Level Overview
Build foundational understanding of AI, its capabilities and limitations, risks, and the oversight professional\'s role in governing AI responsibly.
This level contains 5 chapters with 18 total lessons. Work through the chapters in order for the best learning experience. Each chapter builds on the competencies developed in the previous one.
Chapters & Lessons
Getting Started
Begin with Chapter 1 and work through each lesson in sequence. All content is vendor-agnostic and designed for professionals working with any AI platform. Take the time to reflect on how each concept applies to your specific oversight role and organizational context.
What This Level Is Really About
Every auditor reaches a point where they realize: the way we've always done things isn't going to be enough anymore. Not because the old approach was wrong, but because the landscape has fundamentally changed. AI is that shift—and for oversight professionals specifically, it creates a set of challenges that most AI training programs never address.
Most AI literacy courses are built for general business professionals. They teach you what AI is, show you a few demos, and send you on your way. This level is different. It is built around one question: what does an auditor, compliance officer, or risk professional need to understand about AI in order to do their job well?
The answer is not primarily technical. You do not need to build AI systems or write code. What you need is conceptual fluency—the ability to understand what AI is doing well enough to evaluate it, question it, challenge it, and govern it. That is precisely what Level 1: Awareness develops.
Why This Matters for Oversight Professionals
AI is already inside your organization. It may be flagging transactions, scoring vendors, prioritizing audit populations, generating contract summaries, or supporting hiring decisions. In many cases, the business units deploying these systems did not formally notify risk, compliance, or internal audit before going live. The technology moved faster than the governance.
This creates a specific problem for oversight professionals: you are being asked to provide assurance over processes that include AI components you may not fully understand. If you do not know how an AI model works at a conceptual level—what it can and cannot do, what its failure modes are, what questions to ask—you cannot provide meaningful oversight. You can produce a report, but it will not catch what matters.
There is also a second pressure: AI is increasingly being used in oversight work itself. Tools that assist with audit sampling, continuous monitoring, contract review, and compliance screening are becoming standard. Professionals who understand these tools will use them effectively and critically. Those who do not will either avoid them (falling behind peers who use them well) or accept their outputs uncritically (introducing new risks under the guise of efficiency).
Awareness is the foundation that prevents both failure modes.
Core Concepts This Level Covers
What AI Is—and What It Is Not
The term "AI" is used to describe a wide range of technologies, from simple rule-based automation to large language models capable of generating human-quality text. Oversight professionals need to distinguish between these categories because they carry fundamentally different risk profiles and require different governance approaches.
A key distinction this level develops: AI is not a decision-maker. It is a pattern-recognition and prediction system trained on historical data. It does not understand context the way humans do; it does not know your organization's strategy, your regulatory environment, or what changed last quarter. It produces outputs that reflect its training data, and those outputs require human interpretation and judgment before becoming decisions.
Capabilities and Limitations
AI is genuinely capable of tasks that used to require significant human effort: processing large volumes of structured data quickly, identifying statistical patterns across thousands of records, flagging anomalies for human review, and synthesizing text across long documents. These are real and valuable capabilities.
But AI also has well-documented failure modes that oversight professionals must understand. It hallucinates—producing confident, plausible-sounding outputs that are factually wrong. It reflects biases present in its training data, sometimes amplifying them. It can be confidently wrong in ways that are difficult to detect without independent verification. It fails in novel situations that differ from its training distribution. These are not edge cases; they are predictable and recurring.
AI Risks in the Enterprise Context
When AI operates inside organizations, it inherits organizational complexity. Data quality issues become model quality issues. Regulatory requirements constrain what AI systems can and cannot do. Third-party AI vendors introduce supply chain risk. Shadow AI—employees using AI tools that were never formally approved or reviewed—creates ungoverned risk exposure that is difficult to detect and harder to quantify.
The risk landscape for AI is not fundamentally different from the risk landscape for other technology and process risks. It is, however, broader and faster-moving than most. Organizations that wait until they have a mature AI governance program to start asking governance questions will find themselves significantly behind.
The Oversight Professional's Role
The most important conceptual shift in this level is understanding that your role with AI is not to become a technical expert—it is to remain an expert in oversight. Your core skills (professional skepticism, verification, documentation, accountability, escalation) apply directly to AI governance. What changes is the vocabulary you need, the questions you ask, and the specific failure modes you look for.
This level establishes that human judgment is not made obsolete by AI. It is repositioned as a critical control. Decisions made with AI assistance still require a human who is accountable, who has applied judgment, and who can explain and defend the outcome. This principle is not optional—it is the foundation of defensible AI governance in any oversight context.
Real-World Examples from Oversight Work
Audit sampling with AI assistance: An internal audit team uses a machine learning model to prioritize which transactions to include in a sample, based on anomaly scores. The model surfaces a set of high-risk items efficiently. But when the audit manager reviews the model's logic, she realizes it is heavily weighting transaction size—a factor that reflects past fraud patterns but misses a category of low-value, high-frequency manipulation that is actually the current risk. Without her judgment, the sample would have looked rigorous while missing what mattered.
Compliance screening with a language model: A compliance team deploys a large language model to review vendor contracts for prohibited clauses. The model is accurate 94% of the time. On a routine review, a team member accepts a flagged "clean" contract without independent verification. The contract contains a clause the model was not trained to recognize—a recent regulatory addition. The error is discovered in an external audit, not by the internal team.
Shadow AI in a business unit: A finance team begins using an AI tool to draft board-level financial summaries. No one in risk, compliance, or IT is aware. The tool has no data retention controls, which means confidential financial data is being processed by a third-party system without a vendor risk assessment, data processing agreement, or security review. The risk is invisible until someone asks the right question.
Each of these scenarios illustrates a risk that awareness-level knowledge can prevent—not technical expertise, but informed, questioning oversight.
Where People Get This Wrong
Treating AI literacy as a technical problem. Many oversight professionals assume they need to understand how AI models work at a mathematical level before they can govern them. This is not true and leads to paralysis. You do not need to understand gradient descent to evaluate whether an AI system has been validated, has appropriate human oversight, and is producing auditable outputs. Focus on the governance questions, not the engineering.
Assuming AI tools used by the oversight function don't need governance. When audit or compliance teams adopt AI tools for their own work—sampling, document review, continuous monitoring—those tools are subject to the same governance requirements as any other AI system in the organization. The fact that the tool is being used by the oversight function does not make it exempt from validation, documentation, or risk assessment.
Conflating "AI reviewed it" with "it was reviewed." An AI tool processing a document is not the same as a professional reviewing a document. Outputs require human verification, particularly when they will be relied upon for decisions. Treating AI output as equivalent to professional judgment creates accountability gaps that become visible only when something goes wrong.
Waiting for a governance framework before asking questions. AI governance frameworks are useful, but waiting for a complete, approved framework before engaging with AI risk is a mistake. The questions you should be asking now—What AI is in use? Who approved it? How are outputs verified? Who is accountable?—do not require a framework. They require awareness and professional skepticism.
Practical Takeaways
At the end of this level, you should be able to do the following in your professional work:
- Identify AI in use. When you encounter a process in your organization, ask whether AI is involved—and if so, what type, what data it uses, and who is accountable for its outputs. This question alone raises organizational awareness.
- Distinguish AI types. Know the difference between rule-based automation, predictive models, and generative AI. Each has different risk profiles, failure modes, and governance requirements.
- Apply professional skepticism to AI outputs. Treat AI outputs the way you treat management representations: as a starting point for inquiry, not a conclusion. Ask how the output was validated and what could cause it to be wrong.
- Recognize AI. Understand what AI is, why it happens, and how to surface it. The question "are there any AI tools your team uses that weren't formally approved?" belongs in your interviews and walkthroughs.
- Understand where human judgment must remain. For any AI-assisted process, identify the human decision point, the accountable individual, and the escalation path. If these do not exist, that is a finding.
- Communicate AI risks to non-technical stakeholders. Use plain language to explain AI risks in terms of organizational impact—not technical mechanisms. This is a core oversight skill at the awareness level.
Key Insight
Awareness is not a passive state. It is not enough to have heard of AI or to know roughly what it does. Level 1 Awareness means you have developed the conceptual foundation to ask the right questions, recognize the right risks, and maintain meaningful oversight of AI-assisted processes—even when you are not the technical expert in the room. That capability is what this level builds, and it is the prerequisite for everything that follows.
Before You Move On
As you work through the five chapters in this level, keep these questions active in your thinking:
- Where is AI currently operating in my organization—including places no one has formally told me about?
- For each AI-assisted process I know of, is there a clear human accountable for the outputs?
- Does my team have the vocabulary to ask good questions about AI, or are we deferring to technical teams by default?
- What would it look like if an AI system in my area failed silently—producing plausible but wrong outputs over a sustained period? Would we catch it?
You do not need to have answers to these questions yet. The point is to be asking them. That is exactly what Level 1: Awareness equips you to do.