Effective assurance over AI starts with a clear understanding of how AI should be governed. This is Module 3 of the AI-Powered Internal Audit Professional Series, a 15-module program developed and published by Business Excellence to equip internal audit professionals with practical, standards-aligned AI capability.
This module gives internal auditors a working command of the two most important AI governance and risk frameworks in use today. The NIST AI Risk Management Framework is examined through its four core functions – GOVERN, which establishes the organizational foundation; MAP, which contextualizes AI systems and their risks; MEASURE, which assesses and tracks those risks; and MANAGE, which implements and monitors responses. ISO/IEC 42001, the first certifiable international standard for AI management systems, is examined as a complementary, auditable structure that organizations can be certified against.
Beyond the frameworks themselves, the module shows how established audit and governance concepts apply directly to AI. The Three Lines Model is mapped onto AI risk: the first line owns AI risks within the business, the second line provides specialist oversight and challenge, and the third line – internal audit – delivers independent assurance. The module also addresses what effective AI governance requires in practice: clearly defined accountability from the board through operational levels, and a coherent AI policy suite covering acceptable use, development, vendor management, data, ethics, and incident response.
A central theme is that governance enables innovation rather than constraining it. Evidence indicates that organizations with mature AI governance deploy AI more quickly and more confidently than those without – a message that helps auditors position governance recommendations constructively with management.
The module is aligned with the NIST AI RMF, ISO/IEC 42001, the IIA Global Internal Audit Standards 2024, and the EU AI Act, and reflects current guidance from authoritative bodies including ISACA.
Delivered as a professional PowerPoint presentation with full speaker notes, the module includes a NIST AI RMF quick reference guide, an ISO 42001 implementation checklist, an AI governance RACI template, an AI policy framework template, and a 10-question knowledge assessment quiz – giving audit teams both the understanding and the tools to evaluate AI governance with confidence.
Got a question about the product? Email us at support@flevy.com or ask the author directly by using the "Ask the Author a Question" form. If you cannot view the preview above this document description, go here to view the large preview instead.
Source: Best Practices in Artificial Intelligence PDF: AI Internal Audit M03: AI Governance and Risk PDF (PDF) Document, Amer Morgan
This document is available as part of the following discounted bundle(s):
Save %!
AI-Powered Internal Audit: Level 1 Foundations Bundle
This bundle contains 4 total documents. See all the documents to the right.
Save %!
AI-IA Professional Series - Complete 15-Module Bundle
This bundle contains 15 total documents. See all the documents to the right.
|
Download our FREE Digital Transformation Templates
Download our free compilation of 50+ Digital Transformation slides and templates. DX concepts covered include Digital Leadership, Digital Maturity, Digital Value Chain, Customer Experience, Customer Journey, RPA, etc. |