← All programs

AI for Internal & IT Audit

Built for audit teams asked to assess AI systems they were never trained to test — delivered in person, hands-on with real techniques.

Internal and IT audit teams are increasingly asked to assess AI systems they were never trained to test — including models the firm bought rather than built. The risk is signing off on something you couldn’t actually examine, or writing findings that don’t hold up. This full-day, hands-on session gives auditors a repeatable way to plan and run an AI audit with real techniques, not theory.

Who it’s for

Internal and IT audit teams, audit partners, and audit professionals.

What your team walks away with

Plan and run an audit of an AI system — its governance, its operation, and the tools to actually test it.

Why this matters now

As supervisors place AI firmly inside model-risk and governance expectations — from long-standing model-risk supervision to the EU AI Act — the audit function is expected to provide independent assurance over it. Boards and regulators now want evidence that someone independent has tested how AI systems are governed, how they behave, and what happens when they fail.

What you’ll learn
  • Build enough working knowledge of AI systems to ask the right questions without becoming a data scientist
  • Plan an AI audit: set scope, identify the real risks and decide what evidence proves a control works
  • Test AI controls across governance, data, the model itself and its outputs
  • Audit third-party and embedded AI you didn't build by examining inputs, outputs and oversight
  • Write up AI audit findings so they're clear, fair and actionable
  • Reuse a structured AI audit work programme on the next system without starting over
What we cover

A starting agenda — every session is shaped around your team, your tools and the risks you’re managing.

  1. What auditors need to understand about how AI systems work The working knowledge of how AI systems actually behave that an auditor needs before testing them — enough to ask the right questions, without becoming a data scientist.
  2. Building an AI audit plan: scope, risks and evidence How to build an AI audit plan: setting scope, identifying the real risks, and deciding what evidence would prove a control works.
  3. Testing AI controls — governance, data, model and output Practical ways to test AI controls across governance, data, the model itself and its outputs.
  4. Auditing third-party and embedded AI you didn’t build How to audit third-party and embedded AI you didn’t build and can’t see inside, by testing inputs, outputs and the firm’s oversight of the vendor.
  5. Common AI audit findings and how to write them up The findings that come up most often in AI audits and how to write them up so they’re clear, fair and actionable.
  6. A reusable AI audit work programme for your team A reusable AI audit work programme your team can run again on the next system without starting from scratch.

Every team’s needs are different. We’re happy to talk it through and tailor the session to yours — let’s talk →

Bring "AI for Internal & IT Audit" to your team.

A short conversation about your team, your risk, and the session that would move them. No pitch deck — just the right scope and dates.

Enquire