AI for Risk, Compliance & Audit
Capable · M21 · lesson 21 of 26 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
📖
in this lesson

Spotting Common AI Mistakes and Red Flags

15 min

Introduction

You will learn to recognize common patterns in AI errors--hallucinations, misstatements, unsupported claims, and logical errors--and techniques to detect these errors efficiently.

At the Assisted Use level, you are moving from understanding concepts to applying them with guidance. You will begin using AI tools under supervision, learning to evaluate their outputs critically and document your verification processes. This is where theory meets practice -- with appropriate guardrails in place.

This lesson is designed to be accessible to professionals at all experience levels while providing the depth needed for practical application. Whether you are encountering these concepts for the first time or building on existing knowledge, the material ahead will strengthen your ability to navigate AI governance challenges with confidence and competence.

Core Concepts

Anti-Patterns / Misuse Risks

Anti-Pattern 1: Believing AI Because It Sounds Authoritative "The AI summary uses specific citations and confident language, so the information must be accurate."

Risk: AI tone can be convincingly authoritative even when the content is hallucinated or wrong.

Safeguard: Verify content based on accuracy, not tone. Don't assume confidence = correctness.


Anti-Pattern 2: Assuming AI Doesn't Hallucinate "AI is a language model; it's not going to make up facts."

Risk: AI hallucinations are well-documented. The model generates plausible-sounding text that can be false.

Safeguard: Assume AI can hallucinate. Verify claims, especially specific facts, statistics, or citations.


Anti-Pattern 3: Not Checking Citations "AI cited NIST SP 800-53, so that citation must be accurate."

Risk: AI frequently cites sources that don't exist or misrepresents actual source content.

Safeguard: Check citations independently. Don't cite sources you haven't verified.


Anti-Pattern 4: Accepting Vague Authority Claims "AI says 'research shows' or 'studies indicate' without specifics, so it must be true."

Risk: "Research shows" is meaningless without identifying which research. AI often uses this phrasing for hallucinations.

Safeguard: Require specific sources. "Research shows" without attribution is a red flag.


Anti-Pattern 5: Skipping Logic Checks "The AI argument seems reasonable, so I won't spend time verifying the logic."

Risk: Logical errors can be hard to spot if you're not looking for them. AI can make subtle logical mistakes.

Safeguard: For important arguments, explicitly check: Does the conclusion follow from the premises?

Human Judgment Checkpoints

When reviewing AI-generated content for errors, ask yourself:

  • Source Verification: Are all citations real? Can I verify them?
  • Statistic Check: Do numbers have sources? Can I find these statistics independently?
  • Logic Check: Does the argument hold? Do conclusions follow from premises?
  • Specificity Check: Are claims specific or vague? Do they pass a sanity check?
  • Consistency Check: Are statements consistent with each other and with known facts?
  • Confidence Check: Is AI expressing appropriate confidence? Or overstating certainty?
  • Tone Check: Does the authoritative tone mask uncertainty or errors?
  • Red Flag Check: Do any red flags suggest potential hallucinations?

[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Traceability / Defensibility Considerations

When you catch an AI error and correct it, document the process:

What to Record: - Error identified (what did AI claim?) - How you detected it (source check, logic check, fact check) - Correct information (what's actually true) - Source for correction (where did you find the correct information) - How the error was corrected (what did you change?)

Why This Matters: - If someone questions your correction: "Why did you change what AI said?" - Your answer: "AI claimed [X], but when I verified it, I found [Y]. Here's my source. [Show verification work.]" - Without documentation: "I just knew it was wrong" provides no credibility.

Responsible AI and Control Considerations

Responsible Error Detection: 1. Vigilance: Assume AI can make errors; verify proactively 2. Documentation: Record errors found and how you corrected them 3. Sharing: When you find systematic AI errors, share lessons with colleagues 4. Tool awareness: Understand your AI tool's limitations and where it's prone to error 5. Humility: Don't assume you'll catch all errors; build in multiple review stages

Control Considerations: - Error detection should be part of your review workflow (documented, systematic) - Multiple reviewers can catch different errors (not all errors will be obvious to one person) - For critical documents, consider independent verification by a peer

[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Practice / Reflection Prompts

  • Hunt for hallucinations. Find an AI-generated summary of a regulation, policy, or research finding. Systematically check 5-10 claims for accuracy. Document what you find. How many hallucinations can you spot?
  • Check citations. In an AI-generated document, pick 3-5 citations and verify them independently. Do they exist? Does the AI representation match the actual source content?
  • Detect logical errors. Find an AI argument or conclusion. Outline the premises and conclusion. Does the logic hold? Are there unstated assumptions?
  • Compare statistics. Take a statistic from an AI-generated document. Search for this statistic in authoritative sources. Is it real? Is it accurately stated?
  • Practice speed. After reviewing several examples, time yourself: How quickly can you detect a hallucinated statistic, misquoted regulation, or logical error? What techniques work fastest?

Practical Application

Understanding concepts in the abstract is valuable, but the real test is whether you can apply them in professional practice. This section bridges the gap between theory and application with concrete scenarios drawn from oversight work.

Use Case 1: Detecting Hallucinated Statistics AI summary claims: "Recent research shows that 78% of organizations experience at least one data breach annually."

Detection process: 1. Where does the 78% come from? AI doesn't cite a source. 2. Search for this statistic: Google "78% of organizations data breach" -> You find no results with this exact number 3. Search for similar research: Look for Verizon Data Breach Investigations Report, Ponemon Institute, other well-known sources 4. Findings: Actual statistics vary (50-60% range depending on organization size and industry), but 78% is not cited anywhere 5. Conclusion: This statistic is likely a hallucination. Don't use it.

Use Case 2: Detecting Misstatement of Regulation AI summary claims: "The SEC Regulation SHO prohibits all short selling of financial services stocks."

Detection process: 1. Read actual SEC Regulation SHO -> Regulation SHO addresses short selling disclosure and delivery requirements, NOT a blanket prohibition 2. AI misstatement: Inventing a rule that doesn't exist 3. Correct statement: Regulation SHO requires disclosure of short positions and delivery of borrowed securities within specific timeframes 4. Conclusion: AI oversimplified (or hallucinated) the regulation. Correct the error.

Use Case 3: Detecting Logical Error AI argues: "Since our control testing shows this control is operating effectively, we should not need to test it again next year."

Detection process: 1. Logic check: Does "effective now" mean "will remain effective"? No. 2. Control testing principle: Regular testing is required regardless of prior results because controls can degrade 3. AI error: Logical fallacy (confusing "effective at point in time" with "no longer needs testing") 4. Conclusion: The logic is flawed. Clarify that continuing testing is appropriate.

Detailed Examples

The following examples illustrate how the concepts from this lesson play out in real-world oversight scenarios. Each example is designed to help you recognize similar situations in your own work and respond with appropriate professional judgment.

Example 1: Detecting Hallucinated Citation

AI Claims: "According to CISA Alert AA21-134A, issued in May 2021, organizations should implement multi-factor authentication for all external-facing applications."

Your Detection Process:

Step 1: Check if CISA Alert AA21-134A exists - Go to CISA.gov and search for AA21-134A - Find: Alert AA21-134A exists (it addresses Kaseya Software Supply Chain Compromise) - Check content: The alert does mention security recommendations, but does it specifically recommend MFA for all external-facing applications?

Step 2: Read the actual alert content - Alert AA21-134A focuses on Kaseya VSA software vulnerabilities - Recommendations are specific to that software and the exploit - It does NOT make a universal statement about MFA for all external-facing applications - Other CISA alerts and guidance (e.g., CISA Cybersecurity Advisories) do recommend MFA, but not this specific alert

Step 3: Conclusion - AI cited a real alert but misrepresented its content (or confused it with other guidance) - The claim about MFA is probably accurate (it IS recommended), but the citation is wrong - If you had relied on this citation as your authority, you might cite the wrong source

Corrected Statement: "CISA and NIST guidance recommend implementing multi-factor authentication for all external-facing applications. (See CISA Cybersecurity Advisories and NIST SP 800-63B for details.)"


Example 2: Detecting Hallucinated Statistic

AI Claims: "According to recent industry surveys, 92% of compliance professionals report that AI tools have reduced their audit time by 30-40%."

Your Detection Process:

Step 1: Search for this statistic - Google "92% compliance professionals AI audit time" -> No direct results - Google "compliance professionals AI tools audit time survey" -> Find some related research, but not this specific statistic

Step 2: Check authoritative sources - Compliance Institute, ISACA, IIA (Institute of Internal Auditors) surveys on AI adoption - These sources may have relevant data, but likely not this exact statistic - Ask: Where would AI have gotten this number? What survey or study?

Step 3: Reasonableness check - 92% is very high (universal adoption among a diverse group) - 30-40% time reduction is specific and significant - This sounds like an invented statistic designed to support a narrative

Step 4: Conclusion - This statistic is likely hallucinated; don't use it in professional work - If you need actual data on AI adoption among compliance professionals, search authoritative sources (ISACA, IIOC, professional surveys)

Safer Alternative: "Some early adopters report that AI tools assist with routine tasks like summarization and initial drafting, potentially reducing time spent on these activities. However, comprehensive data on time savings and ROI for compliance teams is still emerging."


Example 3: Detecting Logical Error

AI Claims: "Since the control testing performed in Q1 2026 showed no exceptions, we can safely conclude that no remediation is needed for that control."

Your Detection Process:

Step 1: Logic analysis - Premise: Control testing showed no exceptions - Conclusion: No remediation needed - Missing link: "Control testing showed effective operation at a point in time" does not mean "control requires no future change"

Step 2: Application to control principles - Control effectiveness can change over time (staffing changes, process changes, system updates) - A control that was effective in Q1 may have degraded by Q2 - Even controls that are working require maintenance and monitoring

Step 3: Audit standard check - Audit standards (PCAOB, AICPA, IIA) require continuous or periodic testing - A single test result does not justify eliminating future testing

Step 4: Conclusion - AI confused "point in time effectiveness" with "ongoing effectiveness" - Logical error: Correct conclusion is that control was effective at that time; continue monitoring/testing

Corrected Statement: "Q1 2026 control testing found no exceptions, indicating effective operation at that time. We will continue testing in Q3 2026 to confirm ongoing effectiveness and identify any degradation due to process or system changes."

Putting It Into Practice

At the Assisted Use level, implementation means beginning to incorporate these concepts into your supervised AI work:

  • Practice with guidance: Use AI tools for low-stakes tasks with a mentor or supervisor available for review. Build confidence gradually before taking on more complex scenarios.
  • Verify systematically: Develop a personal checklist for reviewing AI outputs. Even a simple three-point check (accuracy, completeness, appropriateness) dramatically improves output quality.
  • Document your process: Record what AI tool you used, what prompt or input you provided, what output you received, and what verification steps you performed. This documentation habit is essential.
  • Seek feedback: Share your AI-assisted work products with experienced colleagues. Their input helps calibrate your judgment about when AI outputs are reliable and when they require additional scrutiny.

Key Takeaways

Review the core concepts from this lesson and consider how each one applies to your professional practice.

As you continue through this credential program, you will build on the foundation established in this lesson. Each subsequent lesson adds new dimensions to your understanding and expands your capability to work effectively with AI in oversight roles.