Most internal audit teams no longer need permission to experiment with AI. They need a strategy that says what is approved, what data can be used, who reviews the output, what enters the audit file and how value is measured. Use this as the working template before AI becomes invisible inside planning, fieldwork, reporting and follow-up.
Gartner reported in August 2026 that most audit leaders use AI in some form, but only a minority have a documented strategy.
This is the core gap the template solves: moving from isolated drafting and preplanning use to governed, measurable audit adoption.
IIA Risk in Focus 2026 lists digital disruption, including AI, as a fast-rising global risk for internal audit attention.
The ICAI February 2026 Standards on Internal Audit compendium frames planning, evidence, documentation, reporting and follow-up expectations.
Treat this as a policy-ready outline. It is intentionally written for internal audit adoption, not for auditing the entire company's AI programme. Tailor the fields to the company's data classes, approved tools, SIA documentation policy and audit committee reporting format.
Summarise prior findings and business changes; keep the final audit-universe score visible and editable.
Suggest risks, controls and tests; auditor tailors rows to the actual process and evidence source.
Convert scope into a source-report request list with owner, due date and audit purpose.
Draft exception logic for recurring controls; validate against actual ERP fields before reliance.
Turn verified exceptions into condition-criteria-cause-effect-recommendation format for reviewer editing.
Audit the business use of AI separately from internal audit adoption.
Use this when the engagement is auditing enterprise AI governance rather than the IA function adoption plan.
Score candidate AI tools for data security, determinism, audit-grade evidence and vendor quality before approving them.
Add approved AI use cases and monitoring candidates into the annual plan and committee summary.
Escalate missing source evidence instead of accepting model-generated explanations.
Use this when the AI strategy creates new fraud-readiness and evidence-skepticism procedures.
Move from templates to a controlled RCM, monitoring, observation and ATR workflow.
Gartner, IIA, Deloitte and Protiviti are useful current signals for audit planning, but they are not India-specific legal requirements. For Indian internal audit files, map the strategy to the Companies Act context, the entity's charter, contracts, DPDP obligations where personal data is involved and the ICAI Standards on Internal Audit compendium applicable from 1 April 2026.
An internal audit AI strategy is the documented plan for how the IA function will use AI in planning, fieldwork, monitoring, reporting and follow-up. It should define approved use cases, data boundaries, reviewer responsibility, evidence rules, quality metrics and rollout governance.
This template is for the internal audit function adopting AI in its own work. An AI governance audit tests how the business governs AI systems, data, model changes, incidents, human review and vendor controls.
AI output can help draft, summarise or classify, but it should not stand alone as audit evidence. Internal audit should verify conclusions against source reports, system logs, confirmations, contracts, tickets or other retained evidence.
The template is designed to support documentation under the ICAI February 2026 SIA compendium, especially planning, evidence, documentation, review, reporting and follow-up. It does not certify compliance; auditors must tailor it to the engagement.
A strategy becomes useful only when it changes the file: planned use cases, approved data sources, source-evidence checks, reviewer sign-off and repeatable monitoring rules. That is where the public template should flow into the internal audit module.