Upgrade to Pro — share decks privately, control downloads, hide ads and more …

AI Governance for Internal Auditors: A Practica...

AI Governance for Internal Auditors: A Practical Introduction

AI Governance for Internal Auditors: A Practical Introduction by Paul A Lucas

Avatar for Paul A. Lucas

Paul A. Lucas

May 01, 2026

Other Decks in Business

Transcript

  1. AI Governance and Internal Audit Practical Foundations AI A concise

    30-minute course for audit, risk, compliance, governance and technology professionals Governance • Risk • Controls • Assurance Paul Lucas Governance, Internal Audit and Risk Executive | AI Governance and Investigations AI Governance and Internal Audit: Practical Foundations 1
  2. Course roadmap 0 Five short lectures. Practical, non-technical and risk-based.

    1 Why AI governance matters Strategic use, trust and organizational risk 2 Accountability and board oversight Roles, policies, decisions and escalation 3 Key AI risks How to use the course Listen for the governance logic, not a single universal checklist. AI risk varies by context, use case, impact and organizational maturity. Data, bias, privacy, security and third parties 4 Controls across the lifecycle Intake, testing, oversight, monitoring and incidents 5 How internal audit assesses AI Planning, criteria, evidence, findings and reporting Practical outcome You should be able to ask better questions about AI accountability, controls, evidence and boardlevel reporting. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 2
  3. Lecture 1 Why AI governance matters AI creates opportunity only

    when trust, accountability and control keep pace. AI Governance and Internal Audit: Practical Foundations 3
  4. LECTURE 1 AI is becoming part of ordinary decisions 1.1

    It is not just a technology issue. Customer service, claims, eligibility and triage Procurement, HR, fraud detection and due diligence Governance question Where is AI being used, what decisions does it influence, who owns it, and what could go wrong? Cybersecurity, monitoring and investigations Document review, summarization and generative AI support Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 4
  5. LECTURE 1 AI governance is about responsible use 1.2 Good

    governance enables innovation. It does not simply block it. Not this “AI is too risky, so avoid it.” Not this “AI is technical, so governance can wait.” Aim for this “Use AI deliberately, with clear accountability, controls and monitoring.” Responsible AI governance gives leaders confidence to adopt useful tools while understanding trade-offs, limitations and risks. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 5
  6. LECTURE 1 Trustworthy AI has several dimensions 1.3 Performance alone

    is not enough. Valid & reliable Safe & secure Fair & accountable Transparent Privacy-aware An AI system can be accurate in aggregate and still be unacceptable if it is unfair, insecure, opaque, unlawfully uses data or lacks meaningful human oversight. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 6
  7. LECTURE 1 What can go wrong? 1.4 Common failure patterns

    are predictable. Unknown or unapproved AI use Poor-quality or inappropriate data Biased or unfair outcomes Audit lens AI failures often reflect ordinary control failures in a new context: unclear ownership, weak evidence, poor monitoring, and inadequate challenge. Overreliance on automated recommendations Weak vendor and security controls No monitoring, incident response or escalation ! Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 7
  8. LECTURE 1 Key takeaway 1.5 The governance objective is informed

    confidence. Core message AI governance helps organizations use AI deliberately, proportionately and responsibly. Internal audit role Provide independent assurance and practical insight on whether AI risks are identified, controlled, monitored and reported. Ask first: what is the use case, who is affected, who owns the risk, and what evidence shows the controls work? Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 8
  9. Lecture 2 Accountability and board oversight AI risk needs named

    owners, clear decision rights and useful reporting. AI Governance and Internal Audit: Practical Foundations 9
  10. LECTURE 2 Accountability must be specific 2.1 “Everyone is responsible”

    often means no one is accountable. Business owner Owns the use case, purpose, outcomes and risk acceptance. Technology owner Manages technical design, implementation, security and changes. Internal audit Provides independent assurance on governance, risk management and controls. Control functions Provide challenge on risk, legal, privacy, compliance, security and ethics. Board or committee Oversees material AI exposure, risk appetite and management actions. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 10
  11. LECTURE 2 Board oversight is not model management 2.2 The

    board needs decision-useful reporting. What boards need Material use cases, risk trends, incidents, risk acceptance, unresolved issues and management actions. What boards do not need Every parameter, line of code, technical tuning choice or vendor marketing claim. Effective oversight asks: is management using AI within risk appetite, with suitable controls, evidence and escalation? Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 11
  12. LECTURE 2 A simple AI governance operating model 2.3 Useful

    governance connects strategy, risk and execution. Board oversight Risk appetite, challenge and visibility Executive ownership Priorities, accountabilities and resources AI governance forum Intake, classification, approval and escalation Use-case owners Controls, performance, data and incidents Assurance Independent review and continuous improvement Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 12
  13. LECTURE 2 Policy translates risk appetite into behavior 2.4 Policies

    should answer practical questions. Which AI uses require approval? What data may not be entered into public tools? Who reviews high-impact use cases? Audit test Do policies exist, are they understood, and is there evidence that people follow them? When is human oversight required? How are incidents escalated? What evidence must be retained? Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 13
  14. LECTURE 2 Key takeaway 2.5 Accountability should be visible in

    decisions and evidence. Look for Named owners, clear approvals, recorded decisions, defined escalation and evidence of challenge. Red flags Unclear ownership, shadow AI, ceremonial human review, weak board reporting and vendor-driven governance. Good AI governance is not the absence of risk. It is the presence of accountable, informed and documented decision-making. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 14
  15. Lecture 3 Key AI risks AI risk is broader than

    model performance. AI Governance and Internal Audit: Practical Foundations 15
  16. LECTURE 3 AI risk categories 3.1 Think in clusters rather

    than one technical risk. Data quality Bias & fairness Privacy Security Model reliability Third parties Transparency Human overreliance The significance of each risk depends on the use case, affected people, decision impact and control environment. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 16
  17. LECTURE 3 Data and bias risks 3.2 AI often reflects

    the data and assumptions behind it. Data questions Is the data relevant, lawful, accurate, complete, representative and fit for the intended purpose? Bias questions Do outcomes differ materially across relevant groups, contexts or locations, and has management assessed why? Audit evidence Lineage, quality checks, test results, limitations, approvals, exception handling and remediation. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 17
  18. LECTURE 3 Privacy, security and confidentiality 3.3 AI can change

    the way sensitive information moves. Personal data may be reused for new purposes Prompts may disclose confidential information Vendors may retain, train on or process data externally Control focus Approved tools, data-classification rules, contractual terms, access controls, logging, security testing and incident response. APIs and integrations may expand the attack surface Logs may contain sensitive data Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 18
  19. LECTURE 3 Third-party and vendor risk 3.4 Using a vendor

    does not transfer accountability. Before use Due diligence on purpose, data, security, explainability, performance, limitations and legal terms. During use Monitoring of performance, incidents, changes, subcontractors, support and service levels. If things go wrong Escalation rights, evidence preservation, suspension, remediation and exit or continuity planning. The organization remains responsible for how it selects, configures, uses and relies on AI services. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 19
  20. LECTURE 3 Generative AI has distinctive risks 3.5 Confidence is

    not the same as accuracy. Risk Outputs may be plausible but false, incomplete, biased or unsupported. Risk Inputs may disclose confidential, personal or privileged information. Risk Users may skip verification because the output sounds authoritative. Control response Define allowed uses, require verification, protect sensitive data, retain appropriate evidence and maintain human accountability. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 20
  21. LECTURE 3 Key takeaway 3.6 Risk depends on context and

    impact. Lower scrutiny Low-impact productivity support, with limited data and no consequential decision effect. Higher scrutiny AI influencing important decisions, sensitive data, vulnerable groups, legal rights, finance, employment or safety. Classify AI risk by what the system does, who it affects, what data it uses, and what harm or value could result. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 21
  22. Lecture 4 Controls across the AI lifecycle Good controls follow

    the system from idea to retirement. AI Governance and Internal Audit: Practical Foundations 22
  23. LECTURE 4 Think lifecycle, not one-time approval 4.1 AI risk

    changes over time. Intake Register and classify Design Define purpose and criteria Build / Buy Evaluate data, vendor and controls Deploy Approve, train and document Monitor Track drift, incidents and impacts Change / Retire Update, suspend or exit Audit principle A control that worked at launch may not be enough after the model, data, users or business context changes. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 23
  24. LECTURE 4 Intake and inventory controls 4.2 You cannot govern

    what you cannot see. Defined intake process for new AI use cases Inventory records purpose, owner, data, vendor and risk class Approval thresholds for higher-risk uses Evidence to request Inventory extract, approvals, risk classification rationale, governance minutes, policy exceptions and recertification records. Exception process for unapproved or urgent use Periodic recertification of active AI systems Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 24
  25. LECTURE 4 Testing, validation and documentation 4.3 Controls should be

    evidence-based, not assertion-based. Data Lineage, quality, representativeness, lawful use and limitations. Model Performance, robustness, bias, explainability and thresholds. Documentation Purpose, assumptions, limitations, approvals and change history. The question is not “did someone say it works?” The question is “what evidence shows it works appropriately for this use case?” Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 25
  26. LECTURE 4 Human oversight and transparency 4.4 Human review must

    be meaningful. Meaningful oversight Qualified reviewers have information, time and authority to challenge, override or stop the AI-supported decision. Meaningful transparency Users and affected parties receive context-appropriate information about AI use, limitations and review options. Audit red flag A human approves nearly every AI recommendation without documented analysis. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 26
  27. LECTURE 4 Monitoring, incidents and change 4.5 Deployment is the

    beginning of control, not the end. Monitor performance, drift, user behavior and adverse impacts Define thresholds that trigger investigation or escalation Preserve logs and evidence for incidents Manage function Risk treatment includes prioritization, response, recovery, communication and continual improvement. Control material model, data, vendor or use-case changes Suspend or restrict use when risk becomes unacceptable Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 27
  28. LECTURE 4 Key takeaway 4.6 Controls should be proportionate, documented

    and operating. Design Are the controls suitable for the AI use case and risk? Operation Is there evidence that the controls are performed? Adaptation Do controls respond when the system or context changes? AI assurance should test both the design and the operating effectiveness of lifecycle controls. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 28
  29. Lecture 5 How internal audit assesses AI governance Use risk-based

    planning, suitable criteria and defensible evidence. AI Governance and Internal Audit: Practical Foundations 29
  30. LECTURE 5 Start with a risk-based audit question 5.1 Not

    every AI audit needs the same scope. Possible objective Assess whether governance, data, model, human oversight and monitoring controls manage material AI risks to an acceptable level. Scope variables Use case, impact, data sensitivity, jurisdictions, vendors, lifecycle stage and management maturity. Good planning narrows a broad AI topic into a focused, auditable engagement. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 30
  31. LECTURE 5 Use suitable criteria 5.2 Audit conclusions need a

    basis beyond personal opinion. Organizational AI policy and risk appetite Applicable laws, regulations and contractual requirements NIST AI RMF, OECD AI Principles and other recognized frameworks Important If management has not defined criteria for fairness, transparency or acceptable risk, that gap may itself be an audit issue. IIA standards and internal audit methodology ISACA, COBIT and technology-governance practices Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 31
  32. LECTURE 5 Evidence should match the risk 5.3 Inquiry alone

    is rarely enough. Documents Policies, inventories, approvals, contracts, minutes, test reports and logs. Interviews Business owners, data teams, risk, legal, privacy, security, vendors and users. Testing Sample approvals, data controls, monitoring alerts, incidents, overrides and changes. The finding should connect criteria, condition, cause, impact and recommendation. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 32
  33. LECTURE 5 Communicating AI risk 5.4 Translate complexity into decisions.

    Avoid Technical detail without business meaning, vague warnings, or generic statements that AI is risky. Aim for Clear risk statements, evidence, impact, residual risk, ownership, timelines and decisions needed. Useful AI reporting helps management and the board act, not merely admire the complexity. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 33
  34. LECTURE 5 A first AI governance audit checklist 5.5 Use

    this as a practical starting point. 1. Confirm AI inventory and ownership 2. Identify material use cases and affected stakeholders 3. Review policies, approvals and risk classification Downloadable resource idea Convert this checklist into a one-page PDF for learners and include it as a course resource. 4. Test data, vendor, security and human oversight controls 5. Evaluate monitoring, incidents and change management 6. Report material gaps, residual risk and required decisions Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 34
  35. LECTURE 5 Closing: what good looks like 5.6 Responsible AI

    requires disciplined governance and practical assurance. AI governance Visible use cases, named accountability, suitable policies and risk-based oversight. AI controls Evidence-based data, model, vendor, oversight, monitoring and incident controls. Internal audit Independent assurance, practical insight and clear reporting to decision-makers. Final message: AI is new in form, but the audit fundamentals still matter. Governance, risk, control, evidence and accountability. Independent educational resource. Not legal, regulatory, accounting or cybersecurity advice. AI Governance and Internal Audit: Practical Foundations 35
  36. References and independent-use note R Frameworks that informed the course

    content. NIST AI Risk Management Framework 1.0 and AI RMF Playbook OECD AI Principles: transparency, robustness, security, safety and accountability IIA Global Internal Audit Standards, effective January 2025 ISACA AI audit, assurance and technology-governance resources This course is independent and not endorsed by any employer, association, standards body or regulator Sources: nist.gov, oecd.ai, theiia.org, isaca.org. Verify current requirements and guidance before applying in practice. AI Governance and Internal Audit: Practical Foundations 36