This final article in the series looks forward, but it makes a case that is deliberately conservative about where the line between human and machine responsibility must sit: AI can and should be embedded throughout the quality assurance options GIAS provides — the QAIP, internal quality assessment, and both models of external quality assessment — but it must never be permitted to make autonomous decisions about conformance, findings, or improvement. Every one of those judgments must remain the responsibility of a qualified human professional, exercised under governance robust enough to prove it.
Where AI Genuinely Belongs in the GIAS Quality Framework
There is a substantial, legitimate role for AI across every quality assurance mechanism GIAS establishes, and the profession should not shy away from it.
Within the QAIP (Standard 8.3), AI can consolidate evidence continuously across the fifty-two standards, maintaining a current picture of the function's documented conformance rather than one reconstructed periodically.[3] Within internal quality assessment (Standard 12.1), AI can support ongoing monitoring by flagging engagements whose documentation appears to depart from methodology or from a specific standard's requirements, giving human reviewers a prioritized list of items to examine rather than requiring them to review everything with equal, undifferentiated attention.[4] Within performance measurement (Standard 12.2), AI can track key performance indicators in something close to real time, surfacing drift from board-agreed objectives well before an annual reporting cycle would otherwise reveal it.[5] And within external quality assessment — whether full-scope or self-assessment with independent validation (SAIV) — AI can accelerate the evidence-gathering and cross-referencing work that has historically consumed the bulk of an assessment's timeline, as the preceding article in this series argued in more detail.[6]
In each case, the value AI adds is the same: it compresses the labour of finding, organizing, and surfacing relevant information. That is a genuine and, I would argue, an increasingly necessary contribution as the volume of data an internal audit function generates continues to grow.
Where AI Must Stop
The line we want to draw is equally simple to state, even though holding it in practice will require real discipline: AI may surface evidence, patterns, and anomalies. It must never be the entity that decides what those things mean for conformance, for a finding's significance, or for whether the function — or an individual engagement — has met the Standards.
This is not a technological limitation I am describing; it is a governance choice, and it needs to be an explicit one, because the technological limitation is eroding. AI systems are becoming more capable of producing plausible-sounding conclusions, not merely flagged anomalies, and the temptation to let a sufficiently confident system's output stand in for a human conclusion will only grow. GIAS's own definition of internal auditing describes it as a discipline that helps organizations achieve their objectives through "professional judgments" applied without compromise, and its glossary defines objectivity itself as the "unbiased mental attitude that allows internal auditors to make professional judgments, fulfil their responsibilities, and achieve the Purpose of Internal Auditing without compromise."[7] Professional judgment, by definition, is judgment exercised by a professional — a human being accountable to a code of ethics, a licensing or certification body, and ultimately to the board. An AI system has none of those things. It cannot be held to the IIA's Code of Ethics. It cannot lose a CIA credential for negligence. It cannot be asked, in the way a human assessor can, to explain the reasoning behind a judgment call in circumstances the training data did not anticipate. Whatever role AI plays in quality assurance, it cannot inherit the accountability that makes a conclusion about conformance mean anything.
This applies with particular force to quality assurance specifically, because quality assurance is the mechanism that is supposed to catch failures everywhere else in the function — including, potentially, failures in how the function itself is using AI in its audit engagements. A quality assurance process that has delegated its own judgment to an autonomous system has no independent means of catching that system's own errors, blind spots, or drift. It would be, in effect, asking AI to grade its own homework.
The Governance Structure This Requires
If AI is to be embedded across the QAIP, internal assessment, and external assessment processes without ever making autonomous decisions, that boundary needs to be actively governed, not just assumed. I would propose that internal audit functions adopting AI within their quality assurance processes commit to several concrete practices:
Every AI-surfaced finding requires human sign-off before it becomes a conclusion. An AI tool that flags a potential nonconformance is producing a lead for a human reviewer to investigate, not a finding. The distinction should be documented and auditable — literally, since the QAIP itself is subject to assessment — so that an external assessor reviewing the function's quality process can see exactly where AI's contribution ended and human judgment began.
The independent assessor role in a full-scope EQA or SAIV validation must remain unambiguously human, and specifically must continue to include at least one individual holding an active Certified Internal Auditor credential, as Standard 8.4 already requires.[8] Whatever AI tools an assessment team uses to accelerate its own evidence review, the conclusion the assessor signs — the rating of Full Achievement, General Achievement, or Partial/Non-Achievement — must remain a human professional's attestation, made on that professional's own accountability.
Boards and audit committees should ask, as a standing governance question, how AI is used within the function's QAIP — not only how AI is used in audit engagements themselves. GIAS already requires the board to understand the robustness of the quality assessment process in order to build trust in the function; in an AI-embedded environment, that robustness question now has a new dimension, and boards should not assume the answer is satisfactory without asking.[9]
CAEs should treat AI governance within quality assurance as itself a component of the QAIP, subject to the same continuous monitoring, documentation, and improvement discipline as every other aspect of the function. An AI tool that quietly changes its own flagging thresholds, or that is updated by a vendor without internal audit's own review, is a conformance risk in exactly the sense Standard 8.3 exists to catch.
A Deliberately Conservative Position
We recognize this is a more conservative position than some in the profession will want to adopt, particularly as AI tools become demonstrably better at tasks that currently require human review. Our argument is not that AI will remain incapable of producing reliable conformance judgments — it may well become very good at this, sooner than many expect. Our argument is that internal audit's value to the organizations it serves rests specifically on the fact that its conclusions are the product of accountable human professional judgment, exercised by people who can be questioned, challenged, and held responsible in a way no software system can be. Quality assurance is the mechanism that is supposed to guarantee that judgment was actually applied, carefully, throughout the function's work. If quality assurance itself becomes an autonomous process, the guarantee it is meant to provide disappears, even if the AI making the decisions turns out, most of the time, to be right.
Conclusion
The IIA's own guidance already points toward deep AI integration across internal audit's data analytics and assurance capabilities, and quality assurance will be no exception.[10] The five articles in this series have examined the architecture GIAS builds for quality — the QAIP, internal assessment, performance measurement, and the two paths to external validation — and this final piece argues that AI belongs everywhere in that architecture as a tool for gathering, organizing, and surfacing evidence, and nowhere in it as an autonomous decision-maker. The profession should embrace the efficiency AI offers without ever mistaking that efficiency for a substitute for the accountable human judgment that gives internal audit's conclusions their meaning. Robust, explicit, human-centric governance of AI within quality assurance is not a constraint on the profession's future — it is the condition on which that future remains worth trusting.
Endnotes
1. The Institute of Internal Auditors, Global Practice Guides, "Understanding Data Analytics for Internal Auditors" and "Data Analytics Skills for Internal Auditors," issued May 8, 2026.
2. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Domain IV, technology-related CAE responsibilities.
3. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.3, Quality.
4. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.1, Internal Quality Assessment.
5. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 12.2, Performance Measurement.
6. Internal Audit Review Quarterly, "Five Years Is Too Long to Wait: The Case for Continuous Self-Assessment Within the SAIV Model," External Quality Assurance Series, Article 4.
7. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Glossary, "internal auditing" and "objectivity."
8. The Institute of Internal Auditors, 2024 Global Internal Audit Standards, Standard 8.4, External Quality Assessment.
9. Wolters Kluwer, "Domain III: Governing the Internal Audit Function," June 2024.
10. The Institute of Internal Auditors, IPPF & Global Internal Audit Standards Documents, Global Guidance suite, 2026.






