AI for Risk, Compliance & Audit
Aware · M22 · lesson 22 of 30 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
The Oversight Professional's Role with AI
📖
now learning

The Oversight Professional's Role with AI

10 min

Why AI Is a Governance Question, Not Just a Technology Question

When an organization considers deploying AI, the impulse is to treat it as a technology decision: "Let the IT department decide. If it works, it works." This approach creates blind spots that expose the organization to regulatory, operational, and reputational risk.

AI is fundamentally a governance question. Here's why:

The Risk Perspective

AI introduces novel failure modes that traditional systems do not:

  • Accuracy drift: An AI system deployed 18 months ago, once accurate, has degraded as the environment changed. It is now flagging false positives at twice the original rate. Who monitors for this?
  • Bias amplification: An AI system trained on historical data learns to replicate historical discrimination. It approves loans at higher rates for men than women, yet the logic is hidden in millions of parameters.
  • Data dependency: The AI system depends on data quality you have no control over—a vendor's data feed, a third-party integration, user-generated content. If that data becomes contaminated, the system fails silently.
  • Uncontrolled use: An AI system approved for one business unit is copied and deployed by another, in an untested context, without the controls that made it safe in the original context.

These are not IT risks. They are business risks, compliance risks, and strategic risks. Governance is required to identify and mitigate them.

The Compliance Perspective

Regulators increasingly hold organizations accountable for AI deployment:

  • Fair lending rules: If an AI system denies credit to protected classes at higher rates than other customers, it may violate fair lending law—even if the bias was unintentional.
  • Data privacy regulations: If an AI system processes personal data of EU residents, GDPR applies. Consent, data minimization, rights to explanation—all are mandatory.
  • Employment law: If an AI system assesses employees for termination, promotion, or pay, many jurisdictions now require explainability, bias auditing, and employee consent.
  • Financial services rules: Regulators expect organizations to understand models they rely on. "The vendor said it was accurate" is not an acceptable governance response.

Compliance professionals must assess whether AI use complies with these emerging requirements. This is a legal question, not a technology question.

The Audit Perspective

Internal auditors are accountable for verifying that controls are in place and operating effectively. This includes AI systems:

  • Input controls: Is the training data adequate? Is it unbiased? Is it secure?
  • Processing controls: Is there monitoring for accuracy and drift? Are there escalation procedures?
  • Output controls: Is there human review of AI-assisted decisions? Is documentation adequate?
  • Management review: Does leadership monitor AI system performance? Is performance acceptable?

Auditors must develop audit procedures for AI systems. This requires understanding AI, not just IT.

The Governance Perspective

Governance requires that decisions are made through defined processes, with appropriate approval authority, accountability, and documentation. AI systems must fit within this discipline:

  • Approval process: Who approves AI deployment? What are the approval criteria?
  • Escalation: If an AI system is high-risk, what governance committee must approve?
  • Transparency: Do stakeholders understand when AI is being used?
  • Accountability: When an AI-assisted decision causes harm, who is accountable? (The answer: humans, not the AI.)

Enterprise governance ensures that AI deployment reflects organizational values, risk tolerance, and regulatory expectations.

The Governance Takeaway: AI deployment without governance oversight is how organizations incur compliance penalties, lose trust, and fail audits. Oversight professionals are the organizational guardians of governance discipline applied to AI.

Why Oversight Professionals Are Uniquely Positioned to Govern AI

You bring five core competencies to AI governance that are essential and difficult to replace:

1. Evidence Discipline

You are trained to demand evidence and verification. When a business unit claims, "Our AI system is 95% accurate," you do not accept the claim. You ask: "Who tested accuracy? On what data? What does accuracy mean in this context? Was the test independent?"

This evidence discipline is critical governance control. Without it, vendors' marketing claims become organizational policy. With it, you create accountability: "Show me the evidence, or we cannot deploy."

2. Risk Thinking

You think systematically about risk: What could go wrong? How likely? What is the business impact? What controls mitigate? AI systems have identifiable failure modes: hallucination, bias, data contamination, drift, uncontrolled use, shadow AI. You are trained to assess these risks systematically.

A machine learning engineer might ask, "Does the model work?" A risk professional asks, "What are all the ways this model could fail, and what is the business consequence?" These are complementary, but the second is essential for governance.

3. Process Discipline

You understand that governance requires defined processes: Who makes decisions? What is the approval authority? What documentation is required? You know that ad-hoc decision-making is a control failure.

This discipline applies directly to AI governance. Without it, AI systems are deployed informally, without testing or escalation. With it, you establish: deployment criteria, testing requirements, approval thresholds, monitoring processes, and escalation procedures.

4. Healthy Skepticism

You question claims. "How do you know that?" "What is your evidence?" "What are the assumptions?" This skepticism is essential when evaluating AI systems. Vendors claim fairness, accuracy, reliability, transparency. Your job is to verify these claims, not accept them.

A culture of verification, rather than trust, is how governance prevents AI systems from failing undetected in production.

5. Holistic Perspective

You see connections across the organization. You understand that a decision in one area—deployment of an AI system for fraud detection in Finance—affects other areas: compliance risk (fair lending implications), audit scope (new controls to test), operational risk (if the system fails, what happens?), reputational risk (if the system is biased, what is the PR impact?).

This perspective is invaluable for AI governance. It ensures that deployments are not siloed decisions but are integrated into organizational risk and control frameworks.

Your Specific Responsibilities in AI Governance

Based on your role—whether you are in internal audit, compliance, risk management, or enterprise governance—your responsibilities differ. But they share common themes:

Responsibility 1: Identify AI in Use

You cannot govern what you do not know exists. Your first responsibility is to develop a comprehensive inventory of AI systems in use.

This includes:

  • Official AI: Systems formally deployed by technology teams, documented, and approved
  • Departmental AI: Systems deployed by business units (often purchased SaaS tools with AI components)
  • Shadow AI: Systems used informally—an employee using ChatGPT to draft compliance documentation, a team using an analytics tool with embedded ML, an individual using a generative AI tool to process confidential data

Shadow AI is the most dangerous because it is undocumented, uncontrolled, and often involves sensitive data. Your responsibility is to detect it, understand its scope, and escalate it for governance.

How to identify AI in use:

  • Survey business units: "What systems do you use to make decisions? Are any AI-powered?"
  • Review technology implementations: new vendor tools often have AI components not widely understood
  • Monitor SaaS and cloud tools: many include AI/ML features by default
  • Ask about generative AI use: ChatGPT, Claude, Gemini, Copilot usage
  • Assess third-party relationships: do vendors use AI in their services to you?

Responsibility 2: Assess Risk

For each AI system identified, systematically assess risk across five dimensions:

Accuracy Risk: How reliable is the system? What is the documented error rate? How was accuracy measured? Is accuracy being monitored? What is the acceptable tolerance for errors?

Bias Risk: Does the system treat different groups fairly? Has bias testing been performed? What groups were tested (gender, race, age, geography, customer type)? Were any disparities found? If so, how are they mitigated?

Data Risk: What data does the system access or process? Is that data classified appropriately? Are access controls adequate? Is there a privacy impact? Could data be breached? Could data be contaminated?

Operational Risk: If the system fails, what is the business impact? Is there a fallback process? How quickly can the system be taken offline? What is the recovery time?

Compliance Risk: Does the system's use comply with applicable laws and regulations? Are there data privacy implications? Employment law implications? Fair lending implications? Regulatory reporting implications?

Assessment Tool: Create a risk assessment template for AI systems. For each system, document: system name, owner, description, AI type, risk ratings across the five dimensions, mitigating controls, and escalation status.

Responsibility 3: Verify Controls Are in Place

For each risk identified, verify that controls exist to mitigate it:

Input Controls:

  • Is training data documented? What is the source? Is it representative of current use?
  • Is training data validated for quality and bias before use?
  • Is data access restricted to those who need it?

Processing Controls:

  • Is the AI model documented? Is there a model card describing design, performance, limitations?
  • Is accuracy monitored in production? How frequently?
  • Is bias monitored in production? Are performance metrics tracked by demographic group?
  • Is drift detected? Does performance remain acceptable over time?
  • Are there escalation procedures when accuracy degrades or bias is detected?

Output Controls:

  • Is there human review of AI-assisted decisions? What is the review process?
  • For high-stakes decisions, is there additional review or approval required?
  • Are decisions documented? Can they be traced back to the AI system and the human review?

Management Review Controls:

  • Does leadership monitor system performance? How frequently?
  • Are performance metrics reported to governance committees?
  • When performance is unacceptable, is corrective action required?

Responsibility 4: Monitor Ongoing Performance

Verification at deployment is not sufficient. AI systems must be monitored continuously:

  • Is accuracy remaining acceptable? Or is it drifting?
  • Are there signs of emerging bias?
  • Is the system still being used as intended?
  • Have controls remained operating? Or have they been bypassed?
  • Is shadow use developing (the system being used in contexts for which it was not designed)?

Establish monitoring cadence: quarterly at minimum for high-risk systems, at least annually for all others.

Responsibility 5: Escalate and Remediate

When issues are identified, escalate and ensure remediation:

  • Escalate findings appropriately: To data governance, IT security, compliance, business leadership, board committees as needed
  • Require corrective action: Retraining the model, adjusting thresholds, enhancing controls, or system replacement
  • Verify remediation: Do not accept management's word. Verify that corrective actions are effective
  • Document: Maintain audit trail of findings, management responses, and remediation verification

AI Governance Within the Three Lines of Defense

The three lines of defense model structures oversight accountability across the organization. Understanding how AI governance fits within this model is essential:

First Line of Defense: Business Operations and Management

Responsibility: Business units that deploy or use AI systems are responsible for ensuring they operate correctly and comply with organizational policy.

First-line AI controls include:

  • Testing before deployment
  • Monitoring accuracy and bias in production
  • Documenting decisions made with AI assistance
  • Escalating AI system issues to management and governance
  • Retraining systems when performance degrades

First-line responsibility for AI governance: Business leadership must understand which systems are AI-powered, what their limitations are, and ensure adequate first-line controls are in place and operating.

Second Line of Defense: Compliance, Risk, and Data Governance Functions

Responsibility: These functions—compliance teams, risk management, data governance, IT security—establish AI policies, standards, and monitoring processes. They work with the first line to embed controls.

Second-line AI functions include:

  • Compliance: Ensures AI use complies with applicable regulations; provides legal assessment; documents compliance determinations
  • Risk Management: Assesses AI risks; establishes risk appetite and tolerance; monitors enterprise-wide AI risk posture
  • Data Governance: Establishes standards for training data quality, security, and bias; oversees data used in AI systems
  • IT Security: Ensures AI systems are secure; protects models and data from unauthorized access or tampering

Second-line oversight: These functions monitor first-line controls and provide assurance to executive leadership that AI governance is effective.

Third Line of Defense: Internal Audit

Responsibility: Internal audit independently assesses whether first and second-line controls are operating effectively and provides assurance to senior leadership and the audit committee.

Third-line AI audit procedures include:

  • Testing controls over AI systems (input, processing, output, management review)
  • Assessing whether AI is being used appropriately and within governance
  • Identifying shadow AI and escalating for governance
  • Following up on prior-year audit recommendations related to AI systems
  • Providing board audit committee with assessment of organizational AI risk posture

Third-line independence: Internal audit must have sufficient expertise in AI governance to conduct meaningful audits. This may require training, hiring expertise, or engaging external specialists.

Integration Example: Three Lines of Defense for a Fraud Detection AI System

  • First Line (Finance): Tests the fraud detection system before deployment; monitors accuracy and false positive rates daily; escalates when accuracy drops below 85%; investigates and documents false alarms; retrains when performance degrades
  • Second Line (Risk + Compliance): Assesses bias quarterly (stratified performance by vendor type, geography, department); monitors data quality; ensures compliance with fair lending regulations; escalates bias findings to leadership
  • Third Line (Internal Audit): Tests first-line control procedures quarterly; verifies data quality controls are operating; validates accuracy monitoring results; tests a sample of flagged transactions; assesses management's response to bias findings; reports to audit committee on system's control environment

Detecting Shadow AI: A Critical Responsibility

Shadow AI—AI systems used informally, without governance oversight—is perhaps the most significant AI governance risk. It includes:

  • Employees using ChatGPT or Claude to draft compliance documentation, policies, or risk assessments
  • Teams using AI-powered analytics without documenting that AI is involved
  • Individuals processing confidential data through public generative AI platforms
  • Business units deploying AI tools purchased as SaaS without IT or governance approval

Shadow AI is dangerous because:

  • It is uncontrolled: There is no testing, no monitoring, no escalation process
  • It is often inaccurate: Users are unaware of AI limitations (hallucination, bias, lack of understanding) and accept AI output without verification
  • It poses compliance risk: Sensitive data processed through public AI platforms may violate data privacy regulations
  • It creates reputational risk: If biased AI output is used to make a decision, the organization bears responsibility

How to detect shadow AI:

  • Ask directly: In surveys and business reviews, ask teams: "Do you use any AI tools? ChatGPT? Claude? Copilot? Other AI-powered tools?"
  • Monitor external tool usage: Use cloud access security brokers (CASB) and security tools to detect use of public AI platforms
  • Review recent technology implementations: When business units report new tools or efficiency gains, ask whether AI is involved
  • Listen for language clues: Terms like "I used an AI to..." or "The model suggested..." indicate shadow AI
  • Assess risk: For shadow AI identified, assess: Is sensitive data involved? Is the output used in decisions affecting customers, employees, or compliance? Is accuracy verified?

How to remediate shadow AI:

  • Educate: Help teams understand AI limitations, particularly hallucination and bias
  • Establish policy: Define where AI use is acceptable, where it is prohibited, and where it requires controls
  • Provide alternatives: If teams need AI-powered tools, provide approved, controlled alternatives rather than forcing them to choose between prohibition and violation
  • Escalate appropriately: For high-risk shadow AI (processing of sensitive data, use in high-stakes decisions), escalate to compliance and leadership

Case Examples: AI Governance in Action

Case 1: Internal Audit Testing Controls Over Vendor Payment Fraud Detection

Scenario: Finance has deployed an AI system to flag suspicious vendor payments for investigation. The system has been in production for 18 months.

Your audit objective: Verify that controls over the system are adequate and operating effectively.

What you would test:

  • Training data: Request documentation of the system's training data. Verify it is representative: vendor types, payment amounts, geographies, departments. Assess whether it reflects current transaction patterns or historical patterns that have changed.
  • Accuracy monitoring: Pull the last 12 months of accuracy monitoring reports. Verify accuracy remains above 85% (your governance threshold). If accuracy has degraded, follow up on whether management detected it and took corrective action.
  • Bias monitoring: Request stratified performance metrics: is the system accurate across vendor types, geographies, departments? If performance varies significantly, this suggests bias. Escalate to risk management.
  • False alarm investigation: Test a sample of transactions flagged by the AI system but not investigated (false positives). For each, verify: was there documented reason to not investigate? Was the override documented? How frequently is the system overridden? (High override frequency suggests the system's threshold may be miscalibrated.)
  • Escalation process: When accuracy or bias issues are detected, is there a defined escalation process? Has it been tested?

Possible findings:

  • "The fraud detection system lacks documented procedures for override decisions. In 12 of 20 transactions sampled, no documentation existed explaining why an AI flag was not investigated. We recommend: establish override decision documentation requirement; implement monthly reporting on override frequency and reasons; assess whether high override rates indicate system miscalibration."
  • "Accuracy monitoring is not stratified by vendor type. Preliminary analysis suggests the system performs accurately for small, recurring vendors but is less accurate for large, one-off transactions. We recommend: conduct stratified accuracy analysis; assess whether the system requires bias mitigation or retraining."

Case 2: Compliance Assessment of Employee Risk Scoring AI

Scenario: The organization is considering deploying an AI system to assess employee compliance risk and inform disciplinary decisions.

Your compliance responsibility: Assess whether the proposed use complies with applicable laws.

What you would assess:

  • Data privacy: What employee data will the system process? Conduct a data privacy impact assessment (DPIA) under GDPR, CCPA, or other applicable regulations. Determine what consent is required, what data minimization principles apply, and what retention rules govern the data.
  • Employment law: In what jurisdictions are employees located? Review employment law requirements in those jurisdictions for AI in employment decisions. Many jurisdictions now require: explainability (employees have right to know why they were scored as high-risk), fairness assessment (system must not discriminate based on protected characteristics), and consent.
  • Anti-discrimination law: Assess whether the system could have disparate impact on protected groups. If it does, can the organization justify it as business-necessary?
  • Transparency and notice: Must employees be notified that an AI system is being used? Do they have a right to explanation? To opt out?

Possible compliance determination: "The employee risk scoring system may be deployed subject to: (1) Explicit employee consent obtained before data collection; (2) Transparency notice: employees must be informed that an AI system is used to assess risk; (3) Explainability: employees must be able to request explanation of their risk score; (4) Fairness assessment: the system must be tested for disparate impact across protected groups; any disparities must be addressed; (5) Bias monitoring: monthly analysis of outcomes by protected group; findings reported to HR and legal; (6) Data minimization: only collect and retain data necessary for the assessment; (7) GDPR compliance: for EU-based employees, GDPR Article 22 rights apply—employees may contest fully automated decision-making. Recommendation: engage legal counsel in compliance jurisdictions before deployment."

Case 3: Risk Management Assessment of Enterprise AI Risk Posture

Scenario: The organization has conducted an AI inventory and identified 12 AI systems in use. You need to assess enterprise-wide AI risk.

Your risk assessment objective: Characterize the organization's aggregate AI risk and make a recommendation on risk appetite.

What you would assess:

  • System inventory: For each of the 12 systems, categorize by risk: high-risk (affects customers, involves sensitive data, involves decisions affecting compliance), medium-risk (internal use, less critical to business), or low-risk (advisory only, easily overridden).
  • Control maturity: For high-risk systems, assess maturity of controls across five dimensions: accuracy monitoring, bias monitoring, data quality, human review, and escalation. Rate each as mature, developing, or immature.
  • Shadow AI: Assess prevalence. Is there significant shadow AI use? If so, how much sensitive data is at risk?
  • Governance: Is there an AI governance policy? Is it enforced? Do business units understand it?

Possible risk conclusion: "Based on our assessment, the organization has moderate AI risk. Three high-risk systems (fraud detection, customer credit assessment, employee performance) are in use. Of these, one (fraud detection) has mature controls; two have developing controls. We recommend: (1) Accelerate control maturity for the two customer-facing systems to mature by Q3; (2) Conduct enterprise AI governance assessment; (3) Establish policy prohibiting processing of sensitive data through public AI platforms (shadow AI); (4) Provide training on AI acceptable use for all employees; (5) Establish enterprise AI governance committee with representation from business, compliance, risk, and audit."

Key Takeaways: Your Role in AI Governance

  • AI governance is not optional. AI deployment brings governance obligations that touch risk, compliance, audit, and control. Oversight professionals are accountable for ensuring governance is in place.
  • You are uniquely positioned. Your evidence discipline, risk thinking, process discipline, skepticism, and holistic perspective make you ideally suited to govern AI. Leverage these strengths.
  • Your responsibilities span five core functions: Identify AI in use; assess risk; verify controls; monitor performance; escalate and remediate. These apply across audit, compliance, and risk roles.
  • Three lines of defense provides the structure. First line operates AI systems and first-line controls. Second line establishes policy, standards, and monitoring. Third line audits. All three are necessary for effective governance.
  • Shadow AI is a critical risk. Most dangerous is AI in use that you do not know exists. Detecting and governing shadow AI is a priority responsibility.
  • Verification, not trust. Do not accept vendor claims, management assertions, or employee confidence without verification. Evidence discipline applied to AI is governance at its best.
  • Human judgment is essential. AI assists decision-making; humans are accountable. Governance ensures that humans remain in the loop, understand AI limitations, and maintain final authority.