List your product on Stack Search

Get in front of thousands of GRC decision-makers

Stop Treating AI Risk as an Assurance Silo

Stop Treating AI Risk as an Assurance Silo

By
Key Takeaways
  • Start With Mission-Critical Objectives: AI risk cannot be meaningfully assessed in isolation. Organizations first need to understand which mission-critical objectives AI could help or harm.
  • AI Is a Capability, Not an Objective: Bias, security, privacy, compliance, and model reliability matter because of the effect they can have on achieving the objectives that matter most to the organization.
  • Avoid Creating Another Assurance Silo: Treating AI as a standalone risk category risks repeating the fragmented approaches already seen across cybersecurity, SOX, business continuity, AML, and other areas.
  • Connect AI Governance to Performance: Boards need to understand how AI changes the uncertainty surrounding critical objectives, including whether that uncertainty remains within an acceptable level.
  • Risk and Internal Audit Have an Opportunity to Reposition: An objective-centered approach can move both functions beyond risk lists and control deficiencies toward providing insight that is more directly relevant to management and boards.
Deep Dive

In a recent LinkedIn post, I asked why so many organizations are trying to assess AI as a standalone risk. I think that question gets to the heart of what is going wrong with much of the discussion around AI governance. There is no shortage of people trying to work out how organizations should govern AI. New frameworks are appearing, risk taxonomies are being built, internal audit teams are developing programs, and familiar questions are being asked about bias, security, compliance, privacy, and hallucinations.

My concern is where they are being asked. Too often, AI is being treated as though it were a risk in its own right, something that can be assessed, scored, controlled, and reported separately from the rest of the organization. In other words, we appear to be building another assurance silo.

We have plenty of those already. SOX, cybersecurity, business continuity, anti-money laundering, privacy, compliance, and other specialist areas have gradually developed their own frameworks, assessments, terminology, and reporting. Much of the work within those disciplines is necessary. The problem comes when the discipline itself becomes the starting point.

AI should not be the starting point either. AI isn't an objective. It is a capability. The reason its risks matter is because AI can help or hinder the objectives on which an organization's success depends. That changes the questions we should be asking.

Start With the Objective

Instead of beginning with “What are our AI risks?”, I believe organizations should begin by identifying their mission-critical objectives. Which objectives matter most to long-term success? Which strategic and value-creation objectives are most important? Which value-preservation objectives have to be protected? And where, among those objectives, is AI capable of materially changing the likelihood of success?

Only then does it make sense to move into the familiar questions about bias, security, compliance, reliability, and the rest. ISO 31000 defines risk as the “effect of uncertainty on objectives.” COSO ERM uses a similarly objective-centered conception of risk. Taken seriously, that definition has consequences for the way AI risk should be assessed.

If we have not defined the objective, what exactly does it mean to call an AI risk “high”? High relative to what? What consequence are we concerned about? How much uncertainty is management willing to accept in pursuit of that particular objective?

An AI system used in an area where errors could create serious regulatory, financial, or safety consequences presents a very different governance problem from one being used to improve an internal process where mistakes can be spotted and corrected quickly. The technology may pose some of the same technical risks in both cases. Their importance to the organization can be completely different.

This is why I think the first set of questions needs to be broader. Which mission-critical objectives could AI help or harm? How could AI change the uncertainty around achieving them? What level of uncertainty is acceptable? Who is responsible for providing reliable information on whether those objectives are likely to be achieved? And who ultimately decides whether the remaining uncertainty, including that associated with AI, is acceptable to the CEO and board?

Now we are talking about governance and performance, not simply AI controls.

The Problem With Another Silo

The alternative is already becoming familiar. A specialist team develops an AI risk taxonomy. Controls are mapped against it. Compliance assesses regulatory obligations. Technology looks at security. Internal audit develops an AI audit program. Findings and risk ratings eventually make their way upward.

All of that can produce a considerable amount of activity. It does not necessarily tell a board what it most needs to know. Can the board see which mission-critical objectives are being materially affected by AI? Can it see whether AI is increasing or reducing uncertainty around their achievement? Can it see the combined effect of AI alongside the other sources of uncertainty affecting the same objective?

If not, more assurance work may simply mean more assurance reports. This is not an argument for ignoring the specialist issues. Bias matters. Privacy matters. Security matters. Hallucinations and model reliability matter. Regulatory compliance certainly matters. Organizations need people who understand each of these areas.

But they should feed into an assessment of what matters most rather than become the organizing principle themselves. Take a mission-critical objective and look at everything that could materially affect its achievement. AI may be one source of uncertainty. Cybersecurity may be another. People, suppliers, regulation, financing, operational capacity, geopolitical events, or dozens of other factors may also matter.

Management does not ultimately have to achieve an “AI objective” or a “cyber objective.” It has to achieve the organization's objectives. The assurance model should reflect that reality.

A Bigger Question for Risk and Internal Audit

For me, the AI discussion is part of a much older problem. Risk functions have spent decades identifying, categorizing, scoring, and reporting risks. Internal audit has traditionally devoted enormous attention to identifying and reporting what it believes are weaknesses or deficiencies in management's internal controls. Both professions do important work. But both risk becoming less relevant when that work becomes detached from the objectives senior management and boards are actually trying to achieve.

AI offers another opportunity to make a choice. We can create another specialist assurance structure, add AI to the collection of risk categories, build another register, and produce another stream of reports. Or we can use the arrival of AI to ask a more useful question: what does this mean for the objectives that matter most?

That would change the role of risk and internal audit. The risk function would spend less time trying to “own” AI risk and more time helping management understand AI's effect on mission-critical objectives. Internal audit would look beyond whether a generic set of AI controls exists and ask whether senior management and the board are receiving reliable information about the uncertainty surrounding those objectives.

It also puts accountability where it belongs. Who owns the objective? Who decides how much uncertainty is acceptable? Does the person accountable for achieving it have reliable information about the risks and opportunities involved? Does the board know when the uncertainty surrounding a mission-critical objective has moved beyond what it is prepared to accept?

Those are not AI questions. They are governance questions. AI has simply given us another reason to start asking them properly. My daughter Lauren served as both a chief risk officer and chief audit executive. She eventually left the risk and internal audit professions after seeing both functions become increasingly marginalized. I wish I could say the professions have changed dramatically since then. I don't think they have.

That experience is part of what led me to write Mission Critical Governance: Focusing on What Matters Most. The book makes the case for moving away from risk-list ERM and legacy approaches to internal audit and toward governance built around the objectives that matter most and the uncertainty surrounding their achievement.

I believe that shift could make risk and internal audit considerably more relevant to CEOs, boards, shareholders, and other stakeholders. AI governance is a good place to begin. There will be no shortage of AI frameworks, risk registers, controls, and assurance programs in the years ahead. The danger is that organizations become very good at assessing AI without becoming any better at understanding what AI means for their success.

If we want AI governance to improve decision-making and board oversight, the objective has to come first.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong