Audit committees need an AI evidence pack, not just more AI expertise

Artificial intelligence is moving onto audit committee agendas faster than many committees are becoming comfortable overseeing it.
Processing Content
The
Those findings may prompt boards to add more technology expertise. That can help, but expertise alone will not solve the oversight problem. An audit committee cannot challenge management effectively if it receives only a policy summary, a list of pilot projects or a demonstration of the newest tool. It needs evidence.
A practical response would be a short AI governance evidence pack for material use cases. Management could include it in the committee’s regular pre-read and update it each quarter. The pack would not need to explain how every model works. It would show what has changed, where the important risks sit, what controls are operating, and which exceptions still need attention.
The first section should identify scope and accountability. Which AI systems are material to financial reporting, internal control, compliance, forecasting or other areas within the committee’s mandate? What business purpose does each system serve? Who owns it? Which executive is accountable when an output is wrong or a control fails?
This matters because AI oversight does not automatically belong to the audit committee.
The second section should show material changes. Audit committees do not need a static inventory that looks the same every quarter. They need to know whether a model, vendor, data source, configuration or intended use has changed since the previous meeting. A system that was tested six months ago may no longer present the same risk after a major update or expansion.
The third section should summarize validation and controls. When was the system last tested? What were the main findings? Where is human review required? What thresholds trigger escalation? Can one person approve both the system’s use and its output? Is there a record of overrides and corrections?
The fourth section should focus on exceptions and incidents. A good pack should not bury the committee in routine metrics. It should highlight failed tests, control exceptions, security or privacy incidents, inaccurate outputs with significant consequences, unresolved high-risk findings and overdue remediation.
This is where familiar accounting discipline can improve AI oversight. Committees already understand materiality, exception aging, accountable owners, remediation dates and the difference between a policy and evidence that a control actually operated. Those ideas are just as useful when the subject is AI.
The fifth section should summarize assurance. What has internal audit reviewed? Has compliance, risk management, information security or legal challenged the use case? Did the external auditor consider the system because it affects financial reporting or internal control? What remains outside the current assurance scope?
The pack should remain concise. One or two pages may be enough for many organizations, supported by appendices when the committee wants more detail. It should also use a materiality threshold. A low-risk writing assistant does not require the same attention as a system that influences an accounting estimate, approves transactions, monitors compliance or supports an external disclosure.
There is also a danger that a standardized pack becomes another box-checking exercise. The solution is not to add more fields. It’s to make the pack exception-based and decision-focused. Each section should help the committee answer one question: Is there anything here that requires challenge, escalation, additional assurance or a change in risk appetite?
Technology expertise will remain valuable. Training will remain necessary. But audit committees do not need to become teams of model engineers. They need reliable information that helps them exercise judgment.
An AI evidence pack would not eliminate uncertainty. It would give committees a consistent way to see where AI matters, what changed, whether controls are working, and who is responsible when they are not. That’s a more practical foundation for oversight than another presentation about AI’s potential.