Quaintitative

For internal audit

AI risk management for internal audit

Your job is not to run the controls. It is to give independent assurance they work.

Under the MAS AI Risk Management Guidelines (AIRG), internal audit is the third line: independent assurance that the AI risk framework is designed well and actually operating. You test whether the things the Guidelines expect are happening in practice, not just written in policy. Is AI being identified across the firm, including embedded and shadow AI? Are materiality assessments genuine and consistently applied? Is independent validation real, and does ongoing monitoring catch problems? And is there an evidence trail, inventory, materiality rationale, test results, that a reviewer could follow after the fact?

The practical test is the one a supervisor will also apply: when you ask for the evidence, does it exist, or only the intention? A framework that cannot produce its records on request is a finding. A fuller guide for internal audit is coming.

Where to start

I developed the AIRG while leading AI risk supervision at MAS, and now advise internal audit functions independently. I am building a fuller guide for internal audit; subscribe to get it, and future updates on the AIRG.

Subscribe for updates