For internal audit and assurance professionals. Curated, not algorithmic.

July 2026

zhaomichelle.substack.com ·
AI Model Drift: The Silent Threat to Operational Integrity and Audit Vigilance

AI models, unlike traditional software, are susceptible to 'drift'—a silent degradation of accuracy over time due to changing real-world conditions, even when the underlying code remains untouched. This phenomenon poses significant risks, as models can continue to operate without error messages while generating increasingly incorrect outputs, leading to substantial financial losses and flawed decision-making. Internal audit professionals must recognize that a running AI system is not necessarily a 'right' AI system, necessitating a shift in audit focus from mere operational uptime to continuous monitoring of decision quality and the implementation of robust response mechanisms.

News & Blogs · Global Read more
huggingface.co ·
Hugging Face Discloses AI-Driven Security Incident and Response

Hugging Face recently disclosed a security incident where an autonomous AI agent system intruded into their production infrastructure. The attack exploited vulnerabilities in their data-processing pipeline, leading to unauthorized access to internal datasets and credentials. Hugging Face successfully contained the breach, revoked compromised credentials, and enhanced their security protocols, notably using their own AI for detection and forensic analysis.

News & Blogs · Global Read more
zhaomichelle.substack.com · · Curated 2 weeks ago
Navigating AI Deployment: Technical Risks and Audit Considerations for Live Systems

This article highlights critical technical risks that emerge when AI models transition from controlled development to real-world deployment. For internal audit and assurance professionals, understanding these risks—such as training-serving skew, lack of human oversight, unchecked generative AI outputs, and adversarial inputs—is crucial for evaluating the robustness of AI systems and ensuring organizational accountability. The Air Canada chatbot case serves as a stark reminder that organizations are fully responsible for their AI's actions, underscoring the need for robust controls and clear accountability frameworks in AI deployment.

News & Blogs · Global Read more
zhaomichelle.substack.com · · Curated 2 weeks ago
AI Deployment: The Critical Gap in Governance – Why Existing Controls Are Being Bypassed

This article highlights a critical oversight in AI deployment: the frequent bypass of established IT governance frameworks. Internal auditors must recognize that AI models, despite their advanced nature, are still production changes requiring the same rigorous change management, authorization, and ownership protocols as any other software. Failure to apply these existing controls creates significant, avoidable risks, as demonstrated by real-world incidents where AI systems operated without proper oversight or accountability.

News & Blogs · Global Read more
securityaffairs.com ·
EY Investigates Data Breach from Compromised Third-Party Support System

Ernst & Young (EY) has launched an investigation into a data breach stemming from a compromised third-party IT support system. The breach, which occurred between March 28 and April 12, 2026, involved an unauthorized party accessing and downloading client documents, potentially containing sensitive tax information. EY has secured its systems, notified federal authorities, and is offering identity monitoring services to affected clients.

News & Blogs · Global Read more
alexandracar.substack.com · · Curated 3 weeks ago
Navigating the US Tech Stack Trap: Auditing AI Vendors in a Patchwork Compliance Environment

The US AI regulatory landscape presents a significant challenge for organizations procuring AI systems. While federal policy encourages innovation with light regulation, individual states are rapidly enacting diverse and stringent AI-related laws. This creates a complex compliance environment where traditional software procurement due diligence is insufficient, and organizations deploying AI systems can inherit substantial legal and reputational risks from their vendors' AI development practices.

News & Blogs · North America Read more
alexandracar.substack.com · · Curated 3 weeks ago
The Global AI Accord: An Independent Call for Binding AI Governance

This article introduces "The Global AI Accord," an independently developed proposal for international AI governance, modeled after the Montreal Protocol. For audit and assurance professionals, this highlights the growing imperative for structured, global frameworks to manage AI risks and ensure responsible development. Understanding such initiatives is crucial for anticipating future regulatory landscapes and embedding robust AI governance within organizational assurance programs.

News & Blogs · Global Read more
alexandracar.substack.com · · Curated 3 weeks ago
Voluntary AI Frameworks: A Litigation Trap for Unwary Organizations

Internal audit and assurance professionals must recognize that seemingly 'voluntary' AI frameworks, like the NIST AI Risk Management Framework (RMF), are rapidly evolving into de facto legal standards of care in U.S. courtrooms. Organizations failing to demonstrate alignment with these frameworks risk significant legal exposure in negligence cases, even as federal guidance shifts. This creates a critical need for robust AI governance and demonstrable compliance, especially given the divergence between federal and state-level expectations regarding AI ethics and impact.

News & Blogs · North America Read more
normanmarks.wordpress.com · · Curated 3 weeks ago
IIA's New ERM Position Paper: A Critical Review for Internal Audit Professionals

The IIA has released a new "Statement of Position" on internal audit's role in Enterprise Risk Management (ERM), replacing a long-standing guidance document. This article critically examines the new paper, highlighting its strengths, weaknesses, and implications for internal auditors navigating their responsibilities in ERM. It's crucial for audit professionals to understand these evolving guidelines to ensure their ERM assurance and advisory services remain independent, objective, and effective.

News & Blogs · Global Read more
optro.ai ·
Internal Audit Talent Strategies for the AI Age: Preserving the Human Edge

Internal audit is undergoing a significant transformation driven by AI, necessitating a re-evaluation of talent strategies. This article emphasizes the importance of strengthening uniquely human skills while developing expertise in AI, analytics, and IT audit. It outlines how AI will automate many traditional audit tasks, freeing up internal auditors to focus on more strategic, advisory roles.

News & Blogs · Global Read more
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →