News & Blogs

AI Governance: Learning from Cyber's Evolution to Avoid Past Mistakes

Global · · normanmarks.wordpress.com

This article highlights the critical need for robust AI governance, drawing parallels with the evolution of cybersecurity governance. It emphasizes that internal audit and assurance professionals must understand the maturity of their organization's AI governance, provide assurance and advice, and ensure that AI deployment considers all risks and opportunities. The core message is to proactively apply lessons from cyber risk management to AI, translating technical risks into business impacts that leadership can act upon, thereby avoiding a repeat of past governance failures.


The Urgent Need for Proactive AI Governance

The rapid proliferation of Artificial Intelligence (AI) across organizations presents both immense opportunities and significant risks. This article, featuring insights from Yakir Golan of Kovrr, argues that organizations must learn from the evolution of cybersecurity governance to establish effective AI governance frameworks. Historically, cyber risk was initially relegated to technical teams, far removed from board-level discussions. It took years of costly incidents and increasing regulatory pressure for cyber risk to be recognized as a material business risk requiring strategic oversight. AI, however, is being adopted at an unprecedented pace, leaving a much shorter window to implement robust governance structures. Internal audit and assurance professionals are uniquely positioned to guide their organizations in this critical area, ensuring that AI risks are identified, assessed, and managed proactively.

Avoiding the Pitfalls of Past Cyber Governance

The article points out that many organizations are making the same mistakes with AI governance that hindered early cybersecurity efforts. Responsibility for AI governance is often fragmented across data science teams and individual business units, leading to a lack of a holistic view of AI operations and accountability. Furthermore, a communication gap persists, with technical teams speaking in specialized jargon while boards require information translated into business impact and financial terms. This disconnect prevents effective strategic decision-making and risk prioritization. For internal auditors, this highlights the importance of fostering a common language around AI risk, translating technical vulnerabilities into quantifiable business consequences that resonate with leadership. Without this, AI exposure remains abstract, making it impossible for boards to weigh and prioritize threats effectively.

Establishing a Defensible AI Governance Baseline

To build resilient AI governance, the article advocates for applying core disciplines matured within cybersecurity. The foundational step is establishing comprehensive AI asset visibility, creating a definitive inventory of all AI applications, including sanctioned and 'shadow AI' instances. Following this, targeted control assessments should pinpoint underlying vulnerabilities. Crucially, these findings must be translated into loss scenario modeling, quantifying potential operational and financial impacts. Approaches like AI Risk Quantification (AIRQ) are vital for systematically translating technical risks into terms that leadership can understand and act upon, enabling strategic prioritization of remediation efforts and efficient allocation of resources. Internal audit can play a pivotal role in validating these processes and ensuring their effectiveness.

The Opportunity for a Faster Path to Maturity

Unlike cybersecurity, which endured a decade of painful lessons to reach its current governance maturity, AI has the advantage of a proven precedent. The history of cyber governance demonstrates that technical risks inevitably impact the balance sheet and cannot be managed in isolation. Organizations that recognized this pattern early in cyber's evolution were better prepared. The key differentiator was the ability to identify where risk resided and communicate its implications in actionable terms to leadership. AI governance demands the same combination: visibility to understand where AI risk lives, and financial translation to articulate its significance. Internal audit and assurance professionals have a unique opportunity to leverage these lessons, guiding their organizations to establish robust AI governance frameworks without repeating the protracted and costly learning curve experienced with cybersecurity.


Read more
Comments

No comments yet. Be the first.


Sign in to join the discussion.

Sign in or Create account
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →