AI/ML, Governance, Risk and Compliance

The AI governance audit your clients aren’t ready for

COMMENTARY: Most clients think an AI policy means they have AI governance. An audit will quickly expose the gap. Can they show which tools are being used, what data those tools touched, and who approved access? In many cases, they cannot. That gives MSPs and MSSPs a clear opening to offer AI readiness assessments, visibility, access controls, and ongoing compliance support.


According to Grant Thornton's 2026 AI Impact Survey of nearly 1,000 senior business leaders, 78 percent lack full confidence that their organization could pass an independent AI governance audit within 90 days. This is not about a subset of laggards or smaller businesses without dedicated security teams. It describes the majority of organizations, across industries and at scale, as AI deployment accelerates across every function. For channel partners, it is a conversation they are already having with their clients.

I spend a lot of time talking to enterprise security and compliance leaders. The gap depicted here is real, and it is widening. The problem is not that organizations haven't tried. They have policies, AI committees, and working groups. What most of them lack is operational governance: the visibility, the access controls, and the audit trail that a regulator or external auditor will actually demand.

That distinction matters more than ever because the window to get ahead of the incoming wave of AI regulation is narrowing.

The regulatory environment is not waiting

Three converging frameworks are reshaping what AI governance must look like in practice.

The EU AI Act entered force in August 2025, with obligations rolling out through 2027. It requires organizations to maintain audit logs, document data provenance, and demonstrate meaningful human oversight throughout the AI system lifecycle. Those obligations are structurally harder to meet when AI workloads run in shared environments where visibility into data flows depends on what a provider chooses to expose. Shadow AI adds a direct compliance dimension here — an employee feeding sensitive customer data or intellectual property into an unsanctioned model can create EU AI Act exposure just as readily as it creates a data security incident.

NIST's AI Risk Management Framework is shaping U.S. federal procurement requirements, embedding AI governance expectations into vendor contracts and agency management. The SEC's 2026 examination priorities flag AI governance as a scrutiny area for the third consecutive year, with examiners reviewing whether firms' actual AI usage matches their public representations and whether adequate oversight policies exist. Each of these frameworks asks the same fundamental question: can you demonstrate where your AI systems accessed sensitive data, who authorized it, and what happened to it afterward?

The channel opportunity in the readiness gap

IBM's 2025 Cost of a Data Breach Report found that among organizations that experienced a breach, 63 percent either had no AI governance policy or were still developing one. Nearly all of those breached organizations, 97 percent, lacked proper AI access controls on the systems involved. Osterman Research's 2026 State of AI study adds a harder finding: more than four in five organizations expressed confidence in their ability to prevent unauthorized AI-related data access, yet up to 72 percent of those confident organizations had experienced an unauthorized access incident in the past 12 months. Confidence built on documentation is not the same as control built on operational infrastructure.

The visibility gap is widening alongside it. The share of organizations unable to determine whether employees are using unsanctioned AI tools has nearly tripled in a single year, from 6.3 percent to 17.6 percent. For AI agents specifically, that blind spot reaches 21.1 percent. You cannot govern systems you cannot see — and in most cases, neither can your clients.

Most channel partners are already party to these conversations, as implementation partners, managed security providers or procurement advisors. The question is whether you are ahead of your clients on this or catching up alongside them.

Three conversations worth having now

  1. An AI governance assessment gives clients a baseline against the EU AI Act, NIST AI RMF, or SEC disclosure expectations. Most do not know where they stand. Helping them find out is the type of conversation that consistently surfaces deeper remediation work.
  2. The audit trail conversation addresses a gap most clients have not yet recognized: the AI tools they are deploying are often not producing the activity logs a regulator will ask for. This is a discoverable, high-urgency problem.
  3. The data visibility conversation gets to the foundation. Governance frameworks consistently ask the same underlying question: do you know what data your AI systems are touching, and can you prove it? Data visibility and access controls are the prerequisite layer that board-level AI governance discussions typically miss. Partners who can articulate this gap credibly and help close it are positioned as strategic advisors rather than procurement channels.

The window for leadership is open

The organizations building AI governance infrastructure now, before a regulatory deadline forces the issue, will have a measurable advantage. Their channel partners will too.

The compliance gap is not a technical problem that will resolve itself as AI matures. It is an organizational and operational one, and it is the kind of problem the channel has always moved fastest to solve. The only question is who builds that practice first.


ChannelE2E Perspectives columns are written by trusted members of the managed services, value-added reseller, and solution provider channels or ChannelE2E staff. Do you have a unique perspective you want to share? Check out our guidelines here and send a pitch to [email protected].

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Ronan Murphy

Ronan Murphy is the Chief Data Strategy Officer at Forcepoint. He is an accomplished executive with over 20 years of experience in the tech industry.
Ronan is the Founder and Executive Chairman of Smarttech247 Group Plc, a multi-award-winning managed cybersecurity company. Ronan is also the Co-founder of Getvisibility, one of the world’s leading AI data governance & security software companies.

Recognized for his expertise, Ronan has been honored with membership in the Artificial Intelligence Advisory Council in Ireland. This council is composed of experts from various fields and is tasked with providing independent advice to the Irish government on AI policy.

You can skip this ad in 5 seconds