An operations director catches you after a steering meeting. They are onboarding eleven new third party logistics providers next quarter. What usually goes wrong here, they ask. What controls do organizations normally put around this. What would you fix first.
Good question, right person, asked while it can still change something. In most audit functions it is also a six week question. It joins the intake list, gets weighed against the annual plan, waits for a slot, then becomes an engagement with a scope memo, walkthroughs, testing and a draft report. The answer lands after the providers are live.
The director did not want an engagement. They wanted an answer. We gave them a process, because a process was the only delivery mechanism we had.
Two reasons, one door
Organizations engage internal audit for two fundamentally different reasons, and we have spent decades treating them as one thing.
Some engage us because they must. Regulators expect an independent function, and the audit committee needs assurance it can rely on. The IIA’s Global Internal Audit Standards, effective since January 2025, set out what that function looks like and who is answerable for what. Independence, objectivity, professional judgment, accountability. Those are governance and legal concepts before they are technical ones, and each attaches to a named human being. A model can produce a conclusion. It cannot be independent, because independence is a relationship with the organization rather than a property of the analysis. It cannot be accountable, because accountability means someone can be asked to answer for a judgment and be wrong in public.
Others engage us because they can. A business leader with a real problem knows that somewhere in the building sits a group of people who have watched this process fail in four other divisions. They want that knowledge, and they are largely indifferent to the certification behind it.
We have never had to separate the two, because both arrived through the same door. The auditor who signs the opinion is the auditor who answers the corridor question. AI separates them, because the second reason no longer requires the first.
What the machine can actually answer
A general purpose model answers the logistics question badly. It will tell you that vendor due diligence matters and that segregation of duties in procurement is important. Thank you.
Connect that same model to the organization’s own material, which is the argument I made about building the knowledge layer before the automation layer, and the answer changes character. Your control matrix. Three cycles of prior findings. The incident log. The two vendor onboarding audits already done in other regions. Now “what usually goes wrong here” has an answer about your organization rather than about procurement in general.
For a large share of the risk and control questions the business brings us, that is enough. My own estimate is something like four in five, and I want to be careful with it. It is an estimate rather than a measured figure, and it counts advisory requests only, not assurance engagements, which come from the plan rather than from someone walking up and asking. It is a different cut from the eighty percent of audit work that is knowledge work I have written about before. That was about how we spend our time. This is about what the business wants.
The must column and the can column
Put the work in two columns and it sorts more cleanly than you might expect.
Must. An opinion the board can rely on. Judgment where the evidence conflicts and someone has to decide which version of events to believe. Challenge to management, which requires a person with the standing to hold a position in a hostile room. Anything a regulator, a standard or the charter reserves to the function.
Can. Risk identification on a process nobody has looked at yet. Control design advice while the design is still open. Benchmarking against how comparable organizations handle the same risk. Pattern recognition across incidents, tickets and prior findings.
Take the access review. The periodic recertification, sampled, evidenced, reported and signed, sits in the must column. Continuous flagging of access that does not match what the identity is actually doing sits in the can column, and I have argued it is the control the agent population now demands anyway. Same subject, two services, and only one needs an engagement wrapped around it.
This does not shrink audit. It splits it.
The reflexive read is that if a machine answers the questions, the function gets smaller. I read it the other way.
Advisory is rationed by capacity today. The queue is the real control on how much advice internal audit gives, not the charter and not the methodology. And every question we cannot take is not a question that stops existing. It gets answered by someone with less context, or by nobody while the decision goes ahead anyway.
Split the function in two and the arithmetic changes. Formal assurance stays human and stays deliberate, because deliberation is a feature when someone has to sign. Advisory becomes AI-native and available on demand, and stops competing for the same hours. That is the part of the orchestrator argument I underrated when I built it. The interesting capability was never running methodology faster. It was holding a useful conversation with the business without an engagement around it.
One survey figure makes this urgent rather than theoretical. In the Avalara research I wrote about last month, only 7 percent of more than 1,500 finance leaders said their organization puts governance ahead of speed. I read that as an incentive problem rather than neglect, and also a latency problem. People route around governance because it arrives after the decision, not because they dislike it. Advice delivered in five minutes competes on speed’s own terms.
Three things this breaks
Self review. If your AI advises on a control design and your function later provides assurance over that design, the threat is the one the Standards already handle for people. Being a machine does not dissolve it. Decide who owns the advice, and how that gets disclosed when the assurance work comes round.
The business will hear assurance. “Audit’s AI said this was fine” will be quoted in a steering committee within a month of go live. That is not an opinion. Label the output before you ship it, because the label is the only thing standing between advice and implied assurance.
Somebody owns the advisor. Its sources, its currency, its errors, its access to findings not yet released. That accountability sits in the must column, which is a neat result. An AI advisory service needs a human answerable for it before it needs anything else.
Where I would start
Pull last year’s intake log and sort every request into two piles. Needed an engagement. Needed an answer. That ratio is your business case, and I expect the second pile is larger than the function’s self image assumes.
Take the most common request type in that second pile and write out what a good answer looks like, including which of your own sources it would have to read. That is the scope of your first advisory service, and it is smaller than a project. Then name the human who owns it.
The future here is not human against machine. It is human where governance requires it, and AI where the business simply needs to know something. The half we keep is the half we always said was the real work. The corridor question was never the job. It was the toll we paid to stay close enough to the business to do the job, and we are about to stop paying it.