Every conversation with an Audit Committee comes down to one question: can we rely on this? Can we rely on the access controls, on the change process, on the numbers in the report? Artificial intelligence has not changed that question. It has changed almost everything about how we answer it.
Internal audit now sits in an unusual position. We are expected to use AI to work faster, to audit the AI our organisations are adopting, and to keep giving the same level of assurance while both are moving. Each of these is a different problem, and treating them as one is where most audit functions get stuck.
Shift one: from samples to populations
Sampling exists because people cannot read every record. We test twenty five changes out of two thousand and form a view on the rest. That trade off made sense when every test was manual.
With analytics and AI assistance, many tests no longer need a sample. We can review every change ticket for missing approvals, every privileged account for activity after the owner left, every firewall rule for an expired business justification. The exceptions come to us, and our time goes into understanding them instead of finding them.
This does not make sampling obsolete. Judgement based tests, such as whether a risk acceptance was reasonable, still need a person reading a small number of cases carefully. What changes is the default. Full population testing should be the starting point wherever the data allows it, and sampling the exception we can justify.
Shift two: AI is now something we audit
Most organisations already run AI, whether they planned to or not. It arrives inside SaaS products, in vendor tools with a new feature switched on, and in staff pasting text into public chat tools. Very few have a complete list.
For audit, that makes AI a new auditable area with familiar control questions underneath it:
- Inventory and ownership. Where is AI used, who owns each use, and who approved it?
- Data. What data goes in, where does it go, and is any of it confidential, personal or regulated?
- Change control. When a model, a prompt or a vendor's AI feature changes, does anyone review it before it reaches production?
- Output monitoring. How does the business know the output is still accurate, fair and within its intended use?
- Third parties. Do vendor contracts say how our data is used to train or improve their models?
None of these are exotic. They are ITGC questions applied to a new kind of system. Frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001 give useful structure, but the first step is simpler: add AI to the audit universe and rate it like any other area.
Shift three: AI inside the audit function
This is the shift that affects auditors personally. AI tools can draft observations, summarise evidence, map controls to frameworks and prepare first versions of audit programs. Used well, they remove hours of formatting and repetition from every engagement.
Used carelessly, they introduce exactly the risks we warn others about. Confidential evidence pasted into an unapproved tool. A confident sentence in a draft finding that no document supports. A team that stops reading the evidence because the summary looked fine.
The rule I apply is short: AI drafts, the auditor decides. Every statement in a finished observation must trace back to evidence a reviewer can open. If it cannot be traced, it does not go in the report, however well it reads.
The other lesson is about consistency. The value of AI in an audit team does not come from one person with clever prompts. It comes from shared, repeatable workflows: the same structure for observations, the same review steps, the same standard for evidence, used by everyone. That is what turns a personal shortcut into a capability the function can rely on.
What stays human
Three parts of the job do not move to a machine.
Professional scepticism
Knowing when an explanation is too neat, or when a clean report hides a process nobody follows, comes from experience and attention. AI can surface anomalies. It cannot be suspicious on your behalf.
Judgement about significance
Whether a gap is a minor observation or a matter for the Audit Committee depends on context, history and the organisation's appetite for risk. That call carries accountability, and accountability needs a name attached to it.
The conversation
Most control improvements happen because an auditor and a control owner agreed on what was wrong and what a realistic fix looks like. That agreement is built in a room, not in a document.
Where to start
For heads of audit wondering where to begin, a practical sequence:
- Build or request an inventory of AI use across the organisation, including vendor features.
- Add AI to the audit universe and risk assess it alongside everything else.
- Set clear rules for your own team: approved tools, what data may never be used, and the review standard for AI assisted work.
- Pick one repeatable task, such as drafting observations or full population testing of one control, and pilot it properly.
- Invest in people. The auditor who understands data and AI will be more valuable, not less.
The auditors who do well in the next decade will not be the ones who use the most AI. They will be the ones who can tell the difference between an answer that sounds right and an answer that is right, and who can prove it.