NeuGroup
Articles
September 30, 2026

Talking Shop: How Internal Audit Is Approaching AI Governance

Talking Shop: How Internal Audit Is Approaching AI Governance
# Talking Shop
# AI
# Compliance

Editor’s note: NeuGroup’s online communities provide members a forum to pose questions and give answers. Talking Shop shares valuable insights from these exchanges, anonymously. Send us your responses:  [email protected] .

Talking Shop: How Internal Audit Is Approaching AI Governance
Context: As corporations rapidly deploy AI, internal audit teams are (unsurprisingly) devoting more time and attention to the governance and controls surrounding this fast-evolving technology. A  recent survey  by the Institute of Internal Auditors found that digital disruption, including AI, had the largest increase in audit priority, rising ten percentage points to 42%. However, the IIA notes that the same category’s risk rating, at 58%, “remains notably higher, underscoring the need for organizations to adapt their skills, governance structures and evaluation criteria to more effectively keep pace.”
How to do that? The IIA says the focus should be on the  framework around AI —including governance, accountability, data quality, model transparency and human oversight—rather than simply testing whether an AI model produces the right answer. The member of  NeuGroup for Internal Audit Executives  asking about AI audits who shared the table below received answers that reveal companies at different stages of the journey, from planning their first reviews to conducting recurring AI governance audits and preparing more technical examinations of agentic AI.
Member question: “Is anyone planning to do (or has anyone already done) an audit of AI? Below are the areas we are thinking about. I'd be interested to get any feedback on this or any other information you'd be willing to share.”

Peer answer 1: “We have done some targeted AI work on some key initiatives and are in the middle of a more general audit now using framework components from the National Institute of Standards and Technology (NIST). You may want to consider the  four subcategories : govern, map, measure and manage.”
Peer answer 2: “We’ve done AI governance audits in late 2024 and again in late 2025; more recently we did a targeted review of an agentic AI monitoring vendor and are currently planning a more technical audit of agentic AI architecture, orchestration, guardrails, etc. We’ve used  co-source partners  to some extent, especially on the more techy aspects.”
Peer answer 3: “Good scope. I would recommend you also consider questions around the use of  PII  data and third-party data explicitly. To your question, we are considering it, but are waiting for a few forthcoming programs to be implemented first.”
Peer answer 4: Earlier this quarter, we leveraged  KPMG co-sourcing  to lead an AI governance and security audit. I can talk you through the scope of our review.”