AI for Risk, Compliance & Audit
Proficient · M19 · lesson 19 of 26 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
📖
in this lesson

Maintaining Testing Rigor with AI Assistance

15 min

Introduction

To establish quality standards and control procedures for AI-assisted audit and compliance testing, ensuring that AI accelerates work without compromising professional standards, evidence quality, or conclusion defensibility.

At the Independent Application level, you are expected to apply AI tools and techniques without direct supervision in routine scenarios. You should be able to independently assess AI output quality, identify when outputs require additional review, and produce work products that meet professional standards with AI assistance.

This lesson is designed to be accessible to professionals at all experience levels while providing the depth needed for practical application. Whether you are encountering these concepts for the first time or building on existing knowledge, the material ahead will strengthen your ability to navigate AI governance challenges with confidence and competence.

Core Concepts

Practical Use Cases

Use Case 1: Quality Control Procedures for AI-Supported Control Testing Scenario: You are designing an audit program for control testing of approval authority controls across a $2B transaction population. AI will be used to test 100% of transactions against approval authority matrices.

Quality control procedures:

  • Input validation:
  • - Confirm transaction population is complete (no missing transactions)
  • - Validate that approval authority matrices in AI system match current documented delegation limits
  • - Perform sample reconciliation (test 20 random transactions to confirm AI can access and interpret data correctly)
  • Methodology validation (pre-testing):
  • - Define approval authority control objective: "All transactions must be approved by authority level matching transaction amount and type"
  • - Test AI logic: Configure AI to flag transactions where approver's authorization level 50% of exceptions, specific transaction type has >10% exception rate)
  • - If patterns are unexpected, stop and reconsider whether AI logic is correct
  • Finding validation:
  • - For each flagged exception, confirm it is a genuine control violation (not a data quality issue, system lag, or documented exception)
  • - Investigate root causes of exceptions
  • - Determine whether exceptions are isolated errors or indicative of systemic control weakness
  • Peer review:
  • - Independent auditor reviews testing documentation, validates that AI methodology was appropriate
  • - Reviews sample of flagged exceptions to confirm they are genuine
  • - Confirms that conclusions about control effectiveness are supported by evidence

Use Case 2: Quality Control for Anomaly-Based Compliance Testing Scenario: Compliance audit of data integrity in customer records. AI is used to identify records with missing required fields, inconsistent data, or unusual patterns. 5,000 records are affected.

Quality control procedures:

  • Understand the baseline:
  • - Before AI analysis, understand what data quality challenges are expected in this population
  • - Establish what percentage of records with missing optional fields is acceptable (vs. genuinely concerning)
  • - Define materiality: What data issues would create material compliance risk?
  • Validate AI findings:
  • - AI flags 500 records with missing beneficial ownership information
  • - Compliance validates: Are these records actually missing required information, or is the field completed in a different location/system?
  • - Of 500 flagged, 400 are confirmed as missing required info, 100 are data quality/system issues
  • Investigate scope:
  • - 400 confirmed gaps represent what % of total customer base?
  • - Are these mostly newly added customers (higher tolerance for incomplete data) or long-standing customers (lower tolerance)?
  • - What is root cause? New customer on-boarding process gap? System limitation? Lack of training?
  • Risk assessment:
  • - Do the missing data gaps create material compliance risk? (e.g., unclear beneficial ownership in customer classified as "high risk" = material; unclear beneficial ownership in customer classified as "low risk" = lower risk)
  • - What is appropriate remediation?
  • Peer review:
  • - Compliance manager reviews findings and agrees that the data gaps are material
  • - Concurs that the root cause and remediation recommendations are appropriate

Anti-patterns / Misuse Risks

Anti-pattern 1: Skipping Peer Review for AI-Supported Work Risk: You conduct AI-supported testing and report findings without peer review because "AI results are objective and do not require review."

Why it fails: - AI methodology requires validation (Did you configure it correctly? Is the logic sound?) - AI results require interpretation (What do these results mean?) - Professional standards require quality control and review - Peer review often catches issues that the original auditor missed

Example of misuse: "AI testing is automated and objective. No need for peer review."

Better practice: "All audit work, including AI-supported work, undergoes peer review. Peer review for AI-supported work specifically validates AI methodology, output, and interpretation."


Anti-pattern 2: Treating "No Exceptions" as "Control Effective" Risk: AI tests a population and finds no exceptions. You conclude the control is effective without investigating further.

Why it fails: - No exceptions may indicate effective control, OR it may indicate that AI testing logic was misconfigured, population was incomplete, or exceptions exist but were not flagged - You have not validated that AI is working correctly - You have not considered whether absence of exceptions is realistic given the population and control design

Example of misuse: "AI found no approval authority exceptions in 10,000 transactions. Control is effective."

Better practice: "AI found no approval authority exceptions in 10,000 transactions. Performed validation testing: sampled 50 transactions and manually verified approval authority for each (100% aligned with AI results, confirming AI is working correctly). Based on 0 exceptions in 10,000 transactions and validation of AI methodology, control is operating effectively."


Anti-pattern 3: Insufficient Documentation of AI Contribution Risk: Your testing documentation mentions AI was used, but does not clearly explain what AI did, what output was generated, or what professional validation was applied.

Why it fails: - A reviewer cannot assess the quality of the work - You have not maintained transparency about AI involvement - If AI was misconfigured, that problem is not visible in documentation - Peer reviewers cannot effectively validate the work

Example of misuse: "AI testing was performed. See attached results. Control is effective."

Better practice: [See Use Case 1 above -- detailed documentation of input, methodology, validation]


[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Human Judgment Checkpoints

Checkpoint 1: Testing Design Before you execute AI-supported testing: - Is my testing approach aligned with audit standards and my audit objective? - Have I defined what constitutes a control exception before I run the test? - Have I validated that AI methodology matches my testing approach? - What quality control procedures will I apply during and after testing?

Checkpoint 2: Result Interpretation After AI testing is complete: - Do the results make sense given what I know about the population and control environment? - Have I investigated any anomalies or unexpected results? - Have I confirmed that AI testing logic worked correctly (validation sample)? - Have I determined materiality of any identified exceptions?

Checkpoint 3: Peer Review Readiness Before presenting findings: - Is my documentation clear enough that an independent reviewer could understand my testing approach? - Have I explained what AI contributed and what professional validation was applied? - Have I documented any limitations or caveats in my testing? - Would a competent peer agree with my conclusions based on the evidence presented?

Checkpoint 4: Evidence and Conclusion Alignment For each conclusion: - Is there sufficient evidence (type and quantity) to support this conclusion? - Have I considered alternative explanations for the evidence I gathered? - Is my conclusion proportionate to the evidence? - Could a peer reviewer disagree with my conclusion? If so, how would I defend it?

Traceability / Defensibility Considerations

Create a Quality Control Checklist for AI-Supported Testing: Develop an audit-specific checklist, including: - Input data validated (completeness, accuracy, reconciliation) - AI methodology documented and validated pre-testing - AI testing parameters configured and reviewed - Population results summarized and reasonableness confirmed - Exceptions investigated (not just counted) - Findings documented with evidence - Peer review completed with documented sign-off - Conclusions supported by documented evidence

Document Decision-Making: For each material judgment, document: - What evidence was available - What alternative interpretations were considered - Why you chose your interpretation - Any professional disagreement with AI findings

Maintain Validation Evidence: Keep: - Pre-test validation documentation (methodology reviewed, logic confirmed) - Sample of flagged exceptions with investigation notes - Population-level results and analysis - Any adjustments made based on review findings

[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Responsible AI and Control Considerations

Automation Bias Risk: There is a tendency to accept AI results without sufficient scrutiny. Combat this by: - Always performing a validation sample of AI results - Actively looking for anomalies in AI output rather than accepting it at face value - Requiring documented peer review of AI methodology and results - Maintaining healthy professional skepticism

Quality Control for Quality Control: Ensure your quality control procedures themselves are adequate: - Is peer review actually independent and rigorous, or is it pro-forma? - Are reviewers given sufficient time and guidance to effectively review AI-supported work? - Are gaps discovered in peer review actually corrected, or are they noted and ignored? - Is there accountability for quality deficiencies in AI-supported work?

Practice / Reflection Prompts

  • Current QC: What quality control procedures do you currently apply to your audit testing? What would change if you used AI to support that testing?
  • Validation Approach: Design a validation procedure for an AI-supported test you might perform. What sample size would be sufficient? What would you validate?
  • Peer Review Guidance: Create guidance for peer reviewers of AI-supported audit work. What should they specifically focus on?
  • Documentation Standard: Draft a documentation standard for AI-supported testing. What must be documented? What level of detail is necessary?
  • Risk Scenarios: What AI errors or misconfigurations do you think would be most likely to occur in your audit environment? How would your QC procedures catch them?

[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Glossary / Terms

  • Quality control: Procedures designed to ensure that work meets professional standards and is free of significant error.
  • Peer review: Independent review of work by someone not involved in the original work, designed to validate methodology and conclusions.
  • Validation testing: Testing performed to confirm that a methodology or system is working correctly (e.g., sample validation of AI output).
  • Automation bias: The tendency to accept automated or AI-generated results without appropriate skepticism.

Related Lessons

  • Lesson 1: AI in Control Testing: Opportunities and Boundaries (control testing design)
  • Lesson 2: Using AI for Data Analysis in Audit and Compliance Testing (data analysis rigor)
  • Chapter 3, Lesson 3: Peer Review and Quality Assurance for AI-Assisted Work Products (collaborative QA)
  • Chapter 4, Lesson 1: What Makes an AI-Assisted Work Product Defensible (broader defensibility standards)

End of Chapter 2

Estimated time commitment: 3 hours for all three lessons

Reflection checkpoint: Consider how you would integrate quality control procedures into AI-supported control testing in your audit environment. What procedures already exist? What would need to be added or modified?

Detailed Examples

The following examples illustrate how the concepts from this lesson play out in real-world oversight scenarios. Each example is designed to help you recognize similar situations in your own work and respond with appropriate professional judgment.

Example 1: Quality Control Catch -- AI Over-Reporting

Scenario: AI identifies 47 "unusual" vendor payments based on statistical outliers. Testing documentation states: "47 vendor payment exceptions identified. Further analysis recommended."

Peer review step: - Reviewer asks: "How many of these 47 have you investigated?" - Answer: "None yet. Flagged for follow-up." - Reviewer says: "You cannot report findings without investigation. You have not established whether these are control violations or normal variance. Either investigate before reporting or remove from findings."

Outcome: Audit team investigates 47 exceptions, confirms 3 as control issues, reclassifies 44 as acceptable variance or data quality issues. Final finding reports 3 issues, not 47.

Lesson: Anomalies are not findings until they are investigated and confirmed.


Example 2: Quality Control Issue -- Insufficient Sample Size

Scenario: AI-supported control testing of reconciliations. AI tests all 8,000 monthly reconciliations for timeliness and sign-off. AI finds 98% compliant (only 160 exceptions). Auditor concludes: "Control is operating effectively."

Peer review step: - Reviewer asks: "How are you interpreting this 98% result? Is that sufficient evidence that the control is effective?" - Auditor: "Yes, 98% compliance indicates good control operation." - Reviewer: "That conclusion depends on your materiality and precision expectations. Did you pre-define what level of exceptions would be material? What statistical confidence does 98% provide? Have you investigated the 160 exceptions to determine root causes?" - Auditor: "I assumed 98% is good... but I have not investigated the exceptions or established materiality thresholds." - Reviewer: "Investigate the exceptions. Determine whether they indicate control design issues or execution lapses. Apply professional judgment about whether the control is adequately effective."

Outcome: Auditor investigates exceptions, determines that 120 were due to timing differences (immaterial) and 40 were legitimate missing sign-offs (control execution issue). Concludes control is effective with noted improvement opportunity.

Lesson: Even strong statistical results require investigation and professional interpretation.


Putting It Into Practice

Independent application requires a disciplined approach to integrating these concepts into your workflow:

  • Establish personal standards: Define your own quality criteria for AI-assisted work products. What level of verification satisfies you professionally? Document these standards and apply them consistently.
  • Build verification routines: Create repeatable processes for checking AI outputs against source materials, professional standards, and organizational requirements.
  • Exercise professional judgment: Identify situations where AI assistance is appropriate and where human judgment must prevail. This discernment is the hallmark of Level 3 competence.
  • Contribute to organizational learning: Share your experiences -- both successes and challenges -- with your team. Your practical insights help improve AI governance for everyone.

Key Takeaways

  • Quality control and peer review are non-negotiable, even for automated or AI-supported testing. AI results require validation and interpretation.
  • Establish explicit quality control touch-points: input validation, methodology validation, output validation, finding investigation, and peer review.
  • Validation procedures should include samples of AI results to confirm AI is working correctly and flagging genuine issues, not false positives.
  • Documentation of AI-supported work should be transparent about AI's contribution, professional validation applied, and assumptions or limitations in the analysis.
  • Peer review of AI-supported work should specifically address AI methodology, validation, and interpretation -- not just accept AI findings as "objective."

As you continue through this credential program, you will build on the foundation established in this lesson. Each subsequent lesson adds new dimensions to your understanding and expands your capability to work effectively with AI in oversight roles.