Internal Controls in the Age of AI

AI is moving faster than many organisations’ control environments. That creates a critical question for both the public and private sectors: How do we unlock the value of AI without losing control of the risks?

The answer isn’t to slow innovation down. Nor is it to introduce layers of controls that make AI practically unusable. It is to build a holistic, proportionate and intelligent internal control environment that evolves alongside the organisation and the technology.

A strong control environment should connect the dots between:

  • Governance, providing clear accountability for AI, data, decisions and outcomes.

  • Risk management, identifying not only traditional risks, but also AI-specific risks such as bias, hallucination, privacy, cybersecurity, intellectual property and model failure.

  • Policies and procedures which must provide practical guardrails that enable people to use AI safely rather than simply telling them what they cannot do.

  • Data controls, checking to ensure the information entering AI systems is appropriate, accurate, secure and properly governed.

  • Human oversight, understanding where human judgement must remain central, particularly where AI outputs could materially affect people, public services, customers or financial decisions.

  • Monitoring and assurance particularly constantly testing whether controls actually work in practice, rather than assuming that a policy or framework is sufficient.

  • Culture and capability, giving people the knowledge to understand both the opportunities and limitations of AI.

Importantly, AI itself can become part of the control environment if it is understood, implemented, and monitored effectively.

Used appropriately, AI can help organisations identify anomalies, analyse large volumes of transactions, monitor control exceptions, assess patterns of risk, support assurance activities and provide earlier warning of emerging issues.

All of which introduces an important principle:

We should not use AI to automate a control simply because we can. We should automate where the risk, control objective, data quality and level of human oversight make it appropriate to do so. The organisations that derive sustainable value from AI will not necessarily be those that deploy the most technology. They will be those that understand the relationship between innovation, risk, governance, people and control, and design these elements as part of one connected system.

In an increasingly AI-enabled world, internal control should not be viewed as a barrier to innovation, but as an integral part of the infrastructure that makes responsible innovation possible.

The question for boards, executives, audit committees and public sector leaders is therefore not simply: “How can we use AI?” It is:

“What control environment do we need to use AI confidently, safely and effectively?”

Next
Next

Building a Stronger Business for the Future