DAY 1: UNDERSTANDING AND AUDITING THE AI GOVERNANCE ENVIRONMENT
Day 1 establishes the foundation internal auditors need to provide credible assurance over AI. The focus moves from simply understanding AI governance frameworks to determining what internal audit should assess, what evidence it should expect to find, where accountability resides and how AI governance should influence the audit universe and assurance plan.
Session 1: The Changing Internal Audit Mandate in an AI-Enabled Organisation
AI is changing both the organisational risk universe and the environment in which internal audit operates. Internal auditors need to understand where AI is being used, how it affects mission-critical objectives and where new or interconnected risks may emerge.
Key areas covered:
- Understanding how AI changes the organisational risk universe
- Identifying AI-enabled activities across business processes
- Recognising generative AI, predictive analytics and automated decision-making as emerging assurance areas
- Identifying approved, embedded and potentially unapproved or shadow AI
- Connecting AI use to strategy, performance and mission-critical objectives
- Assessing the potential impact of AI on value creation and value preservation
- Understanding how AI changes existing financial, operational, compliance, technology and reputational risks
- Determining when AI becomes sufficiently material to require internal audit attention
- Considering the implications of AI for the internal audit universe and risk-based audit plan
- Maintaining internal audit independence and objectivity when internal audit itself uses AI
Practical Exercise: Participants map where AI could exist across a typical organisation and develop an initial AI Audit Universe, linking AI applications to business processes, mission-critical objectives, material risks and potential assurance requirements.
Toolkit: AI Audit Universe and AI Use Case Identification Template.
Session 2: Auditing AI Governance Using King V
The original programme positions King V as the central governance anchor. For internal audit, the key question becomes: How does internal audit assess whether the governing body and management are exercising effective oversight of AI?
Key areas covered:
- Applying King V as the governance baseline for assessing AI oversight
- Evaluating ethical and effective leadership in AI-related decision-making
- Assessing governing body oversight of technology and information
- Determining whether accountability for AI has been clearly established
- Evaluating the relationship between AI governance and organisational purpose
- Assessing whether AI supports sustainable value creation and preservation
- Evaluating stakeholder considerations in AI-enabled decisions
- Assessing transparency and disclosure relating to AI systems and their outcomes
- Evaluating governance structures for responsible AI deployment
- Determining whether significant AI risks are appropriately escalated to executive management and the governing body
- Assessing whether the governing body receives sufficient and reliable information to discharge its oversight responsibilities
Practical Exercise: Participants conduct a King V AI Governance Gap Assessment, examining a hypothetical organisation’s AI governance arrangements and identifying potential governance weaknesses, audit evidence requirements and matters that may need to be reported to the audit committee.
Toolkit: King V AI Governance Audit Checklist.
Session 3: Navigating the AI Governance Framework Ecosystem from an Internal Audit Perspective
No single framework provides internal audit with everything required to assess AI governance, risk and control. Internal auditors need to understand how the different frameworks complement one another and how they can be used as sources of criteria when planning and executing assurance engagements.
Key areas covered:
- Positioning King V as the overarching governance anchor
- Understanding ISO/IEC 42001 as the structural foundation for an AI management system
- Applying COSO to enterprise risk management and internal control
- Using NIST AI RMF to understand the Govern, Map, Measure and Manage dimensions of AI risk
- Positioning COBIT within technology and information governance
- Applying the Three Lines Model to accountability and independent assurance
- Understanding how the frameworks complement rather than compete with one another
- Selecting appropriate criteria for different types of AI audit engagements
- Connecting governance principles to operational controls and audit evidence
- Integrating AI assurance into the broader GRC and combined assurance architecture
Practical Exercise: Participants develop an AI Governance Framework Alignment Map showing how the different frameworks contribute to:
Governance ? Risk Management ? Technology Governance ? AI Management ? Internal Control ? Assurance
The exercise requires participants to identify which framework provides the most appropriate audit criteria for different aspects of an AI-enabled environment.
Toolkit: AI Governance Framework Alignment Map.
Session 4: Auditing ISO/IEC 42001 and the AI Management System
ISO/IEC 42001 provides internal audit with a structured basis for assessing whether an organisation has established appropriate management arrangements for AI. The internal audit focus is not simply whether policies exist, but whether governance, risk management and controls operate effectively throughout the AI lifecycle.
Key areas covered:
- Understanding the purpose and structure of an AI management system
- Assessing the scope of the organisation’s AI management arrangements
- Evaluating AI policies and governance requirements
- Assessing defined roles, responsibilities and ownership
- Evaluating AI risk assessment processes
- Reviewing AI impact assessment practices
- Assessing controls across the AI lifecycle
- Evaluating governance over design, development and acquisition
- Assessing deployment, operation and ongoing monitoring
- Reviewing change management and model updates
- Assessing decommissioning and retirement of AI systems
- Evaluating documentation, evidence retention and audit trails
- Assessing monitoring, corrective action and continual improvement
- Determining readiness for internal and external assurance
Workshop: Participants review a hypothetical AI management system against the core governance and management requirements of ISO/IEC 42001. They identify control gaps, determine the audit evidence required and formulate potential internal audit observations.
Toolkit: ISO/IEC 42001 Internal Audit Readiness Assessment.
Session 5: The Three Lines Model, Combined Assurance and Internal Audit Independence
The final session of Day 1 establishes where internal audit fits within the organisation’s broader AI governance and assurance architecture.
The objective is to ensure that internal audit provides independent third-line assurance without assuming management responsibility for designing, implementing or operating AI governance and controls.
Key areas covered:
- Clarifying management’s ownership of AI risks and controls
- Defining first-line responsibilities for AI-enabled processes
- Understanding second-line oversight by risk management, compliance, legal, cybersecurity, privacy and data governance
- Defining internal audit’s independent third-line assurance role
- Protecting internal audit independence when advising on emerging AI governance arrangements
- Distinguishing advisory work from assurance engagements
- Mapping assurance activities across the Three Lines Model
- Assessing the quality and reliability of assurance provided by other functions
- Determining when internal audit can place reliance on other assurance providers
- Identifying assurance gaps and unnecessary duplication
- Considering specialist and external assurance for technically complex AI risks
- Establishing escalation and reporting mechanisms for material AI governance weaknesses
- Connecting AI assurance to the organisation’s broader combined assurance approach
Practical Exercise: Participants develop an AI Combined Assurance Map structured around:
Mission-Critical Objective ? AI Risk ? Key Control ? Control Owner ? First-Line Monitoring ? Second-Line Oversight ? Third-Line Assurance ? External Assurance ? Assurance Gap
Participants identify areas of over-assurance, under-assurance and duplication and determine where internal audit should provide independent assurance.
Toolkit: Three Lines AI Assurance Map and AI Combined Assurance Assessment.
DAY 2: AUDITING AI RISK, CONTROLS AND ASSURANCE
Day 2 moves from understanding the AI governance environment to the practical assurance responsibilities of internal audit. Participants work through the AI risk universe, evaluate controls, consider the audit implications of data and models, and develop a risk-based approach to auditing AI-enabled processes.
Session 6: Building the AI Risk Universe
Internal audit needs a structured understanding of the risks introduced or amplified by AI. This session develops an AI-specific risk universe that can be integrated into the organisation’s existing audit universe and risk-based internal audit planning process.
Key areas covered:
- Bias and discrimination in AI-supported decisions
- Privacy and protection of personal information
- Cybersecurity threats affecting AI systems and data
- Hallucination, accuracy and reliability of AI-generated outputs
- Model drift and deterioration in model performance
- Lack of explainability and transparency
- Poor data quality, integrity and lineage
- Regulatory and compliance exposure
- Third-party AI and vendor dependency
- Reputational risk and AI washing
- Workforce disruption and inappropriate automation
- Over-reliance on AI without adequate human oversight
- Ethical risks and unintended stakeholder consequences
Workshop: Participants assess a hypothetical AI implementation, identify root causes and consequences, determine inherent risk, evaluate existing controls and assurance activities, and assess residual risk.
Toolkit: AI Risk Universe and AI Risk Assessment Template.
Session 7: Auditing AI Controls – General Controls and Application Controls
This session translates AI risks into the controls internal audit should expect to find and test. Participants distinguish between the broader general controls that support the AI environment and the application controls embedded within individual AI-enabled processes.
Key areas covered:
- AI governance and oversight controls
- User access and authorisation controls
- Data governance and data quality controls
- Model development, approval and validation controls
- Change management and version control
- Preventive, detective and corrective controls
- Automated versus manual controls
- Human-in-the-loop and human-on-the-loop controls
- Exception management and escalation
- Model performance and drift monitoring
- Logging, audit trails and traceability
- Incident management and corrective action
Workshop: Participants develop an AI Risk and Control Matrix for an AI-enabled business process, linking:
Objective ? Inherent Risk ? Root Cause ? Control Process ? Preventive Controls ? Detective Controls ? Level of Automation ? Residual Risk ? Assurance Response
Participants then design audit procedures to test both control design and operating effectiveness.
Toolkit: AI Risk and Control Matrix and AI Controls Assessment.
Session 8: Auditing Data, Models and Third-Party AI
Internal auditors do not need to become data scientists, but they must understand the governance and control questions that need to be asked when providing assurance over AI.
Key areas covered:
- Data ownership and accountability
- Data quality, completeness, accuracy and integrity
- Data lineage and traceability
- Training, validation and operational data
- Model approval and independent validation
- Model performance and monitoring
- Model drift and performance thresholds
- Changes to models and algorithms
- Third-party AI providers and vendor dependency
- Contractual controls and accountability
- Cloud-based and externally hosted AI solutions
- Availability and reliability of audit evidence
- The appropriate use of technical specialists and other assurance providers
Case Study: Participants conduct an internal audit review of an organisation using a third-party AI solution. They identify key risks, control weaknesses, evidence requirements and areas where internal audit may need to rely on specialist or external assurance.
Toolkit: AI Model Governance Review Checklist, Data Governance Checklist and Third-Party AI Risk Assessment.
Session 9: Designing and Executing the Risk-Based AI Internal Audit
This session brings the previous sessions together by moving from the AI risk universe to a practical internal audit engagement.
Key areas covered:
- Defining the audit objective and scope
- Linking the audit to mission-critical organisational objectives
- Identifying the AI systems and processes within scope
- Establishing suitable audit criteria
- Using King V, ISO/IEC 42001, COSO, NIST AI RMF and COBIT as sources of audit criteria
- Developing the AI audit programme
- Identifying key controls for testing
- Testing control design and operating effectiveness
- Using data analytics and continuous auditing
- Evaluating governance and accountability
- Determining when specialist technical expertise is required
- Developing findings based on root cause, risk, control weakness and organisational impact
Workshop: Participants design a risk-based internal audit programme for an AI-enabled process, including audit objectives, key risks, expected controls, audit procedures, evidence requirements and reporting criteria.
Toolkit: Risk-Based AI Internal Audit Programme Template.
Session 10: Reporting AI Assurance to the Audit Committee and Building the Internal Audit AI Roadmap
The final session focuses on converting technical AI risks and audit findings into information that supports effective governance and decision-making.
Internal audit’s value will not be determined by its ability to explain the technology. It will be determined by its ability to explain what the technology means for the organisation’s objectives, risks, controls, accountability and long-term value.
Key areas covered:
- Reporting AI risk in the context of mission-critical objectives
- Translating technical findings into governance and business implications
- Distinguishing isolated control weaknesses from systemic governance failures
- Reporting significant residual AI risk
- Communicating limitations in assurance coverage
- Developing meaningful AI key risk and assurance indicators
- Reporting emerging and interconnected AI risks
- Identifying gaps and duplication across assurance providers
- Integrating AI into the annual and rolling internal audit plan
- Building AI capability within the internal audit function
- Determining when to develop, recruit or source specialist capability
- Moving towards continuous assurance over high-risk AI environments
Final Practical Exercise: Participants develop an Audit Committee AI Assurance Dashboard covering:
Mission-Critical Objective ? Material AI Risk ? Key Controls ? Control Effectiveness ? Assurance Provider ? Assurance Coverage ? Residual Risk ? Internal Audit Conclusion ? Required Action
The masterclass concludes with each participant developing a 90-Day Internal Audit AI Assurance Roadmap, identifying the immediate actions required to assess their organisation’s AI exposure, update the audit universe, identify assurance gaps, strengthen internal audit capability and incorporate material AI risks into future audit planning.




