Deployer Assurance Checklist (CA IVO Voluntary)
SB 813 Ch.179 is a voluntary IVO path — not a California operating license
Operator checklist for California deployers who may later want an Independent Verification Organization assessment. Senate Bill 813 (McNerney) was approved by the Governor and filed with the Secretary of State on 2026-09-09 as Chapter 179, Statutes of 2026. It directs the Government Operations Agency, on or before 1 January 2028, to develop IVO application requirements, designation criteria, and suspension procedures. Government Code §8898.4(a)(3) states the chapter does not require any person that develops, deploys, or operates an AI system or model to engage an IVO or undergo a covered AI audit as a condition of operating in California. Do not treat unsigned bills as law. Companion context from the same 2026-09-09 Governor Newsom signing post: Assembly Bill 1405 (Bauer-Kahan) creates a state registry for AI auditors — registry/independence standards, not an IVO-to-operate mandate. Primaries: LegInfo SB 813 chaptered text; Governor Newsom 2026-09-09 AI safeguards post.
Core Workflows (6)
Each workflow represents a critical business function. Click any workflow to see detailed automation architecture.
Read the chaptered statute, not a draft
Led by: DeployerUse the LegInfo chaptered bill text (SB 813, Chapter 179, Statutes of 2026; approved/filed 2026-09-09). Definitions that matter: IVO means an AI auditor designated by GovOps as having demonstrated expertise assessing risks of an AI system or model and identifying the metrics and methodologies behind that assessment. Ignore unsigned or un-chaptered bills (including AB 1883 and similar) as if they were current California law.
Scope the voluntary path
Led by: Deployer§8898.4(a) is explicit: the chapter does not establish liability solely for failure to comply with a standard under the chapter; does not constitute state endorsement of any AI system; does not require IVO engagement or a covered AI audit to develop, deploy, or operate in this state; and does not require an IVO to conduct legal-compliance audits merely to register. Operate first; IVO is optional assurance, not a permit.
Track GovOps criteria (due 1 January 2028)
Led by: DeployerOn or before 1 January 2028, GovOps must develop IVO application requirements (qualifications, designation criteria, proposed benchmarks/metrics/methodologies), procedures to suspend or terminate designation (including independence, misrepresentation, cybersecurity lapses), and published criteria for who qualifies. The agency must convene working groups (including engineers from competing AI companies and AI safety experts) and report findings to the Legislature. Until those criteria exist, there is no designated IVO list to “check the box” against.
Assemble a deployer evidence pack
Led by: DeployerIf you want to be ready for a future voluntary IVO, collect what the statute says IVOs will be judged on: risk assessment of the system or model in operation, metrics and methodologies, technical expertise, conflict-of-interest and independence controls, and documentation. Keep that pack as operator evidence. Do not claim a legal safe harbor — §8898.4(b) says a standards-aligned audit is relevant to, but not conclusive of, a harm action.
Note AB 1405 as companion context only
Led by: DeployerThe Governor’s 2026-09-09 signing post also covers AB 1405 (Bauer-Kahan): a state registry for AI auditors with independence, transparency, and integrity standards. Use it as companion context for who may later appear on a registry. It is not a substitute for SB 813’s voluntary IVO path and it is not a requirement to engage an IVO before operating.
Optional IVO engagement (after designation exists)
Led by: DeployerOnce GovOps designates IVOs, a deployer may voluntarily engage one. A designated IVO must report annually to the agency and Legislature no sooner than 12 months after initial designation (standards/methodologies, governance/funding relevant to independence, application-info changes), with allowed redactions for trade secrets, cybersecurity, public safety, or national security. Until designation exists, skip this step.