Internal Audit
Internal audit is an activity within an organization that independently reviews how well the organization manages its risks, controls, and operations, and offers assurance and advice to help improve them. As commonly defined, it is designed to add value and improve an organization's operations. It typically reports to management and governance bodies rather than serving external stakeholders directly.
Internal auditing is commonly defined by The IIA as an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. In practice it assesses risk management, control, and operational (governance) processes for alignment with business objectives, with internal auditors functioning as audit professionals who work within the organization. In model risk and AI governance contexts, internal audit is typically positioned as the third line of defense, providing independent assurance over the design and operating effectiveness of risk management and control activities carried out by the first and second lines; it does not itself own or operate those controls. The scope, standards, and independence arrangements vary by organization, jurisdiction, and applicable professional standards, and this entry does not address external audit, which serves different objectives and stakeholders.
Why it matters
In AI governance and model risk management, internal audit provides a layer of independent assurance that risk and control activities are actually working as intended, rather than merely existing on paper. Because internal audit is typically positioned as the third line of defense, its role is distinct from those who build models (commonly the first line) and those who set policy and independently challenge or validate them (commonly the second line). This separation matters: without an independent function assessing the design and operating effectiveness of controls, an organization may have no objective basis for confidence that its stated governance and model risk practices are being followed. As commonly defined by The IIA, internal audit is designed to add value and improve an organization's operations, and in the AI context that value often comes from surfacing gaps between documented controls and actual practice.
Internal audit also helps management and governance bodies discharge their oversight responsibilities. Because it typically reports to management and governance bodies rather than to external stakeholders, it serves as an internal source of assurance that boards, committees, and senior leaders can rely on when making decisions about model use and AI risk. It is important, however, not to overstate what internal audit can deliver: it assesses and advises on risk management and controls, but it does not eliminate risk, nor does it own or operate the controls it reviews.
The scope and authority of internal audit vary by organization, jurisdiction, and applicable professional standards, so its precise role in any given AI or model risk program depends on how that program is structured. This entry addresses internal audit as an internally-administered function and does not cover external audit, which serves different objectives and stakeholders.
Who it's relevant to
Inside IA
Common questions
Answers to the questions practitioners most commonly ask about IA.