Organisations plan assurance drive on AI

Organisations plan assurance drive on AI

Organisations plan to boost internal audit coverage over the potential risks arising from the deployment of AI technology, according to a survey by Gartner. For example, planned internal audit coverage for AI-enabled cyber threats and AI control failures leapt from 10 per cent each in 2023 to an expected 52 and 51 per cent in 2024…

Organisations plan to boost internal audit coverage over the potential risks arising from the deployment of AI technology, according to a survey by Gartner.

For example, planned internal audit coverage for AI-enabled cyber threats and AI control failures leapt from 10 per cent each in 2023 to an expected 52 and 51 per cent in 2024 among chief audit executives, the report said. Internal audits over unreliable outputs from AI models jumped from 14 per cent in 2023 to a planned 42 per cent in 2024.

Confidence gaps

“Perhaps the most striking finding from this data is the degree to which internal auditors lack confidence in their ability to provide effective oversight on AI risks,” said Thomas Teravainen, research specialist at Gartner’s legal, risk and compliance leaders practice. “No more than 11 per cent of respondents rating one of the aforementioned three top AI-related risks as very important considered themselves very confident in providing assurance over it.”

Publicly available and in-house generative AI applications create a range of new or increased risks. Those include data and information security, privacy, IP protection and copyright infringement. There is also concern over the bias and trust of AI outputs, with some complaining that the applications “hallucinate” by providing incorrect information.

Regulatory focus

Better risk management is crucial for firms operating in Europe following the adoption into law of the EU Artificial Intelligence Act in March 2024. The AI Act takes a risk-based approach in its four categories of AI systems: minimal, limited, high and unacceptable risk.

The regulation imposes stiff penalties for those who violate its provisions. Most violations are expected to cost companies €15 million, or 3 per cent of annual global turnover. But for infringements of the unacceptable risk category – which refers to AI-enabled manipulation of people, including the use of biometric data – fines can climb to €35 million or 7 per cent of annual global turnover. 





← Previous

Whitepaper: The Modern Approach to Global Conflicts of Interest
With organizations always looking to scale, the interactions between staff, vendors, and deals become multifaceted.…






Next →

Larger organisations bear brunt of cyber attacks
Large (74 per cent) and medium-sized (70 per cent) businesses and high income charities (66…

9 SEPTEMBER 2026

Owning your space: confidence, visibility & voice

This event marks the formal public launch of the IRM Women in Risk Special Interest Group. The session is themed around the most pressing personal and professional challenges identified by women in the risk profession today.

Find out more

10 SEPTEMBER 2026

Beyond compliance

Managing equity compensation risk through automation, governance and the unified equity compensation risk & automation framework (UECRAF).

Find out more

17 SEPTEMBER 2026

Building an effective risk culture in your organisation

The proactive cultivation of an effective risk culture can serve as a strategic differentiator, enhancing the organisation’s resilience, agility, and reputation in the eyes of customers, investors, and regulators alike.

Find out more

Advertisement