Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Auditing AI-Assisted Decisions in Your OrganizationInternal Controls & Audit
6 min readFor Risk Managers

Auditing AI-Assisted Decisions in Your Organization

Your finance team just used an AI agent to draft a revenue recognition memo. Your compliance officer ran a vendor risk assessment through a large language model. Your internal audit director asked ChatGPT to summarize control deficiencies from the last three quarters.

None of them documented what they asked, how they verified the output, or whether the AI had access to current guidance.

This isn't a traditional risk management problem. It's a decision-making issue. If you're responsible for internal controls, you need to understand how AI is changing your organization's decision-making process before you can assess whether those decisions are sound.

The Problem: AI in Your Decision Stream

Grant Purdy, who chaired the committee that developed AS/NZS 4360 (the predecessor to ISO 31000), spent his post-retirement consulting years asking executives a single question: how do you make decisions?

Not "what are your risks?" or "what's your risk appetite?" Just: walk me through how you decide.

That question matters more now than it did when Purdy was asking it. AI agents are embedded in workflows you might not see. Your staff are using them to draft memos, analyze data, summarize regulations, and assess vendors. The tools are fast, confident, and often wrong.

If you don't know how decisions are being made, you can't evaluate whether the controls around those decisions are effective. And if your audit program still assumes humans are reading source documents and applying judgment without algorithmic assistance, you're testing the wrong process.

What You Need Before Starting

Before you can audit AI-assisted decision-making, you need three things in place:

An inventory of where AI is being used in decision processes. Not where it's approved or sanctioned, but where it's actually happening. This means talking to people, not reviewing procurement records. You're looking for shadow AI: the analyst who runs financial data through Claude, the compliance manager who uses Copilot to draft policy language, the auditor who asks Gemini to explain a new standard.

A working definition of what constitutes a "decision" in your control environment. For Sarbanes-Oxley Act purposes, this includes any conclusion that affects financial reporting: revenue recognition judgments, reserve estimates, control effectiveness assessments, deficiency evaluations. For operational risk, it includes vendor approvals, exception grants, and incident response actions. Be specific about which decisions require human verification and which can be automated.

Access to decision-makers who will tell you the truth. If your audit approach is adversarial, people won't admit they're using AI. You need to position this as process improvement, not gotcha compliance. Frame it as: "We need to understand how you're working so we can make sure the controls actually fit the process."

Step-by-Step Implementation

Step 1: Map Decision Points to Control Activities

Start with your existing process documentation. For each control in your Sarbanes-Oxley Act program or operational risk framework, identify the decision it's meant to influence. A three-way match control supports the decision to pay an invoice. A vendor risk assessment supports the decision to onboard a supplier. A journal entry review supports the decision to post a non-routine transaction.

Now ask: is AI involved in any of these decisions? Don't assume it isn't just because your IT department hasn't deployed an enterprise AI tool. People are using consumer AI products to draft, analyze, and summarize information that feeds into controlled processes.

Step 2: Interview Decision-Makers About Their Actual Workflow

This is where you follow Purdy's approach. Sit with the people who execute the controls and ask them to walk you through their last three instances of performing the task. Not the documented procedure, the actual steps.

Listen for phrases like "I asked it to summarize," "I ran it through," or "I had it draft." When you hear those, probe:

  • What exactly did you ask the AI to do?
  • What output did it give you?
  • How did you verify that output?
  • What would you do if the AI gave you an incorrect answer?
  • Do you know what data sources the AI is accessing?

Step 3: Assess the Reliability and Bias Risk of AI Outputs

For each AI-assisted decision you've identified, evaluate whether the person using the AI can reasonably verify its output. This isn't about whether AI is "good enough." It's about whether the human in the loop has sufficient expertise and information to catch errors.

Consider a scenario where a compliance analyst uses an AI agent to determine whether a new vendor falls under OFAC sanctions. The AI says no. Can the analyst verify that answer? Do they know which sanctions lists the AI checked? Do they know the AI's training data cutoff? Do they know how to spot a false negative?

If the answer to those questions is no, you have a control deficiency. The decision is being made by a tool the decision-maker can't effectively oversee.

Step 4: Document AI Usage in Control Descriptions

Update your control narratives to reflect actual practice. If a control description says "the controller reviews the reconciliation for completeness and accuracy," but the controller is actually using an AI tool to flag anomalies before reviewing, your control description is wrong.

This matters for AS 2201 compliance. If your external auditors are testing a control based on a description that doesn't match the actual process, they're not testing the right thing. And if you're relying on that control for Sarbanes-Oxley Act certification, you're certifying a process that doesn't exist.

Step 5: Define Verification Requirements for AI-Assisted Decisions

For each decision point where AI is used, specify what verification is required. This might mean:

  • Spot-checking AI summaries against source documents
  • Requiring dual review when AI generates draft conclusions
  • Maintaining logs of AI queries and outputs for audit trail purposes
  • Restricting AI use to research and drafting, not final determinations

Make these requirements explicit in your procedures. "Use professional judgment" isn't sufficient when the judgment is being augmented by a tool that hallucinates.

Validation: How to Verify It Works

You'll know this process is working when you can answer three questions for any control in your program:

Can you trace a decision back to its inputs? If the decision involved AI, you should be able to see what was asked, what was returned, and how it was verified. If you can't reconstruct that chain, your audit trail is incomplete.

Can the person who made the decision explain how they verified the AI output? They should be able to tell you specifically what they checked, not just that they "reviewed it." If they can't articulate their verification steps, they're not actually verifying.

Would your external auditors accept the control as designed? If you're describing an AI-assisted process to your auditors, they need to be able to test it. That means documented inputs, documented outputs, and documented verification. If any of those pieces are missing, the control isn't auditable.

Maintenance and Ongoing Tasks

This isn't a one-time assessment. AI tools are changing rapidly, and your staff will adopt new ones without telling you. Build ongoing monitoring into your control testing:

Quarterly: Review AI usage patterns in high-risk decision areas. Talk to the people executing controls. Ask what's changed in their workflow. Don't wait for them to submit a process change request.

Semi-annually: Update control descriptions to reflect current practice. If AI usage has expanded, your documentation needs to reflect that before your external auditors show up to test.

Annually: Reassess which decisions require human verification. As AI tools improve, the verification requirements might change. But don't assume improvement means you can reduce oversight. You need evidence that the tool is reliable for your specific use case.

The question Purdy asked executives still matters: how are you making decisions? But now you need to add a follow-up: and how do you know those decisions are sound when they're informed by tools you don't fully control?

That's not a risk management question. It's an internal control question. And it's one you need to answer before your auditors ask it for you.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like