Internal audit has two AI responsibilities
Anthony Pugliese’s discussion of global AI trends points to a dual mandate for internal audit. The function must learn to use AI responsibly in its own work while independently assessing how the wider organisation governs AI.
Those responsibilities cannot be separated. An audit team that cannot explain its own models, data, prompts and review controls will struggle to challenge the business credibly.
1. Approve use cases before choosing tools
Begin with a controlled list of audit use cases: document summarisation, population analysis, anomaly detection, risk sensing or draft working-paper support. For each use case, define what data may be used, what output is permitted and where human review is mandatory.
Do not place confidential audit evidence into an unapproved public tool. Vendor terms, retention, model training, access and data location should be assessed before use.
2. Preserve the evidence trail
AI can accelerate analysis, but it can also make conclusions difficult to reproduce. Working papers should retain enough context for an experienced auditor to understand how the result was produced and challenged.
| Evidence area | What to retain |
|---|---|
| Purpose | Approved audit objective and permitted AI use |
| Input | Source population, extraction date and completeness checks |
| Processing | Tool, model or version, material prompts and parameters |
| Output | Generated result and exceptions identified |
| Review | Auditor validation, corrections and final conclusion |
| Security | Data classification, access and deletion evidence |
3. Keep professional judgement accountable
AI may identify patterns, but it does not accept audit risk or sign an opinion. The audit lead remains accountable for scope, sampling, contradictory evidence, materiality and conclusions. Every material AI-assisted result needs a named reviewer who can defend it without relying on the tool’s confidence score.
4. Audit enterprise AI as a lifecycle
An inventory is the starting point, not the audit programme. Internal audit should select systems based on impact and examine the full lifecycle:
- Approval and risk classification
- Data provenance, quality and permitted use
- Development, testing and independent validation
- Human oversight and appeal routes
- Security, access and supplier controls
- Monitoring for drift, incidents and unintended outcomes
- Change, retirement and record retention
5. Build AI capability without weakening independence
Pugliese highlights the need for continuous upskilling. Audit teams need enough technical understanding to challenge model owners while preserving independence. Training should cover data literacy, model limitations, privacy, cybersecurity, bias, evidence reliability and the organisation’s governance requirements.
Internal audit can advise on control design before deployment, but management must own the decisions and operate the controls. Document that boundary clearly.
Questions for the audit committee
- Which AI systems could materially affect customers, employees, safety or reporting?
- Who owns each outcome and who can stop deployment?
- Has internal audit assessed the completeness of the AI inventory?
- Can management demonstrate human oversight and incident escalation?
- Is the audit function’s own AI use governed and reviewable?
ICyberWave perspective
AI does not remove the need for audit evidence; it raises the standard for traceability and challenge. ICyberWave supports AI-governance audits, evidence design, control testing and internal-audit readiness. Use our audit working papers guide and ISO 42001 guide to develop your assurance plan.

