β‘ Quick Summary
Published by the ISACA Sydney Chapter Special Interest Group, this research paper examines the dual challenge facing audit functions: leveraging AI to automate and enhance assurance workflows while simultaneously governing and assuring AI systems across the organization. Drawing on industry frameworks, academic literature, and a survey of 45 risk and audit practitioners alongside eight senior executive interviews, the paper reveals an acute governance lagβ84.1% of respondents report that AI governance has failed to keep pace with AI capabilities.
Crucially, only 22.2% believe AI-generated evidence would withstand external regulatory scrutiny. The paper establishes the foundational principle that AI tools represent mere inputs: legal, operational, and professional accountability remains strictly anchored to named human auditors and organizational leadership.
π§© What's Covered
The document provides an in-depth examination of the emerging risks, architectural concerns, and governance gaps when embedding AI into assurance functions:
- The AI-Enabled Audit Lifecycle: A structured socio-technical framework spanning data ingestion, preparation, model configuration, execution, exception detection, human challenge, audit trail traceability, issue evaluation, reporting, and continuous feedback.
- Adoption Trends and Drivers: Empirical data showing functions moving toward full-population testing (68.9%) and early issue detection (64.4%), while navigating the shift from sample-based reviews to continuous controls monitoring (CCM) driven by standards like APRA CPS 230 and CPS 234.
- Audit Quality and Evidence Integrity Risks: Analysis of automation bias, over-reliance, false assurance, and the non-deterministic nature of generative models that complicates evidentiary defensibility and reproducibility.
- Security, Architecture, and Data Governance: Examination of expanded attack surfaces (prompt injection, agentic privilege escalation), privacy leakage during population analysis, lineage degradation across retrieval pipelines, and sovereign data residency challenges.
- Accountability Chains and Legal Precedents: Analysis of IIA Standards, NIST AI RMF, ISO/IEC 42001, and EU AI Act requirements alongside case law (such as Moffatt v Air Canada and Pintarich v DCT), confirming that organizations cannot disclaim automated outputs or delegate due professional care.
- Human-in-the-Loop Operationalization: Clear criteria establishing mandatory human review triggers (materiality, high-consequence impact, low model confidence) and addressing the productivity paradox of over-verifying automated outputs versus accepting unverified results.
- AI Lifecycle Governance: Core control requirements across creation, development, independent validation, approval, deployment, drift monitoring, and decommissioning.
π‘ Why it matters?
As audit functions face increasing pressure to adopt generative AI and continuous controls monitoring, deploying tools without rigorous governance risks automating flawed logic, bias, and compliance blind spots at enterprise scale. This paper clarifies that AI cannot exercise professional skepticism, determine materiality, or assume liability. It equips audit committees, CAEs, and risk practitioners with clear arguments to enforce model validation, defendable audit trails, and competency-backed human oversight.
β What's Missing
As Part 1 of a two-part series, the paper intentionally focuses on framing the conceptual problems, risks, and survey findings rather than providing technical implementation roadmaps, specific control testing scripts, or step-by-step audit templates. Practical controls, an assurance maturity model, and specific operational guidance are deferred to Part 2.
π₯ Best For
Chief Audit Executives (CAEs), IT auditors, technology risk leaders, GRC professionals, CISOs, model risk managers, and audit committee members seeking to govern internal AI adoption or structure continuous assurance workflows.
π Source Details
Title: The Dual Challenge of AI in Audit: Automating Assurance & Governing The Technology That Does It (Part -1)
Author / Organization: ISACA Sydney Chapter Special Interest Group: AI in Audit & Assurance (Lead Author: Aman Deep; Co-Chair: Krishna Bagla)
Publication Date: 2026
Document Type: Technology Governance Research Paper (37 pages)
π Thanks to
Lead author Aman Deep, Co-Chair Krishna Bagla, working group contributors (Narayana Madineni, Amritha Shetty, Akhilesh Das, Raj Balakrishnan, Naveen Sharma, Anju Madawala, Sorin Toma, Saravanaguru Kumaraguru, Ashwin Jadhav, Brady Newell, Vishal K Senthilkumar, Vicente Arteaga), reviewers (Arnold Chan, Vinod Bijlani, Asaf Ahmed), and ISACA Sydney Chapter Leadership (Chirag Joshi, Shalbin Samuel).