AI in the Entity: Questions every Board and Audit Committee should be asking

24 SEP 2026
AI
Assurance
Digital Adoption and Transformation
Management
Risk

Artificial Intelligence (AI) has quickly evolved from an experimental technology into a strategic business tool. Organizations are integrating AI across finance, operations, human resources, customer service, and decision-making to improve efficiency, reduce costs, and generate insights.

However, as AI becomes embedded in critical processes, it introduces new risks. Unlike traditional systems, AI can produce unpredictable outputs, rely on complex algorithms, adapt to changing data, and influence decisions with limited transparency. This creates challenges related to accountability, data privacy, cybersecurity, compliance, and ethical use.

 

For boards[1]  and audit committees[2], the question is no longer whether to adopt AI, but whether it is being governed effectively. A strong AI governance framework is becoming essential to ensure responsible adoption while managing emerging risks.

AI Is No Longer Just an IT Matter

Technology governance was once primarily the responsibility of IT departments, but AI has changed that. As AI increasingly influences financial reporting, procurement, customer interactions, credit decisions, and strategic planning, it has become a governance issue with direct implications for financial performance, regulatory compliance, corporate reputation, and stakeholder trust.

To manage these risks, organizations need clear governance frameworks that ensure AI is used responsibly, monitored continuously, and aligned with business objectives. This is where the audit committee plays a vital role.

The Expanding Role of the Audit Committee

The audit committee’s responsibilities have expanded beyond financial reporting, internal controls, and risk management to include oversight of AI governance. This means understanding where AI is used, whether clear accountability exists, how AI-related risks are managed, whether controls adequately address AI-generated outputs, and how evolving regulations may impact AI-enabled processes.

Fact-checking and human verification have also become essential controls.

AI-generated outputs should not be assumed to be accurate simply because they appear credible or come from sophisticated AI systems. Audit committees should ensure that management has processes in place to independently verify facts, figures, citations, sources, and other important information generated or supported by AI before it is used in financial reporting, management decisions, regulatory submissions, or external communications.

Audit committees do not need to be AI experts, but they should ensure that management has a strong AI governance framework in place, with appropriate controls for fact-checking, human review, oversight, documentation, and independent assurance.

 

 

Building an Effective AI Governance Framework

Although every organization will adopt AI differently, an effective governance framework should include a few essential elements:

  • Clear governance and accountability: Define ownership of AI systems and assign responsibility for risk management, compliance, and performance oversight.
  • Responsible AI policies: Establish guidelines for ethical AI use, human oversight, data governance, and approval processes before deployment.
  • Data quality and security: Ensure strong controls over data integrity, privacy, and cybersecurity to reduce the risk of inaccurate or biased outputs.
  • Risk assessment and monitoring: Regularly assess AI models for accuracy, bias, explainability, cybersecurity risks, third-party dependencies, and regulatory compliance, with continuous monitoring as models evolve.
  • Documentation and transparency: Maintain clear documentation of AI models, data sources, testing, validation, and ongoing monitoring to support oversight and independent assurance.

The Auditor’s Perspective

AI does not replace traditional audit principles, it expands them. Internal and external auditors must assess whether AI is governed effectively, whether AI-generated information is reliable for financial reporting and decision-making, whether appropriate controls are in place, and whether risks related to third-party AI providers, regulatory compliance, and ethical use are properly managed.

AI can be a valuable tool for auditors, improving efficiency, audit coverage, and the quality of audit work. It can analyze large volumes of data, identify unusual patterns, support risk assessment, and automate the review of documents and transactions, allowing auditors to focus more on higher-risk areas and professional judgment.

However, these benefits depend on reliable data, proper controls, validation, and human oversight. AI should therefore be viewed as a tool that enhances—not replaces—the auditor’s professional judgment, skepticism, and accountability. As its use continues to grow, assurance engagements are also likely to expand to areas such as AI governance, data quality, model management, and responsible AI practices.

AI Governance in Practice: When Professional Services Firms Get It Wrong

The risks of uncontrolled AI use are no longer theoretical. Recent incidents involving major professional-services firms have shown how AI-generated hallucinations, fabricated citations, and insufficient human oversight can undermine the reliability of professional work.

In 2026, PwC[3], EY, and KPMG faced scrutiny in different markets over reports containing inaccurate, fabricated, or unverifiable references, while separate audit-quality controversies involving major professional-services firms also emerged in Canada. These Canadian cases were not necessarily related to AI-generated hallucinations or fabricated citations, but they further highlight the importance of strong professional oversight and quality controls. Deloitte Australia had previously faced similar criticism over a government-commissioned report involving AI-generated errors and fabricated references. These cases highlight that the key issue is not the use of AI itself, but the lack of appropriate governance, human oversight, and controls around its use.[4]

AI can improve productivity and support research and analysis, but its outputs should never be treated as automatically reliable. Organizations need clear rules for AI use, human review, source verification, accountability, and documentation of controls before AI-assisted work is released or relied upon.[5]

For auditors and audit committees, these incidents are a practical warning. The important question is no longer simply whether an organization uses AI, but whether it has effective controls to identify, prevent, and correct AI-related errors before they affect financial reporting, regulatory submissions, business decisions, or reputation.

Questions Every Audit Committee Should Ask

To strengthen AI oversight, audit committees should regularly ask:

  • Which business processes rely on AI?
  • What are the key risks associated with each AI application?
  • Who is accountable for AI governance?
  • How are AI-generated outputs validated before informing business decisions?
  • How is sensitive data protected?
  • Has independent assurance been obtained over AI-related controls?
  • Is the organization prepared for emerging AI regulations?

Asking these questions helps audit committees move AI oversight from reactive compliance to proactive governance. It enables them to identify risks before they materialize, clarify accountability, challenge management’s assumptions, strengthen internal controls, and ensure that AI-generated information is appropriately validated before it influences financial or business decisions. Ultimately, these questions help the audit committee determine whether the organization is using AI in a manner that is reliable, transparent, secure, compliant, and aligned with the organization’s risk appetite.

Looking Ahead

The Rise of AI Governance Frameworks and Regulations[6]

As generative AI tools such as ChatGPT, Claude, and others become widely adopted, governments and regulators have recognized that AI can create significant risks related to data privacy, cybersecurity, bias, fraud, national security, and decision-making. Recent events have demonstrated that these risks are not merely theoretical. In 2026, Anthropic, the developer of Claude, became involved in a significant dispute with the U.S. Department of Defense after the company declined to remove restrictions on the use of its AI models for fully autonomous weapons and mass domestic surveillance. The U.S. government subsequently designated Anthropic as a national-security-related supply-chain risk and directed federal agencies to stop using its technology, although a federal judge later blocked the designation.

The case illustrates an important governance question: who determines how powerful AI systems may be used, and what safeguards should apply when AI is deployed in high-risk environments? It also demonstrates that AI governance extends beyond technical performance to issues of accountability, acceptable use, human oversight, national security, ethics, and regulatory compliance.

In response to these emerging risks, governments and international organizations are introducing regulations, standards, and governance frameworks designed to promote the responsible, transparent, and accountable use of AI.

Some of the most influential initiatives include:

  1. The European Union’s AI Act: Setting the Global Standard

The European Union’s AI Act is the world’s first comprehensive law regulating artificial intelligence. It follows a risk-based approach, imposing stricter requirements on AI systems that pose greater risks, particularly those used in sectors such as financial services, healthcare, recruitment, and critical infrastructure.

High-risk AI systems must meet standards for transparency, risk management, human oversight, and accountability. Organizations that fail to comply may face significant financial penalties, reinforcing the importance of strong AI governance.

  1. The NIST AI Risk Management Framework: A Practical Guide for Organizations[7]

In the United States, the focus has been less on legislation and more on providing organizations with practical guidance. The National Institute of Standards and Technology (NIST) developed the AI Risk Management Framework (AI RMF) to help organizations identify, assess, manage, and continuously monitor AI-related risks throughout the AI lifecycle.

Although the framework is voluntary, it has quickly become one of the most widely recognized references for organizations looking to build responsible AI governance programs. Many multinational companies now use it as a foundation for managing AI risks while supporting innovation.

  1. ISO/IEC 42001: Bringing AI Governance into Management Systems[8]

Recognizing the need for an internationally consistent approach, the International Organization for Standardization (ISO) introduced ISO/IEC 42001, the world’s first management system standard specifically designed for artificial intelligence.

Much like ISO/IEC 27001 transformed information security management, ISO/IEC 42001 provides organizations with a structured framework for governing AI. It encourages organizations to establish clear policies, define roles and responsibilities, implement risk management processes, and continuously monitor and improve their AI systems. The standard helps organizations embed responsible AI practices into their day-to-day operations rather than treating AI governance as a standalone compliance exercise.

  1. OECD AI Principles: Building Trust in Artificial Intelligence[9]

Alongside regulatory and management frameworks, the Organization for Economic Co-operation and Development (OECD) has developed a set of internationally recognized principles that have shaped AI policies around the world.

The OECD emphasizes that AI should be trustworthy, transparent, accountable, fair, and secure. These principles provide a common foundation for governments and organizations seeking to encourage innovation while protecting individuals, businesses, and society from the potential risks associated with AI.

Today, these principles have influenced national AI strategies in dozens of countries and continue to serve as a benchmark for responsible AI governance worldwide.

Why This Matters for Auditors

AI governance is becoming a natural extension of corporate governance and internal control. In addition to evaluating financial reporting and compliance, auditors are increasingly expected to assess whether organizations have appropriate AI governance policies, defined accountability, reliable controls over AI-generated outputs, adequate protection of sensitive data, and compliance with emerging regulations and standards.

As AI adoption accelerates, boards and audit committees will need to demonstrate that AI is governed through a structured framework supported by effective controls and oversight. The question is no longer whether an organization uses AI, but whether it does so within a governance framework that management, auditors, and stakeholders can trust.

AI offers significant opportunities to improve efficiency, innovation, and decision-making, but it also introduces governance challenges that extend beyond technology. Organizations that establish robust AI governance frameworks will be better positioned to manage risk, maintain stakeholder trust, and adapt to evolving regulations.

For audit committees, overseeing AI is quickly becoming as essential as overseeing financial reporting and internal controls. Ultimately, the success of AI will depend not only on the technology itself, but on the strength of the governance that supports it.

 

 

Ultimately, responsible AI use should be part of everyday professional practice, not simply a compliance requirement for auditors. Everyone using AI has a responsibility to verify information, protect confidential data, apply professional judgment, and remain aware of the risks of AI-generated outputs. Building this culture across the organization is essential to ensuring that AI remains a trusted tool that enhances, rather than compromises, the quality and integrity of professional work.

This evolution is already visible around the globe, where policymakers are increasingly addressing the use of AI in education and by students. As AI becomes more embedded in professional and academic life, the question is no longer simply whether AI should be regulated, but whether organizations and individuals should be held accountable for how they use it—much like the expectations that have developed around cybersecurity and data protection.

 

 

 

 

References

This article should be supported by authoritative sources rather than news articles. I recommend citing:

  1. International Auditing and Assurance Standards Board
  2. Institute of Internal Auditors, guidance on AI governance and internal audit.
  3. Committee of Sponsoring Organizations of the Treadway Commission, Achieving Effective Internal Control Over Sustainability and Emerging Technologies and the Internal Control Framework.
  4. National Institute of Standards and Technology, AI Risk Management Framework (AI RMF 1.0). https://www.nist.gov/itl/ai-risk-management-framework
  5. Organization for Economic Co-operation and Development, OECD AI Principles. https://oecd.ai/en/ai-principles
  6. International Organization for Standardization, ISO/IEC 42001:2023 — Artificial Intelligence Management System.
  7. World Economic Forum, publications on AI governance and responsible AI.
  8. PwC just got caught trying to pass AI slop as authentic research | TechSpot
  9. Deloitte admits AI hallucinated quotes in government report, offers partial refund | TechSpot
  10. European Union. Regulation (EU) 2024/1689 (EU AI Act).

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689

 

[1] The governing body responsible for strategic oversight and governance

[2] A board committee responsible for oversight of financial reporting, internal controls, risk management, and audit matters

[3] PwC just got caught trying to pass AI slop as authentic research | TechSpot

 

[4] Deloitte admits AI hallucinated quotes in government report, offers partial refund | TechSpot

 

[5] https://www.nist.gov/itl/ai-risk-management-framework

 

[6] World Economic Forum, publications on AI governance and responsible AI.

 

[7] National Institute of Standards and Technology, AI Risk Management Framework (AI RMF 1.0). https://www.nist.gov/itl/ai-risk-management-framework

 

[8] International Organization for Standardization, ISO/IEC 42001:2023 — Artificial Intelligence Management System.

 

[9] https://oecd.ai/en/ai-principles

 

Related Insights