Internal Audit's 'Independence' is a Proxy: AI Demands a Shift to Provable Objectivity
This article argues that internal audit's traditional concept of "independence" is an outdated proxy for provable objectivity, a weakness exposed by the rise of AI. It highlights how the IIA's own recent guidance implicitly acknowledges this by defining independence along a continuum and decomposing it into specific elements. For audit and assurance professionals, this is a critical call to action to move beyond a borrowed, ill-fitting term and instead build a robust, evidence-based governance architecture that ensures and demonstrates the trustworthiness of audit conclusions, especially as AI increasingly integrates into audit processes.
The Evolving Definition of Independence in Internal Audit
The article critically examines the long-standing use of the term "independence" within internal audit, asserting that it has always been a proxy for what the profession truly seeks: provable objectivity. The author contends that internal auditors, by their very nature as employees, cannot be independent in the same structural sense as external auditors. The advent of artificial intelligence in audit functions further highlights this conceptual gap, as questions about an AI agent's trustworthiness naturally gravitate towards its programming, controls, and data integrity, rather than its "independence." This shift in focus reveals that the core concerns have always been about the reliability and unbiased nature of the audit work, regardless of whether it's performed by a human or a machine.
The Global Internal Audit Standards define independence as freedom from conditions that impair unbiased work, focusing on reporting lines, access, and positioning. However, this definition contrasts sharply with the structural independence demanded of external auditors, which involves legal and economic separation. The article points out that the IIA's more recent guidance, such as the Three Lines Model, implicitly acknowledges this distinction by describing independence along a continuum and breaking it down into essential elements like reporting lines, autonomy, and access. This decomposition, along with the introduction of "cooling-off periods" for advisory work, suggests a move towards managing objectivity through specific conditions rather than relying on a binary concept of independence.
Building a New Architecture for Objective Assurance
The author argues that the gap between the technical definition of independence and its common connotation is not harmless. It allows the profession to claim credibility without specifying the underlying mechanisms that ensure it, and it hinders the development of a more robust, evidence-based assurance framework. The current reliance on "independence" can also create contradictions, particularly as internal audit increasingly embraces advisory roles. The article suggests that instead of defending a borrowed term, the profession should focus on demonstrating the trustworthiness of an embedded, collaborative function through transparent and verifiable mechanisms.
To address these challenges, the article proposes a new governance architecture for objective assurance, emphasizing evidentiary requirements over structural conditions. This architecture would include:
- Mandate integrity: Ensuring that scope changes are recorded and attributable to named individuals.
- Evidence immutability: Implementing write-once workpapers with appended, traceable alterations.
- Finding traceability: Documenting the complete path of every finding from draft to final report, including modifications and rationales.
- Reasoning transparency: Recording the basis for all judgments, human or machine, in sufficient detail for re-examination.
- Reproducibility: Ensuring that a second competent party can reach the same conclusion given the same evidence and criteria.
- Attributable authorship: Clearly identifying who or what produced each finding, along with relevant details about their competence or configuration.
This shift would make audit conformance falsifiable, allow for the measurement of finding suppression, enable audit committees to ask more effective questions, and provide a framework for assessing machine-assisted work. Ultimately, it would protect the profession from criticism by replacing a vague, borrowed term with a demonstrable, transparent, and robust system for ensuring objective assurance in the age of AI.
Read more