A Practical Framework for Auditing AI 

Frameworks are not the barrier to auditing AI. Translation is. 

Most internal audit functions are not short on frameworks to choose from. Between NIST, ISO, OWASP, and a growing list of AI-specific standards, there is no shortage of guidance available. What is missing is a practical way to turn that guidance into an actual audit plan, one that a CAE can hand to a team and say, “start here.” 

This piece offers one way to do that, using three of the most relevant frameworks available today and showing how they work together rather than in competition with one another. 

Why a Crosswalk, Not a Single Framework 

For CAEs looking to close the AI readiness gap, the path forward does not require building a proprietary AI audit methodology from scratch. Several credible frameworks already exist, the challenge is translating them into audit-ready, actionable steps. 

Three of the most relevant frameworks today include: 

  • NIST AI Risk Management Framework (AI RMF): broad, lifecycle-based risk management 
  • AIUC-1: framework-specific guidance for auditing AI governance and controls 
  • OWASP Top 10 for LLMs / Agentic Applications: application security risks specific to modern AI systems 

Individually, each is useful. Together, they form a practical foundation for AI auditing, if internal audit can connect them. That connection is the crosswalk. 

Step 1: Create an Initial AI Inventory 

The first step is building an AI inventory that maps directly to the “Map” function in NIST AI RMF, which focuses on understanding AI use, context, and risk exposure. At the same time, AIUC-1 emphasizes completeness of the audit universe, while OWASP implicitly highlights the importance of knowing where AI-driven applications exist. 

What this looks like in practice: 

  • Identify AI use cases across business units 
  • Classify by type (predictive model, generative AI, agentic workflow, etc.) 
  • Capture ownership and business purpose 
  • Tag systems with potential exposure (customer-facing, regulated, etc.) 

This is the non-negotiable starting point. Without visibility into what AI is in use, audit scoping becomes guesswork. 

Step 2: Perform a Lightweight Risk Assessment 

Rather than inventing new criteria, internal audit can align risk assessment to common themes across frameworks. The table below translates abstract framework language into audit scoping criteria — enabling prioritization without overengineering. 

Table 1: AI Risk Assessment Crosswalk 

Risk Dimension NIST AI RMF AIUC 1 Perspective OWASP Alignment Audit Focus
Business Impact Map (Context, Use Case) Risk based audit planning What decisions does the AI drive?
Data Risk Govern + Measure Data governance controls Training data poisoning Is data reliable and appropriate?
Model Behavior Measure + Manage Model validation expectations Prompt injection, model manipulation Is output predictable and explainable?
Governance and Oversight Govern Core control domain Who owns and oversees the AI?
Security Exposure Manage ITGC extension OWASP Top 10 risks Can the system be exploited?
Regulatory Sensitivity Govern + Map Compliance alignment Is this a regulated use case?

Step 3: Start With a Governance Review 

An AI governance audit is the most effective starting point because it aligns strongly across all three frameworks. NIST anchors it under the Govern function. AIUC-1 treats it as a core emphasis area. OWASP assumes governance gaps are the root cause of most exploitability. 

Table 2: Governance Review Crosswalk 

Control Area NIST AI RMF (Govern) AIUC 1 Expectation Audit Questions
AI Policy Framework Risk management structures Governance framework required Is there a formal AI policy?
Roles and Responsibilities Accountability structures AI system ownership Who is accountable for each AI system?
AI Inventory System mapping Audit universe completeness Do we know all AI systems in use?
Risk Classification Risk tiering Risk based audit approach Are high risk systems clearly defined?
Approval and Oversight Lifecycle governance Control checkpoints Are systems reviewed before deployment?

Step 4: Develop a Pilot AI Audit 

When conducting a pilot audit, internal audit can structure procedures using a blended model: the NIST AI RMF lifecycle (Map, Measure, Manage) for flow, AIUC-1 controls for audit rigor, and OWASP risks for technical depth in modern systems. 

Table 3: Pilot Audit Structure 

Audit Phase Framework Anchor Key Activities
Scoping NIST Map Identify system purpose, stakeholders, risk level
Control Identification AIUC 1 Map expected controls across lifecycle
Risk Testing OWASP + NIST Measure Test for vulnerabilities, bias, drift, misuse
Evaluation NIST Manage Assess effectiveness of mitigation strategies
Reporting AIUC 1 Provide actionable, risk based findings

Step 5: Don’t Skip Agentic AI and LLM-Specific Risk 

Many organizations are rapidly deploying agentic AI applications, copilots, automated workflows, decision agents. These introduce risks not typically covered in traditional audits, and OWASP provides a critical supplement to internal audit approaches here. 

Table 4: OWASP Top Risks Mapped to Audit Procedures 

OWASP Risk (Simplified) What It Means Audit Implication
Prompt Injection Manipulating model inputs Test input validation and guardrails
Data Leakage Sensitive data exposure Evaluate data handling and outputs
Insecure Output Handling Unsafe downstream actions Review integration controls
Over Reliance on AI Blind trust in outputs Assess human in the loop controls
Model Denial of Service Resource exhaustion attacks Validate resilience and monitoring

Building a Repeatable Model 

Rather than choosing one framework, leading internal audit functions are using crosswalks as their operating model: 

  • NIST AI RMF defines what good risk management looks like 
  • AIUC-1 defines what internal audit should evaluate 
  • OWASP defines how AI systems can fail in practice 

This layered approach enables consistency across audits, flexibility across use cases, and credibility with stakeholders. 

Bringing It All Together 

Frameworks are not the barrier, translation is. 

Internal audit functions that succeed in auditing AI systems are not those that adopt a single framework, but those that translate frameworks into audit procedures, crosswalk concepts into practical controls, and use visual tools like the tables above to align stakeholders. This approach makes AI auditing both practical and scalable. 

AI frameworks are multiplying, not consolidating. Waiting for a single standard to dominate is not a viable strategy. Internal audit’s role is not to pick a winner, it is to operationalize what exists today. 

The faster audit functions move from frameworks to execution, the faster they close the gap between expectation and readiness.