AI for Risk, Compliance & Audit
Strategic · M19 · lesson 19 of 26 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Extending Control Frameworks to Cover AI-Assisted Processes
📖
now learning

Extending Control Frameworks to Cover AI-Assisted Processes

15 min

Introduction

Learn how traditional internal control frameworks (COSO, COBIT, ISO 27001) apply to AI-assisted processes and where you need to add new or enhanced controls specific to AI.

At the Workflow Integration level, you are designing and implementing AI-enhanced processes across your function. You need to think systematically about how AI fits into existing workflows, what controls are necessary, and how to measure the effectiveness of AI-integrated processes at scale.

This lesson is designed to be accessible to professionals at all experience levels while providing the depth needed for practical application. Whether you are encountering these concepts for the first time or building on existing knowledge, the material ahead will strengthen your ability to navigate AI governance challenges with confidence and competence.

Core Concepts

Practical Use Cases

Use Case 1: Applying COSO to AI-Enhanced Audit Testing

An audit function uses AI to flag unusual transactions for auditor review (see Chapter 1).

COSO Control Environment - Principle: Competence--auditors understand AI basics (trained on L1-L2) - Principle: Accountability--the audit partner is accountable for audit quality; the AI tool vendor is accountable for tool performance - Principle: Values--the organization values evidence-based auditing; AI supports gathering more evidence

COSO Risk Assessment - Risk: AI model is biased and over-flags certain types of transactions (e.g., transactions from certain user groups) - Risk: AI model degrades over time as transaction patterns change - Risk: Auditors over-rely on AI flags and miss exceptions in non-flagged transactions - Risk: AI output is not well-explained; auditors can't defend why a transaction was flagged

COSO Control Activities - Control: Before deploying AI, validate that it does not have systematic bias (test on historical data for different user groups, business units) - Control: Quarterly, monitor AI accuracy (compare AI flags to audit conclusions; track false positive rate) - Control: Document the AI model logic (what triggers a flag?) - Control: Test non-flagged samples to ensure AI is not missing exceptions - Control: Auditors review all AI-flagged items; documentation shows auditor judgment on each item

COSO Information & Communication - All auditors are trained on how the AI tool works, what it flags, and how to use it responsibly - Results of quarterly monitoring (accuracy, bias metrics) are communicated to audit leadership

COSO Monitoring - Quarterly, audit leadership reviews AI performance metrics (false positive rate, false negative rate, consistency across locations) - If performance degrades, root cause analysis is performed (is the AI model no longer appropriate for current transaction types?) - Testing of checkpoint controls (audit manager reviews a sample of auditor decisions to confirm they are exercising judgment, not auto-approving)

COBIT Governance - CIO and CAE jointly sponsor the AI tool - Change management: Changes to AI rules or parameters go through a formal approval process

Result: AI tool is integrated into the audit control framework; performance is monitored; it is auditable.

Use Case 2: Applying COSO to AI-Enhanced Compliance Monitoring

A bank's AML team uses AI to screen transactions and prioritize them for analyst review (see Chapter 1).

COSO Control Environment - Principle: Integrity and ethics--the organization is committed to AML/CFT compliance; AI supports this - Principle: Competence--analysts are trained on AML/CFT principles and how to use the AI tool - Principle: Accountability--the Chief Compliance Officer is accountable for AML compliance; the AI vendor is accountable for tool performance

COSO Risk Assessment - Risk: AI model is biased and under-flags transactions from certain customer segments - Risk: AI model drifts; new money laundering typologies are not detected - Risk: Analysts rely too heavily on AI risk scores without exercising independent judgment - Risk: Transactions are not properly screened due to model errors

COSO Control Activities - Control: AI model is developed on representative data and tested for bias (compare false positive/negative rates across customer segments) - Control: Monthly, performance is monitored (SAR rate, flag rate, false positive rate) - Control: AI model is retrained annually with new transaction data - Control: All AI-flagged transactions are reviewed by analysts; analyst has authority to override AI flags - Control: Spot-checking of non-flagged transactions to ensure model is not missing issues

COSO Information & Communication - Analysts are trained on AML/CFT and on how to use the AI tool - AML team leadership is regularly informed of model performance and any issues

COSO Monitoring - Monthly AML metrics review (flag rate, SAR rate, model performance) - Quarterly testing of controls (are analysts actually reviewing AI-flagged transactions? Are they exercising judgment or auto-approving?) - Annual model validation (is the model still appropriate? Should it be retrained?)

COBIT IT Governance - IT team manages the AI tool (deployment, uptime, security) - Change management process for any changes to the model or rules

Result: AML compliance is monitored using AI; AI performance is monitored; controls are documented and tested.

Anti-patterns / Misuse Risks

Anti-Pattern 1: Assuming Traditional Controls Cover AI Believing that existing controls (access control, segregation of duties) are sufficient for AI. Example: An organization has strong IT controls; they assume that is sufficient for their AI system.

Risk: AI-specific risks (bias, drift, model degradation) are not controlled.

Prevention: Explicitly identify AI-specific risks and design controls for them.

Anti-Pattern 2: Hybrid Control Frameworks Without Integration Using both traditional framework (e.g., COSO) and a separate AI governance framework, creating confusion about accountability. Example: Audit function uses COSO for most controls but has a separate AI governance checklist.

Risk: Confusion about who is accountable; gaps or overlaps in controls; difficulty in explaining control environment to auditors.

Prevention: Adapt a single framework to include AI; don't create parallel governance.

Anti-Pattern 3: Controls on Paper Only Documenting controls in the framework but not actually implementing or testing them. Example: Framework includes "Monitor AI accuracy monthly," but no one actually does this.

Risk: Controls don't operate; AI performance is not monitored; failures are not caught.

Prevention: Assign clear ownership; build monitoring into regular meetings/processes; audit controls to ensure they operate.

Anti-Pattern 4: Ignoring Framework Maturity Attempting to achieve Level 5 (optimized) controls before Level 2 (repeatable) are in place. Example: An organization tries to build a sophisticated AI governance program before basic controls (procedures, monitoring) are in place.

Risk: Overinvestment; frustration; controls are not actually followed.

Prevention: Start at Level 1 or 2; mature over time.

[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Human Judgment Checkpoints

Checkpoint 1: Framework Adaptation Have you identified how your organization's control framework applies to AI? What gaps exist? What new controls are needed?

Checkpoint 2: Risk Assessment Have you identified AI-specific risks in your function? For each risk, is there a corresponding control?

Checkpoint 3: Accountability For each AI system, is it clear who is accountable for its accuracy, compliance, and performance? Is accountability documented?

Traceability / Defensibility Considerations

Documentation - Document how AI systems are integrated into the control framework - For each AI system, document the risks (bias, drift, over-reliance, etc.) and the controls that mitigate those risks - Show how roles and accountability are defined

This documentation demonstrates that AI governance is thoughtful and systematic.

[Practical Tip]

As you work through these concepts, consider how each one applies to your current role. Think of a specific scenario from your recent work where this concept would have been relevant. Building these mental connections between theory and practice is the fastest way to internalize new knowledge and make it actionable in your daily responsibilities.

Responsible AI and Control Considerations

Bias and Fairness in Framework - Framework should explicitly address bias as a risk for AI systems - Controls should include bias testing and ongoing monitoring - Results should be tracked by demographic groups or business units to identify bias

Practice / Reflection Prompts

  • Current Framework Review: What control framework does your organization use (COSO, COBIT, ISO 27001, custom)? How is it currently structured?
  • AI Risk Identification: For the AI applications in your function (or proposed), what are the specific risks? Create a matrix: AI system / Risks / Current controls / Gaps
  • Framework Adaptation: How would you adapt your organization's framework to address AI risks? What new principles, processes, or controls are needed?
  • Accountability Map: For each AI system, define who is accountable for accuracy, compliance, performance. Document this.
  • Maturity Assessment: For each AI control, what maturity level is it at (Ad Hoc, Repeatable, Defined, Managed, Optimized)? What would it take to move to the next level?

Detailed Examples

The following examples illustrate how the concepts from this lesson play out in real-world oversight scenarios. Each example is designed to help you recognize similar situations in your own work and respond with appropriate professional judgment.

Example 1: A Well-Extended Framework Audit team integrates AI into COSO framework: - Control Environment: Auditors are trained on AI; management is committed to AI-enhanced audit - Risk Assessment: Identifies specific AI risks (bias, drift, over-reliance) - Control Activities: Implements controls for each risk (bias testing, model monitoring, checkpoint design) - Information & Communication: Procedures are documented; staff are trained - Monitoring: Quarterly review of AI performance; testing of controls

Framework is adapted without being fundamentally changed; AI fits within the traditional control structure.

Example 2: A Poorly-Extended Framework (Anti-Pattern) Compliance team uses AI without extending framework: - No explicit governance of AI (unclear who is accountable) - No monitoring of AI performance (no one reviews whether the tool is working) - No documented controls for AI (unclear what controls exist) - Framework is not updated to address AI-specific risks

Result: AI operates outside the control framework; if a regulator asks "What controls govern your use of AI?", the team has no good answer.

Putting It Into Practice

Workflow integration requires systematic thinking about how these concepts fit into broader organizational processes:

  • Design with controls in mind: When integrating AI into workflows, build verification checkpoints and quality controls into the process from the start -- not as afterthoughts.
  • Measure effectiveness: Establish metrics that track both the efficiency gains from AI integration and the quality of AI-assisted outputs over time.
  • Train and support others: As you integrate AI into team workflows, ensure that all team members understand the controls, verification requirements, and escalation procedures.
  • Iterate based on evidence: Use data from your monitoring processes to continuously improve AI-integrated workflows. What works well? Where do errors occur? How can controls be strengthened?

Deeper Analysis and Professional Context

Overview

To truly internalize these concepts, it helps to understand them not just as abstract principles but as practical tools that directly affect how oversight professionals add value in their organizations. The landscape of AI governance is evolving rapidly, and professionals who develop deep understanding of these topics -- rather than surface-level familiarity -- will be best positioned to navigate uncertainty and provide meaningful guidance.

The Organizational Perspective

Consider how these concepts look from different organizational vantage points. Executive leadership needs assurance that AI risks are being managed without unnecessarily constraining innovation. Business units need practical guidance they can follow without extensive technical training. Technology teams need clear requirements they can build into AI systems and workflows. And oversight professionals -- including you -- serve as the connective tissue, translating between these perspectives and ensuring that governance is effective across all of them.

This multi-stakeholder dynamic means that your understanding of these concepts must be both deep enough to engage meaningfully with technical details and accessible enough to communicate to non-specialists. The ability to operate effectively across these levels is what distinguishes exceptional oversight professionals from adequate ones.

Building Professional Confidence

One of the most common challenges oversight professionals face with AI is confidence. The technology feels new, the terminology is unfamiliar, and the pace of change can be overwhelming. But here is a reassuring truth: the core skills of oversight work -- critical thinking, verification, documentation, professional skepticism, and communication -- are exactly the skills that matter most in AI governance. You are not starting from scratch; you are extending capabilities you have already developed.

The professionals who struggle most with AI governance are not those who lack technical knowledge -- it is those who either defer entirely to technology teams (abdicating their oversight responsibility) or reject AI entirely (missing the opportunity to improve their work). The most effective approach is engaged, informed participation: learning enough to ask the right questions, maintaining healthy skepticism, and continually developing your understanding.

[Continuous Learning Imperative]

AI capabilities are evolving faster than any governance framework can fully capture. This means that the specific rules and guidelines you learn today may need updating tomorrow. What does not change is the need for professional judgment, ethical reasoning, and systematic thinking. Focus on building these enduring capabilities alongside topic-specific knowledge, and you will be well-equipped for whatever the AI landscape brings next.

Connecting Theory to Your Role

As you complete this lesson, challenge yourself to identify at least three specific ways these concepts connect to your current role. Where might you encounter these issues in your daily work? How would you apply these principles in a real scenario? What questions would you ask? This exercise transforms passive learning into active professional development, and it is the difference between understanding a concept and being able to use it when it matters.

Key Takeaways

  • Frameworks are adaptable: COSO, COBIT, ISO 27001 can and should be adapted to address AI
  • AI-specific risks: Identify risks unique to AI (bias, drift, over-reliance) and design controls for them
  • Traditional controls apply: Access control, segregation of duties, documentation apply to AI systems
  • Accountability matters: Clearly define who is responsible for each AI system's accuracy and performance
  • Maturity progression: Start at repeatable level; mature over time as controls stabilize
  • Integration is key: Don't create a separate AI governance framework; integrate AI into the existing control framework

As you continue through this credential program, you will build on the foundation established in this lesson. Each subsequent lesson adds new dimensions to your understanding and expands your capability to work effectively with AI in oversight roles.