For internal audit
AI risk management for internal audit
Your job is not to run the controls. It is to give independent assurance they work.
Under the MAS AI Risk Management Guidelines (AIRG), internal audit is the third line: independent assurance that the AI risk framework is designed well and actually operating. You test whether the things the Guidelines expect are happening in practice, not just written in policy. Is AI being identified across the firm, including embedded and shadow AI? Are materiality assessments genuine and consistently applied? Is independent validation real, and does ongoing monitoring catch problems? And is there an evidence trail, inventory, materiality rationale, test results, that a reviewer could follow after the fact?
The practical test is the one a supervisor will also apply: when you ask for the evidence, does it exist, or only the intention? A framework that cannot produce its records on request is a finding. A fuller guide for internal audit is coming.
Where to start
- The complete guide to AI risk management in finance in Singapore - the whole picture in one place.
- The AIRG in practice - identification, inventory, materiality and lifecycle controls as a working system.
- The AIRG explained - the guidelines your firm is supervised against.
- ISACA Advanced in AI Audit (AAIA) - the advanced audit-specific AI certification for experienced auditors.
I developed the AIRG while leading AI risk supervision at MAS, and now advise internal audit functions independently. I am building a fuller guide for internal audit; subscribe to get it, and future updates on the AIRG.