Home / Current Issue / Paper 1722848
The Importance of Auditing Artificial Intelligence: A Governance, Risk, and Assurance Perspective
Subject area: Science,Engineering and Technology · Area of research: AI Auditing
DOI: 10.64388/IREV10I3-1722848
Abstract
Artificial intelligence (AI) has moved from experimental deployment to embedded infrastructure across finance, operations, healthcare, retail, and public administration. As organizations delegate consequential decisions — credit scoring, fraud detection, hiring, medical triage, dynamic pricing, and regulatory reporting — to machine learning models and generative AI systems, the assurance function faces a widening gap between what these systems do and what boards, regulators, and stakeholders can verify. This paper argues that auditing AI is no longer a specialized niche but a core extension of internal audit's mandate to provide independent, objective assurance over governance, risk management, and control. It examines the drivers behind AI audit — financial, regulatory, ethical, and reputational — surveys the emerging standards landscape (IIA's Global Technology Audit Guide series, ISO/IEC 42001, NIST AI RMF, and the EU AI Act), and proposes a practical audit approach spanning governance, data, model, and monitoring layers. The paper concludes that organizations which fail to build AI-specific audit capability expose themselves to undetected model drift, algorithmic bias, regulatory non-compliance, and erosion of stakeholder trust — risks that are financially and reputationally material.
References
[1] Institute of Internal Auditors (IIA) — Global Technology Audit Guide series on Artificial Intelligence
[2] International Organization for Standardization — ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system
[3] National Institute of Standards and Technology (NIST) — AI Risk Management Framework (AI RMF 1.0)
[4] European Union — Regulation (EU) 2024/1689 (EU AI Act)
[5] Saudi Data and Artificial Intelligence Authority (SDAIA) — AI Ethics Principles and Generative AI Guidelines
How to cite this paper
@article{1722848,
author = {Syed Rizwan Shahid},
title = {The Importance of Auditing Artificial Intelligence: A Governance, Risk, and Assurance Perspective},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {3},
pages = {795-798},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1722848.pdf},
abstract = {Artificial intelligence (AI) has moved from experimental deployment to embedded infrastructure across finance, operations, healthcare, retail, and public administration. As organizations delegate consequential decisions — credit scoring, fraud detection, hiring, medical triage, dynamic pricing, and regulatory reporting — to machine learning models and generative AI systems, the assurance function faces a widening gap between what these systems do and what boards, regulators, and stakeholders can verify. This paper argues that auditing AI is no longer a specialized niche but a core extension of internal audit's mandate to provide independent, objective assurance over governance, risk management, and control. It examines the drivers behind AI audit — financial, regulatory, ethical, and reputational — surveys the emerging standards landscape (IIA's Global Technology Audit Guide series, ISO/IEC 42001, NIST AI RMF, and the EU AI Act), and proposes a practical audit approach spanning governance, data, model, and monitoring layers. The paper concludes that organizations which fail to build AI-specific audit capability expose themselves to undetected model drift, algorithmic bias, regulatory non-compliance, and erosion of stakeholder trust — risks that are financially and reputationally material.},
month = {September},
doi = {https://doi.org/10.64388/IREV10I3-1722848}
}