Executive summary
AI adoption, AI-enabled fraud and organisational change are moving at different speeds. The AI Assurance Gap is the distance between those trajectories and the capability of Internal Audit to independently challenge and assure them. Closing it requires deliberate transformation of skills, methodology, fraud coverage and operating model — not simply adopting a tool.
AI capability is advancing rapidly. Organisations are embedding AI into processes, decisions and operating models. At the same time, fraudsters and other threat actors are exploiting the same technologies to increase the scale, sophistication and credibility of their attacks.
Internal Audit sits in the middle of this acceleration.
The strategic question is no longer simply whether internal auditors should use AI. It is whether Internal Audit transformation is developing the skills, tools, methodologies and operating model required to provide credible assurance over an increasingly AI-enabled organisation and risk environment.
At DisInnova, we describe the potential divergence as the AI Assurance Gap: the distance between the speed at which AI-related risks and organisational adoption are developing and the capability of Internal Audit to independently challenge and assure them.
Four different speeds of change
The AI environment is not moving at one uniform speed.
Four trajectories matter for Internal Audit:
1. AI capability and availability
AI models, tools and applications continue to develop rapidly. Capabilities that were specialised or expensive are increasingly accessible to organisations, employees, customers and external actors.
For Internal Audit, this changes both the object of assurance and the tools available to perform assurance.
2. AI-enabled fraud capability
Fraudsters do not operate under the same governance, procurement, model-risk, data-protection or change-management constraints as regulated organisations.
Generative AI can help malicious actors increase the scale and sophistication of social engineering, impersonation, synthetic identities, phishing and other forms of fraud.
This creates an important asymmetry: the actors exploiting AI may be able to adapt faster than the institutions defending against them.
3. Organisational AI adoption
Organisations are moving from experimentation toward embedding AI into business processes, customer interactions, analytics, decision-making and control environments.
But enterprise adoption must operate within governance frameworks, legacy technology, regulation, risk appetite, data constraints and change-management processes.
Internal Audit therefore needs to understand not only AI technology, but how AI changes governance, accountability, risk ownership and controls across the organisation.
4. Internal Audit AI capability
Internal Audit is also adopting AI, but capability should not be measured by whether auditors can use a generative AI assistant.
A mature Internal Audit AI capability requires much more:
- sufficient AI literacy across the function;
- specialist capability where deeper technical assurance is required;
- updated risk assessment and audit planning;
- methodologies for reviewing AI governance and controls;
- appropriate use of data and AI within audit execution;
- understanding of AI-enabled fraud and emerging threats;
- appropriate quality, confidentiality and human-oversight controls over Internal Audit's own use of AI; and
- the ability to credibly challenge management on AI-related risk.
The relevant benchmark is therefore not simply “Are we using AI?”
It is: “Can Internal Audit provide credible assurance over the risks created by the organisation's use of AI?”
The assurance gap
If organisational AI adoption and AI-enabled threats develop faster than Internal Audit capability, an assurance gap emerges. Closing it usually means deciding how far to transform the Internal Audit operating model, not simply adding a tool.
The consequences can be significant.
Internal Audit may find itself reviewing increasingly sophisticated AI-enabled processes using methodologies designed for a different risk environment.
Risk assessments may underestimate emerging exposures.
Audit plans may remain focused on traditional risks while material AI-related risks develop across business processes.
Fraud assurance may lag changes in the threat landscape.
And Audit Committees may receive assurance that does not fully reflect the organisation's changing risk profile.
The objective is not for Internal Audit to compete with AI engineers.
The objective is to maintain sufficient capability to independently assess whether governance, risk management and controls remain effective as the organisation changes.
AI-enabled fraud makes the capability question more urgent
The development of AI-enabled fraud makes this issue particularly important.
AI can lower the cost of producing convincing fraudulent communications, increase the scalability of attacks and make impersonation more sophisticated.
For Internal Audit, fraud-risk assessment therefore cannot remain static.
Audit functions should consider whether existing fraud scenarios, controls, detection mechanisms and assurance programmes adequately address AI-enabled techniques.
The question for CAEs is not only whether fraud controls worked historically.
It is whether those controls remain appropriate for the emerging threat environment.
What should Chief Audit Executives be asking?
CAEs should consider:
- Where is AI already being used across the organisation?
- Which AI-related risks could materially affect the organisation?
- Does the audit universe adequately capture AI-enabled changes to existing risks?
- Does the audit team have sufficient AI literacy to challenge management?
- Where are specialist skills required?
- Are existing fraud-risk assessments considering AI-enabled fraud scenarios?
- Is Internal Audit using AI appropriately within its own methodology?
- Are quality, confidentiality, evidence and human-oversight requirements clear?
- Is the Audit Committee receiving meaningful assurance over AI governance and risk?
- Is Internal Audit capability developing at least as fast as the risks it is expected to assure?
A question for Audit Committees
This is also an Audit Committee issue.
Audit Committees increasingly need to understand whether Internal Audit remains appropriately positioned, skilled and resourced for the organisation's changing risk environment, which is often where Board and Audit Committee advisory support proves valuable.
That means looking beyond traditional measures such as completion of the annual audit plan.
A more fundamental question is whether the Internal Audit function itself is transforming quickly enough to remain relevant and credible.
If the organisation is changing faster than its assurance function, completing the existing audit plan may provide false comfort.
Closing the AI Assurance Gap
Closing the gap does not require every Internal Audit function to become an AI laboratory.
It requires deliberate transformation.
Internal Audit functions should assess their current maturity, identify capability gaps, reconsider the audit universe and risk assessment, develop appropriate AI assurance methodologies, strengthen fraud-risk coverage, determine where specialist capability is necessary, and introduce AI into audit delivery where it genuinely improves assurance.
Technology is only one component.
People, methodology, governance, data, skills and operating model matter just as much.
The objective of Internal Audit transformation should ultimately remain unchanged: providing relevant, independent and credible assurance over the risks that matter.
But as those risks change, the function providing assurance must change with them.
Is Internal Audit building AI capability at least as fast as the risks it is expected to assure?
DisInnova helps Internal Audit functions assess their current operating model, identify capability gaps and design practical transformation programmes aligned with their organisation's evolving risk environment.
Key takeaways
- AI capability, AI-enabled fraud, organisational adoption and Internal Audit capability are advancing at four different speeds.
- The benchmark is not whether auditors use AI, but whether Internal Audit can credibly assure the risks created by the organisation's use of AI.
- Fraud-risk assessment cannot remain static; existing scenarios and detection should be retested against AI-enabled techniques.
- Audit Committees should look beyond plan completion and ask whether the assurance function is transforming fast enough.
- Closing the gap requires people, methodology, governance, data and operating-model change — technology is only one component.
Written by
DisInnova Editorial Team
DisInnova's insights are prepared by a senior practitioner-led advisory firm with credentials across internal audit, IT audit, governance, risk management, controls, fraud examination, strategy, corporate governance and financial services, including CIA, CISA, CFE, CRMA, CRISC and related professional certifications.
This article is general advisory information and does not constitute legal, regulatory, audit, tax, investment or professional assurance advice.



