A-LIGN's take on AI code reviews (AI-only vs. human-in-the-loop):
Bottom line: They're not seeing fully AI-only code review (no human) accepted as standard. Most clients keep a human at the approval/push-to-prod step, especially for higher-risk changes. Auditors are tool-agnostic โ what matters is a controlled, accountable, risk-based process. Core evidence stays the same; AI review just adds AI-governance evidence on top.
ISO 27001: Not prescriptive about the tool or the technology. Needs an effective, risk-based change process with clear accountability and oversight.
ISO 42001: Human-in-the-loop is tiered by risk โ high: human approves before the action; medium: human monitors and intervenes as needed; low: minimal/periodic human involvement, and could make a case no humans are needed for low-risk changes as long as automated process is in line with organizational change management process and controls. AI governance must be integrated into the broader GRC environment.
SOC 2: AI in review is accepted, provided control activities exist around the AI tool/agent. Note: AICPA is updating SOC 2 for emerging tech โ draft updates expected Q4, clearer requirements by year-end.
FedRAMP 20x: Likely fine. CM KSIs already expect automation (persistent, automated testing/validation of changes). AI review with proper guardrails fits 20x's direction.
Evidence: Existing artifacts unchanged (PR record, review comments, approval, CI results, branch protection, audit log) โ only reviewer identity changes. AI review adds four things: logical access (who can access/modify agents, in the UAR), drift/hallucination monitoring and response, CI/CD integration config, and CI/CD security thresholds and their update process.