
Key insights
- You don’t need to build AI governance from scratch, but you do need to adapt existing controls so they match how AI enters your workflows and changes risk.
- You should be able to explain what each AI tool does, what data it can access, where people review the work, and how it was approved for use.
- AI can help teams review full populations instead of small samples, but wider coverage only helps when output is checked by people who understand the work.
- Vendor AI deserves close attention because many capabilities arrive through third parties, and your organization may still be accountable for how those tools use data and affect workflows.
Assess AI risk before control gaps grow.
Artificial intelligence (AI) has quietly moved from pilot projects into everyday operations. In many organizations it’s already inside workflows without anyone having formally decided it should be.
That reality reframes the accountability question. It’s no longer only about who owns a bad decision after the fact. It’s about who owned the process that allowed a given AI use to reach a live, and often regulated, workflow in the first place.
For leaders across operations, technology, compliance, risk management, and internal audit, the same disciplines and principles apply. If you’re trying to manage AI without slowing the business down, the starting point is understanding where it’s being used, who’s accountable, and which controls matter most.
Speaker: Tim Dively — The risk that gets too little attention in my opinion is really around shadow artificial intelligence. So, entering through both vendors and employees and then the internal audit programs that aren’t yet mature enough to see where that’s actually happening within the organization.
As we know, AI is often already inside a variety of different workflows, sometimes without anyone having decided that it should be. So that accountability question isn’t just who owns a bad decision after the fact, it’s who owned the process that let each AI instance reach a live regulated workflow in the first place. We’ll unpack much more of this as we go through each of our different perspectives with that. But I would say that shadow AI to me is number one.AI governance isn’t net new
A common misconception is that AI requires a brand-new control universe. It usually doesn’t. The governance disciplines most organizations already run, such as approved tools inside a sanctioned environment, clear rules for what data can be used and where it can go, retention, and logging, already exist in some form.
The work is to recognize where AI changes the risk profile and to right-size existing governance, risk management, and compliance programs against it, rather than standing up a separate and duplicative structure.
The opposite failure is just as common. Applying one heavy layer of control to every AI use, regardless of what that use actually does, creates friction and slows adoption. Applying one light layer to everything is easier, but it leaves real risk unmanaged. Neither extreme holds up well.
Speaker: Tim Dively — AI governance is not net new. This is not something that is like, oh, my gosh, here’s another cost center that I’ve got to stand up as it relates to this. It’s an entirely different discipline. So we tend to kind of throw everything into that AI bucket and convince ourselves that we have to reinvent the whole control environment. And we really don’t from that perspective.
So the governance disciplines you already run elsewhere, like the approved tools inside of a sanctioned environment, clear rules for what data can and can’t do, where it can and can’t go, retention logging, all those sorts of things already exist within your organization, whether you’re a financial institution or probably elsewhere in these other institutions and organizations that we’ve talked about.
So, to me, that governance expectation is really to recognize: What is the impact of AI? What’s the nuance of AI from a risk perspective within your organization? And making sure that we’re right-sizing those programs against that.
Know what the AI is actually doing
Before an organization can decide what controls make sense, it must answer a plain question: What kind of AI is this, and what is it doing? A tool summarizing documents isn’t the same as a model that influences credit or fraud outcomes, and the controls should reflect that difference.
Many organizations are asking how to document AI usage to satisfy external auditors, and what kinds of controls reviewers look for. The starting point is evidence that the AI passed through a governance process at all.
Learn how AI is transforming business operations across critical areas and why now is the time to build an AI-ready strategy.
If a capability is running in a system and producing output, it carries inherent risk regardless of how helpful it is. Being able to show what the AI does, what it can access, where people are involved, and how it was approved before going into production is what makes the specific controls defensible later.
From sampling toward whole populations
One of the more practical shifts is in how organizations review transactions, processes, and controls. Traditional sampling was often necessary because reviewing an entire population by hand wasn’t feasible. That constraint is loosening.
With the right prompt and a controlled environment, teams can analyze full populations rather than a selected few, whether that’s every vendor contract against a policy or an entire fixed-asset roll-forward reconciled and tied out in a fraction of the prior time.
The value is not speed alone. It’s coverage. A caution belongs alongside the benefit, though. Output still needs a human review. It remains possible for a model to tie to the wrong record or to flag something that turns out to be an error, which is why a review structure stays essential.
Speaker: Erica Carlson — Changing from the sample-based testing ... That is something we all try to make sure we collect or select the sample that is going to identify an issue, but population-based testing is really where we need to be at.
And having these tools that you can easily develop a prompt and test against it is a great way to do it. Instead of testing just 40 transactions, for example, test everything. Then you’re going to be able to see: Where are the segregation of duty issues? Where did the dual control not work? Also, maybe outliers for out of normal business hour transactions that are getting originated. That’s going to allow you to really add the value in reporting to the management and to the committees.Vendor and third-party AI deserve specific attention
For most organizations, the fastest-moving AI risk isn’t the model they built. It’s the AI arriving through vendors. Existing vendors are adding AI features to products approved years ago, and new vendors bring their own.
A recurring theme concerns tooling: which platforms to use, and whether to disclose AI use to vendors and customers. The more durable point is upstream of any single tool.
Regulators, governing bodies, and reviewers are increasingly asking a direct question: Which of your vendors are using AI, and what’s it doing? A vendor management program that can’t answer that, including capabilities delivered by fourth or fifth parties behind a contracted vendor, has a gap.
Contract language, documented intended use, and a clear view of scalability matter more than any single due-diligence packet. Receiving a SOC 2 Type 2 report isn’t the same as understanding what it says.
Speaker: Tim Dively — The existing vendors that you’ve historically had and have had for a significant amount of time are starting to integrate artificial intelligence and other sorts of digital modernization. And then you’ve got many of the new solutions that are out there and those vendors coming in. And so the goal is eventually to get coterminous sort of pieces with it to where you’re pretty satisfied within your vendor management program that as of X, Y, Z date, we’re aware of existing vendors who are using these things.
And also, any new vendor that we are considering bringing in, we’re taking care of those sorts of things. And so, to me, the one thing within the net new bucket I think that is really important is really around contract language. Making sure that you’re accounting specifically as it relates to the impact of AI and their relationships. Because the biggest thing that I think Erica and I see from our chairs is that the features and the functionality within the vendors that you’ve signed that contract with aren’t being provided by those particular vendors, they’re being provided to you by a fourth or fifth-party vendor.
So that’s where you really need to understand that, and be able to call that out, because that’s what the regulator’s going to ask, “Which of your vendors are using AI?” And if your program doesn’t account for that and you can say, “Hey, critical and high vendors, these are the ones who are using AI,” that next question is going to be, “But what’s it doing?” You’ve got to be able to explain that, too.
The human element doesn’t go away with AI
Adopting AI responsibly still depends on people. Judgment, professional skepticism, and the communication skills to ask the right questions become more important, not less, as more output is machine-generated.
There’s also a quieter risk worth naming: using AI for its own sake. Not every process needs it, and stepping back to ask whether a given use is the right fit is part of good governance.
Not implementing AI governance is also a decision
For organizations still deciding whether to begin, it helps to see inaction for what it is. Choosing not to adopt AI in any controlled form is itself a bet the technology won’t meaningfully change how work gets done.
Across industries, that’s an increasingly difficult bet to defend. For example, banking has absorbed waves of change before, from remote deposit capture to mobile banking, each of which introduced risk that was managed rather than avoided. Approached with governance and appropriate controls, AI belongs in the same category.
The organizations positioned well are not the ones with the most tools. They’re the ones that started with a real business need, understood how the AI would be used, applied governance appropriate to the risk, and kept people involved in key decisions.
Speaker: David Heneke — If you are consciously making a choice to not start using AI in some form or fashion, controlled AI with governance and making sure we have the risks mitigated, you’re making the bet that this technology is not going to drastically transform the way that we do business regardless of what industry you’re in.
At CLA, we pride ourselves in serving small privately held businesses, owner-controlled businesses that in the past there was always the issue with, “Can I get my business scaled up enough to make it where profitability is strong on the basis of scale?”
If we do this right, AI could be a great equalizer for smaller companies when it comes to competing with larger entities because of what it can do for you and the power that it has. So don’t be afraid of it. Because the way I also look at this, we’ve undergone a lot of evolution.
How CLA can help with AI governance
Many organizations are trying to support responsible AI use while answering practical questions about ownership, controls, documentation, and vendor risk.
CLA can help assess AI governance, vendor risk, internal controls, and audit readiness so your organization can understand where AI is being used, what risks it introduces, and whether current processes support responsible oversight.
Contact us
Assess AI risk and build clearer accountability before control gaps grow. Complete the form below to connect with CLA.