Most internal audit functions trying to get ahead on AI fall into a small number of predictable traps. And the functions that are getting it right share an equally small number of habits.
Knowing both lists is often the fastest way to see where your own function stands.
This piece is less about frameworks and more about patterns. What we consistently see in practice when audit functions attempt to step into AI risk, and what separates the ones making real progress from the ones that stall.
Part One: Where Organizations Get Stuck
1. They Do Not Know What They Have
The most common starting point problem: there is no complete, accurate inventory of AI systems in use across the organization.
Without visibility into what AI is deployed, where, and by whom, audit scoping becomes guesswork. Teams end up auditing the AI systems they know about, which are rarely the highest-risk ones. The systems that sit closest to credit decisions, hiring, fraud detection, or customer pricing are often the ones that arrived through a vendor contract or a business unit initiative, with no formal inventory record and no clear ownership.
Audit cannot provide assurance over what it cannot see. Building the inventory is not a precondition to starting, it is the first audit.
2. They Over-Rely on Frameworks
Frameworks are useful. They are not sufficient on their own.
The failure mode here is mapping AI risk to existing control frameworks without adapting them to AI’s specific characteristics. An IT general controls framework was not designed to address model drift, bias in training data, or the governance gaps that emerge when a vendor builds and maintains the model while the business relies on its outputs.
Organizations that approach AI audit by asking ‘which of our existing controls apply here?’ are starting from the wrong question. The right question is: ‘what does good governance, development, deployment, and monitoring look like for this specific AI system, and do our controls reflect that?’
Frameworks give you a structure. Translation into the audit context is the work.
3. They Lack Cross-Functional Coordination
AI sits at the intersection of IT, data, legal, compliance, and business functions. Each of those functions has partial visibility. None of them has the full picture. And internal audit, operating through traditional channels, often struggles to pull that picture together.
The practical consequence: audit teams end up with findings that are technically accurate but organizationally disconnected. They identify a governance gap in a system that three different functions thought someone else owned. They flag a data quality issue without access to the people who can act on it.
Effective AI auditing requires relationship-building before fieldwork begins. The audit team needs to understand who the relevant stakeholders are across functions, what each of them owns, and where the accountability gaps already exist.
4. They Get the Technical Calibration Wrong
There are two versions of this failure, and both are common.
The first: audit teams go too deep into model mechanics. They spend cycles on technical details that do not connect to the risk-relevant controls, lose the thread of what they are auditing, and produce findings that the business cannot act on.
The second: audit teams avoid technical substance entirely. They conduct an AI governance review that touches documentation and policy but never engages with how the system works, what it is trained on, or whether its outputs are being monitored. The result is assurance that does not hold up.
Effective AI auditing focuses on risk-relevant controls. That means understanding enough about how AI systems work to ask the right questions, without requiring the audit team to become data scientists.
5. They Do Not Have the Right Skills
AI assurance requires a blend of capabilities that most audit teams were not built around: audit expertise, data literacy, and risk management insight. Few functions currently have all three in-house.
The response to this gap matters. Functions that acknowledge it and build toward it, through targeted hiring, co-sourcing with specialists, or structured partnerships with data and IT teams, make progress. Functions that try to conduct AI audits with existing capabilities unchanged tend to produce work that is either superficial or disconnected from operational reality.
Closing the skill gap does not require rebuilding the team. It requires being deliberate about where the gaps are and how to address them.
Part Two: What Good Looks Like
1. They Build an AI Audit Universe
Functions making real progress have explicitly incorporated AI systems into their audit universe. Not as a category, but as individual systems, each assessed for risk based on impact and exposure.
This means knowing which AI systems exist, what decisions they influence, who owns them, and what regulatory or reputational risk they carry. It means treating the AI inventory as a living document, not a one-time exercise.
The audit universe is the foundation. Everything else depends on it.
2. They Develop Repeatable Methodologies
Rather than approaching each AI audit as a new problem, high-performing functions build structure: standard scoping criteria, control frameworks tailored to AI characteristics, and consistent reporting formats.
This repeatability serves two purposes. It makes individual audits more efficient. And it makes the audit program more credible, to leadership, to regulators, and to the business functions being audited. A function that can explain how it audits AI, not just what it found, is a function that has moved from reactive to capable.
3. They Leverage Hybrid Skill Sets
The functions closing the AI assurance gap fastest are not the ones waiting to hire a team of AI specialists. They are the ones combining what they have with what they need.
In practice, this looks like pairing internal audit professionals with data scientists or IT auditors for specific engagements. It looks like co-sourcing technical assessments for high-risk use cases while keeping the audit management and findings reporting internal. It looks like building structured relationships with risk, compliance, and technology teams so that audit has access to the right expertise when it needs it.
Depth and practicality are not in conflict. Hybrid approaches make both achievable.
4. They Focus on Governance First
The most effective AI audit functions consistently prioritize governance above technical review, not because technical risk does not matter, but because governance creates leverage.
Strong AI governance reduces downstream risk across every other audit domain. It clarifies accountability, surfaces the systems that need the most scrutiny, and creates the policy and process infrastructure that technical controls depend on. An organization with weak AI governance will produce flawed AI risk assessments, inconsistent deployment practices, and monitoring programs that are not acted on even when they surface problems.
Governance first is not a shortcut. It is the highest-return starting point.
5. They Integrate AI Into Enterprise Risk Management
The functions that are furthest ahead have stopped treating AI as a separate audit category and started embedding it into how they think about enterprise risk overall.
This means AI appears in the annual risk assessment, not as a standalone topic but as a dimension of credit risk, operational risk, regulatory risk, and reputational risk. It means AI-related findings are reported alongside findings in other areas, not siloed in a separate AI audit report that leadership reads once and sets aside.
When AI risk is integrated into enterprise risk management, it gets the attention and resource allocation it warrants. When it is treated as a specialty topic, it tends to remain one.
Closing the Gap
The distance between the two lists above is closeable. And it typically does not require an internal audit function to become AI experts overnight.
What it requires is a shift in how the function approaches the problem: from treating AI as a technical issue to recognizing it as an enterprise risk question; from conducting one-off governance reviews to building an integrated annual plan; from uncertainty about where to start to structured experimentation that builds capability over time.
The AuditBoard survey that opened this series captured a real gap between what organizations expect from internal audit on AI and what audit functions currently feel ready to provide. That gap is real. It is also solvable.
The functions that close it fastest will not be the ones that waited for a single AI audit standard to emerge or for their teams to develop complete technical fluency. They will be the ones that started, built incrementally, and treated each audit as a step toward a more capable program.