The findings below are the panellists’. The commentary around them, and the full argument, are in the white paper.
One
Integration is asserted far more often than it is practised
Functions believe they are joined up. The evidence — shared taxonomies, shared scoring, shared timing — says otherwise. Research cited on the panel put agreement on a common risk taxonomy at 36%.
Two
The annual plan is dated before it reaches the committee
The argument is not for less planning. It is for planning that runs continually on live risk intelligence — and for retiring the coverage debates that produce no assurance.
Three
Conformance should be a by-product of the work, not a project
If proving conformance with the Global Internal Audit Standards requires a special exercise every five years, the purpose of the Standards has been misread.
Four
Defensible evidence has five characteristics
Traceable, timely, explainable, independently verified, and connected to accountability. Regulators are not assessing technology. They are assessing governance.
Five
Boards have attention on AI, but not a governance map
Agenda time is rising. Visibility of where AI is actually deployed is not. Invisible AI arrives through business applications, third parties and individual experimentation.
Six
Continuous monitoring is not the same as assurance
When the alert fires tomorrow, who does something differently? Without that answer, an organisation has automated its anxiety rather than improved its assurance.
“What an organisation cannot see consistently, it cannot govern consistently. And if we cannot govern it, we cannot assure it.”
Mostafa Hassan · Chief Audit Officer, BEEAH Group
What defensible evidence looks like in the AI era
The framework offered on the panel by Faizal Chaudhury, and the most reusable part of the hour. Five characteristics, all of which have to hold.
1TraceableWhere an AI system influences a customer outcome or a financial decision, there is a complete chain: what data was used, which model version produced the output, who approved it, which controls applied.
2Timely and continuousNot periodic testing. Ongoing monitoring of defined indicators, with thresholds set in advance, breaches escalated, and escalation acted upon.
3ExplainableIn plain language, management can say what the model does, why it exists, what risk it introduces and what its limitations are — and can show the reasoning behind an output, not only the output.
4Independently verifiedNot developer assertion or vendor representation. Testing for accuracy, robustness, bias, security and performance over time, with clear separation between model owners, validators and approvers.
5Connected to accountabilityThe most persuasive evidence is not a dashboard. It is evidence that a named person owns the risk, supported by policies, a governance forum that receives regular reporting, and a record of management acting when a threshold is breached.
“Whether it is regulators, the board or auditors, they are not evaluating technology. They are evaluating governance.”
Faizal Chaudhury · SVP and Head of Internal Audit, Bayview Asset Management
Frequently AskedQuestions
What is always-on assurance?
Always-on assurance is an operating model in which assurance evidence is generated continuously by the work itself, rather than assembled periodically for a committee or an assessment. Planning runs continually against live risk intelligence, conformance evidence is captured at the point of work, and monitoring covers a defined set of leading indicators tied to significant risks. Judgement, oversight and accountability remain separate; only the underlying data is shared.
What is the difference between orchestration and consolidation?
Consolidation merges functions. Orchestration keeps them separate while allowing them to operate on single-sourced, trusted data with defined access permissions. Independence is a property of judgement, not of data — sharing a signal does not surrender objectivity, and five separate collection efforts produce five datasets and five versions of the truth.
What makes evidence defensible when AI influences a decision?
Five characteristics, all of which have to hold: the evidence is traceable to the data, model version and approver; it is timely and continuous rather than periodic; it is explainable in plain language including the reasoning behind an output; it is independently verified rather than resting on developer or vendor assertion; and it is connected to a named owner and a governance forum that acts on threshold breaches.
Why do boards say they lack a governance map for AI?
Because most AI does not enter an organisation through a procurement decision. It arrives inside business applications, through third parties, in embedded features and through individual experimentation. Without a living inventory of where AI is deployed and which uses touch a customer, an employee, a financial decision, a regulatory obligation or a critical operation, the board cannot say who owns the risk or how exceptions are monitored.
When do the EU AI Act high-risk obligations apply?
Obligations for high-risk systems listed in Annex III apply from 2 December 2027 following the deferral agreed under the Digital Omnibus. The substance of those obligations — an inventory of systems in use, defined accountability, logging and human oversight — is being asked for well before that date by counterparties, insurers and auditors, and is already good practice.
Can conformance with the Global Internal Audit Standards be demonstrated continuously?
Yes, if evidence is generated by the workflow rather than assembled alongside it. Supervision, review, scoping decisions and conclusions captured once at the point of work can be reused wherever they are needed, which turns the external quality assessment from a project into a read-out. The test offered on the panel: can you demonstrate conformance on an ordinary Tuesday afternoon?
WHITE PAPER
Always-On Assurance: the six findings in full
The complete write-up of the session, with the defensible evidence framework, the regulatory position as it stands, and ten questions to take to your next audit committee. Written for chief audit executives, heads of risk and compliance, and audit committee members.
Why the annual plan and the audit universe are being questioned
The five characteristics of defensible evidence
Five questions board reporting on AI should answer
Making conformance evidence a by-product of the work