Cherry Bekaert: Risk & Cybersecurity · 2025-05-30 · 27 min
Key moments - from our scoring
Substance score
33 / 100
Five dimensions, 20 points each
As part of the IIA's Vision 2035 initiative, this episode explores internal audit's expanding role in overseeing artificial intelligence deployments across enterprises. Scott Payton, a partner in Cherry Bekaert's risk advisory practice, breaks down the critical differences between traditional AI - such as machine learning and RPA, which have existed since around 2010 - and generative AI, which represents a fundamentally new technology capable of creating novel content through neural networks and deep learning. The discussion addresses concrete risks organizations face: algorithmic bias learned from historical data sets, hallucinations where AI generates plausible but fictitious information (illustrated through an attorney whose ChatGPT-written brief cited nonexistent case law), AI drift where models change behavior over time after deployment, and data privacy violations. Payton emphasizes that internal auditors must help organizations develop comprehensive AI roadmaps and governance frameworks - including accountability, transparency, bias detection, and security controls - rather than applying traditional IT audit approaches. The episode covers regulatory landscape shifts, including the EU AI Act (effective August 2026), state-level AI laws across 31 U.S. states and territories, and the Trump administration's deregulatory approach. Frameworks referenced include the IIA's AI governance model, NIST AI Risk Framework (focused on internal development), and the need for citizen developer training alongside IT governance.
Traditional AI like machine learning and RPA (which emerged around 2010) uses rule-based algorithms with predictable outputs, similar to Netflix recommendations. Generative AI, which is new, uses neural networks and deep learning to create novel content - writing, images, code, music - by predicting the next word, pixel, or note, making its behavior less predictable and more subject to drift over time.
AI drift occurs when a deployed generative AI algorithm continues to learn and change its behavior over time, even after being validated and placed into production. This matters because auditors may place reliance on AI results that later change negatively, requiring ongoing monitoring rather than one-time testing.
Generative AI learns from the data sets used to train it, absorbing any historical bias present in that data. For example, if hiring data contains past discrimination against women or minorities, the AI will learn and perpetuate that bias, making pre-training data evaluation critical.
Organizations should define a comprehensive generative AI roadmap at the enterprise level, clarifying their North Star and intended scope - from small pilot projects to full organizational transformation - before implementing governance frameworks, policies, and controls.
No single comprehensive U.S. federal framework exists; the IIA has released an AI governance model, and NIST offers the NIST AI Risk Framework (though it focuses on internal AI development). The EU AI Act is the world's first comprehensive law, becoming fully enforceable in August 2026, while 31 U.S. states have enacted varying AI regulations.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers a few actionable concepts - AI drift as an ongoing monitoring risk and a two-phased audit framework - but the bulk is entry-level AI explainer content that any business reader of the Wall Street Journal already knows. Significant padding from repeated affirmations and generic framing crowds out substantive density.
what we ultimately put in production that over time changes...if we're placing reliance on that without proper monitoring, this AI drift can have a negative impact
phase two comes in six months, year, two years later when we look and we refresh phase one...But then we also do a deeper dive on the actual control set
Almost every example and framework is recycled - the Netflix recommendation algorithm, the ChatGPT lawyer hallucination story (one of the most circulated AI cautionary tales), and generic bias-in-training-data explanations. There is no contrarian or first-principles argument anywhere in the episode.
attorney...he had had the briefs written, he went back and double checked all the language, he really liked it all and turned into the judge. And the judge was really enjoyed what he was reading until he went and looked at the case law
if you like to binge watch on Netflix, a lot of the information, the algorithms that present to you your next stop or you might be interested in, and a lot of that is based on artificial intelligence
Scott Payton is a legitimate risk advisory partner at a credible firm, but this is a house podcast featuring the firm's own partner, and his experience is advisory and audit-facing rather than operational AI deployment at scale. No evidence he has built or governed AI systems inside a real enterprise.
we were working with a large, uh, a large multinational organization and the President challenged the organization find every opportunity to leverage generative AI
as we think about AI and be successful, it really is starting with that whiteboard, looking at the use cases
The regulatory landscape section provides genuinely specific data points - 45 states with proposed bills, 31 enacting laws, Colorado's high-risk AI requirement, Tennessee's Elvis Act, and the EU AI Act's August 2026 enforcement date. However, operational examples are almost entirely unnamed and vague, weakening the overall evidential quality.
45 states have proposed AI related bills in 2024. 31 states and territories have enacted AI laws
Tennessee has the Ensuring Likeness, Voice and Image Security Act Elvis barring unauthorized AI simulations of a person, likeness and voice
The host asks exclusively generic, open-ended setup questions and provides no meaningful pushback or follow-up on any claim. The conversation is structured as a pure PR vehicle, with the host literally describing himself as speaking 'in my ignorance' and both parties exchanging 'right?' as a rhythmic filler throughout.
In my ignorance, Scott, is there any, is there any other information that I'm not really asking you about
Wow, okay. That's a lot of information. So that's incredible
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of our Internal Audit podcast series, John Heagy , Senior Manager, and Scott Peyton , Partner in our Risk Advisory practice, discuss the evolving role of internal audit in artificial intelligence (AI) oversight. They unpack the differences between traditional and generative AI, explore how internal audit function is leveraging these technologies, and examine the risks that come with AI adoption - while providing risk mitigation and identification strategies. This is the final episode in our four-part internal audit series. Catch up on the first three episodes The Evolving Role of Internal Audit: Unpacking IIA’s Vision 2035 Report , Top 3 Critical Skills for the IA Profession and The Client's Guide to Data Analytics in Internal Audit .
Transcribed and scored by The B2B Podcast Index.
Speaker A: Hello, everybody. Welcome to the final podcast in our series supporting the IIA's internal audit awareness Month. This is all a series that we created based off of the IIA's Vision 2035 report, which was highlighted at a recent district conference by the president of the iia. And, um, my name is John Hagee. I'm a senior manager in the risk advisory practice at Cherry Beckert. On today's podcast, I'm joined by Scott Payton, a partner and risk advisory leader at Cherry Becker. Nice to have you, Scott.
Speaker B: Hey, John, thanks so much. Glad to be here.
Speaker A: Awesome. Today's topic, we're really delving a bit into AI and how that plays into the changing landscape and the dynamic environment that we've created and that we are now participants in, whether we like it or not. If you don't mind, if we can just start at the basics. For me, especially when we talk AI. What are we talking about?
Speaker B: Yeah, no, John, I appreciate that. And again, great to be here today. And you know, as we look back to the IAA's Vision 2035 report, it was a great report for those that haven't had a chance to read it. And they really call out a lot of what's going to be happening in the industry. Right? Many of us are passionate about internal audit and where the industry is going. Uh, and in that Vision report, uh, there were several different key, um, themes or messages. One of them was AI.
Speaker A: Right.
Speaker B: Uh, there's two aspects to AI as it relates to internal audit. One is, how is AI going to be impacting the organizations in which we operate? Right. Not just our internal audit function, but broader, uh, how is it going to impact, uh, the organizational operations, financial reporting and so on. Um, and then also, uh, how does, uh, AI impact us as we execute as internal auditors? Uh, but to go to your question, John, when we talk about AI, what are we talking about and what's all the buzz about of late? Right? And so, uh, you can't pick a newspaper, the Wall Street Journal, New York Times, pick your periodical, um, and not read something about AI.
Speaker A: Right?
Speaker B: The, the impact of, uh, need for data centers, the impact on chip manufacturers, the impact on, uh, on higher education. The list goes on and on. Um, but is AI new? Not necessarily.
Speaker A: Right.
Speaker B: So, uh, we talk about AI. We usually break it down into two different categories. First is traditional AI. Uh, sounds, uh, almost tongue in cheek, right? So traditional artificial intelligence, but it's been out there a while, right? We think about, um, AI and um, uh, its genesis around things like robotics, process automation, RPA, machine learning. It's been around since 2010, right? So 15 years, give or take. Um, and it's been used for many, many things. Right? So, um, if you like to binge watch on Netflix, a lot of the information, the algorithms that present to you your next stop or you might be interested in, and a lot of that is based on um, um, um, artificial intellig, artificial intelligence. Um, and so again, AI, uh, has been around for a while. The thing that's really been pressing us lately though is a new method of artificial intelligence. And you guys have heard it before, likely generative AI. And we'll talk more and more about the, um, the uh, the difference between generative AI and traditional AI as we get into our podcast. Uh, but, but with generative AI, um, its function is different when we think about traditional AI. Um, it really is artificial intelligence in that it has a very complex way of using algorithms to go down, uh, decision tree or a thought process. Um, but the algorithms are rule based, the output is pretty predictable and consistent meaning, uh, that presented with um, using the Netflix example, um, folks that tend to watch these types of programs are likely going to be interested in uh, these types of programs as well. Uh, generative AI though is a little different. Um, generative AI is actually generated writing, right? Thus the name, the next whatever, the next pixel, the next note, the next word, right? So it can take through its learning, it takes a long, long time for these algorithms to learn, um, and create that next item, right? So it can write music, it can write, um, your, your research paper, it can create a picture, right? Uh, it's using uh, neural networks, deep learning from large data sets, things of that nature, um, to go through that creation process. Um, so again, traditional AI think, uh, facial recognition, that's been around a long time. Ah, autonomous vehicle driving, text generation and language modeling, chatbot, social media monitoring tools has been around for a while. Generative AI, it's new. And I think that this, as internal auditors, as we think about how it impacts our organization, creates a whole new set of risks and also opportunities for us. Uh, but with that, John, I hope that answers your question.
Speaker A: No, it does. Honestly, it's both frightening and promising. And although the most frightening thing I heard there was the 2010 was 15 years ago. I wasn't ready for that. No, I mean, I appreciate that. So that helps me out a little bit. Maybe we can delve a little bit more into kind of real life examples, real things that you've seen, things that we're seeing in the marketplace. How are these things really hidden and uh, what are the risks with them?
Speaker B: Yeah, it's a great question John. And you know, I think when we, you know, when Chat GPT came about and it was everywhere, uh, it was really exciting honestly.
Speaker A: And I think you and I both
Speaker B: would, would sit in the camp of propeller heads, right? I've got a hat with propeller on top of it and I enjoy breaking it out on a frequent basis. Uh, but for those of us that were in the middle of all that happening, it was, it was exciting in that the, the art of the possible was not endless. But I tell you what, it created some really exciting things. Everything from um, the shortcutting and really truncating the time um, to discover new ways to apply medicine or solve complex um, issues uh, in medicine, in business, um, other areas. Generative AI um allows us uh, to leverage technology, um to answer a lot of questions, to help us navigate a lot of uh, unexplored areas to go through that creation process that we talked a little bit about earlier. Uh, but to go to some specific examples, broad use cases for AI and generative AI, uh at the enterprise and also for internal audit. And so one is um, going to kind of the hardcore business side of thing is code generation or software development, right? So you think about um, using generative AI with it, with an algorithm that's been trained to generate code in a particular area and you can use a prompt and just say write code. That allows me to uh, set my alarm for 5am every day and out it goes and it generates the code and comes back. Um, so it allows us to using prompts, um, create new content again, pixels, uh, songs, things of that nature. But sticking with business, um, new software, uh, or policies, things of that nature using prompt. So again really powerful tool. Uh, one of its early adoption uh was around cybersecurity. Both the black hat and the white hat guys and gals, right? So um, obviously uh, with cybersecurity some of the negative sides of that are uh, deepfakes, right? So that can be using generative AI having uh, it mimic uh the speech patterns uh for a phone call. And so you can use generative AI to have a malicious phone call that calls somebody and tells them to wire money to XYZ account. Uh similarly uh, cybersecurity is also uh, able to um, uh cybersecurity, uh the white hat folks, those defending our enterprises are able to use generative AI to identify anomalies, to search um, the thousands or millions of activity that uh, are going on in Our systems identify those anomalies that don't look right and bring those to the surface. Um, so couple of examples there. Um, the other examples are around uh, uh, content creation for blog posts, social media updates, marketing events, um, even legal documents. Um, the story I often point to, which uh, I still chuckle at is um, attorney. This is early days with Gen AI, right. We really enjoyed the, the ability to have uh, chat, GPT, write his, his briefs. Um, and so he had had the, the briefs written, he went back and double checked all the language, he really liked it all and turned into the judge. And the judge was really enjoyed what he was reading until he went and looked at the case law. Um, and so generative AI creates new. Right. So it created all new case law that was fictitious. So his entire brief was hung on things that didn't really exist.
Speaker A: Right.
Speaker B: So generative AI is a really amazing powerful tool. Uh, but it's, but I think with those opportunities also comes the risks, uh from a business perspective of needing to make sure that we validate. Right. Um, and so we'll get a little bit into that when we talk about how do we audit AI and the risks on that side. But uh, but again powerful tool, a lot of opportunities. But again uh, with those risks that are out there. Um and so the other thing I'd mentioned uh, around risks with AI as we get this are things like bias. Right? So a generative AI algorithm, uh, is basically ah, an algorithm that starts to get populated and over time learns as it goes through and it learns by making mistakes, right. And learns on data that we feed it, right? So um, you can pose it questions. Is this yes or no, right or wrong? Uh, left or right? And so as it learns, um, it creates a pathway. So again think how we learn. Uh, right. Maybe you're learning to draw and you do your first drawing and don't like the, the way the proportions are and you learn from that. Right? So uh, a generative AI algorithm learns in much the same way, right? It's not necessarily absolute right and wrong, but just directionally is it going the way that I would like to go. Um, and so with that we can create bias. So if we have as an example a large data set that talks about people that are hired for business and if we've done a wonderful job and there is no bias historically with uh, uh, men or women or minorities or, or even geolocations or um, uh, first language for the folks that were hired, if we had no bias in the hiring, we've had in the past intentional or unintentional, then it would probably be okay. The challenge though is that there typically is bias in our data sets. So as generative AI learns, it is going to learn the bias that our data sets have inherently in them. Um, so to be able to think through that and understand that before we train our generative AI models, uh, around any topic is going to be a critical aspect. Then there's, there's a whole slew of other risks around generative AI, um, data privacy and security violations. Right. As we think about the data that's used to train our generative AI models and also what data is put into generative AI algorithm after it's been released.
Speaker A: Right.
Speaker B: Can. Did our customers allow us to use generative AI models, ah, to process their information? Yes or no?
Speaker A: Right.
Speaker B: So data privacy and security is significant hallucinations, information we think is accurate and complete, or results of the generative AI, um, uh, response based on a prompt.
Speaker A: Right.
Speaker B: Uh, is it accurate or not? Uh, maybe it's there, maybe it's not. One, uh, thing from an auto perspective I really want to hit on pretty hard on our conversation is the notion of, uh, AI drift, uh, really what happens when you think about generative AI? Its purpose is to learn, to become better. What does that mean from an audit perspective? What that means is that what we ultimately put in production that over time changes.
Speaker A: Right.
Speaker B: Changes for good, perhaps changes in a negative way surely could. Right. So if we have an algorithm that's out there that we've proved and we have comfort that is providing accurate and complete information, potentially it's fraud investigation or fraud, uh, analysis. It could be data analytics as it relates to our financial reporting. Right. So as we think about the results and the fact that they change over time, if we're placing reliance on that without proper monitoring, this AI drift can have a negative impact, uh, of the results and how we're leveraging AI within, within the tool. Um, so, so, so again, as we think about AI, a lot of risks that are new, it's a new way of software technology helping drive our processes. But it's going to be really important to understand those risks and with that come back with a different way of auditing against that.
Speaker A: Wow, okay. That's a lot of information. So that's incredible. So, uh, a couple of things to follow up on that on. If you don't mind, Scott, I wanted to give you kind of a chance to respond to a few recent events that we've kind of seen a lot of desperation about getting AI involved on the one hand, I'm, uh, sure you saw the Newark airport a few weeks back, and honestly, in the days following since, they've been kind of bringing up, hey, we're short on air traffic control, we're running out. I think it even got to the point where they recommended not flying into the Newark airport. Right. I know this has been one of the major areas that they've been focusing on, uh, getting AI in there. And then the. And then last week, I'm sure you saw Google Veo released there, uh, a lot of AI footage that was basically indistinguishable from real people. And they spoke on their own. And it got to that point, you know, it's here and it's coming. And so you're talking about all of these kind of risks that are coming along with it. How do we know the data is secure? Like, how do. How can our, our organizations, how can our, our clients. How can our. How can internal audit departments, how can they all prepare for this and get, get security and make sure that this is handled? Like what, uh, in terms of the actual to do for the, for the companies and for the internal audit departments, where, where do they play into this?
Speaker B: Yeah, it's a great question, and one, one that I have to say that every organization that we've worked with has really, I wouldn't say struggle with, but there's a lot of learning. And so we talked quite a bit about, um, how generative AI, um, has a mind of its own.
Speaker A: Right.
Speaker B: So as it gets out there and learns and morphs and changes over time, it, uh, creates a whole different risk profile from a technology perspective. But even before that, right. How do we consider, uh, what's our overall strategy and approach for leveraging generative AI? And I would just invite, just for a moment, all uses of artificial intelligence. There's this notion of AI is out there, it's reliable, it's dependable, and it sure can be with the proper guardrails. Um, I think as an auditor, as I think about generative AI and all forms of artificial intelligence, um, the question is, when is it reliable and when is it not reliable? Um, or is it reliable within the context, within certain controls around the output of the AI models and algorithms? Uh, question is, how can we be, um, successful in our deployment of AI? And ultimately, I think there absolutely is a step one, and step one is this at an enterprise level, asking ourselves the question, what is our generative AI? And again, more broadly, our artificial intelligence roadmap. What does it look like? Right? What is Our end game. What's our North Star? Where are we going? Is it a small uh, m. Small activity that we're going to have that might have a little bit of impact on our operations? Or are we revamping our entire organization around? And we've seen organizations take both tacks.
Speaker A: Right?
Speaker B: Um, scary enough we were working with a large, uh, a large multinational organization and the President challenged the organization find every opportunity to leverage generative AI to automate to M drive efficiency, to leverage technology to do work, to redeploy people into higher functioning areas. That's an example of um, an organization that's full on, they're taking it all on. Um, so depending on the roadmap for your organization, um, the response is going to be different, right? So if it's a small footprint, if you're putting your toe in the water, you're letting, see how things play out, um, that, that's, that. I think with that then I think you're going to have a different, a different response. As far as the rest of the um, organization around artificial intelligence, what I'm saying, the rest of the organization around AI. Ah, what does that mean? Um, so, so the thought is this generative AI in particular is not like traditional it. We've talked quite a bit about that. But uh, so with the morphing of generative AI results, its uh, activity, um, its reach, right? We have to have a different footprint. So what I would invite as an auditor is this. Go work with your organization, the enterprise. Erase the whiteboard of all the things that, all the different aspects that we might traditionally rely on. The governance model, policies, procedures, controls, expectations, reliability, process. Erase all that and start with what is our roadmap? What does it look like? Uh, from a high level perspective, what's the near term midterm and long term use of generative AI? Okay, now that we know that a little bit or a lot, um, now we have an appreciation for what level of um, reliance we're going to have, uh, for AI. Now the next question is what aspects do we need to have? Well we absolutely need to have governance and that's, that's a great place to start. Governance and nurse management framework, uh, looking at accountability, transparency, searching for bias, security and so on. Um, and then as we look at the next, the long term strategy we need to consider what are the use cases that we're going to have, uh, what train, how are we going to train our algorithms, how are we going to migrate these algorithms to, to production and ultimately how we're going to have ongoing monitoring of the generative AI platforms that are out there. And finally, is the training of our employees. Right. What does acceptable use look like? Right, so if it's in the world of IT and it is managing it, that's one area. The other area is, uh, the citizen developer aspect. Right. If we have people that are in organization outside of it, using it, what does that training look like? What is the awareness, uh, of that? Um, so again, as we think about AI and be successful, it really is starting with that whiteboard, looking at the use cases, looking at what the risks are, and then asking the question, does our existing IT infrastructure and broader enterprise infrastructure and governance policies, procedures and controls, do they or do they not mitigate those risks to appropriate level? And oftentimes there's a significant revamping or an entirely new set of policies, procedures and controls and governance structure that's going to be important to implement.
Speaker A: Yeah, and you mentioned there on the governance side, that was particularly, particularly interesting. So I know the White House released guidance, I think it was a month ago or so, and uh, you know, they, they identified basically a framework for how that you're supposed to implement it. And they also identified areas. I forgot the exact terminology, but it was something like high impact or something like that. Uh, and you know, I know NIST is, is typically the standard from a governance, like from the White House standpoint, I think the prior administration recommended the NIST standards. Are there any other governance organizations that you'd recommend that the people follow, that companies kind of keep an eye on who are really keeping their finger to the pulse and getting an idea of what kind of governance policies a company should have in place?
Speaker B: Yeah, I appreciate you raising the question, John. It's an important one. Um, and again, driving it back to an internal audit perspective is what is the framework, laws and regulations that we should be paying attention to. And what I would share is, is you're absolutely right. So you think about the United States and then a little broader. Right. So right now the US still lacks comprehensive federal AI law. Right. And so the new administration did revoke the Biden AI um, legislation, um, that was in there, um, and President Trump, uh, um, then replaced it with a new order. Uh, it's titled Removing Barriers to American Leadership. And AI really shifts towards deregulation, um, and explicitly prioritizes AI innovation and US competitiveness. And so I think in this push, uh, this is where President Trump is driving AI, which is really maximizing the value, um, uh, of um, the United States, uh, in the global footprint leveraging AI. Um, and to your point, uh, I think he's trying to usurp nist uh and ist, uh in its framework. Um, so what I would share with you is that again in the US we don't have a lot of one. We don't have an overall federal law or regulation that really has chapter and verse. It's not there. As you look to the states, we do have a lot of states with state level action. 45 states have proposed AI related bills in 2024. 31 uh, states and territories have enacted AI laws. Some very, very small and focused.
Speaker A: Uh right.
Speaker B: So Colorado passed the first ah broader AI law requiring high risk AI um, used to be to have reasonable cases care. Right. To prevent bias. So there's things out there. New Hampshire has one around criminalizing uh malicious deep fakes. Tennessee, I love this one. Tennessee has the Ensuring Likeness, Voice and Image Security Act Elvis barring unauthorized AI simulations of a person, likeness and voice. So there are, there are laws out there. Again as auditors it's important for us to know what those laws are. How do they impact our organization that needs to be part of our RCM or our, what is a good look like model.
Speaker A: Right.
Speaker B: RCM is kind of a stretch right now with AI. So um, what's out there to press against? I think the EU has the EU AI act, um and it was the world's first comprehensive AI law released um in mid 2024 uh after uh, intensive uh inner institutional negotiations. It was a pretty significant uh effort um, that they had out there. It's in effect now. It doesn't become uh, fully enforceable until August of 2026. So we've got a two year, years, two year phasing period. So again there are laws, regulations out there. Um, many of them are micro focused. Um, the EU has a pretty broad one. Um, so I think as we think about that whole uh, uh notion of uh, what is going to look like, what do we point to and what do we think about from um a rules based perspective. Not a lot out there. The one thing I would share, the IIA has, it has a very good and re released AI model that you can leverage. Right. It talks about the black box side of IT governance. So check out the IAA look at their AI framework. NIST also has a framework, the NIST AI Risk Framework. But be careful with the a, the one from nist, it's focused primarily on development of AI as it relates to um, internal development within organizations. If you're not using, if you're not Developing it internally. Um, it's a great framework, but it may not be applicable. So again, as you look at what's out there, um, know that there's a lot, but there really isn't a comprehensive go to framework that covers all of it.
Speaker A: I think that we've kind of hit all of the major areas that we wanted to for kind of what it's looking like in the marketplace, what all the, what it looks like to kind of actually have an organization audit their own AI use, what it means to kind of have a governance policy over it. You know, in my ignorance, Scott, is there any, is there any other information that I'm not really asking you about that you want to make sure that, that me and the listeners know?
Speaker B: Um, yeah, John, the thing I'd leave you and the folks that are listening with is this is from internal audit perspective, right? AI is going to be a critical aspect to look at. Uh, what we find internal auditors to be found success with is having a two phased approach on how they audit AI. The first, the first phase and this is going to be done, um, is initial, uh, audit engagement is to look at the governance and also look at the risk management of AI. And we talked quite a bit about that. Right. So in phase one, kind um, of a soft audit, go in and ask a lot of those questions that we've just talked about. What's the governance structure look like? How do we have policies and procedures in place? Are they relevant to generative AI specifically or not? Are the controls in place to monitor, uh, things like, um, AI drift, um, hallucinations, deep fakes.
Speaker A: Right.
Speaker B: Asking all those questions.
Speaker A: Right.
Speaker B: Again, um, phase one, governance and risk management. Phase two comes in six months, year, two years later when we look and we refresh phase one, we look at governance, risk management again. But then we also do a deeper dive on the actual control set.
Speaker A: Right.
Speaker B: So now we're getting to actually looking at AI development, AI release, AI monitoring.
Speaker A: Right.
Speaker B: Um, and so having that two phased approach would be a really successful way to go ago. Um, and so I think from an audit perspective that's, that's what I'd leave from, for auditors, a, uh, really important, um, uh, approach. Um, the other thing I'd leave all of us with is this. And you said at the top, on the top of our, of our podcast, John, you couldn't be more right in my estimation, which is AIs here, it's affecting all of us. It's not a matter of if, it's a matter of when and if. You're not using it, I, uh, guarantee you one of your suppliers, your third parties you rely on heavily, they are.
Speaker A: Right.
Speaker B: So all of us are in this dance. All of us need to be thinking about it. It needs to be in our audit plans.
Speaker A: Right?
Speaker B: Even if it's a just a light risk assessment, we need to be there. Um, so again, John, I appreciate all the questions, and I've really enjoyed our conversation today. Uh, but I think that's. Those are the two topics or the two points I would lead. I would leave us with.
Speaker A: Well, thank you, Scott, for joining us, for sharing your insights, your knowledge, your thoughts, and leaving us with a lot to think about. And thanks to our audience for tuning in for the Risk Advisory podcast. This is the final episode for Internal Audit Awareness Month. Please feel free to check in, um, on the other episodes that we had prior. Evolving Role of Internal audit unpacking the IIA's Vision 2035 report top three critical skills for the IIA profession. The IA profession. Excuse me. And data. Ah, analytics and internal audit. This is all@ah, cbh.com podcasts. As always, please like share and subscribe. Thanks again for listening.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.