could reconcile one agency's inventory and inspect a sample of approval and monitoring records. The credible value hypothesis is clearer accountability and less effort assembling defensible evidence. Do not claim that this older audit describes the customer's present posture or proves actual discrimination. Establish current remediation status independently and include the agency's explanation when documenting any disputed control gap.
Pre-sales engineering
Role takeaway
Fit is evidence integration across inventory, configuration, contracts and test records. Prerequisites include named system owners, an agreed AI definition and access to supplier documentation. Build a trace from each material risk to its test, result and approval, including exceptions. Validate output accuracy and subgroup behavior using use-case-specific criteria; generic security reviews cannot establish these properties. Test whether a model or vendor change triggers renewed review. A proposed proof of value should reconstruct one complete approval history and repeat the relevant evaluation. Deployment may span cloud, on-premises and hybrid environments; the audit supports a governance approach, not selection of a hosting model.
Delivery
Role takeaway
Reconcile existing systems, document required procedures and assign recurring review to operational owners. Central IT supplies common definitions and templates, while agency leaders accept residual risks. Dependencies include procurement cooperation, specialist evaluation skills and access to legacy records. Train staff on how to identify AI features and report uncertain classifications.
- Proposed acceptance criteria
- every sampled system has a named owner, documented data terms, retained test evidence and an approved disposition for exceptions. Exercise a supplier change and verify that review occurs. Risks include stale inventories and treating a policy document as operational proof; report disputed findings and remediation evidence separately.
Implementation considerations
Lighthouse Advisory interpretation across the operating dimensions a public-sector buyer must settle before this evidence becomes a design. Each note answers the question under its heading for this specific source.
Architecture and integration
What must connect, and where does the AI sit in the workflow?
Trace inventories to actual configurations and retained evaluation artifacts across hosted and internally managed systems. This governance audit supplies no model or hardware benchmark.
Governance
Who approves, reviews and stays accountable for outcomes?
Resolve AI-definition disputes and require evidence that agency review responsibilities operate in practice.
Security and privacy
What data, permissions and controls need testing?
Map data ownership, vendor reuse and retention to enforceable terms and system behavior.
Accessibility and workforce
Who is affected, and what skills or accommodations follow?
Distinguish tool-use training from the skills needed to detect bias and inaccurate outputs; include affected users in validation.
Procurement
What should contracts, pricing and exit terms secure?
Make supplier testing access and data-use obligations explicit, with accountable exception approval.
Operating model
Which teams own the service once it runs?
Central IT provides usable procedures; agency owners retain risk acceptance and regular performance review.
What changed
Full archive contains separate NYC and SUNY audits, but not this statewide 2023-S-50 report. Historical source newly included for the policy-to-procedure distinction and documented auditee disagreement, not as a fresh audit.
Publication history
- 2026-09-09State Government · Issue 043 resources
Stable resource ID: ny-state-ai-governance-audit-2023-s-50