Action: AI is a Top Risk for Internal Audits 

Action: AI is a Top Risk for Internal Audits 

The bell has officially rung! Internal Auditors are moving fast to assess the enterprise risks of generative AI. What began as a fringe concern about model accuracy and data leakage has become one of the top focus areas in 2025 corporate audit plans.

According to Jefferson Wells’ 2025 Internal Audit Priorities Survey, 67% of audit leaders are now auditing GenAI use, including its governance. That’s a decisive signal: organizations are no longer looking at AI through a success-only lens. They’ve experienced AI failures and are acting now. 

Audit committees and leadership know something has changed, but they’re not aligned on the approach. As Gartner captures in Oct 2025’s What Audit Committees Want to Hear from You, Chief Audit Executives believe they need to digitize and increase their audit efficiency, whereas Audit Committees are emphasizing the need for risk assessment... and … keeping up with the changing technology risk landscape. 

Despite this misalignment, we know their findings will be material! According to The Conference Board’s Oct 2025 study, 72% of S&P 500 companies now flag AI as a material risk in their public disclosures. That’s up from just 12% in 2023. 

As Forrester warned at its Technology & Innovation Summit, AI failures are inevitable. CIOs will be asked to “bail out” CEOs on projects that fail to deliver promised automation or growth. The next phase, Forrester argues, must bring CFO-level scrutiny into the equation. 

Auditor reports go to the Audit Committee, CEO, and CFO, but the implications will reach further. 

Without quantifying AI risk in financial terms, reputation, performance, and capital efficiency remain exposed. The question now is whether AI audit findings will drive the necessary cultural shift. It’s a huge question considering per Gartner’s Teravainen “Perhaps the most striking finding from this data is the degree to which internal auditors lack confidence in their ability to provide effective oversight on AI risks,” (only 11% confident).

The most likely next step is structural: finance must be integrated into AI teams and cross-departmental investment discussions. GenAI audits will force organizations to develop financial equivalents of vulnerability scans—quantifying potential loss scenarios, pricing operational exposure, and linking them to insurance coverage and reserves. 

In practice, this will mean: 

  • Cross-functional AI councils that include CFO org representation 
  • Audit frameworks that tie AI use cases to measurable financial metrics 
  • Inclusion of financial risk quantification in every AI business case 

And where internal capabilities fall short, companies will increasingly partner with specialized risk and indemnification experts. As firms like Indemnify AI advocate, the right solution is not to suppress innovation, but to measure, price, and transfer AI risk intelligently, treating it as a managed exposure rather than an unknown. 

The bell has indeed rung. GenAI is no longer just an innovation story; it’s an audit story, a governance story, and a financial story

Internal audit is taking the lead in identifying blind spots, but the organizations that thrive will be those that respond strategically: bringing finance into the conversation, pricing risk, and building assurance frameworks that keep pace with AI’s speed of change. 

Because in the end, what the auditors find isn’t just about compliance; it’s about who’s truly in control of the risk. 

Tags:

Comments are closed