Frameworks are not the barrier to auditing AI. Translation is.
Most internal audit functions are not short on frameworks to choose from. Between NIST, ISO, OWASP, and a growing list of AI-specific standards, there is no shortage of guidance available. What is missing is a practical way to turn that guidance into an actual audit plan, one that a CAE can hand to a team and say, “start here.”
This piece offers one way to do that, using three of the most relevant frameworks available today and showing how they work together rather than in competition with one another.
Why a Crosswalk, Not a Single Framework
For CAEs looking to close the AI readiness gap, the path forward does not require building a proprietary AI audit methodology from scratch. Several credible frameworks already exist, the challenge is translating them into audit-ready, actionable steps.
Three of the most relevant frameworks today include:
- NIST AI Risk Management Framework (AI RMF): broad, lifecycle-based risk management
- AIUC-1: framework-specific guidance for auditing AI governance and controls
- OWASP Top 10 for LLMs / Agentic Applications: application security risks specific to modern AI systems
Individually, each is useful. Together, they form a practical foundation for AI auditing, if internal audit can connect them. That connection is the crosswalk.
Step 1: Create an Initial AI Inventory
The first step is building an AI inventory that maps directly to the “Map” function in NIST AI RMF, which focuses on understanding AI use, context, and risk exposure. At the same time, AIUC-1 emphasizes completeness of the audit universe, while OWASP implicitly highlights the importance of knowing where AI-driven applications exist.
What this looks like in practice:
- Identify AI use cases across business units
- Classify by type (predictive model, generative AI, agentic workflow, etc.)
- Capture ownership and business purpose
- Tag systems with potential exposure (customer-facing, regulated, etc.)
This is the non-negotiable starting point. Without visibility into what AI is in use, audit scoping becomes guesswork.
Step 2: Perform a Lightweight Risk Assessment
Rather than inventing new criteria, internal audit can align risk assessment to common themes across frameworks. The table below translates abstract framework language into audit scoping criteria — enabling prioritization without overengineering.
Table 1: AI Risk Assessment Crosswalk
| Risk Dimension | NIST AI RMF | AIUC 1 Perspective | OWASP Alignment | Audit Focus |
|---|---|---|---|---|
| Business Impact | Map (Context, Use Case) | Risk based audit planning | – | What decisions does the AI drive? |
| Data Risk | Govern + Measure | Data governance controls | Training data poisoning | Is data reliable and appropriate? |
| Model Behavior | Measure + Manage | Model validation expectations | Prompt injection, model manipulation | Is output predictable and explainable? |
| Governance and Oversight | Govern | Core control domain | – | Who owns and oversees the AI? |
| Security Exposure | Manage | ITGC extension | OWASP Top 10 risks | Can the system be exploited? |
| Regulatory Sensitivity | Govern + Map | Compliance alignment | – | Is this a regulated use case? |
Step 3: Start With a Governance Review
An AI governance audit is the most effective starting point because it aligns strongly across all three frameworks. NIST anchors it under the Govern function. AIUC-1 treats it as a core emphasis area. OWASP assumes governance gaps are the root cause of most exploitability.
Table 2: Governance Review Crosswalk
| Control Area | NIST AI RMF (Govern) | AIUC 1 Expectation | Audit Questions |
|---|---|---|---|
| AI Policy Framework | Risk management structures | Governance framework required | Is there a formal AI policy? |
| Roles and Responsibilities | Accountability structures | AI system ownership | Who is accountable for each AI system? |
| AI Inventory | System mapping | Audit universe completeness | Do we know all AI systems in use? |
| Risk Classification | Risk tiering | Risk based audit approach | Are high risk systems clearly defined? |
| Approval and Oversight | Lifecycle governance | Control checkpoints | Are systems reviewed before deployment? |
Step 4: Develop a Pilot AI Audit
When conducting a pilot audit, internal audit can structure procedures using a blended model: the NIST AI RMF lifecycle (Map, Measure, Manage) for flow, AIUC-1 controls for audit rigor, and OWASP risks for technical depth in modern systems.
Table 3: Pilot Audit Structure
| Audit Phase | Framework Anchor | Key Activities |
|---|---|---|
| Scoping | NIST Map | Identify system purpose, stakeholders, risk level |
| Control Identification | AIUC 1 | Map expected controls across lifecycle |
| Risk Testing | OWASP + NIST Measure | Test for vulnerabilities, bias, drift, misuse |
| Evaluation | NIST Manage | Assess effectiveness of mitigation strategies |
| Reporting | AIUC 1 | Provide actionable, risk based findings |
Step 5: Don’t Skip Agentic AI and LLM-Specific Risk
Many organizations are rapidly deploying agentic AI applications, copilots, automated workflows, decision agents. These introduce risks not typically covered in traditional audits, and OWASP provides a critical supplement to internal audit approaches here.
Table 4: OWASP Top Risks Mapped to Audit Procedures
| OWASP Risk (Simplified) | What It Means | Audit Implication |
|---|---|---|
| Prompt Injection | Manipulating model inputs | Test input validation and guardrails |
| Data Leakage | Sensitive data exposure | Evaluate data handling and outputs |
| Insecure Output Handling | Unsafe downstream actions | Review integration controls |
| Over Reliance on AI | Blind trust in outputs | Assess human in the loop controls |
| Model Denial of Service | Resource exhaustion attacks | Validate resilience and monitoring |
Building a Repeatable Model
Rather than choosing one framework, leading internal audit functions are using crosswalks as their operating model:
- NIST AI RMF defines what good risk management looks like
- AIUC-1 defines what internal audit should evaluate
- OWASP defines how AI systems can fail in practice
This layered approach enables consistency across audits, flexibility across use cases, and credibility with stakeholders.
Bringing It All Together
Frameworks are not the barrier, translation is.
Internal audit functions that succeed in auditing AI systems are not those that adopt a single framework, but those that translate frameworks into audit procedures, crosswalk concepts into practical controls, and use visual tools like the tables above to align stakeholders. This approach makes AI auditing both practical and scalable.
AI frameworks are multiplying, not consolidating. Waiting for a single standard to dominate is not a viable strategy. Internal audit’s role is not to pick a winner, it is to operationalize what exists today.
The faster audit functions move from frameworks to execution, the faster they close the gap between expectation and readiness.