AI and the future of risk: From oversight to insight

Coworkers collaborating with analytics dashboard laptop
Blog

The role of the chief audit executive (CAE) has always been to stay one step ahead of risk. But with artificial intelligence (AI) now embedded in how organizations make decisions, run operations, and manage risk, the CAE is emerging as the architect of trust. The role is helping organizations match rapid technological advances with robust oversight and ethical guardrails.

 

This new reality elevates the CAE to a strategic advisor to the business on AI governance, controls, and ethics.

 

For internal audit leaders, the proliferation of AI creates a dual and urgent challenge: How can they govern AI as a risk while also harnessing it as a tool to transform risk management?

 

These questions were at the center of Genpact's inaugural Chief Audit Executives' Forum, held on March 26, 2026, in New York. The forum brought together CAEs from leading global corporations and Genpact's Enterprise Risk Consulting leaders to explore how internal audit can help organizations navigate change, stay ahead of risk, and lead in an AI-driven world.

 

This paper brings together key perspectives from the forum to explore how AI is redefining risk oversight. AI is enabling a shift from traditional point-in-time audits to more continuous assurance models while also creating new governance and cyber challenges. It also spotlights why responsible AI matters most, covering everything from managing model risks and tracking data lineage to keeping AI decisions explainable as companies ramp up their adoption.

 

We approach the topic through five lenses – intelligence, indicators, interventions, inflection, and imperative – that help translate emerging risks into leadership actions for internal audit (see figure 1).

Risk assurance lenses and strategic focus table

Figure 1: The five lenses used to view emerging risk and executive action

AI as risk – the emerging accountability gap

According to Genpact's enterprise AI research, almost 50% of 500 executives surveyed think that governance is struggling to keep pace with AI advancements. This concern is even greater among risk management leaders, with 52% sharing this view.

It feels like two trains colliding; leadership is pushing speed and AI agent deployment, while assurance teams are focused on governance, which takes time.

CAE, $8B regional banking institution

This gap is not a future problem. It's a present one. And the signal is no longer coming solely from regulators or technology vendors. It's coming from the boardroom.

 

Boards now regularly ask: Do our AI systems align with our risk tolerance? What is our preparedness if there is a material AI failure? How are we governing AI vendors, and what happens if their AI fails? These are no longer theoretical questions reserved for innovation committees. They are audit committee agenda items. A CAE from a mass media leader put it plainly at Genpact's CAE Forum 2026: "The board now expects regular updates on AI readiness. This is no longer optional or ad hoc."

 

The regulatory environment is further accelerating this urgency. The EU AI Act now imposes binding obligations for high-risk AI systems across financial services, healthcare, and recruitment. The National Institute of Standards and Technology AI Risk Management Framework (NIST AI RMF), ISO/IEC 42001:2023, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) guidance for generative AI, and the Institute of Internal Auditors (IIA) Global Internal Audit Standards are reshaping what "adequate assurance" means in an AI-driven world. Jurisdictions from South Korea to California to India have introduced or enforced AI governance legislation in 2025–2026 alone. Noncompliance under AI laws is not a future risk; it's a current exposure.

Three converging challenges that traditional audit models cannot solve

AI's rapid ascent is rewriting the very nature of risk and rendering traditional audits obsolete. Internal audit leaders now face three powerful challenges.

 

1. Keeping AI responsible at scale

 

As AI adoption races ahead of governance, internal audit must move beyond traditional frameworks to quickly establish structured, auditable frameworks that can manage model risk, data lineage, and explainability at scale (see figure 2).

AI governance lifecycle triangular framework diagram

Figure 2: AI governance framework

 

What makes this a challenge is that AI risk is evolving beyond traditional model validation. It now spans bias, drift, autonomy, and third-party exposure, with decisions often emerging from complex, interconnected systems rather than single models. At the same time, weak visibility into AI usage and dependencies is amplifying exposure.

 

Additionally, AI systems rely on distributed data pipelines, making traceability essential for managing compliance, privacy, and integrity risks. Meanwhile, explainability must operate at two levels: understanding individual decisions and explaining how multiagent systems arrive at outcomes. Without this, organizations cannot defend decisions, meet regulatory requirements, or maintain trust.

 

2. Cyber risk and AI risk have converged, but the controls haven't

 

A critical insight from the CAE Forum is that AI risk materializes at the intersection of governance gaps, control weaknesses, and insufficient vendor oversight, not in any single domain (see figure 3). Yet most organizations are still treating AI governance, cybersecurity, and third-party oversight as separate audit streams.

AI risk diagram highlighting governance and oversight

Figure 3: AI risk emerges at the intersection of AI governance gaps, control weaknesses, and insufficient vendor oversight

 

Attendees stressed that shadow AI is now one of the most pervasive and ungoverned risks in the enterprise. Productivity tools, vendor-embedded AI, and unsanctioned model usage are creating data leakage exposure that traditional security operations center (SOC) frameworks were never designed to detect. AI-driven threats such as hyper-personalized phishing, polymorphic malware, agentic intrusions, and adversarial model attacks are evolving faster than defensive control cycles can respond. This means that point-in-time cyber assessments no longer reflect real risk. And governance frameworks that lack visibility into real-time AI usage are structurally blind.

Shadow AI is one of the hardest challenges. We're seeing it across tools, vendors, and even meeting platforms.

CAE, $200B+ healthcare services leader

3. Annual audit planning cannot manage continuously evolving risk

 

The board's mandate for the CAE has evolved. Rather than looking backward at control performance, the board is asking whether those controls can keep pace with changing risks and remain effective over time (see figure 4). That's a challenge traditional point-in-time audits were never designed to address.

 

Annual audit plans built around fixed risk universes cannot keep pace with AI systems that evolve continuously. Sampling-based testing cannot provide the coverage of full-population AI-driven data analysis. And audit functions that spend most of their capacity on administrative execution cannot elevate to the strategic risk advisory role that boards now expect.

Evolving control architectures and board mandates

Figure 4: The shift in CAEs' mandate from the board about audit coverage of AI risk

Five actions that reposition internal audit as a strategic AI risk leader

1. Build a complete AI risk universe starting now

 

The foundation of effective AI governance is knowing what you are governing. Audit leaders must initiate a structured exercise to identify every material AI system operating across the enterprise – first-party and third-party – and assign clear accountability owners to each. This is not an IT inventory exercise. It's the first independent act of AI governance assurance. Until this exists, the audit plan has a structural gap that no amount of testing can close.

 

2. Shift from point-in-time to continuous assurance

 

Leading internal audit functions are already making this transition. AI-powered continuous monitoring platforms can ingest data from fragmented ERP systems, procurement databases, access logs, and external risk feeds, detecting control failures in real time rather than after the fact. Machine learning-based anomaly detection, real-time risk dashboards, and dynamic audit planning models are enabling audit teams to shift from "we tested 30 samples and found two exceptions" to "we monitored all transactions in real time and here are the systemic patterns."

 

3. Converge AI governance, cyber, and third-party oversight into a single assurance model

 

The Integrated AI Risk Convergence (IARC) Framework, a six-pillar model aligning AI governance, cybersecurity, and third-party oversight, represents the new standard for audit functions operating in an AI-driven environment. Audit leaders must shift focus from auditing individual domains to auditing the connective tissue between oversight streams. This means moving beyond basic compliance toward resilience assurance and assessing whether AI systems are controlled, adaptive, explainable, and recoverable under adversarial conditions.

Diagram of AI assurance triangle framework

Figure 5: The Integrated AI Risk Convergence (IARC) Framework: The six pillars of structured convergence

 

Concrete steps include:

 

  • Developing AI-specific vendor assessment procedures for top suppliers by AI exposure

  • Embedding AI audit rights into all new and renewed material contracts

  • Establishing an AI incident reporting protocol with the chief risk officer (CRO) and CTO that positions internal audit at the center of AI risk intelligence

     

4. Recognize responsible AI as a mandatory audit imperative

 

Responsible AI is no longer a best-practice aspiration but a mandatory audit responsibility. Audit functions must assess whether AI systems are operating fairly, transparently, and within defined risk tolerances.

 

This means building audit programs for model risk management, data lineage integrity, algorithmic bias testing, and explainability at scale. The COSO guidance for generative AI, NIST AI RMF, and the IIA Audit Framework together provide the multi-framework architecture needed, since no single standard covers the full AI lifecycle. Governance maturity, not technological sophistication, is what determines sustainable AI adoption outcomes.

COSO guidance is helping us shape how we think about AI governance and controls.

CAE, $2B environmental services provider

5. Build the talent and operating model the AI era requires

 

The audit team of 2026 needs a blended profile: traditional auditors alongside data scientists, technologists, and specialists in AI ethics and model risk. Every auditor needs baseline AI fluency, such as understanding how models work, how to challenge AI outputs, and how to identify AI-specific control failures.

 

Audit functions that cannot build this capability organically must co-source the expertise they need. Many organizations are leveraging strategic partners to expand their AI audit talent and advisory pool. The skills gap cannot be closed by goodwill and training programs alone. It requires deliberate investment, a defined target operating model, and audit committee endorsement.

CAEs: The time to act is now. Not in the next governance cycle

AI risk has become a board-level concern, with a growing gap between audit committee expectations and actual audit function delivery. Chief audit executives who proactively bridge this gap gain lasting credibility. Doing this requires internal audit to move beyond periodic compliance and adopt a forward-looking risk-intelligence role that audits AI systems and delivers actionable foresight.

 

The future of assurance is powered by AI, guided by people, and driven by purpose. For chief audit executives, the opportunity to redefine risk and assurance has never been greater – and the window to act has never been shorter.

 

The question is not whether AI will transform internal audit. It already has. The question is whether your function will lead that transformation or spend the next three years catching up.

Genpact Intelligence

Get ahead and stay ahead with our curated collection of business, industry, and technology perspectives.

Genpact Intelligence hub logo

An AI expert is a click away