EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
How EY can help
-
EY IA services can help your business define the IA vision to create value from thought leadership, digital insights, and risk management. Learn more.
Read more
CAEs and internal audit functions face a tall order: to guard against risks from technologies that they likely don’t fully understand and to continue to evolve, without hamstringing functions that see AI and GenAI adoption as do-or-die imperatives. To stay ahead, internal audit must get up to speed on AI risks and controls to properly check and verify alignment and provide assurance that the use of the AI systems within the organization is responsible.
As AI capabilities scale and evolve, traditional calendar driven audit planning is increasingly misaligned with the velocity of risk. Instead of relying solely on annual AI audit plans, internal audit should adopt a rolling, trigger based approach to AI coverage. Triggers may include events such as the deployment of high impact AI use cases, significant model changes, expansion to new data sources, regulatory developments, third party AI adoption or sustained breaches of defined risk thresholds.
By defining these triggers in advance and agreeing proportionate audit responses, internal audit can move resources quickly to the areas of greatest risk and value. This approach preserves independence and rigor while reducing decision latency, allowing internal audit to remain relevant in moments that matter most.