Back

Integrated GRC & AI Governance for Internal Audit

R4,900.00

COURSE OVERVIEW

Artificial intelligence is rapidly changing the environment in which internal audit operates. AI is increasingly embedded in strategic decision-making, financial and operational processes, customer interactions, fraud detection, cybersecurity, human resources, data analytics and automated decision-making.

For internal audit, the challenge is no longer simply to understand AI. The profession must be able to provide credible and independent assurance over how AI is governed, how its risks are managed and whether the controls surrounding AI-enabled processes are appropriately designed and operating effectively.

This two-day masterclass positions internal audit within the emerging AI governance and assurance environment. King V provides the overarching governance context, while ISO/IEC 42001, COSO, NIST AI RMF, COBIT and the Three Lines Model provide complementary structures for evaluating AI governance, risk management, internal control and assurance.

The programme follows the internal audit assurance journey from understanding where AI is being used and how it affects mission-critical objectives, through identifying material AI risks and evaluating governance arrangements, to testing controls and reporting assurance conclusions to executive management, audit committees and governing bodies.

The emphasis throughout is practical. Participants will develop an AI Audit Universe, assess AI governance maturity, construct an AI Risk and Control Matrix, evaluate general and application controls, map combined assurance coverage, design a risk-based AI audit programme and develop an Audit Committee AI Assurance Dashboard.

The objective is to enable internal audit functions to move beyond general AI awareness and begin building a structured, risk-based and defensible approach to AI assurance.

 

COURSE OUTCOMES

By the end of this masterclass, participants will be able to:

  • Understand how AI is changing the organisational risk universe and the mandate of internal audit.
  • Identify where AI is being used across the organisation and determine which AI applications warrant internal audit attention.
  • Assess AI governance and accountability using King V as the overarching governance baseline.
  • Apply ISO/IEC 42001 as a structured basis for evaluating the organisation’s AI management system and assurance readiness.
  • Use COSO, NIST AI RMF and COBIT as complementary criteria when assessing AI-related governance, risk and controls.
  • Evaluate material AI risks including bias, privacy, cybersecurity, hallucination, model drift, explainability, data quality, regulatory exposure and third-party dependency.
  • Differentiate between AI general controls and application controls and design appropriate internal audit procedures.
  • Assess data governance, model governance, human oversight, monitoring, audit trails and third-party AI arrangements.
  • Clarify the respective responsibilities of the first, second and third lines for AI governance, risk management and assurance.
  • Develop an integrated AI assurance map that identifies assurance gaps, duplication and opportunities for reliance.
  • Design a risk-based internal audit engagement for an AI-enabled process.
  • Evaluate the design and operating effectiveness of AI-related controls.
  • Report significant AI governance, risk and control matters in the context of mission-critical organisational objectives.
  • Develop an AI assurance dashboard suitable for reporting to the Audit Committee.
  • Build a 90-day roadmap for strengthening the internal audit function’s AI assurance capability.

 

WHO SHOULD ATTEND

This masterclass is designed specifically for professionals responsible for providing independent assurance over governance, risk management and internal control, including:

Chief Audit Executives, Heads of Internal Audit, Internal Audit Executives, Internal Audit Managers, Senior Internal Auditors, IT Auditors, Technology Auditors, Cybersecurity Auditors, Data and Analytics Auditors, Combined Assurance Specialists, Risk and Assurance Professionals, and Audit Committee Members.

The programme will also benefit internal audit professionals who are beginning to incorporate AI-related risks into their audit universe and annual audit planning processes.

 

-
+

DAY 1: UNDERSTANDING AND AUDITING THE AI GOVERNANCE ENVIRONMENT

Day 1 establishes the foundation internal auditors need to provide credible assurance over AI. The focus moves from simply understanding AI governance frameworks to determining what internal audit should assess, what evidence it should expect to find, where accountability resides and how AI governance should influence the audit universe and assurance plan.

Session 1: The Changing Internal Audit Mandate in an AI-Enabled Organisation

AI is changing both the organisational risk universe and the environment in which internal audit operates. Internal auditors need to understand where AI is being used, how it affects mission-critical objectives and where new or interconnected risks may emerge.

Key areas covered:

  • Understanding how AI changes the organisational risk universe
  • Identifying AI-enabled activities across business processes
  • Recognising generative AI, predictive analytics and automated decision-making as emerging assurance areas
  • Identifying approved, embedded and potentially unapproved or shadow AI
  • Connecting AI use to strategy, performance and mission-critical objectives
  • Assessing the potential impact of AI on value creation and value preservation
  • Understanding how AI changes existing financial, operational, compliance, technology and reputational risks
  • Determining when AI becomes sufficiently material to require internal audit attention
  • Considering the implications of AI for the internal audit universe and risk-based audit plan
  • Maintaining internal audit independence and objectivity when internal audit itself uses AI

Practical Exercise: Participants map where AI could exist across a typical organisation and develop an initial AI Audit Universe, linking AI applications to business processes, mission-critical objectives, material risks and potential assurance requirements.

Toolkit: AI Audit Universe and AI Use Case Identification Template.

Session 2: Auditing AI Governance Using King V

The original programme positions King V as the central governance anchor. For internal audit, the key question becomes: How does internal audit assess whether the governing body and management are exercising effective oversight of AI?

Key areas covered:

  • Applying King V as the governance baseline for assessing AI oversight
  • Evaluating ethical and effective leadership in AI-related decision-making
  • Assessing governing body oversight of technology and information
  • Determining whether accountability for AI has been clearly established
  • Evaluating the relationship between AI governance and organisational purpose
  • Assessing whether AI supports sustainable value creation and preservation
  • Evaluating stakeholder considerations in AI-enabled decisions
  • Assessing transparency and disclosure relating to AI systems and their outcomes
  • Evaluating governance structures for responsible AI deployment
  • Determining whether significant AI risks are appropriately escalated to executive management and the governing body
  • Assessing whether the governing body receives sufficient and reliable information to discharge its oversight responsibilities

Practical Exercise: Participants conduct a King V AI Governance Gap Assessment, examining a hypothetical organisation’s AI governance arrangements and identifying potential governance weaknesses, audit evidence requirements and matters that may need to be reported to the audit committee.

Toolkit: King V AI Governance Audit Checklist.

Session 3: Navigating the AI Governance Framework Ecosystem from an Internal Audit Perspective

No single framework provides internal audit with everything required to assess AI governance, risk and control. Internal auditors need to understand how the different frameworks complement one another and how they can be used as sources of criteria when planning and executing assurance engagements.

Key areas covered:

  • Positioning King V as the overarching governance anchor
  • Understanding ISO/IEC 42001 as the structural foundation for an AI management system
  • Applying COSO to enterprise risk management and internal control
  • Using NIST AI RMF to understand the Govern, Map, Measure and Manage dimensions of AI risk
  • Positioning COBIT within technology and information governance
  • Applying the Three Lines Model to accountability and independent assurance
  • Understanding how the frameworks complement rather than compete with one another
  • Selecting appropriate criteria for different types of AI audit engagements
  • Connecting governance principles to operational controls and audit evidence
  • Integrating AI assurance into the broader GRC and combined assurance architecture

Practical Exercise: Participants develop an AI Governance Framework Alignment Map showing how the different frameworks contribute to:

Governance ? Risk Management ? Technology Governance ? AI Management ? Internal Control ? Assurance

The exercise requires participants to identify which framework provides the most appropriate audit criteria for different aspects of an AI-enabled environment.

Toolkit: AI Governance Framework Alignment Map.

Session 4: Auditing ISO/IEC 42001 and the AI Management System

ISO/IEC 42001 provides internal audit with a structured basis for assessing whether an organisation has established appropriate management arrangements for AI. The internal audit focus is not simply whether policies exist, but whether governance, risk management and controls operate effectively throughout the AI lifecycle.

Key areas covered:

  • Understanding the purpose and structure of an AI management system
  • Assessing the scope of the organisation’s AI management arrangements
  • Evaluating AI policies and governance requirements
  • Assessing defined roles, responsibilities and ownership
  • Evaluating AI risk assessment processes
  • Reviewing AI impact assessment practices
  • Assessing controls across the AI lifecycle
  • Evaluating governance over design, development and acquisition
  • Assessing deployment, operation and ongoing monitoring
  • Reviewing change management and model updates
  • Assessing decommissioning and retirement of AI systems
  • Evaluating documentation, evidence retention and audit trails
  • Assessing monitoring, corrective action and continual improvement
  • Determining readiness for internal and external assurance

Workshop: Participants review a hypothetical AI management system against the core governance and management requirements of ISO/IEC 42001. They identify control gaps, determine the audit evidence required and formulate potential internal audit observations.

Toolkit: ISO/IEC 42001 Internal Audit Readiness Assessment.

Session 5: The Three Lines Model, Combined Assurance and Internal Audit Independence

The final session of Day 1 establishes where internal audit fits within the organisation’s broader AI governance and assurance architecture.

The objective is to ensure that internal audit provides independent third-line assurance without assuming management responsibility for designing, implementing or operating AI governance and controls.

Key areas covered:

  • Clarifying management’s ownership of AI risks and controls
  • Defining first-line responsibilities for AI-enabled processes
  • Understanding second-line oversight by risk management, compliance, legal, cybersecurity, privacy and data governance
  • Defining internal audit’s independent third-line assurance role
  • Protecting internal audit independence when advising on emerging AI governance arrangements
  • Distinguishing advisory work from assurance engagements
  • Mapping assurance activities across the Three Lines Model
  • Assessing the quality and reliability of assurance provided by other functions
  • Determining when internal audit can place reliance on other assurance providers
  • Identifying assurance gaps and unnecessary duplication
  • Considering specialist and external assurance for technically complex AI risks
  • Establishing escalation and reporting mechanisms for material AI governance weaknesses
  • Connecting AI assurance to the organisation’s broader combined assurance approach

Practical Exercise: Participants develop an AI Combined Assurance Map structured around:

Mission-Critical Objective ? AI Risk ? Key Control ? Control Owner ? First-Line Monitoring ? Second-Line Oversight ? Third-Line Assurance ? External Assurance ? Assurance Gap

Participants identify areas of over-assurance, under-assurance and duplication and determine where internal audit should provide independent assurance.

Toolkit: Three Lines AI Assurance Map and AI Combined Assurance Assessment.

 

DAY 2: AUDITING AI RISK, CONTROLS AND ASSURANCE

Day 2 moves from understanding the AI governance environment to the practical assurance responsibilities of internal audit. Participants work through the AI risk universe, evaluate controls, consider the audit implications of data and models, and develop a risk-based approach to auditing AI-enabled processes.

 Session 6: Building the AI Risk Universe

Internal audit needs a structured understanding of the risks introduced or amplified by AI. This session develops an AI-specific risk universe that can be integrated into the organisation’s existing audit universe and risk-based internal audit planning process.

Key areas covered:

  • Bias and discrimination in AI-supported decisions
  • Privacy and protection of personal information
  • Cybersecurity threats affecting AI systems and data
  • Hallucination, accuracy and reliability of AI-generated outputs
  • Model drift and deterioration in model performance
  • Lack of explainability and transparency
  • Poor data quality, integrity and lineage
  • Regulatory and compliance exposure
  • Third-party AI and vendor dependency
  • Reputational risk and AI washing
  • Workforce disruption and inappropriate automation
  • Over-reliance on AI without adequate human oversight
  • Ethical risks and unintended stakeholder consequences

Workshop: Participants assess a hypothetical AI implementation, identify root causes and consequences, determine inherent risk, evaluate existing controls and assurance activities, and assess residual risk.

Toolkit: AI Risk Universe and AI Risk Assessment Template.

 Session 7: Auditing AI Controls – General Controls and Application Controls

This session translates AI risks into the controls internal audit should expect to find and test. Participants distinguish between the broader general controls that support the AI environment and the application controls embedded within individual AI-enabled processes.

Key areas covered:

  • AI governance and oversight controls
  • User access and authorisation controls
  • Data governance and data quality controls
  • Model development, approval and validation controls
  • Change management and version control
  • Preventive, detective and corrective controls
  • Automated versus manual controls
  • Human-in-the-loop and human-on-the-loop controls
  • Exception management and escalation
  • Model performance and drift monitoring
  • Logging, audit trails and traceability
  • Incident management and corrective action

Workshop: Participants develop an AI Risk and Control Matrix for an AI-enabled business process, linking:

Objective ? Inherent Risk ? Root Cause ? Control Process ? Preventive Controls ? Detective Controls ? Level of Automation ? Residual Risk ? Assurance Response

Participants then design audit procedures to test both control design and operating effectiveness.

Toolkit: AI Risk and Control Matrix and AI Controls Assessment.

 Session 8: Auditing Data, Models and Third-Party AI

Internal auditors do not need to become data scientists, but they must understand the governance and control questions that need to be asked when providing assurance over AI.

Key areas covered:

  • Data ownership and accountability
  • Data quality, completeness, accuracy and integrity
  • Data lineage and traceability
  • Training, validation and operational data
  • Model approval and independent validation
  • Model performance and monitoring
  • Model drift and performance thresholds
  • Changes to models and algorithms
  • Third-party AI providers and vendor dependency
  • Contractual controls and accountability
  • Cloud-based and externally hosted AI solutions
  • Availability and reliability of audit evidence
  • The appropriate use of technical specialists and other assurance providers

Case Study: Participants conduct an internal audit review of an organisation using a third-party AI solution. They identify key risks, control weaknesses, evidence requirements and areas where internal audit may need to rely on specialist or external assurance.

Toolkit: AI Model Governance Review Checklist, Data Governance Checklist and Third-Party AI Risk Assessment.

 Session 9: Designing and Executing the Risk-Based AI Internal Audit

This session brings the previous sessions together by moving from the AI risk universe to a practical internal audit engagement.

Key areas covered:

  • Defining the audit objective and scope
  • Linking the audit to mission-critical organisational objectives
  • Identifying the AI systems and processes within scope
  • Establishing suitable audit criteria
  • Using King V, ISO/IEC 42001, COSO, NIST AI RMF and COBIT as sources of audit criteria
  • Developing the AI audit programme
  • Identifying key controls for testing
  • Testing control design and operating effectiveness
  • Using data analytics and continuous auditing
  • Evaluating governance and accountability
  • Determining when specialist technical expertise is required
  • Developing findings based on root cause, risk, control weakness and organisational impact

Workshop: Participants design a risk-based internal audit programme for an AI-enabled process, including audit objectives, key risks, expected controls, audit procedures, evidence requirements and reporting criteria.

Toolkit: Risk-Based AI Internal Audit Programme Template.

 Session 10: Reporting AI Assurance to the Audit Committee and Building the Internal Audit AI Roadmap

The final session focuses on converting technical AI risks and audit findings into information that supports effective governance and decision-making.

Internal audit’s value will not be determined by its ability to explain the technology. It will be determined by its ability to explain what the technology means for the organisation’s objectives, risks, controls, accountability and long-term value.

Key areas covered:

  • Reporting AI risk in the context of mission-critical objectives
  • Translating technical findings into governance and business implications
  • Distinguishing isolated control weaknesses from systemic governance failures
  • Reporting significant residual AI risk
  • Communicating limitations in assurance coverage
  • Developing meaningful AI key risk and assurance indicators
  • Reporting emerging and interconnected AI risks
  • Identifying gaps and duplication across assurance providers
  • Integrating AI into the annual and rolling internal audit plan
  • Building AI capability within the internal audit function
  • Determining when to develop, recruit or source specialist capability
  • Moving towards continuous assurance over high-risk AI environments

 Final Practical Exercise: Participants develop an Audit Committee AI Assurance Dashboard covering:

 Mission-Critical Objective ? Material AI Risk ? Key Controls ? Control Effectiveness ? Assurance Provider ? Assurance Coverage ? Residual Risk ? Internal Audit Conclusion ? Required Action

The masterclass concludes with each participant developing a 90-Day Internal Audit AI Assurance Roadmap, identifying the immediate actions required to assess their organisation’s AI exposure, update the audit universe, identify assurance gaps, strengthen internal audit capability and incorporate material AI risks into future audit planning.