Cherry Bekaert: Risk & Cybersecurity · Cherry Bekaert

Auditing AI: Internal Audit's Expanding Role

·27 min·17 clips
The show closes its Internal Audit Awareness Month series with a conversation shaped by the IIA's Vision 2035 report. John Hagee starts with a straightforward question about what AI actually is, and Scott Payton answers by placing the topic in internal audit's changing landscape. The discussion then moves from definition to consequence. It focuses on generative AI, customer data, privacy, security, and the risk of hallucinations. Payton treats AI as a new kind of software that can drive business processes and, in turn, raise new assurance questions. He also highlights the need to ask whether a business has permission to feed certain customer data into a model. That makes the governance issue immediate. The discussion then turns to AI drift, which Payton describes as the way a deployed model can keep changing over time. That can be helpful, but it can also introduce negative movement in results. He ties the risk to places where organizations rely on AI for fraud investigation, fraud analysis, data analytics, or financial reporting support. Once reliance starts, monitoring matters. Without monitoring, a model that once looked accurate and complete can become less reliable over time. The episode keeps coming back to that practical problem. Internal audit has to understand the risks first and then audit differently. The tone stays measured throughout. It is less about spectacle than about orientation. The hosts speak as practitioners trying to translate a new technology into familiar control language. The result is a clear reminder that AI needs to be understood and audited within the control environment. For listeners in audit and risk, the episode works as a structured way to think about what needs checking. It also helps clarify what needs evidence and what needs ongoing review.

As heard by us

AI changes audit from release-time confidence to ongoing monitoring for drift.

The episode widens the scope of internal audit as AI shifts from future planning to day-to-day work. Using the IIA's Vision 2035 framing, it asks what changes when generative tools handle customer information, shape fraud investigation and analysis, and support financial…

Read the full review in PlayNext →

Why you'd press play

You want a calm audit lens on AI risks before the tools you rely on start changing in production.

Read the full recommendation in PlayNext →
Listen to the show on