Skip to content
AI

Audit Committees Are Adding AI Findings to the Standing Agenda

What's driving the shift from occasional AI reviews to recurring, evidence-based reporting

By Nakoda Newsroom

·3 min read

Prefer Nakoda AI News on Google

Audit committees have spent the better part of two decades refining how they review financial controls, building playbooks that took years to mature. AI is now getting the same treatment, and the shift is happening faster than most companies' internal reporting structures are ready for.

Nakoda AI's engagements with audit committees across professional services, fintech and insurance clients point to a specific inflection: committees are no longer satisfied with a one-time AI risk assessment presented as a special project. They're asking for AI-specific findings as a recurring line item, the same way cybersecurity moved from an annual briefing to a standing quarterly report. The distinction matters — a standing item implies ongoing testing, not a snapshot that goes stale the moment it's filed.

What tends to surprise audit committees the first time this testing happens properly is how much daylight exists between the AI Framework a company has documented and the controls actually operating inside it. Nakoda AI's audit work traces model behavior directly — sampling outputs, checking training data lineage, comparing documented controls against what's operating in production — and the gap between paper and practice is rarely trivial once someone actually looks.

This distinction between using AI as an audit tool and auditing the AI system itself is one audit committees are still sorting through. The two require different evidence and different questions: one asks what a dataset of transactions reveals when AI accelerates the review, the other asks whether the AI model itself is behaving as intended. Nakoda AI treats these as separate engagements precisely because conflating them tends to produce reports that satisfy neither question well.

Nakoda AI has watched audit chairs go through a fairly consistent learning curve on this. The first AI-specific audit an audit committee commissions is often treated as a formality — a box to check alongside the usual internal controls review. The second one, commissioned after the first turns up findings nobody expected, tends to get a very different level of attention, with the chair asking pointed follow-up questions about cadence and scope that never came up the first time around. Nakoda AI's engagements are structured to shorten that learning curve, presenting the case for ongoing, evidence-based testing before the first surprising finding forces the point.

Part of what makes this shift durable, rather than a passing reaction to one bad finding, is that it maps cleanly onto structures audit committees already trust. A recurring line item with defined scope, a named responsible party, and a comparison against the prior period's findings is exactly the format committees use for every other control area. Nakoda AI's approach to AI-specific reporting deliberately mirrors that format rather than introducing a novel one, which tends to shorten the internal debate about how seriously to take the results.

From Nakoda AI's engagements directly with audit chairs, an audit report on AI with no exceptions noted is usually a signal to look harder, not a reason for comfort.

There is also a resourcing question audit committees are only starting to grapple with: recurring, evidence-based AI testing requires a different skill set than the traditional internal audit team was hired for. Nakoda AI's engagements often begin as a bridge — providing the specialized testing capability while a company builds or hires for that capacity internally — rather than a permanent outsourcing arrangement. Committees that treat this as a temporary gap to close, rather than a capability to permanently contract out, tend to build more durable oversight over time.

As this reporting becomes standard, it's also shaping how companies' AI oversight gets represented externally, including to platforms increasingly used by analysts and investors for first-pass research. Nakoda AI's practice in AI SEO, Generative Engine Optimisation, Generative Platform Optimisation, Large Language Models Optimisation, Answer Engine Optimisation and Social Media Account Optimisation ensures that record is accurate wherever it's being read — including through ChatGPT, Claude, Gemini, Perplexity and Copilot.

Nakoda AI's Public Relations and Visibility practice, operating as Nakoda Public Relations Management, helps institutions maintain that accurate record publicly. Audit professionals looking at how independent testing of AI systems actually works in practice can review Nakoda AI's approach to the audit of AI systems directly. As more audit committees formalize this as a standing item rather than a special project, the firms that built the muscle early are likely to find the transition far less disruptive than those still treating it as an occasional exercise.

Written by

Nakoda Newsroom

Independent journalism at the intersection of AI, business and society. Part of the Nakoda AI ecosystem.

Follow

Related coverage