CORAA
CORAA University / AI governance audit

AI governance internal audit workpaper

Build an engagement-ready file for auditing enterprise AI governance: inventory, owners, data/privacy controls, model change controls, human review, incidents, monitoring rules and evidence requests.

Review profile
Readiness
66/100
AI systems
3
High-risk systems
1
Gaps / follow-ups
0
AI system inventory
SystemOwnerUse caseData usedRiskStatus
Governance ownership and RACI
AreaOwnerResponsibilityEvidence
Internal audit control tests
DomainExpected controlTestEvidenceResult
Evidence request list
AreaRequestOwnerDue
Continuous monitoring triggers
TriggerMetric / ruleOwnerCadence
Enterprise internal audit

AI governance is now part of the audit universe.

Use this workpaper when AI has moved from experimentation into a business process. Convert approved tests into a programme, and route unresolved gaps into the observation and ATR workflow. Build the programme or prepare the dashboard.

How it works

The workpaper turns AI governance into auditable fields: system inventory, owner, intended purpose, data used, risk rating, governance responsibility, expected control, test step, evidence and result.

Use it for advisory readiness, internal audit assurance or pre-board review. In India, tailor the file to the approved audit plan, the DPDP Act and Rules where personal data is processed, sector regulation, contracts, cyber/security controls and the actual AI systems deployed by the entity.

Worked example

An enterprise internal audit team is asked to review three AI use cases before presenting AI governance status to the audit committee.

Inputs
ModeInternal audit assurance review
MaturityDefined
AI systems3
Output
ExportAI inventory, RACI, control tests, PBC and monitoring workbook
Next fileProgramme, dashboard and ATR tracker

Common mistakes

Auditing AI without an inventory
The audit cannot be complete if management cannot list the AI systems, owners, data sources, user groups and deployment status.
Treating voluntary frameworks as law
NIST AI RMF and ISO/IEC 42001 are useful governance references, but they are not a substitute for applicable Indian law, sector regulation or legal advice.
Looking for one Indian AI Act
India’s current AI governance approach is principle-based and existing-law-led. Test DPDP, sector rules, contracts, IT/cyber controls and internal policies instead of assuming one horizontal AI statute.
Letting human review become symbolic
A reviewer name is not enough. The file should show what was reviewed, what was overridden, and which evidence supported the final decision.

Frequently asked questions

What should internal audit test in AI governance?+
Start with AI inventory completeness, board or committee oversight, ownership, data protection, model and prompt change control, validation, incident monitoring, human review, vendor oversight and evidence retention.
Does India have a standalone AI Act for internal audit to test?+
No single horizontal AI Act should be assumed for this workpaper. As of the current India AI Governance Guidelines approach, internal audit should test applicable existing laws and obligations: DPDP for personal data, sector regulation, contracts, IT and cybersecurity controls, consumer or labour obligations where relevant, and the company’s own AI policy.
Is NIST AI RMF mandatory in India?+
No. NIST AI RMF is a voluntary risk-management framework. Indian internal audit teams can use its Govern, Map, Measure and Manage structure as a practical reference while still testing applicable Indian law, contract and sector requirements separately.
How is this different from an AI audit tool evaluation checklist?+
An AI audit tool evaluation checklist assesses software used by the auditor. This workpaper audits the company’s own AI governance: the AI systems in business processes, the owners, the controls and the evidence.

Authoritative sources

Parliament
MeitY - Digital Personal Data Protection Act, 2023Use where AI systems process digital personal data; test purpose, access, retention and responsibility separately from general AI governance.
PIB - DPDP Rules, 2025 notifiedGovernment release states the Rules were notified on 14 November 2025 and operationalise the DPDP Act framework.
PIB - India AI Governance GuidelinesMeitY release describes a safe, inclusive and responsible AI governance framework using existing legislation wherever possible.
NIST AI Risk Management Framework 1.0Voluntary framework for managing AI risk; useful for Govern, Map, Measure and Manage structure.
NIST AI RMF PlaybookSuggested actions for operationalising AI RMF outcomes; not a mandatory checklist.
The IIA Artificial Intelligence Auditing FrameworkProfessional guidance for internal auditors assessing AI strategy, governance, risks and controls.
ISO/IEC 42001:2023AI management system standard; public ISO page describes an AIMS for responsible AI use.
ICAI
ICAI IASB - Compendium of Standards on Internal AuditUse SIA planning, evidence, documentation, reporting and follow-up principles when tailoring the workpaper.
Always confirm against the latest version of the source. Regulations evolve and amendments are common.
Related calculators
AI in audit and internal audit guideAI audit tool assurance frameworkInternal audit resource hubInternal Audit module
Share this tool
Last reviewed: 2026-08-30 · For informational purposes only — not professional advice.