Internal Audit

    AI in Internal Audit: Five Assurance Priorities from IIA CEO Anthony Pugliese

    ICyberWave Editorial
    Sep 26, 2026
    Internal Audit
    Internal audit team reviewing evidence, approvals and assurance records

    Internal audit has two AI responsibilities

    Anthony Pugliese’s discussion of global AI trends points to a dual mandate for internal audit. The function must learn to use AI responsibly in its own work while independently assessing how the wider organisation governs AI.

    Those responsibilities cannot be separated. An audit team that cannot explain its own models, data, prompts and review controls will struggle to challenge the business credibly.

    1. Approve use cases before choosing tools

    Begin with a controlled list of audit use cases: document summarisation, population analysis, anomaly detection, risk sensing or draft working-paper support. For each use case, define what data may be used, what output is permitted and where human review is mandatory.

    Do not place confidential audit evidence into an unapproved public tool. Vendor terms, retention, model training, access and data location should be assessed before use.

    2. Preserve the evidence trail

    AI can accelerate analysis, but it can also make conclusions difficult to reproduce. Working papers should retain enough context for an experienced auditor to understand how the result was produced and challenged.

    Evidence areaWhat to retain
    PurposeApproved audit objective and permitted AI use
    InputSource population, extraction date and completeness checks
    ProcessingTool, model or version, material prompts and parameters
    OutputGenerated result and exceptions identified
    ReviewAuditor validation, corrections and final conclusion
    SecurityData classification, access and deletion evidence

    3. Keep professional judgement accountable

    AI may identify patterns, but it does not accept audit risk or sign an opinion. The audit lead remains accountable for scope, sampling, contradictory evidence, materiality and conclusions. Every material AI-assisted result needs a named reviewer who can defend it without relying on the tool’s confidence score.

    4. Audit enterprise AI as a lifecycle

    An inventory is the starting point, not the audit programme. Internal audit should select systems based on impact and examine the full lifecycle:

    • Approval and risk classification
    • Data provenance, quality and permitted use
    • Development, testing and independent validation
    • Human oversight and appeal routes
    • Security, access and supplier controls
    • Monitoring for drift, incidents and unintended outcomes
    • Change, retirement and record retention

    5. Build AI capability without weakening independence

    Pugliese highlights the need for continuous upskilling. Audit teams need enough technical understanding to challenge model owners while preserving independence. Training should cover data literacy, model limitations, privacy, cybersecurity, bias, evidence reliability and the organisation’s governance requirements.

    Internal audit can advise on control design before deployment, but management must own the decisions and operate the controls. Document that boundary clearly.

    Questions for the audit committee

    1. Which AI systems could materially affect customers, employees, safety or reporting?
    2. Who owns each outcome and who can stop deployment?
    3. Has internal audit assessed the completeness of the AI inventory?
    4. Can management demonstrate human oversight and incident escalation?
    5. Is the audit function’s own AI use governed and reviewable?

    ICyberWave perspective

    AI does not remove the need for audit evidence; it raises the standard for traceability and challenge. ICyberWave supports AI-governance audits, evidence design, control testing and internal-audit readiness. Use our audit working papers guide and ISO 42001 guide to develop your assurance plan.

    Hi! I'm your AI Assistant 💬