AI for Risk, Compliance & Audit
Capable · M26 · lesson 26 of 26 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Writing Clear, Professional Internal Communications with AI Support
📖
now learning

Writing Clear, Professional Internal Communications with AI Support

15 min

Introduction

You will learn how to use AI to draft internal communications--memos, emails, stakeholder updates, board summaries--that are clear, professional, and appropriate for their audience, while ensuring that you review and take ownership of the message before it's sent.

At the Assisted Use level, you are moving from understanding concepts to applying them with guidance. You will begin using AI tools under supervision, learning to evaluate their outputs critically and document your verification processes. This is where theory meets practice -- with appropriate guardrails in place.

This lesson is designed to be accessible to professionals at all experience levels while providing the depth needed for practical application. Whether you are encountering these concepts for the first time or building on existing knowledge, the material ahead will strengthen your ability to navigate AI governance challenges with confidence and competence.

Core Concepts

Anti-Patterns / Misuse Risks

Anti-Pattern 1: Sending Unreviewed AI Drafts "I asked AI to draft a memo to the board about a critical finding and sent it the same day without reviewing it myself."

Risk: The memo may contain inaccurate information, inappropriate tone for a board memo, or unclear messaging that leads to misunderstanding or lack of action.

Safeguard: Always review AI-generated communications for accuracy, tone, and appropriateness before sending. Have appropriate stakeholders (policy lead, compliance, communications) review for major communications.


Anti-Pattern 2: Losing Your Voice "I use AI so much for drafting that my memos don't sound like me anymore. They're all generic and formal."

Risk: Professional communication should carry your judgment and voice. Over-reliance on AI-generated language can make communications sound impersonal or robotic, reducing impact.

Safeguard: Use AI drafts as starting points, then personalize them. Add examples, context, and tone that reflect your leadership and judgment.


Anti-Pattern 3: Missing Critical Context "I drafted a memo about a control improvement and sent it without mentioning that this is part of our remediation for a prior audit finding."

Risk: Without context, the memo may seem like a burden or low priority, rather than a critical remediation. People may not understand why you're asking them to do this.

Safeguard: Ensure that AI-generated memos include sufficient context for the reader to understand the "why" and importance of the message.


Anti-Pattern 4: Tone Misalignment "I asked AI to draft a memo to a manager about their control gap. The AI draft was very formal and pointed, almost accusatory. I sent it without softening the tone."

Risk: An overly critical or formal memo may put the control owner on the defensive rather than motivating them to fix the issue. It could damage your relationship and slow remediation.

Safeguard: Review tone carefully in AI-generated communications, especially when addressing sensitive topics or delivering critical messages. Adjust to be constructive and collaborative.


Anti-Pattern 5: No Approval for Major Communications "I drafted a memo to the board about a material risk and sent it on my own. I figured they'd appreciate the urgency."

Risk: Communicating directly to the board about material risks without prior approval from your leadership (CFO, Chief Risk Officer) can create confusion, undermine your credibility, or result in inappropriate escalation.

Safeguard: For major communications (board memos, regulatory responses, policy announcements), ensure appropriate approval before sending. Verify message alignment with leadership.

Human Judgment Checkpoints

Before sending an AI-assisted memo or communication, ask yourself:

  • Accuracy Check: Is all information in this memo accurate? Have I fact-checked key claims?
  • Tone Check: Is the tone appropriate for the audience and the message? Does it reflect my professional judgment?
  • Completeness Check: Will the reader understand what I'm asking and why? Is there sufficient context?
  • Appropriateness Check: Is it appropriate for me to send this, or should it come from leadership (CFO, Board, Audit Committee)?
  • Timing Check: Is this the right time to send this message? Are there sensitivities or other communications pending?
  • Voice Check: Does this sound like me? Or does it sound generic? Have I personalized it?
  • Ownership Check: Am I comfortable taking ownership of this message? Would I be able to defend it if questioned?

[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Traceability / Defensibility Considerations

Communications create records. Important communications may be reviewed in audits or by regulators.

What to Record: - Original communication (email, memo, etc.) - Who drafted it (you, with AI assistance) - Who reviewed and approved it - Date sent and distribution list - Any follow-up or responses - How you used the communication (e.g., to support a decision, to communicate a finding)

Why This Matters: - A regulator reviews your file and asks: "How did the control owner know to remediate this finding?" - Your answer: "We sent a memo documenting the finding, communicated the remediation timeline, and followed up quarterly. [Attach memo, approval record, and follow-up communications.]" - Without documentation: "I think I told them" raises doubt about whether clear communication occurred.

Responsible AI and Control Considerations

Responsible Communication Practices: 1. Transparency: If you mention AI use, frame it as a drafting tool, not a decision-maker 2. Personalization: Don't let AI drafts become generic; add your voice and judgment 3. Ownership: You are accountable for the message, not the AI 4. Accuracy: Verify that facts and figures in AI-generated communications are correct 5. Sensitivity: Be thoughtful about sensitive messages (findings, bad news); consider tone and timing carefully

Control Considerations: - Important communications (findings, risk updates, policy announcements) should follow organizational approval workflows - Maintain records of communications (in email or document management system) per record retention policies - Major communications should be reviewed for regulatory implications (e.g., audit findings may need to be communicated to external auditors)

[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Practice / Reflection Prompts

  • Take a memo you've written recently. Ask AI to draft a version of it. Compare the two. What did AI capture well? What did AI miss? What would you keep from each version?
  • Draft a difficult message (finding, bad news, policy change) with AI assistance. Before sending, ask a trusted colleague: "Does this tone feel right? How would you react to this if you were the recipient?" Use their feedback to adjust.
  • Personalize an AI draft. Add specific examples, your voice, and context that reflect your organization. Compare the personalized version to the original. Does the personalized version have more impact?
  • Track one communication. Document how it was drafted (AI or not), who reviewed it, what changes were made, and how it was received. Would you do anything differently next time?
  • Experiment with audiences. Ask AI to draft the same message for three different audiences (board, control owner, staff). How does the structure and tone change? Which do you prefer and why?

Practical Application

Understanding concepts in the abstract is valuable, but the real test is whether you can apply them in professional practice. This section bridges the gap between theory and application with concrete scenarios drawn from oversight work.

Use Case 1: Risk Committee Memo Your organization identifies a material emerging cybersecurity risk (AI-powered social engineering attacks). You need to brief the risk committee (board-level), explaining the risk, current exposure, and proposed mitigation.

Process: 1. Research the risk (use techniques from Chapter 1) 2. Outline key points: Risk description, why it matters, exposure level, controls to address it, timeline 3. Prompt AI: "Draft a one-page memo for the board risk committee summarizing [risk]. Include: what is this risk, why is it material for us, what's our current exposure, what will we do, what's the timeline. Use clear language suitable for board-level executives." 4. AI produces a draft memo 5. Review: Does this accurately describe the risk? Is the tone appropriate for the board? Does it answer their key questions? 6. Revise: Adjust for accuracy, add specific numbers or examples, refine language 7. Approve: Have your compliance lead or risk officer review and approve 8. Distribute: Send to risk committee with your signature/approval

Use Case 2: Audit Finding Communication You discovered a control deficiency during an audit. You need to communicate the finding to the control owner (manager), explaining what the issue is, why it matters, and what's needed to fix it.

Process: 1. Document the finding: what was tested, what was expected, what you found, why it matters 2. Prompt AI: "Draft a professional memo communicating an audit finding to the control owner. Include: what we tested, what we found, why this matters, what we need to fix it, timeline for remediation." 3. AI produces a finding memo 4. Review: Is this accurate? Is the tone professional but not accusatory? Does it explain the remediation path clearly? 5. Revise: Add specific examples or context, adjust tone if needed, clarify expectations 6. Review with audit lead: Does this finding communication meet audit standards? 7. Send: Deliver to control owner; schedule a discussion

Use Case 3: Policy Rollout Announcement Your organization implemented a new data governance policy. You need to announce it to all staff, explaining what changed, what they need to do, and where to get help.

Process: 1. Review the policy and identify key points relevant to staff 2. Outline: What is data governance? What changed? What does each employee need to do? Where do they get help? 3. Prompt AI: "Draft an email announcement to all staff about a new data governance policy. Keep it friendly and action-oriented. Include: what data governance is, why we're implementing this, 3-4 key things employees need to do, where to get help or ask questions." 4. AI produces a draft email 5. Review: Is this clear? Will staff understand why this matters? Is it too long? Too formal? Does it answer likely questions? 6. Revise: Simplify language, add one or two concrete examples, adjust length and tone 7. Approve: Have policy owner and communications team review 8. Send: Include links to training, one-pager, or FAQ resources

Detailed Examples

The following examples illustrate how the concepts from this lesson play out in real-world oversight scenarios. Each example is designed to help you recognize similar situations in your own work and respond with appropriate professional judgment.

Example 1: Risk Committee Memo

Background: Your CISO flagged AI-powered social engineering as an emerging threat. Attackers are using deepfakes and AI-generated text to impersonate executives and request transfers, password resets, or sensitive data. Your organization has not experienced a material incident, but controls are not optimized for this threat.

Your Prompt to AI: "Draft a one-page memo for the board risk committee on emerging AI-powered social engineering threats. Explain: (1) What is this threat and how does it work? (2) Why is it material for a financial services company like us? (3) What's our current exposure and controls? (4) What do we recommend doing? (5) What's the timeline? Write in clear, jargon-free language. The audience is board members who are not security experts."

AI Draft: ``` MEMO TO: Board Risk Committee FROM: Chief Information Security Officer DATE: March 10, 2026 RE: Emerging Threat -- AI-Powered Social Engineering Attacks

WHAT IS THIS THREAT? Attackers are using artificial intelligence to create convincing deepfake videos, synthetic audio, and AI-generated emails that impersonate executives or trusted partners. They use these tools to trick employees into: - Transferring money - Resetting passwords - Sharing sensitive data (account numbers, customer information, proprietary data)

Unlike traditional phishing emails (which are obviously fake), AI-powered attacks are highly convincing. Employees may not realize they're being deceived.

WHY IS THIS A MATERIAL RISK FOR US? As a financial services company, we: 1. Hold customer assets and execute transfers routinely 2. Have employees with access to sensitive data and systems 3. Face significant financial and reputational loss if compromised 4. Have a responsibility to protect customer information under regulations like GLBA and Gramm-Leach-Bliley

A successful AI-powered social engineering attack could result in: - Fraudulent transfers (financial loss) - Data breach (regulatory penalty and reputational damage) - Customer trust erosion

WHAT'S OUR CURRENT EXPOSURE? Recent assessments show: - 40% of employees cannot reliably identify deepfake audio - Our email filtering does not specifically screen for AI-generated phishing - Our verification procedures for large transfers lack AI-attack-specific safeguards

We have not experienced a material incident to date, but vulnerability is increasing as AI tools become more accessible.

WHAT DO WE RECOMMEND? 1. Enhanced security awareness training (Q2 2026) focused on AI-powered deception and verification procedures 2. Technical controls: AI-detection tools for email and call authentication (Q3 2026) 3. Operational controls: Mandatory verification procedures for large transfers and sensitive data requests (Q2 2026) 4. Quarterly risk assessment to monitor threat landscape

TIMELINE: Q2: Training rollout, operational control implementation Q3: Technical tool deployment Q4: Effectiveness assessment

We are monitoring this threat actively and will escalate if material changes occur. ```

Your Review: - Accuracy: Does this fairly represent the threat? Yes; CISO confirms this reflects industry trends - Tone: Is this appropriate for the board? Yes; clear, not overly technical, explains business impact - Completeness: Missing anything the board would want to know? -> Add: What are peer organizations doing? Are there regulatory expectations? - Clarity: Will board members understand the recommendations? -> Yes, but add one concrete example of how an attack might work

Your Revised Memo: ``` MEMO TO: Board Risk Committee FROM: Chief Information Security Officer DATE: March 10, 2026 RE: Emerging Threat -- AI-Powered Social Engineering Attacks

WHAT IS THIS THREAT? Attackers are using artificial intelligence to create convincing deepfake videos, synthetic audio, and AI-generated emails that impersonate executives or trusted partners. They use these to trick employees into: - Transferring money to attacker accounts - Resetting passwords or granting system access - Sharing sensitive data (account numbers, customer information, strategic plans)

Unlike traditional phishing (which is obviously fake), AI-powered attacks are highly convincing. Example: An attacker creates an audio deepfake of the CEO calling an accountant: "I need you to transfer $2M to my personal account immediately. Keep this confidential." The accountant hears what sounds like the CEO's voice and complies.

WHY IS THIS A MATERIAL RISK? As a financial services company, we are a target because: 1. We execute large financial transfers daily as normal business 2. Employees have access to sensitive customer data and proprietary information 3. A successful attack could result in significant financial loss and regulatory exposure 4. Customers expect us to protect their information under GLBA, SEC, and banking regulations

Impact of a successful attack: fraudulent transfers, data breach, regulatory penalties, customer trust loss.

CURRENT STATE: Threat intelligence (CISA, FBI) indicates this threat is actively targeting financial services. Our assessment shows: - 40% of employees lack training on deepfake detection - Email filters do not specifically identify AI-generated phishing - Verification procedures for transfers >$100K lack specific protections for voice-based fraud - No incidents reported to date, but vulnerability is increasing as AI tools become more accessible

INDUSTRY CONTEXT: Peer institutions (checked with peer network) are implementing similar controls. Regulators are expected to issue guidance on AI-powered social engineering in H1 2026.

RECOMMENDED ACTIONS: 1. Security awareness training (Q2 2026) covering deepfake recognition and verification procedures 2. Technical controls (Q3 2026): Email AI-detection tools, call authentication systems 3. Process controls (Q2 2026): Mandatory verification for high-value transfers and sensitive data requests 4. Quarterly reassessment of threat landscape and control effectiveness

TIMELINE: Q2-Q4 2026; full implementation by year-end.

Recommendation: Approve 2026 cybersecurity budget allocation for these initiatives and review quarterly progress with Risk Committee. ```

Distribution and Documentation: "Memo drafted with AI assistance; reviewed by CISO for accuracy; revised to include example and peer context; approved by CFO and Chief Risk Officer on 2026-03-10. Distributed to Board Risk Committee on 2026-03-11."


Example 2: Audit Finding Memo

Background: During a financial reporting audit, you found that user access reviews are not being performed quarterly as required by policy. Access was reviewed in Q1 and Q3, but Q2 and Q4 reviews were skipped. You need to communicate this to the IT manager (control owner) and request a remediation plan.

Your Prompt to AI: "Draft a professional but friendly memo to an IT manager about an audit finding on access reviews. Include: (1) What we tested, (2) What we expected, (3) What we found, (4) Why this matters, (5) What we need from you (remediation plan), (6) Timeline. Keep it professional and constructive, not accusatory. The goal is to get their cooperation in fixing the issue."

AI Draft: ``` MEMO TO: IT Manager FROM: Internal Audit DATE: March 10, 2026 RE: Audit Finding -- User Access Reviews Not Performed Quarterly

SUMMARY: During our 2026 financial reporting audit, we tested the operating effectiveness of user access controls. We found that user access reviews were not performed in all required quarters (Q2 and Q4 were not performed). This is a deviation from the User Access Control Policy, which requires quarterly reviews.

WHAT WE TESTED: We reviewed user access control procedures to verify that quarterly reviews are performed timely and documented. We examined: - Access review schedules and plans - Completed access review documentation for 2025 and Q1 2026 - Evidence of management approval of access reviews

WHAT WE EXPECTED: Per the User Access Control Policy, section 3.2: "User access reviews must be performed quarterly (Q1, Q2, Q3, Q4) by system administrators with supervisory approval by the IT Manager."

WHAT WE FOUND: - Q1 2025: Access review performed and documented - Q2 2025: Access review NOT performed - Q3 2025: Access review performed and documented - Q4 2025: Access review NOT performed - Q1 2026: Access review in progress (expected completion March 15)

In discussions with your team, we learned that Q2 and Q4 reviews were not prioritized due to other system projects and staffing constraints.

WHY THIS MATTERS: Quarterly user access reviews are a key control for preventing unauthorized access to critical financial systems. If reviews are not performed timely, unauthorized access could go undetected, creating risk of fraud or error. Additionally, this represents a deviation from documented policy and our regulatory obligations under SOX 404 (financial reporting controls).

WHAT WE NEED FROM YOU: 1. Root cause analysis: Why were Q2 and Q4 reviews not performed? What barriers prevented them? 2. Remediation plan: What changes will you make to ensure quarterly reviews are performed going forward? (e.g., dedicated resource, calendar reminders, process change) 3. Catch-up: When will you complete the overdue Q2 and Q4 reviews? 4. Timeline: When do you estimate completion of the remediation plan?

NEXT STEPS: Please provide the root cause analysis and remediation plan by March 24, 2026. We will follow up in Q2 to verify that quarterly reviews are being performed as planned.

If you have questions or need any clarification, please let me know. We appreciate your attention to this matter. ```

Your Review: - Tone: Is this professional but not accusatory? Yes; it's clear about the issue but focuses on solution - Clarity: Does the IT manager understand what was found? Yes; the table makes it very clear - Actionability: Does it tell them what you need? Yes; specific requests for root cause, remediation plan, timeline - Reasonableness: Is the timeline reasonable? -> Check with audit lead; March 24 is 2 weeks, which is reasonable for planning

Your Final Memo: "[Same as AI draft; approved by Internal Audit Lead on 2026-03-10]"

Documentation: "Audit finding memo drafted with AI assistance to ensure clear, professional communication. Reviewed by Audit Lead for tone and completeness. Sent to IT Manager on 2026-03-10 with request for root cause and remediation plan by 2026-03-24."


Example 3: Policy Rollout Announcement

Background: Your organization implemented a new Data Governance Policy. Key points for staff: (1) All data must be classified, (2) Sensitive/restricted data needs approval to use, (3) Data must be encrypted, (4) Violations can result in discipline. You want to announce this in a way that's motivating, not scary.

Your Prompt to AI: "Draft a friendly, action-oriented email to all staff announcing a new Data Governance Policy. Include: (1) Why we're implementing this (protecting customers and company), (2) 3-4 key things employees need to know/do, (3) One example of how it affects their work, (4) Where to get help. Keep it under 300 words. Use a friendly, professional tone--we want people to embrace this, not fear it."

AI Draft: ``` Subject: New Data Governance Policy -- What You Need to Know

Hi Everyone,

We're rolling out a new Data Governance Policy this month. This policy helps us protect customer information, comply with regulations, and keep our company secure. Here's what you need to know:

WHAT'S CHANGING? 1. All data must be classified. When you work with data, ask: Is this Public, Internal, Sensitive, or Restricted? (See the Data Classification Guide linked below.) 2. Sensitive and Restricted data needs approval. If you use sensitive or restricted data in your work, you'll need approval from your manager and the Data Office. 3. Data must be encrypted when stored or sent. This applies to Sensitive and Restricted data. Your IT team can help. 4. Data must be deleted on schedule. Don't keep data longer than required. Your data owner will tell you the retention timeline.

EXAMPLE: You're in Finance and need to analyze customer account numbers for a report. Account numbers are "Sensitive" data. Before you access them, you need approval from your manager and Data Office. When you're done, delete the data per the retention timeline (e.g., 90 days). This protects customers and keeps us in compliance.

WHO TO ASK: - Questions about your work? Ask your manager - Questions about classification? Visit the Data Office ([email protected]) - Training? Register here: [link] - Still confused? Reply to this email

We're here to help. This policy protects all of us.

Thanks, [Your Name] Data Governance Lead ```

Your Review: - Tone: Is this friendly and motivating? Yes; it explains the "why" (protection) not just the "what" (rules) - Length: Is 300 words appropriate? Yes; people will actually read this - Clarity: Will staff understand what to do? Yes; the example and action items are clear - Completeness: Missing anything? -> Add: What if I violate the policy? (discipline); What if I don't know the classification? (ask your manager)

Your Revised Email: ``` Subject: New Data Governance Policy -- What You Need to Know

Hi Everyone,

We're rolling out a new Data Governance Policy this month. This policy helps us protect customer information, comply with regulations, and keep our company secure. Here's what you need to know:

WHAT'S CHANGING? 1. All data must be classified: Public, Internal, Sensitive, or Restricted (see classification guide) 2. Sensitive/Restricted data needs approval before you use it 3. Sensitive/Restricted data must be encrypted when stored or sent 4. Data must be deleted on schedule per retention timelines

REAL-WORLD EXAMPLE: You're in Finance and need customer account numbers for a report. Account numbers are "Sensitive." You must: - Get approval from your manager and Data Office before accessing them - Encrypt them if you email or store them - Delete them after 90 days (retention timeline)

This protects customers and keeps us compliant.

WHAT IF YOU DON'T KNOW? - Not sure what classification applies? Ask your manager or email [email protected] - Not sure if you can use data? Ask your manager--don't guess - Questions about retention? Contact your data owner - Need training? Register here: [link]

WHAT IF YOU VIOLATE THE POLICY? Policy violations may result in discipline, up to and including termination. We want to help you succeed, so ask questions before you proceed.

We're rolling this out gradually, with training and support. You've got this.

Thanks, [Your Name] Data Governance Lead Contact: [email protected] ```

Approval and Distribution: "Email drafted with AI assistance to ensure clarity and tone. Reviewed by Compliance Officer and Communications team on 2026-03-09. Revised to add example and discipline language. Approved by Chief Compliance Officer on 2026-03-10. Distributed to all staff on 2026-03-11 with link to training and FAQ."

Putting It Into Practice

At the Assisted Use level, implementation means beginning to incorporate these concepts into your supervised AI work:

  • Practice with guidance: Use AI tools for low-stakes tasks with a mentor or supervisor available for review. Build confidence gradually before taking on more complex scenarios.
  • Verify systematically: Develop a personal checklist for reviewing AI outputs. Even a simple three-point check (accuracy, completeness, appropriateness) dramatically improves output quality.
  • Document your process: Record what AI tool you used, what prompt or input you provided, what output you received, and what verification steps you performed. This documentation habit is essential.
  • Seek feedback: Share your AI-assisted work products with experienced colleagues. Their input helps calibrate your judgment about when AI outputs are reliable and when they require additional scrutiny.

Key Takeaways

Review the core concepts from this lesson and consider how each one applies to your professional practice.

As you continue through this credential program, you will build on the foundation established in this lesson. Each subsequent lesson adds new dimensions to your understanding and expands your capability to work effectively with AI in oversight roles.