AI Governance Library

The Dual Challenge of AI in Audit: Automating Assurance and Governing the Technology That Does It (Part 1)

Audit functions face a dual challenge: using AI to improve assurance while providing assurance over the AI systems themselves. The same technologies that improve analytical capability also introduce new risks relating to explainability, evidence integrity, data quality, privacy, and accountability.
The Dual Challenge of AI in Audit: Automating Assurance and Governing the Technology That Does It (Part 1)

⚑ Quick Summary

Published by the ISACA Sydney Chapter Special Interest Group, this research paper examines the dual challenge facing audit functions: leveraging AI to automate and enhance assurance workflows while simultaneously governing and assuring AI systems across the organization. Drawing on industry frameworks, academic literature, and a survey of 45 risk and audit practitioners alongside eight senior executive interviews, the paper reveals an acute governance lagβ€”84.1% of respondents report that AI governance has failed to keep pace with AI capabilities.

Crucially, only 22.2% believe AI-generated evidence would withstand external regulatory scrutiny. The paper establishes the foundational principle that AI tools represent mere inputs: legal, operational, and professional accountability remains strictly anchored to named human auditors and organizational leadership.

🧩 What's Covered

The document provides an in-depth examination of the emerging risks, architectural concerns, and governance gaps when embedding AI into assurance functions:

  • The AI-Enabled Audit Lifecycle: A structured socio-technical framework spanning data ingestion, preparation, model configuration, execution, exception detection, human challenge, audit trail traceability, issue evaluation, reporting, and continuous feedback.
  • Adoption Trends and Drivers: Empirical data showing functions moving toward full-population testing (68.9%) and early issue detection (64.4%), while navigating the shift from sample-based reviews to continuous controls monitoring (CCM) driven by standards like APRA CPS 230 and CPS 234.
  • Audit Quality and Evidence Integrity Risks: Analysis of automation bias, over-reliance, false assurance, and the non-deterministic nature of generative models that complicates evidentiary defensibility and reproducibility.
  • Security, Architecture, and Data Governance: Examination of expanded attack surfaces (prompt injection, agentic privilege escalation), privacy leakage during population analysis, lineage degradation across retrieval pipelines, and sovereign data residency challenges.
  • Accountability Chains and Legal Precedents: Analysis of IIA Standards, NIST AI RMF, ISO/IEC 42001, and EU AI Act requirements alongside case law (such as Moffatt v Air Canada and Pintarich v DCT), confirming that organizations cannot disclaim automated outputs or delegate due professional care.
  • Human-in-the-Loop Operationalization: Clear criteria establishing mandatory human review triggers (materiality, high-consequence impact, low model confidence) and addressing the productivity paradox of over-verifying automated outputs versus accepting unverified results.
  • AI Lifecycle Governance: Core control requirements across creation, development, independent validation, approval, deployment, drift monitoring, and decommissioning.

πŸ’‘ Why it matters?

As audit functions face increasing pressure to adopt generative AI and continuous controls monitoring, deploying tools without rigorous governance risks automating flawed logic, bias, and compliance blind spots at enterprise scale. This paper clarifies that AI cannot exercise professional skepticism, determine materiality, or assume liability. It equips audit committees, CAEs, and risk practitioners with clear arguments to enforce model validation, defendable audit trails, and competency-backed human oversight.

❓ What's Missing

As Part 1 of a two-part series, the paper intentionally focuses on framing the conceptual problems, risks, and survey findings rather than providing technical implementation roadmaps, specific control testing scripts, or step-by-step audit templates. Practical controls, an assurance maturity model, and specific operational guidance are deferred to Part 2.

πŸ‘₯ Best For

Chief Audit Executives (CAEs), IT auditors, technology risk leaders, GRC professionals, CISOs, model risk managers, and audit committee members seeking to govern internal AI adoption or structure continuous assurance workflows.

πŸ“„ Source Details

Title: The Dual Challenge of AI in Audit: Automating Assurance & Governing The Technology That Does It (Part -1)
Author / Organization: ISACA Sydney Chapter Special Interest Group: AI in Audit & Assurance (Lead Author: Aman Deep; Co-Chair: Krishna Bagla)
Publication Date: 2026
Document Type: Technology Governance Research Paper (37 pages)

πŸ“ Thanks to

Lead author Aman Deep, Co-Chair Krishna Bagla, working group contributors (Narayana Madineni, Amritha Shetty, Akhilesh Das, Raj Balakrishnan, Naveen Sharma, Anju Madawala, Sorin Toma, Saravanaguru Kumaraguru, Ashwin Jadhav, Brady Newell, Vishal K Senthilkumar, Vicente Arteaga), reviewers (Arnold Chan, Vinod Bijlani, Asaf Ahmed), and ISACA Sydney Chapter Leadership (Chirag Joshi, Shalbin Samuel).

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.