Home / Current Issue / Paper 1722848
The Importance of Auditing Artificial Intelligence: A Governance, Risk, and Assurance Perspective
Subject area: Science,Engineering and Technology · Area of research: AI Auditing
Abstract
Artificial intelligence (AI) has moved from experimental deployment to embedded infrastructure across finance, operations, healthcare, retail, and public administration. As organizations delegate consequential decisions — credit scoring, fraud detection, hiring, medical triage, dynamic pricing, and regulatory reporting — to machine learning models and generative AI systems, the assurance function faces a widening gap between what these systems do and what boards, regulators, and stakeholders can verify. This paper argues that auditing AI is no longer a specialized niche but a core extension of internal audit's mandate to provide independent, objective assurance over governance, risk management, and control. It examines the drivers behind AI audit — financial, regulatory, ethical, and reputational — surveys the emerging standards landscape (IIA's Global Technology Audit Guide series, ISO/IEC 42001, NIST AI RMF, and the EU AI Act), and proposes a practical audit approach spanning governance, data, model, and monitoring layers. The paper concludes that organizations which fail to build AI-specific audit capability expose themselves to undetected model drift, algorithmic bias, regulatory non-compliance, and erosion of stakeholder trust — risks that are financially and reputationally material.
How to cite this paper
@article{1722848,
author = {Syed Rizwan Shahid},
title = {The Importance of Auditing Artificial Intelligence: A Governance, Risk, and Assurance Perspective},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {3},
pages = {795-798},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1722848.pdf},
abstract = {Artificial intelligence (AI) has moved from experimental deployment to embedded infrastructure across finance, operations, healthcare, retail, and public administration. As organizations delegate consequential decisions — credit scoring, fraud detection, hiring, medical triage, dynamic pricing, and regulatory reporting — to machine learning models and generative AI systems, the assurance function faces a widening gap between what these systems do and what boards, regulators, and stakeholders can verify. This paper argues that auditing AI is no longer a specialized niche but a core extension of internal audit's mandate to provide independent, objective assurance over governance, risk management, and control. It examines the drivers behind AI audit — financial, regulatory, ethical, and reputational — surveys the emerging standards landscape (IIA's Global Technology Audit Guide series, ISO/IEC 42001, NIST AI RMF, and the EU AI Act), and proposes a practical audit approach spanning governance, data, model, and monitoring layers. The paper concludes that organizations which fail to build AI-specific audit capability expose themselves to undetected model drift, algorithmic bias, regulatory non-compliance, and erosion of stakeholder trust — risks that are financially and reputationally material.},
month = {September},
}