← Blog

Internal Auditor AI Risk Checklist: Authorize the Engagement and Sample

Parminder Singh
Parminder Singh··4 min read
Summarize with AI

This internal auditor AI risk checklist turns a planned assurance engagement into an authorized sampling memo. It fixes the independence statement, audit population, sample logic, control tests, evidence custody, and escalation criteria before fieldwork begins, while keeping recurring AI risk reporting in a separate process.

Compliance & Regulationauditforensic-auditai-governancenist-ai-rmfpolicy-enforcement
Internal Auditor AI Risk Checklist: Authorize the Engagement and Sample

Ten approved chatbot requests prove little about bypass traffic if the population excludes denied calls or fallback routes. This internal auditor AI risk checklist creates an engagement authorization and sampling memo that records authority, protects Internal Audit's independence, and fixes the sample logic. Recurring results belong in AI risk reporting for internal auditors. This memo governs the engagement.

TL;DR

  • Obtain board-backed engagement authority and record any actual or perceived impairment to independence before fieldwork.
  • Define the full population by system and period. Include permit decisions, blocks, errors, and known bypass routes.
  • Write the sample method before selecting records. Tie each selection to a risk and explain when results may be projected.
  • Preserve source records under controlled custody, then escalate scope limits or significant exceptions under named criteria.

Internal auditor AI risk checklist for engagement authority

The authorization memo should name the assurance objective and audit executive, state the period and business units covered, then list the systems and model routes in scope. The charter remains the source of authority.

The Institute of Internal Auditors' 2024 Global Internal Audit Standards require documented objectives and scope in the Engagement Objectives and Scope standard. Scope identifies the activities and systems, plus locations and the covered period; restrictions on access to people or data count as limitations. Unresolved limitations must reach the board through the chief audit executive's established method.

Check 2: protect independence before testing

Record the audit team's prior roles with the AI service because a reviewer who designed the destination policy or operates the gateway may have an actual or perceived objectivity impairment. The memo should identify that relationship and use reassignment or independent review as a safeguard.

Management may supply the inventory and explain a control. Internal Audit decides the assurance scope and performs the test. I would stop fieldwork rather than let the control owner choose the sample after seeing exceptions. Preserve the impairment assessment with the authorization, including the chief audit executive's decision.

Check 3: freeze the audit population

Define the population before drawing a sample. For an HTTP AI control, record the time window and timezone, then specify environments and applications. Name the authenticated identities, model endpoints, and policy versions. Count allowed decisions and blocks. Add errors and retries, plus fallback routes.

Reconcile the population against the approved AI inventory and network destination records. The AI governance audit framework provides the risk-to-control map. Preserve the population query and put its row count beside the source-system count on one review screen. Any mismatch becomes an exception before sampling.

Check 4: write the sample logic first

The sampling memo should name the method and selection unit, document population size and sample size, then explain the risk basis and any strata. Define replacement rules and the conditions for projecting results.

The IIA's Engagement Work Program guidance says a work program should document its sampling methodology and population. It also calls for sample size and whether results can be projected. The Gathering Information standard advises testing a complete population when practical. When sampling is chosen, the selection should be as representative as possible. Label targeted selections separately because they answer a different risk question.

Check 5: define control tests and pass criteria

Each test needs one control objective and a repeatable procedure. An authorization test can select user roles and compare decisions with the policy version effective at each timestamp, while a sensitive-data test submits synthetic markers through approved routes. Completeness testing reconciles application request counts with decisions at the enforcement point.

NIST's AI Risk Management Framework 1.0 supports this discipline without prescribing an Internal Audit methodology. Its Govern function calls for an AI inventory and clear risk responsibilities. The Measure function brings independent assessors or internal experts outside the front-line development team into regular assessment. These are organizational outcomes; the audit function retains responsibility for its procedure and conclusion.

Check 6: establish evidence custody

The memo should define who extracts evidence and where the audit copy goes. Record the source and extraction time, then preserve the query and file hash under restricted access. The AI audit log chain-of-custody guide covers the narrower handling of request records.

The IIA's Gathering Information standard requires evidence that supports the engagement and can sustain the conclusion. Reliability improves when Internal Audit obtains the information directly or uses an independent source. For gateway evidence, keep the original decision identifier and policy version. A screenshot pasted into a workpaper loses query context and population completeness.

Check 7: set escalation criteria before exceptions appear

Write escalation triggers into the authorization. Denied source access and an unreconciled population difference are two examples. Suspected record alteration also warrants escalation, as does privileged policy bypass affecting a regulated decision. Assign each trigger to the engagement supervisor or chief audit executive, with the board route for unresolved scope limits.

Do not wait for the final report when a finding requires immediate attention. The IIA's Engagement Communication standard requires effective communication throughout the engagement and timely notice of scope changes. The memo should set the evidence threshold for pausing tests or expanding the sample, including when legal counsel or incident response receives notice.

DeepInspect

DeepInspect supplies a testable control point for authenticated HTTP traffic between enterprise users or agents and LLM endpoints. It evaluates application-supplied identity and request context against policy before forwarding traffic. Each decision creates a signed record outside the calling application's write path.

Those records can support authorization tests and population reconciliation for managed routes. They can also support custody checks when Internal Audit validates completeness and access. DeepInspect cannot authorize the engagement or select the sample. It cannot resolve an independence impairment or issue the audit conclusion. Those duties remain with Internal Audit and its board-approved mandate. Book a demo today.

Frequently asked questions

How is this checklist different from AI risk reporting?

The checklist authorizes one engagement and locks its method before fieldwork. It records independence and scope, then defines the population and sample. Recurring reporting communicates tested results and remediation status. A dashboard cannot retroactively repair an undefined population or a sample chosen by management.

Can Internal Audit rely only on AI gateway records?

Gateway records can support tests for authenticated HTTP traffic routed through that control point after the auditor tests record completeness and integrity. Local model execution and supplier-internal AI need separate evidence. Direct routes that bypass the gateway require separate treatment or a stated scope limitation.

When should an auditor test the full population?

A full-population test fits machine-readable records when the procedure is deterministic and the data set can be reconciled. Sampling remains useful for manual evidence, judgment-heavy reviews, or constrained source access. The memo should explain the choice and retain the query so another auditor can repeat it.