AI Governance Compliance

Schellman: 74% Say They're AI Audit-Ready, Only 27% Actually Are

Technology · AI Compliance 4 min read

Schellman, a leading global provider of attestation and compliance services and the first ANAB-accredited ISO 42001 certification body, has released its State of AI Governance Report 2026, revealing a striking disconnect between how prepared organizations believe they are to govern AI and the actual maturity of the programs behind that confidence.

The survey of 525 U.S.-based professionals involved in evaluating, deploying, securing, or governing AI found that while 90% of organizations have allocated funding for AI governance and 74% believe they could pass an AI compliance audit today, only 27% describe their governance programs as fully mature. The results suggest that many enterprises have built the foundations for AI governance but are still struggling to operationalize policies, oversight, and accountability at the pace AI adoption is accelerating.

"Organizations are not struggling because they lack awareness of AI governance. Most already have policies, funding, and oversight mechanisms in place. The challenge is turning those individual activities into a mature, operationalized program that can withstand regulatory scrutiny."

— Danny Manimbo, Managing Principal and ISO & AI Practice Leader, Schellman

Confidence Outpaces Governance Maturity

While nearly three-quarters of respondents said their organization could pass an AI compliance audit today, the underlying figures tell a different story: just 27% report fully mature AI governance programs, 57% maintain a formal AI governance policy, and only 44% have AI-specific incident response procedures in place. Roughly 64% have a formal AI acceptable use policy actively communicated to employees. Together, these numbers highlight a widening gap between governance activity and genuine governance readiness.

Manimbo notes that as organizations deploy more autonomous AI capabilities, governance can no longer be treated as a one-time exercise. Instead, it has to become a continuous process of oversight, accountability, and validation that keeps pace with rapidly evolving AI systems.

"Customers, regulators, boards, and business partners are no longer asking whether organizations are thinking about governance, they want proof that governance is working."

— Avani Desai, CEO, Schellman

AI Agents Are Moving Into Production

Agentic AI is rapidly moving beyond experimentation. According to the report, 86% of organizations have tested or piloted AI agents, and 46% already have AI agents running in production. Notably, organizations with mature AI governance are far more likely to have agents in production (78%) than those with developing governance programs (22%) — reframing governance as an enabler of AI deployment rather than a brake on it.

Accountability Remains Concentrated

Responsibility for AI adoption and risk remains concentrated among a small number of executives. Some 42% say the CIO or Head of IT is primarily responsible for AI purchasing decisions, and 37% say that same role is ultimately accountable when AI-related risks emerge. Only 54% report AI governance regularly to boards or executive leadership teams, and third-party AI risk remains a major blind spot — just 36% of boards regularly discuss it, despite growing reliance on AI embedded in vendor platforms and enterprise software.

Regulatory Pressure Continues to Grow

Nearly all respondents operate in regions facing AI-related regulatory requirements, yet preparation remains uneven. While 89% have taken action to prepare for U.S. regulations, only 29% have acted on the EU AI Act and just 12% have addressed AI requirements across Asia-Pacific markets. Awareness, in short, is outpacing readiness — organizations know which regulations are emerging but are still building the infrastructure to meet them. At the same time, governance investment is delivering measurable returns, including improved internal efficiency (57%), stronger regulatory readiness (49%), easier AI scaling (43%), and increased customer trust (39%).

Key Takeaways
1

A 47-point confidence gap. 74% of enterprises believe they could pass an AI compliance audit, but only 27% have a fully mature governance program to back it up.

2

Funding isn't the problem. With 90% of organizations already allocating budget, the shortfall lies in operationalizing policies, oversight, and accountability — not investment.

3

Governance accelerates AI. Firms with mature governance run agents in production at far higher rates (78% vs. 22%), positioning governance as an enabler rather than a barrier.

4

Third-party risk is a blind spot. Only 36% of boards regularly discuss risk from AI embedded in vendor platforms, even as reliance on it grows.

5

Awareness outpaces readiness. 89% have prepared for U.S. rules, but only 29% for the EU AI Act and 12% for Asia-Pacific — leaving global compliance uneven.