AI-in-IA · The future of internal audit01 / 20
01
A vision for internal audit
80/20

The future of
internal audit

Mike Broekhof20 essays · AI-in-IA.comAugust 2026Press ? for controls
02
The whole argument, once

Roughly 80% of our work is knowledge work.
Roughly 20% is intelligence work.
We have always been paid for 100%.

Knowledge is still useful. It is no longer scarce, and it has stopped being ours alone.

Audit work has historically combined two sources of value. One is the ability to retrieve knowledge and apply a repeatable methodology. The other is the ability to decide what matters when evidence is incomplete, incentives conflict and the organisation does not behave as its process description suggests. AI forces us to price those two contributions separately.

Which part of my value was the knowledge, and which part was the judgment?

03
Separate the two

Two kinds of work, bundled into one profession

An illustrative estimate, not a measured result. The argument does not depend on the precise ratio. It depends on the two categories being genuinely different. The 80% is the execution vehicle; the 20% is where professional value becomes concentrated as that vehicle is automated.
Knowledge work
  • Read and retrieve
  • Apply frameworks
  • Compare criteria
  • Run structured tests
  • Synthesise evidence
  • Document conclusions
Intelligence work
  • Judge ambiguity
  • Read people and politics
  • Sense emerging risk
  • Challenge senior stakeholders
  • Connect unwritten context
  • Own the judgment
04
This is not a forecast

We have already built the first version

Our audit orchestrator can execute the main steps of an audit methodology. That proves the work can be decomposed and performed. It does not yet prove equivalence to known-good human judgments.

01

Ingest the record

02

Assess risk

03

Design and run tests

04

Draft the outputs

The uncomfortable discovery was that the human had become the bottleneck.Surviving the Oh-Fuck Moment · 30 January 2026

What the experiment established: substantial parts of audit expertise can be expressed as codified pattern recognition: condition against criteria, framework application, repeated testing and disciplined documentation. That exposes traditional sample-based and manually documented work. The remaining question is not whether the steps can run, but how accurately they run and where judgment must intervene.

05
Execution changes first

Why machines already win on several dimensions

Breadth

Full populations replace samples when the criterion can be expressed reliably.

Depth

Extra cross-checks and second-order questions become cheap enough to run.

Speed

hours ≠ weeks

Analysis can arrive while the business decision is still open.

Diligence

page 1page 40

The same attention on page 40 as on page 1.

100% wrong, consistently

A machine can apply the wrong criterion perfectly across the full population. Scale amplifies both diligence and correlated error.

State 1 · advantageBreadth, depth, speed and untiring attention change what execution can cover.
Enter advances this explanation
06
The economics arrive early

The fee falls before the job disappears

Nobody needs to believe AI can replace an auditor. They only need to believe it materially reduces the effort. That belief is enough to reprice the work.

Senior end

Judgment and relationships

Ambiguity, challenge, accountability and board trust remain scarce.

The squeeze

Reliable execution

The experienced professional whose core value is dependable delivery faces the strongest pressure.

Junior end

Challenge the machine

Entry-level work shifts from producing evidence to testing and contesting it.

A CFO or Audit Committee will eventually ask why the function needs the same headcount, timelines and career pyramid. We should have an answer before they ask.

The threat is repricing, not only replacement. Historical fees, staffing and engagement lengths become difficult to defend once execution effort visibly falls. The middle faces the strongest pressure because reliable execution was its core differentiator.

07
Redesign before we are redesigned

Three shifts in where value sits

The answer is not to defend the old allocation of work. Move human capacity towards future failure, system design and accountable judgment while machines absorb repeatable execution.

AssuranceResilienceFrom proving yesterday's compliance to asking what could fail next, and whether the organisation could absorb it.
ExecutorOrchestratorDesign the system, set its quality bar and intervene where judgment is genuinely required.
Knowledge holderJudgment providerDecide which knowledge matters, whether the answer makes sense and what question should have been asked.
08
AI-native control design

Not five gates. Three kinds of control.

Today · dense human reviewDurable accountability and temporary quality checks currently sit together.
Durable

Mandate and scope

Own what receives attention, and what we deliberately exclude.

Durable

Severity and materiality

Apply risk appetite to what a condition means here.

Durable

External word

A named human owns the opinion given to board or regulator.

Durable

Independence

Keep advisory from becoming self-review or implied approval.

Scaffolding

Input admission

Review sources until provenance and authority are reliable.

Exit: source policy + provenance on every claim
Scaffolding

Output verification

Review results until evaluation shows sustained reliability.

Exit: risk-weighted sampling + monitoring
New gate

Negative assurance

Own what the system did not flag, not only what it surfaced.

New gate

Instruction change

Version prompts, context sources and models as methodology.

The control that grows

Knowledge-layer stewardship

A more capable orchestrator amplifies whatever its memory contains. Provenance, correction, staleness and access become more important as every other gate gets cheaper.

Enter advances this explanation
09
Early and effective adoption

Build the knowledge layer first

PHASE 0

Corpus

Connect reports, workpapers, actions, policies, controls, incidents, risks and systems. Read-only.

Proof: answer “what have we said about X?” in minutes.
PHASE 1

Provenance & decay

Add effective dates, supersession, source authority and staleness labels.

Proof: retrieve current policy and label the obsolete one.
PHASE 2

Structured memory

Store risk, control, test, outcome, evidence, severity and action as linked objects.

Proof: replay a closed audit with its outcome hidden.
PHASE 3

Live signals

Connect incidents, changes, access and transactions. Memory becomes monitoring.

Proof: flag a material change before the next audit.
PHASE 4

Advisory surface

Expose governed, cited and logged risk knowledge to the business.

Proof: useful self-service without implied assurance.

Why first? This investment remains useful even if every capability forecast in this deck turns out to be wrong. Build for poisoning, anchoring, confidentiality and legal hold from day one.

Adoption logic: phases 0–1 make current work faster; phase 2 creates the evaluation history needed to widen review; phase 3 supports continuous risk sensing; phase 4 turns accumulated audit knowledge into a governed service.

10
Evidence changes the control

Earn the right to widen review

Autonomy is earned per task, not awarded to the function as a whole. The sequence below compares three representative task classes, then demonstrates the reverse gear.

Selected taskControl mappingSupervise the system
Human review

Review all

Every output

Review exceptions

Plus blind samples

Supervise

Quality at system level

Audit the system

Independent re-performance

System autonomy

Prove steps

Known populations

Meet threshold

Error by class

Monitor drift

Reversals and misses

Stay auditable

By non-builders

↶ REVERSE GEAR: new model, vendor, domain or data source returns that task class to full review until requalified.

Task 1 · repeatableControl mapping can reach system-level supervision once accuracy and drift are measured.
Enter advances this explanation
11
The developmental paradox

If the machine does the 80%, where does the 20% come from?

Judgment used to emerge from repetition: vouching, reconciling and the fourth week of fieldwork taught us what “wrong” looks like. Remove the repetition and we must develop judgment deliberately.

01 · COMMIT

The auditor records a conclusion before seeing the system output.

02 · COMPARE

Reveal the machine's answer and reconcile the differences.

03 · LEARN

Store the disagreement as training data for both human and system.

Blind pre-commitment does three jobs: it trains judgment without the old apprenticeship, produces the evaluation data needed to widen review, and protects against anchoring on organisational precedent.

This does not fully solve the developmental problem. It changes apprenticeship from producing routine work to contesting machine output, explaining disagreements and rotating deliberately through ambiguous decisions. Judgment can no longer be assumed to appear automatically after enough years of execution.

12
Where humans genuinely still win

We carry the whole organisation in our heads

The model carries a context window. We carry what was never written down.

Reality

How the process works, not how it is described.

Behaviour

Who escalates, absorbs or quietly works around.

Politics

What an observation costs the person who owns it.

History

What was tried, why it failed and what was promised.

Meaning

Why the same issue is trivial here and serious there.

Temporary gap

Context the system may gain through better access, memory and retrieval.

Durable restriction

Confidences, investigations and personnel matters that should not enter a broad memory layer.

Our role is translation: place the finding in the organisation, then explain the same truth to the business, ExCo, Audit Committee and supervisor.

Why this changes severity: the same technical condition may be a footnote in one organisation and a board-level matter in another. Auditors combine evidence with culture, history, incentives and implementation reality. That whole-organisation interpretation is likely to be among the last capabilities AI can reproduce reliably.

13
The honest caveat

Do not build your career on a temporary gap

Slide 12 is where this profession wants to stop. It is comforting, and it is currently true. Some context will remain human-held because governance requires it.

Much of the rest is a gap, not a moat. Better memory, deeper access and stronger retrieval will narrow it.

Many AI failures are failures in how we instruct, scope and contextualise it.

Those are skills we can improve. We should not design a five-year operating model around a limitation that may not survive eighteen months.

Plan for the gap closing. Be pleasantly surprised if it doesn't.

The practical distinction: protect context that should remain restricted; engineer access, memory and instruction for everything else. Do not describe a remediable information gap as permanent human uniqueness.

14
The demand side changes too

Our auditees are getting the same tools

The gap closes because systems improve. It also closes because the people who bought our analysis no longer need us to produce it.

They will get most of the insight we would have given them, without waiting eight weeks and without us.When Your Auditee Doesn't Need You Anymore · 12 February 2026

The analysis monopoly fades

Management can connect agents to its own policies, transactions, incidents and controls. “Good enough to act on” is the threshold that matters.

The independence mandate remains

Management's assurance-by-agent becomes a new audit object. Somebody still needs to challenge whether it is trustworthy.

Internal Audit therefore cannot rely on being the only group able to identify a control weakness. Its proposition shifts from producing scarce insight to providing independent challenge, explaining why automated analysis is trustworthy and identifying the assumptions management's own agents may share with their owners.

15
The operating model

One function, two delivery modes

Because they must

Formal assurance

OutputAn independent opinion built to withstand regulator challenge.
AccountableA named human owns scope, severity and the external word.
BoundaryAI analyses; it does not occupy the institutional role of auditor.
Because they can

AI-native advisory

ExperienceAsk in an existing channel; receive an immediate, cited and logged answer.
ServicesControl questions, design challenge and pre-mortem scenarios.
BoundaryLabelled “advice, not assurance”; material questions reach a human.
Business asks“What controls should I consider for this process?”
AI-native advisoryAnswer immediately

Grounded in the knowledge layer, cited, logged and labelled as advice.

Enter advances this explanation

Guardrails: an independence ledger records advice before future audits are scoped; a named product owner owns sources, access, quality and evaluation.

16
The second mandate

Old control questions, a new actor

We must transform our own work with AI and assure the organisation's use of AI. Most governance questions are familiar; the subject is not.

Old question

Who can act, within what authority, with what evidence and which fallback?

New actor

An adaptive agent whose intent can change while its entitlement stays valid.

Name the exceptions: prompt injection, bias, evaluation design and probabilistic model behaviour require genuinely new tests. “Old problems, new actor” is a governance frame, not a complete AI audit methodology.

The practical advantage for auditors is that we do not need to wait for an entirely new profession. Inventory, identity, authorisation, segregation, audit trail, accountability, supplier resilience and change control already give us a strong starting point. The methodology must extend those questions to intent, autonomy and probabilistic behaviour.

17
What this looks like as fieldwork

Six tests we can run now

01 · POPULATION

Reconcile the inventory

Compare the agent register with identities, API keys and vendor usage or spend.

The differences are the finding.

02 · AGENCY

Stay within permission, leave the purpose

Attempt an allowed but out-of-purpose action in a controlled environment.

Least privilege does not constrain intent.

03 · ATTRIBUTION

Reconstruct one transaction

Who instructed, what was accessed, what changed and whose authority was used?

If evidence cannot tell the story, the log is not an audit trail.

04 · STOPPABILITY

Exercise the stop

Test who can stop it, at 03:00 Sunday, and what happens to half-completed work.

Test the mechanism, not the policy.

05 · RESILIENCE

Switch the model

Run the alternative and assess output quality, not merely whether it starts.

An alternative provider is not a tested contingency.

06 · CHANGE

Version the methodology

Request the history of the production prompt, context configuration and model.

The methodology now lives in the instruction.

The technology is not the finding. The governance exception is the finding.

How to use this slide: each test begins with a familiar control objective, then asks how an adaptive actor changes the evidence. Failed reconstruction, unlisted agents, untested substitution or unversioned instructions are concrete findings, not general concerns about AI.

18
What I am asking of us

Start changing the work before the work changes us

This is a shared change programme, not an instruction for individuals to become AI specialists in their spare time. The function must supply governed tools, reusable knowledge and deliberate opportunities to practise judgment. Individuals must bring experimentation, scepticism and a willingness to redesign their own work.

01

Use a real task

Hand a genuine problem to a model. Discover which parts were pattern matching.

02

Master instruction

Scoping, context selection and evaluation are core professional skills.

03

Develop judgment deliberately

Use blind pre-commitment and rotate people through difficult calls.

04

Leave reusable memory

Every engagement should make the next one permanently smarter.

05

Build the foundation

Begin with the corpus, provenance and structured-memory phases.

06

Do not wait for permission to learn

No standard or professional body will hand us the answer in time.

19
Hold the tension

I am not selling you optimism

The threat

Part of the current job becomes obsolete

If most execution becomes machine work, staffing, career pyramids, methodologies and timelines should not remain unchanged.

The opportunity

The scarce work gets our full attention

Judgment, challenge, risk anticipation, culture and behaviour become the profession rather than what fieldwork leaves time for.

Any version of this vision that tells you only one of those things is selling you something.

The point is not to promise that every auditor simply moves into more interesting work. Some capacity will disappear and some roles will be repriced. The opportunity exists only if we deliberately redirect freed capacity towards resilience, organisational intelligence, challenge and accountable judgment before others redesign the function for us.

20
The point

The objective is not to protect the auditor's existing job from AI.

The objective is to redesign internal audit around the things for which a human auditor remains uniquely valuable.

Mike BroekhofAI-in-IA.comAugust 2026