For Chief Audit Executives · Aligned to the 2024 Global Internal Audit Standards
The audit lifecycle on two levels — function and engagement. For each stage, a defensible answer to the only question that matters: where does AI act, and where does a named auditor sign? Built for the function that audits everyone else's AI — and therefore cannot run ungoverned AI of its own.
"Probabilistic output with no audit trail fails the profession's own test by construction. On this Line, every AI-assisted procedure is documented to the GIAS 14.6 standard — prompt, model version, inputs and output logged — so your working papers remain evidence, and your conclusion remains yours."
Before the line
The 2024 Standards make these a conformance matter, not a technology preference. No stage of the Line operates safely until all three hold.
Foundation 1
The internal audit charter and strategy state the function's AI position explicitly. The CAE evaluates the function's technology regularly and can evidence that evaluation to the board.
GIAS Std 10.3 · Technological ResourcesFoundation 2
Every AI output that touches a working paper carries a engagement documentation record: prompt, model version, input hash, output, reviewer. The GIAS Std 14.6 test: an informed, prudent internal auditor could repeat the work and derive the same results.
GIAS Std 8.3 / 12.1 · QualityFoundation 3
Auditors are trained to challenge AI output, not defer to it. Automation bias is named as a documented threat to objectivity and managed like any other impairment.
GIAS Domain II · Ethics & ProfessionalismThe line itself
Select a stage. Each carries its augmentation level, the Standards hook, the division of labour, the evidence lock, the failure mode we see most, an governed system prompt you can deploy today, and a maturity self-check.
The mirror workstream
Unique to Internal Audit: the same Line you run your function on becomes the assurance instrument for auditing the first and second lines' AI. One framework, two mandates — consistent with the IIA's AI Auditing Framework and the Three Lines Model, and mapped to NIST AI RMF, ISO/IEC 42001 and EU AI Act Article 14 human-oversight requirements.
Mirror 1
For each material AI use case in the first line, plot the claimed autonomy level against the evidenced one. The gap between the two is your audit finding.
IIA AI Auditing Framework · GovernanceMirror 2
Where the business claims a human decides, test it like any control: sample the overrides, time the reviews, evidence the sign-offs. A gate nobody has ever closed is not a gate.
EU AI Act · Article 14 oversightMirror 3
Bounded prompting, deterministic policy engines and exception routing are auditable artefacts. Where they are absent, the finding writes itself.
NIST AI RMF · ISO/IEC 42001