Workflow · August 12, 2026
Turn a Gartner Audit AI Gap Into a 90-Day Adoption Roadmap
The task
You're a consultant scoping a Chief Audit Executive (CAE) engagement. The client has AI tools scattered across their internal audit team — some in risk assessment, some in workpaper review — but no strategy tying it together. You need to turn a messy inventory into a defensible 90-day roadmap with governance guardrails, ideally before Friday's steering committee.
Before AI
Normally this is a two-week discovery: interviews, a use-case matrix in Excel, a maturity model borrowed from a prior deck, and a governance section your Risk & Compliance colleague drafts separately. Deliverable lands in ~40–60 billable hours across two consultants.
The Gartner data makes this timelier. 93% of audit leaders report some level of AI use, but only 38% have an AI strategy — meaning most CAEs you meet will need exactly this artifact. Gartner's own analysts note CAEs are prioritizing areas they lack confidence to address, and will need an effective strategy and bold leadership to drive real change.
The workflow
The idea: paste the audit team's raw AI inventory into the first prompt. Each subsequent step sharpens it into a client-ready roadmap.
Step 1 — Diagnose the gap and cluster use cases
You are a senior consultant advising a Chief Audit Executive. Below is a raw inventory of AI use cases currently in play across an internal audit function, plus context about the team. Do three things: 1. **Maturity diagnosis.** Score the function on a 1–5 scale against these dimensions: Strategy & Governance, Data Readiness, Use Case Portfolio, Talent & Skills, Risk & Controls over AI itself. One sentence of evidence per score, drawn only from what's in the input. 2. **Use case clustering.** Group the listed use cases into four buckets: (a) High-value, low-risk — scale now; (b) High-value, high-risk — govern first; (c) Low-value experiments — sunset or consolidate; (d) Gaps — obvious audit activities where AI is missing. Explain the placement in one line each. 3. **Top three risks.** Name the three most material risks this specific portfolio creates for the audit function (independence, model risk, evidence quality, shadow AI, etc.). Be specific to the inventory, not generic. Output as markdown with clear H3 sections. No preamble. INPUT:
Client: Meridian Federal Credit Union (fictional), ~$4.2B assets, 18-person internal audit team. CAE: "Dana Ortiz" — 2 years in role, board wants an AI position paper by Q1. Current AI use cases (self-reported by audit managers): - IT Audit team uses GitHub Copilot for scripting ACL/IDEA data extractions. Informal. - Two seniors use ChatGPT Plus (personal accounts) to summarize regulatory updates from NCUA and CFPB. No logging. - Vendor tool "AuditBoard AI" pilot on issue-tracking narrative generation — 6 months in, 40% of issues use it. - One manager built a Power Automate + Azure OpenAI flow that drafts PBC (prepared-by-client) request lists from prior-year workpapers. Not reviewed by IT. - Continuous auditing platform (fictional vendor "LedgerLens") flags anomalies in GL journals — in production 14 months, tuned quarterly. - QA reviewer uses Claude to compare workpaper conclusions against audit program steps. Ad hoc, ~5 audits so far. - No AI use in: fraud investigations, SOX-equivalent testing, board reporting, model validation of the credit union's own AI/ML credit models. Constraints: - Regulated by NCUA; examiners asked about AI governance in last exam. - No dedicated data scientist on the audit team. - Budget: ~$180K unallocated for FY26 audit tech. - IIA Global Internal Audit Standards (2024) apply.
Step 2 — Build the 90-day roadmap
Using the diagnosis and clustering you just produced, build a 90-day adoption roadmap for this audit function. Structure it as three 30-day phases: - **Days 1–30: Contain and inventory.** Actions that stop shadow AI, formalize what's already working, and produce a defensible inventory. Name the artifact each action produces (e.g., "AI use-case register v1"). - **Days 31–60: Govern and pilot.** Governance mechanisms (approval workflow, model risk tiering aligned to the function's risk appetite, human-in-the-loop rules for audit evidence). Pick ONE use case from bucket (b) to formally pilot with guardrails, and ONE from bucket (d) — the gaps — to scope. - **Days 61–90: Scale and measure.** What moves to production, what KPIs prove value (hours saved, cycle time, issue-quality scores), and what goes to the audit committee. For each phase, output a table with columns: Action | Owner (role, not name) | Artifact | Success signal. Keep to 4–6 rows per phase. End with a one-paragraph "What we deliberately are NOT doing in 90 days and why" — anti-scope. Reference the IIA Global Internal Audit Standards where relevant.
Step 3 — Governance guardrails and CAE talking points
Now produce two final artifacts the CAE can take to the audit committee. **Artifact A: AI-in-Audit Governance Guardrails (one page).** Cover: - Permitted vs. prohibited uses (be specific — e.g., can AI draft an audit opinion? summarize interview notes? generate test scripts?) - Human-in-the-loop requirements by evidence tier (persuasive vs. corroborative) - Independence considerations when the audit function uses the same AI vendor as first/second line - Logging, retention, and reperformance expectations so an external examiner or peer reviewer can trace AI-assisted judgments - Escalation triggers (when a use case needs re-approval) Format as a clean bulleted one-pager. No filler. **Artifact B: CAE audit-committee talking points (5 bullets max).** Each bullet: a claim the CAE can defend, framed for a board audience. Include one bullet that honestly names a limitation or open question — do not oversell. Tone: measured, regulator-aware, not vendor-flavored.
Gotchas
- Anchoring on the inventory. The model will only be as good as what you paste in. If the CAE's inventory is incomplete (and it usually is — shadow AI is the whole point of the Gartner finding), Step 1's "Gaps" bucket will miss things. Run a 20-minute interview with two audit managers before Step 1.
- Regulatory nuance. The prompts don't know your client's specific regulator. For NCUA, OCC, PRA, APRA, MAS clients, hand-edit the guardrails section — LLMs will confidently misstate examination expectations.
- IIA Standards citations. The model may reference the 2024 Standards but occasionally hallucinates domain/principle numbers. Cross-check any specific Standard reference before it goes in a deck.
- Model risk vs. audit-of-AI conflation. These are different problems. Governance of AI used by audit ≠ audit of the enterprise's AI. The prompts stay on the former; if the client wants the latter, that's a separate engagement.
- Vendor neutrality. If your firm has a partnership, the roadmap may need adjusting — the model tends to recommend consolidation onto one platform, which isn't always the right answer.
Time saved
Manual baseline for a scoping deliverable of this shape: 40–60 hours across two consultants. Running these three prompts with a real inventory and 60–90 minutes of consultant editing gets you a defensible v1 in roughly one working day — call it ~6 hours saved per engagement, conservatively, before partner review. The value isn't just speed; it's that only 38% have an AI strategy, so most CAE conversations start from zero and this gives you a credible artifact to react to instead of a blank page.
What we got when we ran it
We executed every prompt above, in order, against the sample input (model: claude-sonnet-4-6). Outputs below are real and unedited apart from length truncation.
Step 1 output
Maturity Diagnosis | Dimension | Score (1–5) | Evidence | |---|---|---| | Strategy & Governance | 2 | No AI policy, framework, or position paper exists yet — the board-requested Q1 deliverable is still pending and current use is entirely self-directed by managers and seniors. | | Data Readiness | 3 | LedgerLens is in production and tuned quarterly against GL data, indicating some structured data pipelines exist, but no data scientist sits on the team and PBC automation pulls from prior-year workpapers without IT review, signaling uncontrolled data handling elsewhere. | | Use Case Portfolio | 3 | The function spans six distinct use cases across IT, continuous auditing, QA, and narrative generation — reasonable breadth for an 18-person shop — but coverage is accidental rather than planned, with material blind spots in fraud, SOX-equivalent, and model risk. | | Talent & Skills | 2 | Individual contributors are self-initiating AI tools (GitHub Copilot, ChatGPT Plus on personal accounts, Claude ad hoc), which shows motivated staff but no team-wide upskilling program, AI literacy baseline, or technical oversight capacity. | | Risk & Controls over AI Itself | 1 | The personal-account ChatGPT usage has no logging, the Azure OpenAI flow bypassed IT, and the QA use of Claude is entirely ad hoc — no use case has documented controls, model documentation, or output-validation procedures on record. | --- ### Use Case Clustering #### (a) High-Value, Low-Risk — Scale Now - LedgerLens GL anomaly detection — 14 months in
…output truncated at 250 words.
Step 2 output
Days 1–30: Contain and Inventory | Action | Owner | Artifact | Success Signal | |---|---|---|---| | Issue a CAE-signed interim AI use directive: no new AI tools on personal accounts, all existing use continues under temporary exemption pending registration; invoke IIA Standard 1.1 (organizational independence requires the CAE to set the conditions under which the function operates) | CAE | Interim AI Use Directive v1 | Zero new unregistered tools appear in weeks 2–4; existing users acknowledge receipt in writing | | Conduct structured interviews with all six known AI users (IT Audit team, two seniors, PBC flow manager, AuditBoard pilot users, QA reviewer) using a standard intake template covering: tool name, data inputs, output use, any human review step, access credentials | Audit Manager (Operations) | AI Use-Case Register v1 (six entries minimum, one row per use case with risk-tier field blank for now) | All six use cases documented with enough detail to assess data residency and output reliance within 15 business days | | Escalate the Azure OpenAI PBC flow to IT Security for retroactive review; freeze the flow from accepting new workpaper inputs until reviewed; document the escalation formally | CAE + IT Audit Senior | IT Escalation Memo + Flow Freeze Confirmation | IT Security acknowledges receipt and schedules review within 10 business days; flow inputs locked | | Migrate the two seniors off personal ChatGPT Plus accounts to a credit-union-licensed, logged alternative (Microsoft Copilot via existing M365 licensing is the lowest-friction option
…output truncated at 250 words.
Step 3 output
Artifact A: AI-in-Audit Governance Guardrails Meridian Federal Credit Union — Internal Audit Function Effective: [Date] | Owner: Chief Audit Executive | Review cycle: Annual or upon material change --- Permitted Uses - Drafting issue narratives, PBC request lists, and audit report language — permitted; all drafts require auditor review and attestation before workpaper finalization - Summarizing regulatory guidance (NCUA, CFPB) — permitted; source document must be cited alongside AI summary; auditor confirms accuracy against original text - Generating data extraction scripts (ACL, IDEA, SQL) — permitted; script must be reviewed and tested by the issuing auditor before execution against live data - Flagging GL journal anomalies for auditor follow-up — permitted as a risk-indicator input; flags are corroborative only and do not constitute a finding without independent auditor validation - Comparing workpaper conclusions to audit program steps for QA purposes — permitted under the documented Claude QA protocol; every flag requires a recorded human disposition Prohibited Uses - AI may not issue, finalize, or sign an audit opinion or formal conclusion — the auditor of record must author the judgment in their own words with documented basis - AI may not serve as the sole basis for a control-deficiency, fraud indicator, or material finding — prohibited regardless of model confidence score - AI may not process personally identifiable information (PII), member account data, or nonpublic examination material unless the tool has been approved for that data classification by IT Security and Legal - Personal-account AI tools (ChatGPT, Claude, Gemini,
…output truncated at 250 words.
Source: news.google.com
More for Consulting & Enterprise professionals →
Get the next one in your inbox