Blog · Regulation

What Would an Auditor Ask About Your AI? The Evidence Internal Audit Needs

Eleye Abdi·28 June 2026·8 min read

Internal audit functions are increasingly adding AI governance to their scope. For most audit teams, this is new territory. AI systems behave differently from the processes and controls that conventional audit methodologies were designed to assess, and the evidence AI governance requires is different from what audit teams are accustomed to collecting.

This article is written for internal audit professionals approaching AI governance for the first time, and for compliance and risk teams preparing to receive an AI governance audit. It maps the questions an audit team will ask to the evidence that adequately answers them.

AI governance audit is not IT audit applied to AI systems. The governance obligations (evidence of monitoring, signed inventory, human oversight documentation) require a different evidence standard than conventional IT controls testing.

How AI Governance Audit Differs from IT Audit

Conventional IT audit assesses controls over systems: access controls, change management, business continuity. The audit objective is to confirm that controls are designed correctly and operating effectively.

AI governance audit has a different primary objective: to confirm that the organisation knows what AI systems are operating, that those systems are being actively overseen, and that evidence of that oversight exists in a form that satisfies regulatory requirements. The controls being tested are governance processes, not primarily technical controls. And the evidence standard is different: not "does the control work?" but "can you prove the governance was operating?"

Audit teams that approach AI governance audit as IT audit will collect the wrong evidence. An audit that confirms access controls on a sanctioned AI system but does not test whether the AI agent inventory is complete has not audited AI governance. It has audited one AI system's IT controls.

The Five Questions an AI Governance Audit Must Answer

1. Is the AI agent inventory complete?

The first audit objective is completeness of the AI agent inventory. Completeness cannot be confirmed by reviewing the inventory itself, only by comparing it to an independent enumeration of what is actually running.

Audit evidence required: a programmatic discovery run against workspace admin APIs (Google Workspace, Microsoft 365, Salesforce, OpenAI, AWS Bedrock) producing an independent enumeration of AI agents. Comparison to the inventory. Material differences constitute a completeness finding.

The finding most audits surface: the inventory covers formally approved tools but not tools discovered through OAuth grant enumeration. The gap is the shadow AI exposure the audit is designed to surface.

2. Is the risk classification appropriate?

For each AI agent, the audit needs to assess whether the risk classification is appropriate and whether the reasoning is documented. A classification without reasoning cannot be tested. The auditor cannot confirm whether it is correct if the methodology is not recorded.

Audit evidence required: the classification methodology, the classification for each agent, the reasoning applied, and evidence that classifications have been reviewed when agent configurations changed materially.

3. Is human oversight operational?

The audit test is whether oversight is operational: whether named individuals with documented authority are actually exercising oversight, and whether there is evidence of oversight activity beyond the assignment of responsibility.

Audit evidence required: responsibility assignments, evidence of oversight activities (review meetings, monitoring records, escalation decisions) and records showing the oversight function has been responsive to findings.

4. Is monitoring producing findings?

A monitoring programme that has never produced a finding is either extremely effective or not running. The audit should assess whether monitoring is designed to detect realistic risk scenarios and whether it has produced findings consistent with the risk profile of the AI agent population.

Audit evidence required: monitoring records for the period, findings identified, actions taken, and evidence that the methodology detects the risk patterns relevant to the organisation's AI estate.

5. Is the evidence defensible?

The final audit question is whether governance evidence meets the standard required for regulatory examination. Can it be verified as unaltered since generation? Can it be reproduced under examination? Does it cover cross-platform patterns? Is it signed in a way that confirms integrity?

Most audit engagements find that evidence meets internal reporting standards but not external examination standards. The gap between "adequate for internal audit" and "adequate for FCA/ICO examination" is where most regulated firms are currently exposed.

A Sample AI Governance Audit Work Programme

  1. Obtain the AI agent inventory and request evidence of how it was produced. Confirm whether programmatic discovery was used or whether the inventory relies on self-reporting.
  2. Run an independent discovery check against workspace admin API outputs and compare to the inventory for completeness.
  3. Select a sample of AI agents and test the classification documentation: methodology, reasoning, and review history.
  4. Obtain monitoring records for the period. Confirm monitoring occurred at the documented cadence and that findings were recorded and acted upon.
  5. Review oversight responsibility assignments and test for evidence of active oversight: meeting records, escalation logs, intervention decisions.
  6. Assess evidence packs for integrity: verify signatures where available, confirm cross-platform coverage, assess whether evidence would meet external examination standards.
  7. Report findings against the five objectives above with specific observations on completeness, classification, oversight, monitoring, and evidence quality.

Further reading: Continuous AI Monitoring vs Annual AI Audits on how monitoring cadence and audit cycle interact.

How AETHER Pulse Supports AI Governance Audit

AETHER Pulse provides the independent discovery capability that Step 2 above requires: a programmatic enumeration across seven platforms comparable to the organisation's own inventory. Its signed evidence packs provide the material that Step 6 requires: dated, signed, verifiable under examination. For internal audit teams, AETHER operates as the evidence source that the work programme is designed to test.

Frequently Asked Questions

Can internal audit teams run AI governance audits without AI expertise?

Yes, with the right work programme and evidence sources. The five objectives above do not require deep AI technical knowledge. They require audit methodology applied to a different evidence type.

How often should AI governance be on the internal audit plan?

Annual AI governance audit is a minimum given active regulatory scrutiny in 2026. High-risk AI deployments may warrant half-yearly review.

Request a Governance Evidence Review →

Working on Article 26 readiness, deployer-side governance evidence, or AI agent risk at a regulated firm? We'd value 15 minutes of your perspective.

Start a conversation