Most AI-generated risk scores look complete long before anyone checks whether they are right.
Auditing an AI-generated decision means confirming three things before anyone acts on it: the output traces back to its source data, it can be reproduced, and a named person reviewed it. Most risk and audit functions can already produce the first kind of decision. Very few can produce the second.
Puntos clave
- Most programs can produce an AI-generated risk decision. Few can audit one on demand, tracing it to source data, reproducing it, and naming who reviewed it.
- Diligent Institute’s 2026 board research found that only 3 percent of boards say AI is extensively embedded in their risk oversight and decision-making, even though 73 percent report confidence in their board’s overall risk oversight.
- A 2025 government report from Deloitte Australia, later found to contain fabricated citations and a fictitious court quote, shows what an unaudited AI output can produce once it reaches a decision-maker.
- The EU AI Act’s Articles 12 and 14, ISO 42001, and the NIST AI Risk Management Framework each require a documented record of how a high-risk AI system produced an output and who reviewed it, not a policy stating that it happened.
- Three checks, whether an output traces to its source, whether it reproduces, and whether a named person signed off, are enough to audit an AI-assisted risk decision before it reaches a board.
- What Happened When an AI-Assisted Report Reached a Government Client Unaudited?
- How Confident Are Boards in Their Own AI-Assisted Risk Data?
- What Do the EU AI Act, ISO 42001, and NIST AI RMF Require Before an AI Decision Reaches a Board?
- The AI Decision Audit Checklist
- How Should Risk and Audit Teams Extend Their Program to Cover AI Decisions?
- Verification Is What Turns Risk Insight Into Risk Action
- Preguntas frecuentes
A government department paid close to A$440,000 for a report it believed had been carefully researched. Months later, academics found citations to papers that were never written and a quote pulled from a court case that never said it.
In my opinion, this is a similar environment to what Gartner® described at ERAC this year. Stephen Osborne, Senior Director Analyst at Gartner, shared that “64 percent of audit leaders now find it harder to spot risks before they have a material impact.”
The firm behind that report was Deloitte Australia, one of the most credentialed professional services firms in the world. The report did not fail because anyone at the firm cut corners. It failed because the review process did not catch the errors before publication, an exposure every risk and audit function carries today.
What Happened When an AI-Assisted Report Reached a Government Client Unaudited?
Deloitte’s ~A$440,000 contract with the Department of Employment and Workplace Relations covered an assurance review that was later found to contain a fabricated quote attributed to a federal court judgment and citations to nonexistent academic papers. The firm refunded part of the fee after acknowledging limited use of generative AI in producing the document.
No one at the firm set out to publish fiction. A model produced content that read as finished, and the review step that should have caught it did not happen before the report reached a client that mattered. The same failure shows up inside a risk program whenever a vendor score, a control rating, or a board metric is treated as finished simply because it was produced quickly. Most programs discover this during an audit, not during design.
How Confident Are Boards in Their Own AI-Assisted Risk Data?
Diligent Institute’s 2026 board research found that 73 percent of directors feel confident their board can oversee the risks ahead of it. The AI-assisted data behind that confidence tells a narrower story:
- Only 3 percent of boards say AI is extensively embedded in their risk oversight and decision-making.
- 40 percent report not using AI in risk oversight at all.
- Fewer than half of directors regularly receive real-time operational data between board meetings.
- Only 8 percent rate their own board’s AI expertise as strong, the lowest score across every domain surveyed.
Confidence in the oversight and confidence in the data underneath it are not moving at the same pace. A risk or audit team fills that distance the moment it lets an AI-generated number move forward unaudited.
What Do the EU AI Act, ISO 42001, and NIST AI RMF Require Before an AI Decision Reaches a Board?
The EU AI Act’s Articles 12 and 14 require high-risk AI systems to support automatic event logging and effective human oversight. ISO 42001 requires top management to assign and communicate clear accountability for every AI system in use. The NIST AI Risk Management Framework adds a further expectation that organizations measure and document an AI system’s behavior on an ongoing basis, not only at launch, with supporting guidance maintained through NIST’s AI Resource Center.
Following the Digital Omnibus entering into force in July 2026, the EU AI Act’s compliance deadline for standalone high-risk systems moved to December 2, 2027, but the underlying requirement did not change. Three frameworks arrived at the same requirement from different directions: document the trail and name who is accountable for reviewing it. None of the three accepts a policy statement in place of a demonstrated, auditable record.
The AI Decision Audit Checklist
Auditing an AI-generated decision comes down to three checks, and each one stands on its own.
- Does the output trace to its source? A risk score or control rating needs a documented path back to the data it was built from, not an assumption the model filled in.
- Can the output be reproduced? If the same input produces a different result on a different day, the number cannot be defended to a regulator, an auditor, or a board member asking a second time.
- Did a named person sign off before it moved forward? A logged, attributable review is evidence. A policy stating that review occurs is not.
Reproducibility is usually where this breaks down first, since model versions change quietly and nobody logs which version ran on which date.
Gartner’s own ERAC session on AI in risk intelligence tools stated that “Anomaly detection, automated risk scoring, workflow assistance, continuous control monitoring, automated evidence collection, and policy and document review are among the more mature AI applications available to assurance leaders today,” according to Nick Sworek, Senior Director Analyst at Gartner.
That maturity is exactly why the three checks above matter now. A mature capability without a mature audit trail behind it is still a governance gap.
How Should Risk and Audit Teams Extend Their Program to Cover AI Decisions?
Doing this does not require a new discipline, only extending the one most risk and audit teams already run:
- Map every place an AI-generated number already feeds board or audit materials.
- Run the three checks above against each one before it moves forward again.
- Assign a named owner for verification, separate from whoever owns the underlying risk.
- Connect the verified output into a single enterprise risk register instead of rebuilding it for each audience that asks.
That mapping exercise tends to surface the same risk verified two different ways in two different systems, because the systems were never built to reconcile with each other. The fix is a data connection, not a new policy.
Verification Is What Turns Risk Insight Into Risk Action
Gartner named this year’s theme “From Risk Insight to Action” because most programs have already solved for insight. What is missing is a documented answer to a simpler question: How do you know the number in front of you would survive an audit?
At ERAC, Gartner reported that “84 percent of audit functions have already adopted audit management software.”
The infrastructure most programs need is already in place. What is missing is extending it to the AI-generated decisions running through it. Risk and audit functions that build this check now are the ones deciding what an AI-assisted decision means to their own board.
Gartner Disclosure
Gartner data and quotations in this article come from three Gartner press releases:
Gartner Press Release, Gartner Says 64% of Audit Leaders Now Find It Harder to Spot Risks Before They Have a Material Impact, September 15, 2026
Gartner Press Release, Gartner Enterprise Risk, Audit & Compliance Conference 2026 Grapevine: Day 2 Highlights, September 16, 2026
Gartner, Press Release, Gartner Says 84% of Audit Functions Have Adopted Audit Management Software, September 16, 2026
GARTNER is a trademark of Gartner, Inc. and/or its affiliates.
