Why AI Belongs in the Internal Audit Universe

An organization can use artificial intelligence in recruiting, procurement, customer service, financial analysis, and cybersecurity without having a department called “Artificial Intelligence.” If the audit universe merely mirrors the organization chart, AI can disappear from the plan even while it is changing decisions, controls, vendors, and risk exposure.
That is the planning problem internal audit needs to solve. AI does not need to justify a standalone audit before it justifies a place in risk assessment. The first task is to make the exposure visible. The second is to decide how it should be covered.
This distinction matters because an internal audit plan is not a catalogue of fashionable topics. It is a response to the risks that could affect the achievement of organizational objectives.
The audit universe is more than a list of departments
Standard 9.4 of the Global Internal Audit Standards requires the chief audit executive to base the internal audit plan on a documented assessment of the organization’s strategies, objectives, and risks, performed at least annually. The plan must also be dynamic and updated timely when significant changes occur in the business, risks, operations, programs, systems, controls, or organizational culture.
The Standards make an important distinction between requirement and implementation guidance. An audit universe is described in the considerations for implementation as one possible way to organize potentially auditable units; it is not itself a mandatory planning structure. Auditable units can include business units, processes, programs, and systems, and they can be linked to risks that cut across several parts of the organization.
That logic is particularly valuable for AI. A demand-forecasting model may sit inside commercial planning. A generative assistant may operate in customer service. A screening tool may belong to human resources. A vendor may embed AI inside a service the organization did not develop itself. Treating “AI” only as a separate auditable entity can obscure its most important characteristic: it is a cross-cutting technology that changes the risk profile of activities already inside the audit universe.
The first planning question therefore should not be, “Do we have an AI audit?” It should be, “Do we know where AI influences objectives, decisions, data, controls, and third parties?”
Visibility starts with understanding where AI is actually used
The IIA's Artificial Intelligence Auditing Framework advises internal audit to understand how the organization uses AI and to work with management to review or develop an inventory that captures, among other things, the purpose of the AI, who uses and manages it, the tools involved, relevant risk considerations, and oversight. The framework also states that if a separate AI-focused risk assessment is not feasible, organizations should at minimum include AI in the overall risk assessment process.
An inventory, however, is not the end state. Its value is in connecting specific AI uses to the risk landscape and to existing auditable units.
A copilot used to draft contracts, for example, may introduce confidentiality, accuracy, and vendor dependency risks into the legal process. A model that prioritizes customers may create compliance, fairness, and reputational exposure in sales. An AI-enabled fraud system may change how finance relies on alerts, exceptions, and human review. In each case, the AI risk belongs to a business decision or process rather than floating as a disconnected technology category.
The NIST AI Risk Management Framework can broaden that conversation through its Govern, Map, Measure, and Manage functions. ISO/IEC 42001:2023 similarly structures AI management around context, leadership, risk, impact, controls, operations, monitoring, and improvement. Neither framework replaces internal audit's planning methodology. They can, however, help prevent an overly narrow assessment that treats AI only as an IT or cybersecurity issue.
AI risk can be covered without creating an engagement called “AI Audit”
Once AI exposure has been identified and assessed, internal audit has several coverage options. The choice should follow risk, governance maturity, assurance already provided elsewhere, and available resources—not a desire to put a fashionable topic on the plan.
| Coverage approach | When it may fit | Example |
|---|---|---|
| Embedded in process audits | AI is concentrated in specific activities and its risks can be tested within the normal engagement objective. | Include model controls in a credit audit or GenAI controls in a customer-service audit. |
| Cross-functional thematic review | Multiple functions use AI and share a common question around inventory, policy, third parties, data, human oversight, or monitoring. | Review how five functions govern approved and unapproved generative AI tools. |
| Standalone AI audit | Exposure is material, governance is immature, high-impact uses exist, change is rapid, incidents have occurred, or risk concentration warrants a distinct conclusion. | Enterprise-wide audit of AI governance and lifecycle management. |
This approach avoids two common extremes. The first is ignoring AI until the function has budget for a specialist audit. The second is scheduling an “AI audit” so broad that it tries to cover governance, models, privacy, cybersecurity, vendors, compliance, and every use case in one engagement.
Coverage can mature progressively. A generalist internal audit team can begin with inventory, accountability, policy, use-case approval, third-party governance, human oversight, incidents, and monitoring. When a conclusion depends on technical properties of the model—advanced statistical validation, robustness, or specialized security testing, for example—the engagement can add specialist support without transferring internal audit's accountability for the overall conclusion.
Risk assessment should follow impact, not the technology label
Not every AI use warrants the same priority. A tool that summarizes public documents and a system influencing credit decisions should not receive the same risk score merely because both use AI.
A useful assessment considers the potential effect on strategic objectives, customers, or employees; the criticality and reversibility of decisions; the sensitivity and provenance of data; the degree of autonomy and human oversight; dependence on external models or providers; legal and regulatory exposure; incidents and exceptions; and the velocity of changes to models, configurations, or use cases.
This analysis also reveals that many AI risks are familiar risks with a new mechanism. AI can amplify fraud, privacy, resilience, third-party, compliance, information-quality, or conduct risk. The planning challenge is not necessarily to invent an entirely new taxonomy. It is to recognize when AI changes the likelihood, impact, or control effectiveness associated with risks internal audit already understands.
Standard 9.4 adds an important governance implication. When a high-risk area or activity is not included in the plan for an assurance engagement, the chief audit executive must communicate the rationale. If AI exposure is assessed as significant but no standalone AI audit is scheduled, there should therefore be a defensible explanation: sufficient coverage may exist inside other engagements, another assurance provider may be relied upon after appropriate evaluation, a thematic review may already address the risk, or resource limitations may have been communicated to the board.
Five questions to test whether AI is really inside the plan
Before closing the enterprise risk assessment, an internal audit function should be able to answer five questions with evidence:
- Do we know where AI is being used or introduced? Include enterprise tools, purchased solutions, AI embedded by vendors, and decentralized use—not only systems branded as AI projects.
- Is each material use connected to business objectives, processes, and accountable owners? A technical inventory without business context cannot support prioritization.
- Does the risk methodology recognize how AI changes existing risks or creates new ones? A generic “technology” category will not capture effects on decisions, customers, data, fraud, or compliance.
- Has internal audit made an explicit coverage decision? Embedded, thematic, standalone, or reliance on another assurance provider.
- Can the plan change when the exposure changes? New use cases, providers, incidents, regulatory developments, or significant model changes should be capable of triggering reassessment.
If the answer to the first question is uncertain, the immediate problem is not “how to audit AI.” The problem is that internal audit does not yet have enough visibility to claim that the audit plan is addressing the organization's significant risks.
Maturity starts before the specialist AI audit
Putting AI in the audit universe does not mean declaring every AI use high risk or immediately building a team of data scientists. It means applying the most basic principle of risk-based planning: understand what can affect objectives and make a conscious decision about the assurance coverage required.
A mature function may conclude that some exposure belongs inside ordinary process audits, another portion needs a cross-cutting thematic review, and only a small number of uses warrant specialist-supported technical assurance. That combination can provide stronger coverage than one annual “AI audit” disconnected from the business processes where the technology actually operates.
The question for the board should therefore move beyond, “Is AI on the audit plan?” A better question is: “Can we demonstrate where AI changes our risk profile and how we are obtaining assurance over that exposure?”
When internal audit can answer that question, AI is no longer an emerging topic waiting for a slot on the calendar. It has become part of the system the function uses to decide what deserves attention.