What Internal Audit Actually Needs From an AI Governance Program
Deloitte identifies a widening gap between how fast organisations deploy AI and how slowly formal governance gets established. Internal audit can close that gap — but only with continuous evidence.
The Governance-Deployment Gap
Deloitte's November 2025 analysis identifies a structural problem in most enterprises deploying AI: the speed of AI pilot deployment is outpacing the speed at which formal governance frameworks get established. This creates a gap that accumulates risk on both sides. On the deployment side, AI systems are operating with inadequate controls documentation, unclear accountability, and no formal evidence of the risk assessment that preceded their approval. On the governance side, audit teams are being asked to assure systems that were never formally governed in the first place.
Internal Audit's Opportunity: Early, Not Retrospective
Deloitte's guidance frames this gap as an opportunity for internal audit to add value early, rather than reviewing AI governance only after incidents occur. Internal audit teams can independently evaluate whether AI governance, risk management, and controls are well designed and operating effectively — if the governance program gives them something to evaluate. The problem is that most current AI governance programs produce point-in-time documentation rather than continuous evidence. A one-time risk assessment carried out at deployment is not evidence of operating effectiveness. An audit trail showing that the risk assessment was repeated after a model update, a control was tested at the last quarterly review, and an obligation was evidenced and closed is.
What Continuous Evidence Looks Like
For internal audit to fulfil its role in AI governance assurance, the governance program needs to provide three things continuously rather than on request: an audit trail that is append-only and timestamped, so every decision, rating change, and control test is traceable to a named reviewer and a date; obligation evidence that moves through a documented workflow with named owners at each stage, not a static status field; and linkage between risks, controls, and incidents, so a new incident that affects a control's operating effectiveness automatically reopens the associated risk acceptance. These are not novel audit requirements. They are standard assurance requirements — applied to AI governance programs rather than financial controls.
The Three Questions Every AI Audit Should Answer
Deloitte's framework for AI audit effectiveness centres on three questions that internal audit should be able to answer for any material AI system: Is the control design appropriate for the risk? Is the control operating as designed? Has a material change occurred since the last assessment that would change the answer to either of the first two questions? A governance program that cannot provide evidence-backed answers to all three questions — without requiring an audit team to manually assemble artefacts from multiple systems — is not audit-ready. It is audit-adjacent.
Wahid AI's 'Assure' stage and exportable audit-ready dossiers directly answer the internal-audit gap Deloitte describes: continuous monitoring and live audit trails mean assurance evidence already exists before an auditor has to ask for it. The platform's append-only audit trail, obligation evidence workflow, and automatic re-opening of risk acceptances when linked incidents occur give internal audit the continuous evidence base Deloitte identifies as the gap most governance programs fail to close.
RELATED TOPICS
Ready to operationalise these governance frameworks?
Wahid AI integrates ISO 42001, EU AI Act, NIST AI RMF, and APRA CPS 230 into one governed workflow. See it in a 30-minute demo.
EXPLORE FURTHER