AI for Risk, Compliance & Audit
Proficient · M18 · lesson 18 of 26 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
📖
in this lesson

Maintaining Professional Standards in AI-Assisted Output

15 min

Introduction

To ensure that professional standards, ethics, and accountability are maintained in AI-assisted work, and to clarify that AI use does not change the fundamental professional standards and responsibilities that apply to audit and compliance work.

At the Independent Application level, you are expected to apply AI tools and techniques without direct supervision in routine scenarios. You should be able to independently assess AI output quality, identify when outputs require additional review, and produce work products that meet professional standards with AI assistance.

This lesson is designed to be accessible to professionals at all experience levels while providing the depth needed for practical application. Whether you are encountering these concepts for the first time or building on existing knowledge, the material ahead will strengthen your ability to navigate AI governance challenges with confidence and competence.

Core Concepts

Practical Use Cases

Use Case 1: Maintaining Competence While Using AI

Scenario: You want to use AI to analyze regulatory requirements for a complex new area (e.g., cryptocurrency regulatory requirements, climate-related disclosure rules). You are not an expert in this area. How do you maintain professional competence?

Approach:

  • Understand the Topic: Before using AI, develop foundational understanding:
  • - Read official regulatory guidance (SEC, regulatory agencies)
  • - Review industry guidance and peer firm practices
  • - Consult with legal counsel or specialists if appropriate
  • - Develop your own view of what requirements apply
  • Use AI to Augment Understanding:
  • - Use AI to synthesize multiple regulatory documents
  • - Use AI to create a framework of requirements
  • - Use AI to identify areas of uncertainty or ambiguity
  • Validate AI Output:
  • - Check AI interpretations against primary regulatory sources
  • - Consult with specialists where interpretation is uncertain
  • - Confirm that AI-identified requirements align with your reading of regulations
  • - Challenge AI where its interpretation differs from yours
  • Maintain Independence:
  • - Your final assessment should be your assessment, not AI's
  • - If you disagree with AI, state your professional view
  • - If you are uncertain about AI's interpretation, say so rather than defaulting to AI
  • Professional Development:
  • - Use the AI-assisted work as a learning opportunity
  • - Deepen your expertise in the area for future work
  • - Do not expect to rely indefinitely on AI for areas where you should develop expertise

Documentation: - Clearly document your review process - State where you validated AI interpretations against primary sources - Note any areas of uncertainty or where you applied professional judgment to modify AI suggestions - This demonstrates that you maintained competence and professional judgment


Use Case 2: Maintaining Independence and Avoiding Bias

Scenario: You are conducting an audit and want to use AI to identify areas of risk focus. However, you are concerned that AI might introduce bias (e.g., over-flagging certain departments or employee groups).

Approach:

  • Understand Potential Bias Sources:
  • - What historical data is AI using? Does it contain past bias?
  • - What population is AI flagging as "high risk"? Does it correlate with protected characteristics?
  • - What assumptions is AI making about risk? Are those assumptions valid?
  • Validate AI Flagging Logic:
  • - Ask AI to explain its risk flagging logic
  • - Validate that logic against actual control risk, not just statistical patterns
  • - Confirm that high-risk population has actual control issues, not just different characteristics
  • Supplemental Analysis:
  • - Analyze whether AI flagging correlates with protected characteristics (location, demographic groups, etc.)
  • - If concerning correlation exists, investigate whether it represents real control risk or bias
  • - Supplement AI analysis with your independent assessment of where control risks actually exist
  • Professional Judgment:
  • - Apply your professional expertise to validate AI's risk assessment
  • - Do not accept AI risk flagging if it is inconsistent with your knowledge of the environment
  • - Be prepared to override AI recommendations if you believe bias is present
  • Documentation:
  • - Document your validation of AI risk flagging
  • - Explain your professional judgment about which areas are highest risk
  • - Note any concerns about bias and how you addressed them
  • - Show that you maintained independence from AI recommendations

Example: AI flags "Department X" as high-risk based on statistical anomalies. However, you know that Department X is in a location with higher payroll costs and different operational patterns. You validate that the statistical anomalies are explained by operational differences, not control deficiencies. You use professional judgment to focus your testing on actual control risks identified through your knowledge of the environment, not AI's statistical patterns.


Anti-patterns / Misuse Risks

Anti-pattern 1: Delegating Professional Judgment Risk: You treat AI recommendations as directives and report them as your professional conclusions without applying independent judgment.

Why it fails: - You have not maintained professional responsibility - Your conclusions do not reflect your judgment - You are vulnerable if AI is wrong and you did not validate - Professional standards are compromised

Example of misuse: "AI recommended 5 findings. I reported all 5."

Better practice: "AI identified 5 potential issues. Professional review determined that [X] are genuine findings, [Y] are not reportable because [reasons], and [Z] require further investigation before a conclusion can be reached."


Anti-pattern 2: Unconscious Bias in AI Validation Risk: You validate AI analysis in a biased way, confirming findings you expect to find and questioning findings you do not expect.

Why it fails: - Your validation is not objective - You may confirm false findings or miss genuine issues - Your professional independence is compromised

Example of misuse: "AI flagged Department X as high-risk; I agree because I have had concerns about that department." [Confirmation bias]

Better practice: "AI flagged Department X as high-risk based on [specific criteria]. I validated whether [criteria] actually indicate control deficiency vs. operational differences. Based on [validation], I concluded [finding]."


Anti-pattern 3: Hiding Data Confidentiality Violations Risk: You provide sensitive data to an external AI tool without authorization and do not document the risk.

Why it fails: - Professional standards are violated - Organization's data protection policies are breached - If discovered, credibility of your work is compromised - Data confidentiality risk may not be remedied

Example of misuse: "AI analysis is valuable, so I provided the data even though I was not sure it was authorized."

Better practice: "Confirmed that external AI tool use was authorized for [data type] before providing data" or "Masked [sensitive data] before providing to external tool" or "Used internal tools instead of external due to data sensitivity."


[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Human Judgment Checkpoints

Checkpoint 1: Competence Assessment Before using AI in an area: - Am I competent in this subject matter, or do I need to develop competence? - How will I use AI to supplement, not replace, my expertise? - What validation will I perform to ensure I maintain competence?

Checkpoint 2: Independence Validation When reviewing AI-assisted conclusions: - Is my conclusion consistent with my independent assessment? - Am I being influenced by AI in a way that compromises my independence? - Would I reach the same conclusion without AI? - Am I appropriately skeptical of AI?

Checkpoint 3: Professional Skepticism As you rely on AI analysis: - Have I validated AI's key conclusions? - Have I looked for alternative explanations? - Have I challenged AI where I have concerns? - Am I applying appropriate skepticism, not blind trust or blind dismissal?

Checkpoint 4: Confidentiality Check When providing data to AI tools: - Am I authorized to use this tool for this data type? - Is the data appropriately protected? - Have I considered alternatives (internal tools, masking)? - Have I documented the decision?

Checkpoint 5: Responsibility Assessment Before finalizing conclusions: - Are these my professional conclusions? - Have I applied professional judgment? - Would I be comfortable standing behind these conclusions? - Have I documented my reasoning?

Traceability / Defensibility Considerations

Document Professional Judgment: In your workpapers, explicitly document: - Where AI was used - How you validated AI output - Where you applied professional judgment (agreeing with, modifying, or disagreeing with AI) - Any limitations in competence (e.g., "new area; validated AI interpretation with specialist") - Any confidentiality or independence considerations - Your conclusion and basis

Maintain Independence Records: Document: - Who made final conclusions (you, not AI) - What validation you performed - Any areas where you overrode or modified AI recommendations - Basis for your professional judgments

Protect Confidential Data: Document: - Data handling decisions (authorized tools, masking, internal tools) - Risk assessments related to data confidentiality - Any exceptions to standard data protection procedures and their justification

[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Responsible AI and Control Considerations

Transparency with Stakeholders: When appropriate, disclose: - That AI assisted your work - How it contributed (data analysis, pattern recognition, research support) - How it was validated - Any limitations or caveats

Professional Development: Commit to: - Deepening expertise in areas where you rely on AI - Developing skills to validate AI output - Staying informed about AI capabilities and limitations - Maintaining professional standards even as tools evolve

Practice / Reflection Prompts

  • Competence: Identify an area where you might use AI to support work. How would you maintain and develop competence while using AI?
  • Independence: Design a process to validate that your AI-assisted conclusions reflect your professional judgment, not AI default recommendations.
  • Skepticism: Outline how you would apply professional skepticism to AI-generated findings. What would you specifically look for?
  • Confidentiality: Review your organization's policies on external AI tool use. What restrictions exist for sensitive data? How would you comply?
  • Responsibility: Draft language for your work product explaining that your conclusions are your professional conclusions, informed by (not directed by) AI analysis.

[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Glossary / Terms

  • Professional competence: The knowledge and skills necessary to perform audit or compliance work effectively.
  • Professional independence: Freedom from influences that would impair professional judgment.
  • Professional skepticism: An attitude that involves a critical assessment of evidence and willingness to question assumptions.
  • Professional responsibility: The accountability of the professional for their conclusions and recommendations.

Related Lessons

  • Lesson 1: What Makes an AI-Assisted Work Product Defensible (defensibility principles)
  • Lesson 2: Creating Audit Reports and Compliance Deliverables with AI Support (practical application)
  • Lesson 4: Case Studies: Defensible vs. Indefensible AI-Assisted Work (examples of standards in practice)
  • Chapter 5: All lessons on escalation and control (maintaining human oversight)

Detailed Examples

The following examples illustrate how the concepts from this lesson play out in real-world oversight scenarios. Each example is designed to help you recognize similar situations in your own work and respond with appropriate professional judgment.

Example 1: Professional Responsibility -- When to Override AI

Scenario: AI analysis of compliance violations identifies 5 issues. AI recommends all 5 be reported as findings.

Your Professional Responsibility: 1. Review each issue professionally - Issue 1: Genuine control deficiency, material. Report as finding. - Issue 2: Isolated exception, immaterial. Do not report as finding; note for monitoring. - Issue 3: Data quality issue, not a control deficiency. Do not report. - Issue 4: Documented and approved exception. Do not report. - Issue 5: Genuine deficiency but management has already remediated. Report as resolved.

  • Report your professional conclusion:
  • - You report 1 open finding (Issue 1)
  • - You note 1 area for monitoring (Issue 2)
  • - You do not report Issues 3, 4, 5 as findings because professional judgment indicates they are not reportable
  • Document your judgment:
  • - AI recommended 5 findings; professional review determined 1 open finding, 1 monitoring item, 3 not reportable because [specific reasons]
  • - This shows that you applied professional judgment, not blindly accepted AI recommendations

Why this matters: Your professional responsibility is to report conclusions based on your professional judgment, not to report whatever AI recommends. This is where professional standards are most critical.


Example 2: Confidentiality -- When to Restrict AI Use

Scenario: You want to use AI to analyze transaction data to identify control exceptions. The transaction data includes customer information, account numbers, sensitive product information, and personally identifiable information.

Professional Responsibility: 1. Assess confidentiality requirements: - Is there authorization to use external AI tools for this data? - Does the AI tool comply with data protection requirements? - Does the tool retain data? For how long? - Is the data adequately masked/anonymized?

  • Determine appropriateness:
  • - If the AI tool is not authorized for sensitive data: Mask or anonymize data before providing to AI
  • - If masking is not possible: Use internal AI tools (not external)
  • - If neither is available: Conduct analysis manually without AI
  • Document the decision:
  • - "Considered using AI for [analysis]. Determined that external AI tools are not authorized for [sensitive data type]. Used internal tools instead" or "Masked [specific data] before providing to external tool"

Why this matters: Professional standards require that you protect confidential information. AI use does not override this responsibility. This may limit where you can use AI, and that is appropriate.


Putting It Into Practice

Independent application requires a disciplined approach to integrating these concepts into your workflow:

  • Establish personal standards: Define your own quality criteria for AI-assisted work products. What level of verification satisfies you professionally? Document these standards and apply them consistently.
  • Build verification routines: Create repeatable processes for checking AI outputs against source materials, professional standards, and organizational requirements.
  • Exercise professional judgment: Identify situations where AI assistance is appropriate and where human judgment must prevail. This discernment is the hallmark of Level 3 competence.
  • Contribute to organizational learning: Share your experiences -- both successes and challenges -- with your team. Your practical insights help improve AI governance for everyone.

Key Takeaways

  • Professional standards (competence, independence, skepticism, confidentiality, responsibility) do not change because you use AI. If anything, they require heightened attention.
  • Your professional judgment is irreplaceable. AI is a tool that augments your work, not a substitute for your expertise.
  • Confidentiality and data protection requirements apply to AI use. Do not use external tools if data sensitivity prevents it.
  • Transparency about your use of AI, your validation of AI output, and your professional conclusions builds confidence in AI-assisted work.
  • Documentation is critical. Show that you maintained professional standards and applied professional judgment throughout the AI-assisted process.

As you continue through this credential program, you will build on the foundation established in this lesson. Each subsequent lesson adds new dimensions to your understanding and expands your capability to work effectively with AI in oversight roles.