Site navigation

Surge in Audit Coverage for AI-Related Risks Amid GenAI Adoption

Michael Edgar

,

Gartner GenAI
Recent surge in audit coverage for AI-related risks highlighted in a new Gartner survey.

As organisations worldwide accelerate their adoption of generative AI (genAI), there is a corresponding rise in efforts to provide audit coverage over the potential risks associated with the technology, according to a recent survey by Gartner. 

“As organisations increase their use of new AI technology, many internal auditors are looking to expand their coverage in this area. There are a range of AI-related risks that organisations face, from control failures and unreliable outputs to advanced cyber-threats,” said Thomas Teravainen, a research specialist with Gartner for Legal, Risk & Compliance Leaders practice.

The survey, which drew analysis from 102 chief audit executives (CAEs), aimed to assess the importance of providing assurance over 35 identified risks. 

Notably, the top six risks showing the greatest potential for audit coverage increases include strategic change management, diversity equity and inclusion, organisational culture, AI-enabled cyber threats, AI control failures, and unreliable outputs from AI models.

Of particular concern, according to Gartner, is the lack of confidence among internal auditors regarding their ability to effectively oversee AI-related risks. “Perhaps the most striking finding from this data is the degree to which internal auditors lack confidence in their ability to provide effective oversight on AI risks,” continued Teravainen

“No more than 11% of respondents rating one of the aforementioned three top AI-related risks as very important considered themselves very confident in providing assurance over it.”

Publicly available GenAI applications, as well as those developed in-house, introduce heightened risks related to data and information security, privacy, IP protection, copyright infringement, and the trustworthiness of outputs, according to Gartner. 


Recommended reading


Given that many enterprise GenAI initiatives are customer-facing, mitigating the risk of unreliable outputs from AI models becomes a priority to safeguard against reputational damage or potential legal ramifications.

“With such a broad array of potential risks coming from all over the business, it’s easy to understand why auditors aren’t confident about their ability to apply assurance,” continued Teravainen. 

“However, with CEOs and CFOs rating AI as the technology that will most significantly impact their organisations in the next three years, continued gaps in confidence will undermine CAEs’ ability to meet stakeholder expectations.”

Tags: ,

Michael Edgar

Staff Writer, DIGIT

Latest News

Editor's Picks Gaming

Xbox Rolls Out Disc-to-Digital Feature

Business Editor's Picks

Report: Scottish SMEs Face Mounting Cost and Revenue Pressures

Cybersecurity

Five Actions CISOs Can Take to Stay Ahead of Disruptions

Events Featured Finance

Just One Week to Go Until Fintech Summit 2026