Galicia's audit-body AI policy requires corroborating evidence and restricts profiling, subject to an express exception

Correction, October 1, 2026. This article restores the express exception to the profiling restriction, distinguishes document identification from annual public reporting and removes an unsupported claim that internal operating rules do not yet exist. The displayed publication date is aligned with the original August 21 record; its timestamp is unchanged.

Galicia Audit Body: AI Output Is Not Sufficient Evidence Alone. The Leveraged Years regulation briefing card.

A public audit institution has published a binding AI policy for its own staff. It states that an AI output is auxiliary and is not sufficient and adequate audit evidence on its own.

The short version

Bottom line: The published policy specifies entry into force on August 21, 2026, the day after publication in the Diario Oficial de Galicia. This review examines that text and has not established whether it was later amended.

The provision that travels: Article 16 provides that results generated by AI systems are auxiliary and do not by themselves constitute sufficient and adequate audit evidence, and that their use must be corroborated by other evidence obtained under the applicable auditing standards.

Prohibitions and exception: Mass or indiscriminate processing of personal data and audit data through AI. Systems that knowably or probably produce discriminatory bias or unfair results. Article 15.4 also prohibits profiling, behavioural prediction, individual risk evaluation or classification of people in the Council's functions, except cases expressly permitted by applicable law and duly authorised.

Who it binds: The Consejo de Cuentas de Galicia and its own staff. It is not a rule for audited entities or for private audit firms. Readers outside the Council can examine its approach without treating it as a rule applicable to them.

Primary sources: Diario Oficial de Galicia num. 157, 20 August 2026, full text · Consejo de Cuentas de Galicia

Editorial Note
Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.
Instrument (EN)
Policy on the use of artificial intelligence in the Consejo de Cuentas de Galicia
Instrument (ES)
Politica de uso de la inteligencia artificial en el Consejo de Cuentas de Galicia
Authority
Consejo de Cuentas de Galicia, the external public-audit body of the Autonomous Community of Galicia
Jurisdiction
Galicia, Spain. Applies to the institution itself
Adopted
Acuerdo del Pleno of 29 July 2026, ordered published by Resolution of 13 August 2026
Published
Diario Oficial de Galicia num. 157, 20 August 2026, section III Otras disposiciones
In force
The day after publication, 21 August 2026, under its single final provision
Bindingness
Binding on the Council and its personnel. Misuse may give rise to responsibilities under applicable law
Signed
Juan Carlos Aladro Fernandez, Consejero mayor
Primary source
https://www.xunta.gal/dog/Publicados/2026/20260820/AnuncioO10-130826-0001_es.html

The sentence that makes this worth reading outside Galicia

First, the scope, because everything below depends on it. This policy binds only the Consejo de Cuentas de Galicia and its own staff. It does not apply to private audit firms, to audited entities, to other Spanish autonomous communities, to national Spanish institutions, or to any jurisdiction outside this one regional public-audit body. It is an internal rule that happens to have been published in a gazette.

With that established: an external audit institution has written down, in a published and binding instrument, that an AI output is not sufficient audit evidence on its own.

Article 16 provides that results generated by artificial intelligence systems have an auxiliary character and do not by themselves constitute sufficient and adequate audit evidence, and that their use must be corroborated through other sources of evidence obtained in accordance with the applicable auditing standards.

Article 16 states a specific requirement for the Council's use of AI. It does not establish a general auditing standard for other organisations.

A reader elsewhere may compare this requirement with their own applicable standards and procedures. This article does not assess the content of other organisations' internal policies.

What it prohibits

The prohibitions are specific rather than atmospheric. Article 8.3 prohibits the mass or indiscriminate processing of personal data and of audit data through AI systems. Audit data is defined broadly, covering draft reports, working papers, correspondence with audited entities and reserved information.

Article 9.1 prohibits the use of AI systems that, knowably or probably, produce discriminatory biases or unfair results. Article 9.3 requires the risk of known or foreseeable bias to be assessed before a system is authorised, and 9.4 requires periodic evaluation to catch biases that were not apparent at authorisation.

Article 15.4 expressly prohibits using AI to build profiles of natural persons, predict behaviour, evaluate individual risks or classify subjects in the exercise of the Council's functions, except where expressly authorised by law and duly authorised internally.

The exception is part of article 15.4 and should accompany any summary of the restriction. The policy does not identify a specific authorised profiling project.

Authorisation, and a register of what is forbidden

Article 13 makes every corporate AI system subject to prior authorisation. Authorised systems are reviewed at least every two years, and a review can confirm, condition or revoke the authorisation.

The Council keeps a register of authorised and prohibited systems, and the policy states that all personnel must know and observe it. Article 12 also refers to conditionally authorised systems and requires the register to be accessible to personnel.

Article 13.4 permits personnel to use other systems subject to three conditions. Staff may use other AI systems only where the information used comes exclusively from open sources, where no Council data or information classified as limited-circulation or confidential is incorporated directly or indirectly, and where the results are not incorporated into audit work in progress.

The policy creates a Committee chaired by the Consejero mayor or a delegate, with an auditor from each sectoral department, the head of IT and the Data Protection Officer. The Secretary General or a delegate serves as secretary. Its functions include authorisation, internal standards and the register. The annual AI-use report enters the Council's annual report and is made public through its transparency portal, with information-security and legitimate-interest redactions.

The disclosure duty inside the working papers

Article 17 requires that every use of AI be documented, and specifically in the audit working papers. More than that, any document produced in the Council in which AI is used must state that fact, the system used, and the person responsible for validating it.

Article 17 covers working papers and all Council-generated documents using AI. Its wording should not be reduced to internal files alone. Article 12 separately requires publication of the annual report's content, subject to stated redactions.

Article 15.3 sets the boundary of what the tool may produce at all. AI may not draw audit conclusions, make formal recommendations, produce legal qualifications, take automated decisions, form professional judgments or make assessments of responsibility.

Article 18 closes it. Full responsibility for the conclusions, valuations and recommendations in audit reports rests with the audit staff and the competent organs, and the policy states that the use of AI neither alters nor attenuates that responsibility.

Why a regional audit body wrote its own rules

The Council states in its preamble that Galicia has an AI law, Ley 2/2025 of 2 April, on the development and promotion of artificial intelligence in Galicia, and that this law does not include the Consejo de Cuentas within its subjective scope. According to the same preamble, the Council nonetheless takes up the principles of that law in exercise of its organisational autonomy as a statutory body.

We report that as the preamble states it. We have not read Ley 2/2025 and we make no claim about what the statute actually contains or requires; the only thing established here is what this policy says about its own relationship to it.

The practical point for a reader is narrower than it looks. An institution not covered by its region's AI statute adopted comparable principles through internal rules instead. How AI governance reaches bodies that sit outside a statute's scope is a live question in a lot of jurisdictions, and this is one worked example of it.

What we did not verify

We read the policy in full as published in the Diario Oficial de Galicia. Every provision described above comes from that text.

We have not read Ley 2/2025 of Galicia. Where we mention it, we report only what this policy's preamble says about its own scope in relation to it, and we make no claim about the statute's content.

The policy's preamble refers to a number of other documents as background. We have not read any of them, so we do not describe them, do not treat them as comparators, and do not rely on them for anything stated above.

We did not check whether other Spanish regional audit bodies have adopted comparable policies. We therefore make no claim that this is the first, the only, or an unusual instrument, and readers should not infer one.

Article 11.3 provides for the Committee to draft internal operating rules for approval by the Pleno. That future-tense provision does not establish whether the rules have since been adopted; their present status was not verified.

We have not seen the register of authorised and prohibited systems, and we do not know whether it will be published or held internally. The policy requires personnel to know it; it does not on its face require publication of the register itself.

Key compliance takeaway

Under the published Council policy, AI output is auxiliary and requires corroboration under applicable auditing standards. Every use must be documented, especially in audit working papers; Council documents using AI must identify that use, the system and the validator. Profiling restrictions include an express legal-authorisation exception. These are requirements for the Council, not a general rule for private audit firms.

Source File

https://www.xunta.gal/dog/Publicados/2026/20260820/AnuncioO10-130826-0001_es.html

Open Diario Oficial de Galicia num. 157 of 20 August 2026 and find the Resolution of 13 August 2026 of the Consejo de Cuentas de Galicia in section III. Read article 16 for the audit-evidence rule, article 15.3 and 15.4 for what AI may not produce and the profiling prohibition, article 8.3 and 9.1 for the two outright prohibitions, article 13 for prior authorisation and the register, and article 17.2 for the duty to name the system and the validator in any document. The single final provision gives entry into force the day after publication.

Los resultados generados por sistemas de inteligencia artificial tendrán carácter auxiliar y no constituirán por sí mismos evidencia de auditoría suficiente y adecuada · Consejo de Cuentas de Galicia, politica de uso de la inteligencia artificial, articulo 16.1, DOG num. 157, 20 August 2026

FAQ

Does this bind private audit firms or audited entities?

The policy regulates AI use within the Consejo de Cuentas de Galicia. It does not establish a general rule for audited entities or private audit firms. Those organisations must assess their own applicable obligations.

What does it say about AI output as audit evidence?

Article 16 provides that results generated by AI systems are auxiliary in character and do not by themselves constitute sufficient and adequate audit evidence, and that their use must be corroborated by other sources of evidence obtained in accordance with applicable auditing standards.

Does an auditor have to disclose that AI was used?

Article 17 requires every use of AI to be documented, especially in audit working papers. All Council-generated documents using AI must identify the use, system and validator. Article 12 separately requires publication of annual AI-use report content, subject to information-security and legitimate-interest redactions.

When did it take effect?

The policy was published in the Diario Oficial de Galicia number 157 on 20 August 2026, and its single final provision states that it enters into force the day following publication. That is 21 August 2026. It was adopted by the Pleno on 29 July 2026 and ordered published by a Resolution of 13 August 2026.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.