The framework

The Internal Audit AI Augmentation Line™

The lifecycle on two levels — function and engagement. For each stage: where AI acts, and where a named auditor signs. Two stages carry special weight — the evidence heartland and the conclusions gate (GIAS Std 14.5).

01

Audit Universe & Risk Assessment

L3 · AI proposes, human decides

Continuous signals; source-linked scores. Ratings stay human.

02

Planning, Coordination & Reliance

L3 · AI proposes, human decides

AI models scenarios; the CAE owns the plan and reliance.

03

Engagement Planning & Scoping

L3 · AI proposes, human decides

AI drafts scope; every exclusion carries a named sign-off.

04

Walkthroughs & Process Understanding

L2 · AI-led, human monitored

Cited narratives from transcripts; inferred steps flagged.

05 · EVIDENCE HEARTLAND

Testing & Evidence Gathering

L2 · AI-led, human monitored

Full-population, deterministic, repeatable — or it isn't evidence.

06

Findings & Root Cause

L3 · AI proposes, human decides

AI drafts with evidence links; significance is a locked human field.

07 · HARD GATE

Reporting & Conclusions

L5 · Human only

The conclusion is non-delegable. AI touches formatting only.

08

Follow-up & Issue Tracking

L2 · AI-led, human monitored

Evidence verified against criteria encoded at report issue.

09

QAIP & Continuous Improvement

L4 · Human-led, AI assists

The Lock audits itself; the CAE owns the quality conclusion.

What each stage carries in the full LineA governed system prompt in the five-clause Lock Prompt™ pattern below, the failure mode we see most in the field, the per-stage Evidence Lock™ specification, and a maturity self-check. The full depth is what the working session is for.

The differentiator

The Evidence Lock™

Four elements that keep AI-assisted work admissible as audit evidence.

1 · Bounded prompting

Curated, versioned prompts for evidential work — never free-form chat into working papers.

2 · Deterministic engine

Rule-based procedures run beneath the model tier; a re-run reproduces the same result, exactly.

3 · The universal gate

Out-of-bounds output routes to EXCEPTION_HUMAN_REVIEW_REQUIRED with evidence attached.

4 · Engagement documentation record

Prompt, model version, input and output hashes, reviewer — your EQA evidence pack assembles itself (GIAS Std 14.6).

The test (GIAS Std 14.6): an informed, prudent internal auditor could repeat the work and derive the same results — whatever produced it.

For upskilling programmes & bootcamps

The Lock Prompt™ — the five-clause anatomy

The IIA's 2026 Global Best Practices guidance names role-based, audit-specific prompt engineering a critical AI capability. This is ours — every prompt on the Line is a versioned artefact built from five clauses, and the pattern is teachable in an afternoon:

1 · ROLE

What the model is for this task — an analyst supporting the function, never the auditor of record.

2 · BOUNDED CONTEXT

The only sources it may draw on — the engagement data inventory, never “general knowledge.”

3 · CRITICAL RULE

The clause that makes output evidential — every assertion cites its source signal; uncited output is invalid.

4 · ANTI-DRIFT BOUNDARY

What the model does not do — it proposes with rationale; ratings and conclusions are set by the named auditor.

5 · EXCEPTION OUTPUT

What happens at the edge — anything it cannot evidence routes to EXCEPTION_HUMAN_REVIEW_REQUIRED with the gap described.

Why it teaches well: each clause answers one documented failure mode — role confusion, staleness, hallucination, scope creep, silent failure. Learn the five clauses and you can read any prompt on the Line — or write your own and have it reviewed like a workpaper, because that is what it is.

Free · 12 questions · ~4 minutes

The Internal Audit AI Augmentation Scan™

Twelve honest statements. Score yourself 1–4 on each. Your result, band and dimension profile render instantly — nothing is transmitted anywhere.

0 of 12 answered

Your scan result

FoundationDevelopingEstablishedAugmentation-Led

What Phase 1 looks like for your function

The two fields that predict EQA pain are testing repeatability and the locked conclusion field. In a 45-minute debrief I'll walk you through your profile against the full Line — the per-stage Evidence Lock™ specification, the governed prompts, and the focused-quarter Phase 1 plan. Your scores go with the email, so we skip the preamble.

Send my result & book the debrief