Audit committees need an AI evidence pack, not just more AI expertise

Artificial intelligence is moving onto audit committee agendas faster than many committees are becoming comfortable overseeing it.

Processing Content

The fifth Audit Committee Practices Report from Deloitte’s Center for Board Effectiveness and the Center for Audit Quality draws on close to 250 audit committee chairs and members. It reports that 82% describe their AI governance oversight as emerging or limited. It also finds that 70% identify technology, including AI, as the skill most needed to improve committee effectiveness. And 41% selected higher-quality discussion and challenge as an important opportunity to improve committee effectiveness.

Those findings may prompt boards to add more technology expertise. That can help, but expertise alone will not solve the oversight problem. An audit committee cannot challenge management effectively if it receives only a policy summary, a list of pilot projects or a demonstration of the newest tool. It needs evidence.

A practical response would be a short AI governance evidence pack for material use cases. Management could include it in the committee’s regular pre-read and update it each quarter. The pack would not need to explain how every model works. It would show what has changed, where the important risks sit, what controls are operating, and which exceptions still need attention.

The first section should identify scope and accountability. Which AI systems are material to financial reporting, internal control, compliance, forecasting or other areas within the committee’s mandate? What business purpose does each system serve? Who owns it? Which executive is accountable when an output is wrong or a control fails?

This matters because AI oversight does not automatically belong to the audit committee. Deloitte’s audit committee guidance emphasizes governance, risk, ethics and disclosures, while boards still need to define who owns each part of AI oversight. A clear scope prevents the committee from becoming the board’s catch-all destination for every technology issue.

The second section should show material changes. Audit committees do not need a static inventory that looks the same every quarter. They need to know whether a model, vendor, data source, configuration or intended use has changed since the previous meeting. A system that was tested six months ago may no longer present the same risk after a major update or expansion.

The third section should summarize validation and controls. When was the system last tested? What were the main findings? Where is human review required? What thresholds trigger escalation? Can one person approve both the system’s use and its output? Is there a record of overrides and corrections?

COSO’s 2026 guidance on internal control over generative AI highlights risks such as model drift, frequent configuration changes, opaque reasoning and prompt-based manipulation. Its control-based approach is useful for management. The audit committee needs a shorter version of the same logic: What can the system do, what could go wrong, and what evidence shows that the safeguards are operating?

The fourth section should focus on exceptions and incidents. A good pack should not bury the committee in routine metrics. It should highlight failed tests, control exceptions, security or privacy incidents, inaccurate outputs with significant consequences, unresolved high-risk findings and overdue remediation.

This is where familiar accounting discipline can improve AI oversight. Committees already understand materiality, exception aging, accountable owners, remediation dates and the difference between a policy and evidence that a control actually operated. Those ideas are just as useful when the subject is AI.

The fifth section should summarize assurance. What has internal audit reviewed? Has compliance, risk management, information security or legal challenged the use case? Did the external auditor consider the system because it affects financial reporting or internal control? What remains outside the current assurance scope?

The Center for Audit Quality has suggested that audit committees ask where AI is used in financial reporting and controls, how AI-enabled processes are monitored as models and data change, who owns the risks, and whether internal audit can test the related controls. The evidence pack would turn those questions into a recurring reporting process.

The pack should remain concise. One or two pages may be enough for many organizations, supported by appendices when the committee wants more detail. It should also use a materiality threshold. A low-risk writing assistant does not require the same attention as a system that influences an accounting estimate, approves transactions, monitors compliance or supports an external disclosure.

There is also a danger that a standardized pack becomes another box-checking exercise. The solution is not to add more fields. It’s to make the pack exception-based and decision-focused. Each section should help the committee answer one question: Is there anything here that requires challenge, escalation, additional assurance or a change in risk appetite?

Technology expertise will remain valuable. Training will remain necessary. But audit committees do not need to become teams of model engineers. They need reliable information that helps them exercise judgment.

An AI evidence pack would not eliminate uncertainty. It would give committees a consistent way to see where AI matters, what changed, whether controls are working, and who is responsible when they are not. That’s a more practical foundation for oversight than another presentation about AI’s potential.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *