CORAA
Resources · Internal Audit AI Strategy

Internal audit AI strategy template.

Most internal audit teams no longer need permission to experiment with AI. They need a strategy that says what is approved, what data can be used, who reviews the output, what enters the audit file and how value is measured. Use this as the working template before AI becomes invisible inside planning, fieldwork, reporting and follow-up.

Download evaluation checklistOpen AI governance workpaper
Why now

AI use is ahead of the strategy gap

93%
audit teams using AI

Gartner reported in August 2026 that most audit leaders use AI in some form, but only a minority have a documented strategy.

38%
with an AI strategy

This is the core gap the template solves: moving from isolated drafting and preplanning use to governed, measurable audit adoption.

No. 2
digital disruption / AI risk

IIA Risk in Focus 2026 lists digital disruption, including AI, as a fast-rising global risk for internal audit attention.

1 Apr 2026
ICAI SIA compendium effective

The ICAI February 2026 Standards on Internal Audit compendium frames planning, evidence, documentation, reporting and follow-up expectations.

Template

The AI strategy document

Treat this as a policy-ready outline. It is intentionally written for internal audit adoption, not for auditing the entire company's AI programme. Tailor the fields to the company's data classes, approved tools, SIA documentation policy and audit committee reporting format.

1. Mandate and boundary
Purpose
Use AI to improve audit coverage, consistency, evidence navigation and reporting quality without transferring judgement to a tool.
Approved scope
Planning, risk assessment, RCM drafting, data-request drafting, monitoring-rule design, exception summarisation and observation drafting.
Prohibited use
Uploading client personal data or books to unapproved tools, using AI to invent evidence, letting AI close exceptions, or treating model output as source evidence.
Owner
Chief Audit Executive or engagement partner, with IT/security and legal/privacy review where client or employee data is involved.
2. Use-case register
Use case
Describe the activity in one sentence: e.g. draft RCM risks for P2P, summarise prior ATR ageing, classify monitoring exceptions.
Data involved
Mark whether the use case uses public information, anonymised data, internal management data, personal data or client books.
Human review
Name the reviewer and the decision they own: approve scope, accept risk rating, clear exception, issue observation.
Evidence output
Define what enters the audit file: prompt log, source report, exception list, reviewer note, locked export or observation draft.
3. Governance gates
Gate 1 - tool approval
Document hosting, retention, training-on-data commitments, access control, audit logs and vendor support before use.
Gate 2 - use-case approval
Approve purpose, data class, expected output, reviewer responsibility and prohibited decisions.
Gate 3 - evidence review
Verify every exception or statement against source reports, system logs, confirmations or approved workpapers.
Gate 4 - periodic review
Review value, false positives, missed risks, incidents, team behaviour and continued need at least quarterly.
4. Audit-quality metrics
Coverage
Population tested, controls mapped, cycles covered and number of recurring rules moved from manual review to monitoring.
Quality
Reviewer changes to AI drafts, false-positive rate, reopened exceptions, repeated evidence gaps and unsupported observation drafts.
Efficiency
Time from data request to fieldwork start, exception clearance ageing, report drafting cycle time and ATR follow-up ageing.
Risk insight
New risks identified, monitoring rules added, repeat findings reduced and audit committee actions triggered.
5. Rollout roadmap
Month 1
Approve AI usage policy, tool list, data boundary, pilot cycles and reviewer documentation standard.
Month 2
Run one pilot on a completed P2P, R2R, H2R, treasury or ITGC engagement and compare with the old file.
Month 3
Move approved use cases into the annual plan, train preparers/reviewers and lock the evidence export format.
Quarterly
Report adoption, quality metrics, incidents, control changes and next use cases to the audit committee or partner group.
Use-case register

Where AI belongs in the IA workflow

Annual planning

Summarise prior findings and business changes; keep the final audit-universe score visible and editable.

Open related tool

RCM drafting

Suggest risks, controls and tests; auditor tailors rows to the actual process and evidence source.

Open related tool

PBC planning

Convert scope into a source-report request list with owner, due date and audit purpose.

Open related tool

Monitoring rules

Draft exception logic for recurring controls; validate against actual ERP fields before reliance.

Open related tool

Observation drafting

Turn verified exceptions into condition-criteria-cause-effect-recommendation format for reviewer editing.

Open related tool

AI governance audit

Audit the business use of AI separately from internal audit adoption.

Open related tool
Decision rules

Keep AI away from final judgement

Allowed
Drafting workpaper narration from verified facts, summarising prior reports, suggesting RCM rows, designing monitoring-rule candidates.
Allowed with approval
Using internal management data, employee data, client books, vendor AI tools, or model output inside an issued report.
Not allowed
Uploading sensitive data to unapproved public tools, generating evidence, changing figures, approving samples, rating issues without reviewer sign-off.
Always document
Tool used, data class, prompt or instruction, source population, reviewer conclusion, changes made and final export retained.
Execution files

Turn the strategy into workpapers

AI Governance Internal Audit Workpaper

Use this when the engagement is auditing enterprise AI governance rather than the IA function adoption plan.

AI Audit Tool Evaluation Checklist

Score candidate AI tools for data security, determinism, audit-grade evidence and vendor quality before approving them.

Internal Audit Annual Plan Generator

Add approved AI use cases and monitoring candidates into the annual plan and committee summary.

Internal Audit Evidence Escalation Tracker

Escalate missing source evidence instead of accepting model-generated explanations.

AI-Enabled Fraud Checklist

Use this when the AI strategy creates new fraud-readiness and evidence-skepticism procedures.

Internal Audit Module

Move from templates to a controlled RCM, monitoring, observation and ATR workflow.

Authority notes

Use global signals as source signals

Gartner, IIA, Deloitte and Protiviti are useful current signals for audit planning, but they are not India-specific legal requirements. For Indian internal audit files, map the strategy to the Companies Act context, the entity's charter, contracts, DPDP obligations where personal data is involved and the ICAI Standards on Internal Audit compendium applicable from 1 April 2026.

Gartner audit AI adoption survey, August 2026IIA Risk in Focus 2026ICAI IASB Compendium of Standards on Internal Audit, February 2026ICAI IASB publications and SIA listDeloitte Internal Audit Hot Topics 2026Protiviti Top Risks 2026 for internal audit teams
FAQ

Implementation questions

What is an internal audit AI strategy?

An internal audit AI strategy is the documented plan for how the IA function will use AI in planning, fieldwork, monitoring, reporting and follow-up. It should define approved use cases, data boundaries, reviewer responsibility, evidence rules, quality metrics and rollout governance.

How is this different from an AI governance audit?

This template is for the internal audit function adopting AI in its own work. An AI governance audit tests how the business governs AI systems, data, model changes, incidents, human review and vendor controls.

Can AI output be audit evidence?

AI output can help draft, summarise or classify, but it should not stand alone as audit evidence. Internal audit should verify conclusions against source reports, system logs, confirmations, contracts, tickets or other retained evidence.

Which SIA areas does this support?

The template is designed to support documentation under the ICAI February 2026 SIA compendium, especially planning, evidence, documentation, review, reporting and follow-up. It does not certify compliance; auditors must tailor it to the engagement.

Next step

Move from policy to operating model

A strategy becomes useful only when it changes the file: planned use cases, approved data sources, source-evidence checks, reviewer sign-off and repeatable monitoring rules. That is where the public template should flow into the internal audit module.

See the Internal Audit moduleOpen IA resource hub