Assurance

AI in Internal Audit: Are CAEs and Audit Committees Ready for the Real Transformation?

Why the hardest barriers to AI in Internal Audit are behavioural and organisational, not technological — and what Audit Committees should be asking of the CAE.

Assurance9 min readPublished 24 August 2026By DisInnova Editorial Team
Internal Audit leaders and Audit Committees considering AI transformation and automation

Executive summary

AI transformation in Internal Audit is often framed as a technology decision. In practice it tests three things: whether auditors want the change, whether Chief Audit Executives have the capability to lead it, and whether Audit Committees are defining success as a stronger function or simply a cheaper one.

Almost every Internal Audit function in the UK now has artificial intelligence somewhere on its agenda. Far fewer have had an honest conversation about what AI transformation would actually require of them — and about who, quietly, may prefer that it does not happen too quickly.

The technology conversation is the easy part. Tools exist. Vendors are plentiful. Proofs of concept are inexpensive. The difficult questions are organisational and human: whether Internal Auditors genuinely want the change, whether Chief Audit Executives and their teams are equipped to lead it, and whether the Board Audit Committee is defining success in a way that produces a better function rather than simply a cheaper one.

The uncomfortable question behind AI transformation

Most published material on AI in Internal Audit describes capability: continuous monitoring, full-population testing, anomaly detection, natural-language review of policies and contracts, automated evidence collection. All of it is real, and much of it is already deployable in mature functions.

What is discussed far less is motivation. Transformation programmes rarely fail because the technology does not work. They fail because the people expected to deliver them have reasonable, unspoken reservations about what success would mean for their own roles, their teams and the way their professional value is measured.

The central proposition of this article is straightforward, and deliberately uncomfortable: the biggest barriers to AI transformation in Internal Audit may not be technological. They may be self-preservation, capability gaps and the way Audit Committees define success.

Question 1: Do Internal Auditors really want AI transformation?

This question is not an accusation. It is a legitimate organisational and behavioural challenge, and it applies in almost every function that automates part of its own work.

Consider the position of an experienced auditor whose recognised strength is thorough, disciplined manual testing. If sampling gives way to full-population analytics, if evidence gathering becomes largely automated, and if walkthrough documentation is drafted by a model and reviewed rather than written, then the skills that earned that individual their standing become less central. In some operating models, over time, the same coverage may be delivered by a smaller team with a different competence profile.

People rarely resist that prospect openly. Resistance is usually more subtle and more rational-sounding: concerns about data quality, reservations about auditability of model output, a preference to wait for the tooling to mature, an argument that the function's risk profile is too judgement-intensive for automation. Each of those concerns can be entirely valid. They can also, sometimes, be a comfortable place to stand.

None of this reflects badly on Internal Auditors. It reflects an entirely predictable dynamic: transformation creates resistance whenever employees believe their relevance or job security may be affected. The responsible response is not to dismiss the concern but to address it directly — by being explicit about what the function is trying to become, what the change means for roles and career paths, and how professional judgement remains central rather than incidental.

Functions that leave this unspoken tend to end up with pilots that never scale. The technology works; the adoption does not.

Question 2: Are CAEs and their teams actually ready to lead it?

The second question is about capability rather than willingness, and it is equally sensitive.

Chief Audit Executives are, almost by definition, experts in Internal Audit methodology, risk assessment, governance and stakeholder management. That expertise remains essential. But leading AI transformation requires a broader competence set, and it is worth being precise about the distinction.

Knowing Internal Audit methodology is one capability. Understanding AI sufficiently to challenge its use — in the business and inside the audit function — is another. Identifying which activities are genuinely suitable for automation is a third. Redesigning audit processes so that automation improves the work rather than accelerating an outdated approach is a fourth. Building and retaining a technologically capable audit team is a fifth. Preserving professional judgement while automating lower-value activity is a sixth, and arguably the hardest.

Few individuals hold all six in equal measure. That is not a criticism of the profession; it is a description of a competence profile that has changed materially in a short period. The relevant question for a CAE is not whether they are already an AI specialist, but whether their own continuing professional education has kept pace with the risks and tools they are now expected to opine on — and whether their team's development plan reflects the function they intend to run in three years rather than the one they inherited.

This is also where AI adoption most often reveals itself to be a broader change programme. Successful adoption requires more than buying technology. It typically requires transforming the Internal Audit operating model — the methodology, the skills mix, the data and analytics foundations, the audit workflow, the assurance model and the way the function interacts with the second line. Automating a methodology that was already imprecise simply produces imprecision at speed. Deploying analytics on data the function cannot access, reconcile or rely on produces confident output with no assurance value.

Sequencing matters. Redesign should generally precede automation, and data readiness should generally precede analytics ambition. Functions that reverse that order usually discover the problem eighteen months and one substantial licence fee later.

There is a further dimension that is rarely acknowledged in Committee papers. Internal Audit's professional identity has been built, for decades, on independent human verification — someone competent looked at the evidence and formed a view. Where part of that verification is performed by a model, the function must be able to explain how it satisfied itself that the model was fit for purpose, that its inputs were complete and that its output was reviewed by someone accountable. That is a methodological question before it is a technical one, and functions that treat it as an IT matter tend to weaken the very standard they exist to uphold.

Question 3: What should the Board Audit Committee be asking?

The third question is the one with the greatest influence on the outcome, because Audit Committees largely determine what "success" means.

When AI enters the Internal Audit conversation at Committee level, the discussion can drift quickly towards efficiency: fewer hours, fewer people, lower cost. Efficiency is a legitimate benefit and should not be treated as an embarrassment. Boards are entitled to expect that a substantial investment in automation produces measurable productivity gains. The risk is not that cost is discussed. The risk is that cost becomes the only lens, and that a genuine opportunity to strengthen assurance is quietly converted into a headcount exercise.

A more demanding Audit Committee will ask what the function will be able to see that it cannot see today. Whether AI-enabled assurance can extend coverage across risks and entities that have historically been reviewed infrequently. Whether risk identification improves because analytics surface patterns that sampling cannot. Whether monitoring becomes continuous or at least materially more frequent in the areas that warrant it. Whether analysis goes deeper, insight arrives faster, and audit resources are prioritised more intelligently. Whether the function releases capacity for the judgement-intensive work — culture, conduct, strategic and emerging risk — that no model performs well. And, ultimately, whether the information reaching the Board is stronger, earlier and better evidenced than before.

These are not soft questions. They are the questions that separate transformation from procurement.

The Committee also has a supervisory responsibility that is easy to under-exercise. It should challenge the CAE's transformation strategy on its merits: the intended outcomes, the investment case and its assumptions, the capability required to deliver it, the risks introduced by the technology itself — model reliability, data protection, bias, explainability and the auditability of AI-assisted conclusions — and the point at which the Committee will judge whether the programme has worked. That challenge is a core part of effective Board and Audit Committee oversight, and it is materially more useful to the CAE than approval without scrutiny. A transformation strategy that has not been tested by an informed Committee is usually a strategy that has not yet been finished.

Value creation versus cost reduction

It is worth being clear that headcount reduction is not automatically wrong. In some functions, particularly those carrying substantial manual testing effort in stable, well-controlled processes, a smaller team supported by strong analytics may represent a better allocation of organisational resources. Boards should be able to say so without accusation.

The failure mode is narrower than that. It occurs when the business case is written entirely in cost terms, because a cost-only case tends to produce cost-only behaviour: the cheapest tooling, the shortest implementation, no investment in data foundations, no capability building, and no change to methodology. Two years later the function is smaller and marginally faster, but no more insightful — and the assurance opportunity has been spent.

The stronger framing treats efficiency as one outcome among several. Internal Audit automation releases capacity; the value depends entirely on what that capacity is redeployed towards. If it funds deeper work on the risks the Board actually worries about, the investment compounds. If it simply disappears from the cost base, it does not.

What a successful Internal Audit transformation should achieve

A credible end state can usually be described without reference to any specific technology. The function understands the organisation's risk profile more completely, because it can analyse more of the underlying data more often. It reaches conclusions faster, with clearer evidence. It spends a greater proportion of its time on matters requiring experience and judgement, and less on retrieval, reconciliation and formatting.

Its people are different, too. The team combines audit and risk expertise with genuine data literacy, and it can challenge the organisation's own use of AI with credibility — a growing expectation in regulated environments, where the business is deploying models faster than most assurance functions are equipped to review them.

And the Audit Committee notices the difference in the only place that matters to it: the quality, timeliness and confidence of what it is told. If a transformation programme cannot eventually be seen in the Committee pack, it is reasonable to ask what it achieved.

Capability building deserves the same seriousness as tooling. A realistic transformation plan states which skills the function will develop internally, which it will recruit, and which it will draw on externally while its own capability matures. It also states what the function will stop doing, because capacity for new work is rarely created by goodwill. Continuous professional education is no longer a compliance formality for Internal Audit leadership; it is the mechanism by which a CAE retains the standing to challenge both the business's use of AI and their own function's.

Conclusion

AI will not resolve the structural tensions inside Internal Audit, and it will not decide what the function should become. Those remain leadership questions.

What AI does is expose them. It makes visible whether a function is willing to change how it works, whether its leadership has kept its own knowledge current, and whether the Audit Committee is asking for a stronger function or simply a smaller one.

AI transformation in Internal Audit should be neither a job-protection programme nor merely a headcount-reduction programme. The objective should be a stronger, smarter and more relevant Internal Audit function — one that sees more, understands more, and gives the Board better grounds for confidence. Everything else, including the technology, is a means to that end.

Discussing this with DisInnova

DisInnova advises Boards, Audit Committees and Chief Audit Executives on exactly these decisions. Our Board and Audit Committee advisory work helps Committees define what they should expect from an AI-enabled audit function and challenge the strategy behind it, while our Internal Audit transformation practice supports CAEs in redesigning mandate, methodology, data, skills and operating model so that automation improves assurance rather than simply accelerating it. If your function is at the point of deciding what transformation should mean in practice, we would welcome a confidential conversation.

Key takeaways

  • Resistance to AI in Internal Audit is often rational self-preservation, not obstruction — it should be addressed openly, not dismissed.
  • Leading AI transformation requires competences beyond audit methodology: challenging AI use, redesigning process, and building data-literate teams.
  • Redesign should precede automation; automating an imprecise methodology produces imprecision at speed.
  • Efficiency is a legitimate benefit, but a cost-only business case tends to produce cost-only outcomes.
  • Audit Committees should judge transformation by coverage, risk insight, timeliness and the quality of what reaches the Board.

Written by

DisInnova Editorial Team

DisInnova's insights are prepared by a senior practitioner-led advisory firm with credentials across internal audit, IT audit, governance, risk management, controls, fraud examination, strategy, corporate governance and financial services, including CIA, CISA, CFE, CRMA, CRISC and related professional certifications.

This article is general advisory information and does not constitute legal, regulatory, audit, tax, investment or professional assurance advice.

Explore DisInnova advisory services for governance, risk and transformation.

Need support with governance, risk, internal audit or AI transformation?

Our advisory services help Boards, Audit Committees and Executive Management strengthen governance, improve Internal Audit, manage risk and deliver responsible digital transformation.

Explore Our Services