Our Mission
AuditDIFF helps people and organizations understand governance requirements, what good implementation looks like, and how independent assurance can build trust.
Why AuditDIFF Exists
Audits create value when the results provide credible information about whether requirements have been met. That value declines when criteria are difficult to interpret. Value also declines when evidence requests become disconnected from risk or when an audit becomes a recurring collection exercise.
AuditDIFF explores a more useful model. Requirements should connect to governance decisions. Decisions should connect to implementation. Implementation should leave evidence. Auditors should be able to test that evidence against defined criteria.
Audits Should Work for Both Sides
For an auditee, a good audit should make expectations understandable and reduce unnecessary evidence collection. The process should identify meaningful gaps and leave the organization with a clearer view of what needs to improve.
For an auditor, the same process has to support independence and professional judgment. Criteria need to be testable. Evidence needs to be relevant and reliable. The auditor needs enough information to corroborate claims rather than simply accept management statements.
These interests are compatible. Clearer requirements can reduce friction for the organization. Stronger evidence and repeatable testing can increase confidence for the auditor.
AI Governance Is the Wider Frame
AI governance connects privacy, cybersecurity, risk, accountability, human oversight, and other disciplines that organizations have often managed separately. Modern enterprise AI also operates across large networks of systems and dependencies. Hundreds or thousands of interconnections can influence a single business process.
Human review alone cannot scale at the speed of automated systems. AI can execute or influence decisions far faster than human judgment can examine each event. Audit and governance therefore need engineering mechanisms that can operate at comparable scale. Automated evidence collection, continuous control testing, reproducible tests, machine-readable criteria, change detection, and traceability can make assurance more timely without removing human judgment.
Automation should strengthen professional judgment rather than replace the auditor. Engineering can handle repeatable collection and comparison. People remain responsible for context, materiality, exceptions, interpretation, and conclusions.
What Does “DIFF” Mean?
In software engineering, a diff shows what changed between two versions. That idea is useful for audit. Instead of repeatedly reconstructing the entire state of a system, an assurance process can focus attention on meaningful changes: a control changed, a model changed, a vendor changed, a risk changed, or evidence no longer matches the expected state.
AuditDIFF also means auditing differently. The name reflects an engineering approach to assurance: make changes visible, preserve traceability, automate repeatable work, and direct human attention toward the differences that require judgment.
Why Start With California Privacy?
California is a practical early test case because a major CCPA rulemaking package is now in effect. The regulations create a sequence of implementation and assurance milestones for risk assessments, cybersecurity audits, and automated decisionmaking technology.
Risk-assessment compliance began January 1, 2026. The first required summary information and attestation are due to the California Privacy Protection Agency by April 1, 2028. ADMT requirements for significant decisions begin January 1, 2027. Cybersecurity-audit reporting and certification deadlines are phased beginning April 1, 2028, based on the applicable revenue tier.
California therefore provides a useful environment for testing the AuditDIFF model. Organizations must interpret requirements and make governance decisions. Covered activities create records and evidence. Some businesses must prepare for independent cybersecurity audits. The regulatory timeline gives this project concrete problems to study rather than hypothetical ones.
Better Audits Can Build Public Trust
Assurance ultimately matters because people rely on systems they cannot fully inspect for themselves. Customers, workers, regulators, business partners, and members of the public may need confidence that an organization has done more than publish a policy or make a claim.
Better audits can narrow that trust gap. Clear criteria make expectations visible. Reliable evidence makes claims testable. Independent review provides a basis for confidence that does not depend solely on the organization being reviewed.
Audit cannot guarantee that harm will never occur. Strong assurance can make governance more transparent and accountable. The result is a more credible basis for trust.
ForHumanity and the Infrastructure of Trust
ForHumanity is a nonprofit public charity focused on the risks associated with artificial intelligence, algorithmic systems, and autonomous systems. The organization develops audit criteria, certification schemes, and education through an open and transparent contributor process.
ForHumanity describes the mission as examining downside risk from AI and automation and engaging in risk mitigation to maximize the benefits of these systems. Independent Audit of AI Systems is central to that work. The broader objective is an infrastructure of trust supported by independent audit.
AuditDIFF is inspired by that vision. This project explores many of the same questions about auditability, evidence, accountability, and trust. AuditDIFF remains an independent project rather than an official ForHumanity program, certification, or product.
How AuditDIFF Publishes
AuditDIFF separates source material from explanation. Legal definitions should look like legal definitions. Regulatory requirements should be identified as regulatory. Standards and ForHumanity terminology should retain their source and authority. AuditDIFF explanations should remain visibly distinct.
Content is organized around practical questions. What is required? What does the requirement mean in practice? What implementation could satisfy the requirement? What evidence could demonstrate implementation? How could an independent reviewer test the evidence?