The number of regulatory frameworks that involve assessments of AI systems for various reasons has exploded in a short time and yet there is little consensus on questions like why, when, how, and for whom they should be done in the first place.
Big Four firm EY, in a recent report, said (citing the OECD) that there are currently over 1,000 AI policy initiatives that include legislation, regulations, voluntary initiatives and agreements in 70 different countries. Despite all being concerned with AI, they often differ in their overall policy objectives, the subject matter being assessed, the purpose behind the assessments, the methodology for conducting them, who is expected to perform the assessment, and even the terminology used to describe them. “AI has been advancing faster than many of us could have imagined, and it now faces an inflection point, presenting incredible opportunities as well as complexities and risks. It is hard to overstate the importance of ensuring safe and effective adoption of AI. Rigorous assessments are an important tool to help build confidence in the technology, and confidence is the key to unlocking AI’s full potential as a driver of growth and prosperity,” said Marie-Laure Delarue, EY’s global vice chair of assurance.
On this last point, this is the reason why EY chose to simply use the term “assessment” to describe the veritable galaxy of different ways of inspecting AI systems.
The EY offices in London.
Jack Taylor/Photographer: Jack Taylor/Getty
Overall, though, the firm identified three main types of assessments based on looking at all the different regulatory frameworks, from international to national to state to local:
Governance assessments: To determine whether appropriate internal corporate governance policies, processes and personnel are in place to manage an AI system, including in connection with that system’s risks, suitability and reliability.
Conformity assessments: To determine whether an organization’s AI system complies with relevant laws, regulations, standards, or other policy requirements.
Performance assessments: To measure the quality of performance of an AI systems’ core functions, such as accuracy, non-discrimination and reliability. They often use quantitative metrics to assess specific aspects of the AI system.
EY conceded that the categorization can be a little slippery sometimes, an assessment that evaluates governance over an AI system, for example, may also be an assessment of conformity such as an assessment of an organization’s AI Management System against the ISO/IEC 42001 standard. The report said that confusion over the myriad AI assessment frameworks can make it difficult to ensure consistent quality and accountability. Even when the objectives align, the specific requirements may still vary across jurisdictions: For example, various U.S. cities and states have policies that include assessments for bias in the AI systems used in hiring and employment, all with different requirements. NYC Local Law 144, for example, has different requirements for measuring bias than the state laws requiring bias assessments in Colorado and Illinois.
There is also little uniformity over things that build confidence in conclusions, such as the extent of evidence required or the requirements for the providers of the assessments. EY noted, though, that assessments conducted by third parties may be viewed as more credible than those conducted by internal teams, especially if third party providers adhere to standards of professional responsibility, ethics and public reporting that internal teams might not be obligated to follow.
Another complicating factor is that mandatory AI assessments that evaluate compliance with a regulation will often be very different from voluntary assessments against a governance standard, such as the voluntary AI Risk Management Framework of the US National Institute of Standards and Technology (NIST).
The report also noted that while there can be very little specificity when it comes to terminology, particularly where it concerns broad terms like “fairness,” “trustworthiness” and “transparency,” which can create ambiguity unless specified further. Without this specificity, the usefulness of certain assessments may be more easily called into question.
There’s also the fact that AI systems themselves are often complex, integrated into larger environments and involve multiple stakeholders, making it difficult to even identify the appropriate subject matter for an assessment. Further, the variation in a model’s results over time (“model drift”) can make assessment outcomes outdated and misleading, and the variability of AI systems can complicate reproducibility. Lastly, the rapid advancement of AI technology may outpace the development of technical standards for evaluating performance.
The EY report said professionals need to understand just what, specifically, they’re assessing and do so with a well-specified business or policy objective. The purpose should then inform the selection of appropriate methodologies and reference standards. AI assessment frameworks should also have a clear and sufficiently defined scope, including the type of assessment (e.g., governance, conformity or performance), the subject matter, and guidance regarding when the assessment should occur.
When determining who should actually perform the assessment, EY said people should keep in mind the competency and qualifications, the objectivity and the professional accountability requirements of potential providers. This is not only to hold the provider accountable, EY said those that follow these standards and guidelines enable confidence and help stakeholders understand how assessments are provided.
The report said business leaders should consider having someone assess their AI systems regardless of whether there is a regulatory requirement to do so, as they can help identify and manage evolving risks, as well as whether the systems work as intended. Further, market dynamics, investor demand or internal governance considerations may make a voluntary AI assessment advisable to build confidence in a business’s AI systems. Moreover, if some AI systems are subject to regulatory obligations, business leaders may choose to use assessments to help measure and monitor compliance.
“As businesses navigate the complexities of AI deployment, they are asking fundamental questions about the meaning and impact of their AI initiatives. This reflects a growing demand for trust services that align with EY’s existing capabilities in assessments, readiness evaluations, and compliance,” said Delarue.
The report calls to mind another published last month by the AICPA and Chartered Professional Accountants Canada which said the rapid rise of AI throughout the global economy opens up new opportunities for accounting professionals to provide independent assurance of these systems to help build trust and confidence in their functions.
It made a similar point to the EY report as well in saying that many are colloquially using terms like “AI audit” or “AI assurance,” to refer to a variety of different types of engagements and assessments. The report noted that some of the services described as assurance services are performed by entities, such as technology consultancies or internal audit teams, that may not follow the same professional standards as assurance engagements performed by CPAs.
The report clarified that what they mean is an engagement in which an assurance practitioner designs and performs procedures to obtain sufficient appropriate evidence, based on the practitioner’s consideration of risk and materiality, in order to express an opinion or conclusion about the subject matter in the form of an assurance report. The two organizations see great opportunity in this area, though not without challenges.
As corporate accounting departments cross the threshold into late July 2026, the adoption of continuous, automated auditing systems has reached a definitive turning point. Driven by advances in artificial intelligence and deep integration with modern Enterprise Resource Planning (ERP) platforms, leading finance organizations are moving away from traditional, periodic post-hoc audits in favor of real-time, 100% transactional verification. This technological transition is redefining internal control environments, reducing compliance costs, and eliminating the structural delays inherent in legacy quarterly closing processes.
Unlike traditional auditing frameworks that rely on statistical sampling—a process that inevitably leaves operational blind spots—continuous auditing software monitors operational data feeds continuously. Every purchase order, electronic invoice, payroll disbursement, and cross-border wire transfer is automatically cross-referenced against established corporate governance parameters, regulatory tax schedules, and anti-fraud algorithms in real time. Anomalies or unauthorized ledger entries are flagged instantly, allowing internal audit teams to investigate and remediate compliance gaps immediately rather than months after the close of a financial period.
The implications for executive financial management are far-reaching. By embedding continuous verification directly into daily transaction workflows, chief financial officers gain uninterrupted visibility into the organization’s true financial standing. Real-time balance sheet auditing eliminates the severe operational bottlenecks associated with month-end and quarter-end financial reconciliations, freeing accounting professionals to focus on strategic financial modeling, tax planning, and capital allocation rather than manual data entry and spreadsheet consolidation.
However, implementing continuous auditing requires accounting leadership to invest heavily in data governance and technical upskilling. Internal audit teams must evolve from manual ledger reviewers into system architects capable of auditing complex algorithms and validating automated data pipelines. Accounting firms and corporate controllers that master continuous auditing will establish a resilient compliance framework capable of meeting stringent international regulatory standards with total transparency.
WASHINGTON — In a major escalation of cross-border trade friction, U.S. President Donald Trump has signed executive orders imposing new 50% tariffs on a wide selection of Canadian exports, citing discriminatory practices by Ottawa targeting American auto, dairy, and beverage industries.
The new duties, announced Monday, will take effect in 30 days. They target a broad spectrum of consumer and industrial goods—ranging from wine, liquor, and milk products to commercial cement, furniture, clothing, and hockey equipment.
Untested Legal Mechanism
To enact the sweeping measures, the administration invoked Section 338 of the Tariff Act of 1930—a rarely used legal provision allowing the executive branch to levy additional tariffs of up to 50% on foreign nations deemed to discriminate against U.S. commerce.
White House officials noted that Section 338 addresses trade discrimination rather than national security or economic emergencies. The move comes months after prior global emergency tariffs faced legal challenges in domestic courts, signaling Washington’s pivot toward alternate statutory authorities to maintain import duties.
Senior administration officials briefed reporters that the measure directly responds to Canadian provincial bans on U.S. alcohol, restrictions on American vehicle exports, and import quota disparities affecting U.S. dairy and cheese producers relative to third-party trading partners.
“While the administration continues to secure reciprocal trade agreements globally, Canada retaliated against efforts to protect domestic industry,” U.S. Trade Representative Jamieson Greer stated.
USMCA Impact and Carve-Outs
Significantly, the newly ordered 50% duties will apply to designated items even if they otherwise comply with the United States-Mexico-Canada Agreement (USMCA).
However, the administration confirmed key targeted exemptions:
Energy products (including oil and natural gas)
Potash and critical minerals
Fish and seafood
Goods already governed by sector-specific duties (such as existing steel and aluminum tariffs)
Administration representatives emphasized that the tariffs do not stem from recent disputes concerning drifting Canadian wildfire smoke, noting that policy options regarding environmental spillover remain under separate review.
Canadian Response and Market Reaction
Following the White House announcement, the Canadian dollar experienced a sharp decline against the U.S. dollar, falling approximately 0.4% during evening trading.
Canadian Prime Minister Mark Carney issued a statement emphasizing that Canada’s earlier counter-duties had merely matched previous U.S. trade actions. “Canada stands ready to engage intensively to address outstanding issues with the U.S. to the mutual benefit of our citizens,” Carney stated, pointing to detailed proposals Ottawa submitted to modernize the USMCA framework.
Ontario Premier Doug Ford took a firmer stance, urging a “dollar-for-dollar” reciprocal response if the measures go into effect on August 19.
With a 30-day implementation window before the duties officially lock in, industry associations and trade groups on both sides of the border are calling for urgent bilateral negotiations to avert further supply chain disruption across North America.
The traditional accounting paradigm—defined by periodic monthly closures and post-hoc annual audits—is rapidly giving way to continuous, automated financial oversight. As of July 2026, forward-thinking accounting practices and multinational corporate finance departments are leveraging continuous auditing systems powered by advanced machine learning models. These systems monitor operational transactions in real time, shifting audit methodologies from sample-based post-analysis to absolute, 100% transaction-level verification.
The operational advantages of continuous auditing are transformative. Standard auditing procedures historically relied on statistical sampling, which, despite rigorous methodology, inherently left gaps where anomalies or fraudulent transactions could go undetected for months. Modern continuous auditing platforms integrate directly with enterprise resource planning (ERP) databases, instantly cross-referencing purchase orders, invoices, bank feeds, and tax records. Any deviation from established control parameters or unusual transaction behavior triggers immediate flags for internal audit teams, dramatically reducing detection lag from quarters to seconds.
Beyond fraud prevention, continuous auditing fundamentally alters internal reporting and decision-making. Executive leadership no longer has to wait weeks after the close of a quarter to evaluate precise financial standing; real-time verified ledger data provides an uninterrupted view of operating margins, tax liabilities, and cash flow dynamics. This real-time visibility enables corporate controllers to adjust capital allocation strategies dynamically, mitigating liquidity constraints and capitalizing on emerging commercial opportunities far more efficiently than competitors bound to legacy reporting cycles.
However, implementing continuous auditing requires accounting professionals to acquire new analytical capabilities. The role of the auditor is evolving from manual data reconciliation toward system validation, algorithmic model governance, and strategic risk interpretation. Accounting firms and corporate finance departments must invest in continuous technical education, ensuring that audit staff possess the data engineering skills necessary to design, maintain, and evaluate complex automated compliance systems.