30-minute course for audit, risk, compliance, governance and technology professionals Governance • Risk • Controls • Assurance Paul Lucas Governance, Internal Audit and Risk Executive | AI Governance and Investigations AI Governance and Internal Audit: Practical Foundations 1
1 Why AI governance matters Strategic use, trust and organizational risk 2 Accountability and board oversight Roles, policies, decisions and escalation 3 Key AI risks How to use the course Listen for the governance logic, not a single universal checklist. AI risk varies by context, use case, impact and organizational maturity. Data, bias, privacy, security and third parties 4 Controls across the lifecycle Intake, testing, oversight, monitoring and incidents 5 How internal audit assesses AI Planning, criteria, evidence, findings and reporting Practical outcome You should be able to ask better questions about AI accountability, controls, evidence and boardlevel reporting. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 2
It is not just a technology issue. Customer service, claims, eligibility and triage Procurement, HR, fraud detection and due diligence Governance question Where is AI being used, what decisions does it influence, who owns it, and what could go wrong? Cybersecurity, monitoring and investigations Document review, summarization and generative AI support Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 4
governance enables innovation. It does not simply block it. Not this “AI is too risky, so avoid it.” Not this “AI is technical, so governance can wait.” Aim for this “Use AI deliberately, with clear accountability, controls and monitoring.” Responsible AI governance gives leaders confidence to adopt useful tools while understanding trade-offs, limitations and risks. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 5
is not enough. Valid & reliable Safe & secure Fair & accountable Transparent Privacy-aware An AI system can be accurate in aggregate and still be unacceptable if it is unfair, insecure, opaque, unlawfully uses data or lacks meaningful human oversight. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 6
are predictable. Unknown or unapproved AI use Poor-quality or inappropriate data Biased or unfair outcomes Audit lens AI failures often reflect ordinary control failures in a new context: unclear ownership, weak evidence, poor monitoring, and inadequate challenge. Overreliance on automated recommendations Weak vendor and security controls No monitoring, incident response or escalation ! Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 7
confidence. Core message AI governance helps organizations use AI deliberately, proportionately and responsibly. Internal audit role Provide independent assurance and practical insight on whether AI risks are identified, controlled, monitored and reported. Ask first: what is the use case, who is affected, who owns the risk, and what evidence shows the controls work? Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 8
often means no one is accountable. Business owner Owns the use case, purpose, outcomes and risk acceptance. Technology owner Manages technical design, implementation, security and changes. Internal audit Provides independent assurance on governance, risk management and controls. Control functions Provide challenge on risk, legal, privacy, compliance, security and ethics. Board or committee Oversees material AI exposure, risk appetite and management actions. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 10
board needs decision-useful reporting. What boards need Material use cases, risk trends, incidents, risk acceptance, unresolved issues and management actions. What boards do not need Every parameter, line of code, technical tuning choice or vendor marketing claim. Effective oversight asks: is management using AI within risk appetite, with suitable controls, evidence and escalation? Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 11
governance connects strategy, risk and execution. Board oversight Risk appetite, challenge and visibility Executive ownership Priorities, accountabilities and resources AI governance forum Intake, classification, approval and escalation Use-case owners Controls, performance, data and incidents Assurance Independent review and continuous improvement Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 12
should answer practical questions. Which AI uses require approval? What data may not be entered into public tools? Who reviews high-impact use cases? Audit test Do policies exist, are they understood, and is there evidence that people follow them? When is human oversight required? How are incidents escalated? What evidence must be retained? Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 13
decisions and evidence. Look for Named owners, clear approvals, recorded decisions, defined escalation and evidence of challenge. Red flags Unclear ownership, shadow AI, ceremonial human review, weak board reporting and vendor-driven governance. Good AI governance is not the absence of risk. It is the presence of accountable, informed and documented decision-making. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 14
than one technical risk. Data quality Bias & fairness Privacy Security Model reliability Third parties Transparency Human overreliance The significance of each risk depends on the use case, affected people, decision impact and control environment. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 16
the data and assumptions behind it. Data questions Is the data relevant, lawful, accurate, complete, representative and fit for the intended purpose? Bias questions Do outcomes differ materially across relevant groups, contexts or locations, and has management assessed why? Audit evidence Lineage, quality checks, test results, limitations, approvals, exception handling and remediation. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 17
the way sensitive information moves. Personal data may be reused for new purposes Prompts may disclose confidential information Vendors may retain, train on or process data externally Control focus Approved tools, data-classification rules, contractual terms, access controls, logging, security testing and incident response. APIs and integrations may expand the attack surface Logs may contain sensitive data Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 18
does not transfer accountability. Before use Due diligence on purpose, data, security, explainability, performance, limitations and legal terms. During use Monitoring of performance, incidents, changes, subcontractors, support and service levels. If things go wrong Escalation rights, evidence preservation, suspension, remediation and exit or continuity planning. The organization remains responsible for how it selects, configures, uses and relies on AI services. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 19
not the same as accuracy. Risk Outputs may be plausible but false, incomplete, biased or unsupported. Risk Inputs may disclose confidential, personal or privileged information. Risk Users may skip verification because the output sounds authoritative. Control response Define allowed uses, require verification, protect sensitive data, retain appropriate evidence and maintain human accountability. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 20
impact. Lower scrutiny Low-impact productivity support, with limited data and no consequential decision effect. Higher scrutiny AI influencing important decisions, sensitive data, vulnerable groups, legal rights, finance, employment or safety. Classify AI risk by what the system does, who it affects, what data it uses, and what harm or value could result. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 21
changes over time. Intake Register and classify Design Define purpose and criteria Build / Buy Evaluate data, vendor and controls Deploy Approve, train and document Monitor Track drift, incidents and impacts Change / Retire Update, suspend or exit Audit principle A control that worked at launch may not be enough after the model, data, users or business context changes. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 23
what you cannot see. Defined intake process for new AI use cases Inventory records purpose, owner, data, vendor and risk class Approval thresholds for higher-risk uses Evidence to request Inventory extract, approvals, risk classification rationale, governance minutes, policy exceptions and recertification records. Exception process for unapproved or urgent use Periodic recertification of active AI systems Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 24
evidence-based, not assertion-based. Data Lineage, quality, representativeness, lawful use and limitations. Model Performance, robustness, bias, explainability and thresholds. Documentation Purpose, assumptions, limitations, approvals and change history. The question is not “did someone say it works?” The question is “what evidence shows it works appropriately for this use case?” Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 25
be meaningful. Meaningful oversight Qualified reviewers have information, time and authority to challenge, override or stop the AI-supported decision. Meaningful transparency Users and affected parties receive context-appropriate information about AI use, limitations and review options. Audit red flag A human approves nearly every AI recommendation without documented analysis. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 26
beginning of control, not the end. Monitor performance, drift, user behavior and adverse impacts Define thresholds that trigger investigation or escalation Preserve logs and evidence for incidents Manage function Risk treatment includes prioritization, response, recovery, communication and continual improvement. Control material model, data, vendor or use-case changes Suspend or restrict use when risk becomes unacceptable Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 27
and operating. Design Are the controls suitable for the AI use case and risk? Operation Is there evidence that the controls are performed? Adaptation Do controls respond when the system or context changes? AI assurance should test both the design and the operating effectiveness of lifecycle controls. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 28
every AI audit needs the same scope. Possible objective Assess whether governance, data, model, human oversight and monitoring controls manage material AI risks to an acceptable level. Scope variables Use case, impact, data sensitivity, jurisdictions, vendors, lifecycle stage and management maturity. Good planning narrows a broad AI topic into a focused, auditable engagement. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 30
basis beyond personal opinion. Organizational AI policy and risk appetite Applicable laws, regulations and contractual requirements NIST AI RMF, OECD AI Principles and other recognized frameworks Important If management has not defined criteria for fairness, transparency or acceptable risk, that gap may itself be an audit issue. IIA standards and internal audit methodology ISACA, COBIT and technology-governance practices Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 31
is rarely enough. Documents Policies, inventories, approvals, contracts, minutes, test reports and logs. Interviews Business owners, data teams, risk, legal, privacy, security, vendors and users. Testing Sample approvals, data controls, monitoring alerts, incidents, overrides and changes. The finding should connect criteria, condition, cause, impact and recommendation. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 32
Avoid Technical detail without business meaning, vague warnings, or generic statements that AI is risky. Aim for Clear risk statements, evidence, impact, residual risk, ownership, timelines and decisions needed. Useful AI reporting helps management and the board act, not merely admire the complexity. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 33
this as a practical starting point. 1. Confirm AI inventory and ownership 2. Identify material use cases and affected stakeholders 3. Review policies, approvals and risk classification Downloadable resource idea Convert this checklist into a one-page PDF for learners and include it as a course resource. 4. Test data, vendor, security and human oversight controls 5. Evaluate monitoring, incidents and change management 6. Report material gaps, residual risk and required decisions Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 34
requires disciplined governance and practical assurance. AI governance Visible use cases, named accountability, suitable policies and risk-based oversight. AI controls Evidence-based data, model, vendor, oversight, monitoring and incident controls. Internal audit Independent assurance, practical insight and clear reporting to decision-makers. Final message: AI is new in form, but the audit fundamentals still matter. Governance, risk, control, evidence and accountability. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 35
content. NIST AI Risk Management Framework 1.0 and AI RMF Playbook OECD AI Principles: transparency, robustness, security, safety and accountability IIA Global Internal Audit Standards, effective January 2025 ISACA AI audit, assurance and technology-governance resources This course is independent and not endorsed by any employer, association, standards body or regulator Sources: nist.gov, oecd.ai, theiia.org, isaca.org. Verify current requirements and guidance before applying in practice. AI Governance and Internal Audit: Practical Foundations 36