Boardrooms get AI-savvy as internal audit steps into the spotlight

The gist
AI governance has leapt from tech jargon to boardroom must-have, with internal audit now steering the enterprise risk conversation.
What to know
- By late 2025, AI governance skills became foundational for all employees, fostering a culture of informed skepticism and vigilance across organizations.
- Boards and CFOs transformed their approach by early 2026, demanding active AI risk management, transparency, and fluency—while audit committees raced to embed AI control frameworks.
- In June 2026, Stacey Schabel took the helm at the Institute of Internal Auditors, driving a strategic shift toward proactive, AI-savvy audit teams and crystal-clear board communication.
AI Governance Becomes Second Nature
AI governance skills now function as an organizational reflex, with success measured by how quickly and confidently teams can review and launch new AI use cases.
By late 2025, AI governance skills had become foundational across all organizational roles, reflecting the pervasive integration of AI into nearly every digital process. This baseline competency, likened to the intuitive judgment people develop to recognize phishing attempts, equips employees with the ability to sense when AI-driven outputs or initiatives feel off, fostering a culture of vigilance and informed skepticism. Such skills are no longer niche but essential, underscoring AI governance as a critical organizational capability.
Success in AI governance is increasingly quantified by the volume and velocity of AI use case deployments, with organizations tracking how quickly they can review and launch AI initiatives as a key performance indicator. A decreasing review-to-launch timeline signals not only streamlined governance processes but also robust collaboration between governance teams and business units, enabling confident scaling of AI applications. This metric-driven approach highlights the maturation of AI governance from a cautious oversight function to an enabler of agile innovation.
Boards Demand AI Accountability
Directors now require explainable, auditable AI decisions and are personally accountable for AI risks, making empathy and curiosity essential boardroom skills.
By early 2026, boards have undergone a profound transformation in their approach to AI governance, moving from passive oversight to demanding active, transparent management of AI-driven risks. This shift is underscored by calls for clear accountability and data integrity, with boards no longer willing to wait for perfect information before establishing governance structures, as emphasized in the May 2026 analysis urging senior, cross-functional committees with real authority—including Chief AI Officers and CISOs—to maintain a living, adaptive framework that regularly updates the board on AI scope, inventory, and policy coverage.
This evolution in boardroom expectations extends fiduciary duties to encompass AI governance, where directors are personally accountable for ensuring AI decisions are explainable, auditable, and grounded in trusted data. Dr. Chong Yukin highlights that while coding expertise is unnecessary, sufficient AI fluency is critical for directors to ask probing questions management might miss, and that trust and curiosity are foundational governance elements—not mere soft skills—without which AI frameworks falter. Empathy also emerges as a vital human element, enabling boards to balance confidence with compliance and to navigate the absence of formal AI governance rulebooks.
The contemporary boardroom demands rigorous transparency and frequent updates on AI governance, driven by heightened market volatility and risk awareness. Directors seek to 'peek under the hood' of decision-making processes to ensure comprehensive risk management without micromanagement, balancing accountability with strategic oversight. Baroness Dambisa Moyo encapsulates this mindset by emphasizing the necessity of balancing risk-taking with long-term sustainability, urging boards to set clear risk appetites and engage deeply with management on AI-driven strategies to position companies for resilience amid unpredictable market dynamics.
Successful AI governance in the boardroom hinges on cultivating strong trust between directors and management, which facilitates adaptability and continuous skill development in this rapidly evolving domain. As one interview noted, continuous AI monitoring disrupts traditional sampling-based controls, rendering old manual processes obsolete and demanding a governance approach that is both dynamic and outcome-focused. Leadership must prioritize AI governance as a business imperative by ensuring unambiguous ownership at all levels and maintaining a regular cadence of committee meetings that focus on business outcomes rather than technology features alone.
CFOs and Committees Take the Lead
CFOs and audit committees now drive AI risk frameworks and disclosure standards, cementing AI oversight as a core pillar of enterprise governance.
By early 2026, CFOs have emerged as pivotal figures in steering AI initiatives through the delicate balance of innovation and governance, leveraging their financial acumen and strategic foresight to avoid the pitfalls of overgoverning or undergoverning AI projects. As one analysis highlights, CFOs 'know how much everything costs... know who is hiring for what role... typically have a lot of discipline... know how to measure things and how to prioritize,' enabling them to plan beyond short-term savings towards sustainable AI integration over the next two to five years. Concurrently, CFOs are increasingly tasked with preparing for AI-related disclosure risks, especially for publicly traded companies where investors demand transparency about AI usage and its implications, underscoring a new dimension of financial leadership in AI governance.
Audit committees are rapidly evolving to incorporate AI oversight into their governance remit, mirroring the trajectory cybersecurity audits followed a few years prior. Industry voices predict that within 12 to 18 months, organizations will establish formal AI control frameworks and assurance processes, with AI governance becoming as routine as financial and cybersecurity controls. This evolution reflects a broader strategic shift where AI is no longer a mere technical concern but a board-level issue impacting enterprise risk, capital allocation, and competitiveness, as Akin Adekeye articulates: 'AI crosses into governance when it impacts risk, capital allocation, and competitiveness.'
The central role of CFOs and audit committees in AI governance is underscored by their responsibility to design structured AI risk frameworks that balance innovation with risk mitigation, ensuring organizations remain competitive without exposing themselves to harm. Adekeye emphasizes that effective governance demands 'board involvement, executive ownership, and clear operating controls,' with CFOs acting as linchpins in this process. Looking ahead, AI governance is expected to standardize, with rising expectations for board literacy, formal control frameworks, and disclosure becoming integral to standard governance practices, signaling a maturation of AI oversight within enterprise risk management.
Legal and finance leaders, notably CFOs and General Counsels, are indispensable in translating AI’s complex technical capabilities into actionable insights on risk, compliance, and strategic decision-making for boards. This bridging role ensures that boards grasp AI’s multifaceted implications beyond the technical sphere, facilitating informed governance. As highlighted in a special episode on AI governance, these leaders help demystify AI for boards, enabling a governance framework that is both robust and strategically aligned with enterprise objectives.
Internal Audit’s Strategic Reinvention
With new leadership, internal audit is shifting from compliance watchdog to strategic advisor, prioritizing emerging risks like AI and cyber alongside traditional assurance.
In June 2026, Stacey Schabel was appointed as the Global Board Chair of the Institute of Internal Auditors (IIA) for the 2026-2027 term, succeeding Stefano Comotti and signaling a strategic leadership shift focused on evolving internal audit’s role. Her 'Risk Focused. Future Ready.' platform positions internal audit as a strategic advisor that not only addresses traditional assurance but also proactively navigates emerging risks such as AI, cybersecurity, and geopolitical uncertainty. This vision underscores the profession’s transition from a backward-looking function to one that provides strategic insight and foresight, aligning audit priorities with the rapidly changing and interconnected risk landscape driven by technology and global disruption.
Under Schabel’s leadership, the IIA is advancing internal audit through a multifaceted approach that includes integrated assurance, stronger governance frameworks, and robust advocacy efforts. A notable initiative is the launch of a new Governance, Risk, and Compliance (GRC) Council designed to help members navigate complex emerging challenges and deliver practical tools. This structural evolution aims to bridge the widening gap between where risk currently resides—especially in AI, cyber, and operational resilience—and traditional audit focus, demanding updated skills, methodologies, and mindsets to maintain relevance and deliver value to organizations.
Talent development and future leadership cultivation are central to Schabel’s strategic priorities, reflecting her passion for mentoring and preparing internal audit professionals to thrive in a complex risk environment. She emphasizes enhancing auditors’ confidence and recognition as strategic partners capable of addressing emerging risks, supported by expanded AI and digital readiness training offered by the IIA. By inspiring mid-career and emerging professionals to appreciate the value and career opportunities within internal audit, Schabel aims to secure a pipeline of future-ready leaders equipped to sustain the profession’s evolution.
Clear Communication Powers Audit Impact
Internal auditors are mastering concise, accessible messaging—often powered by AI—to ensure boards grasp complex risks and the evolving audit role.
By mid-2026, internal audit functions are recognizing that mastering communication is as critical as technical expertise, especially when engaging boards with limited time and diverse backgrounds. As highlighted in the June 8 insights, auditors are increasingly leveraging AI tools to distill complex findings into clear, impactful narratives—sometimes rephrasing content to the level of a fifth grader—to ensure messages resonate and foster understanding. This strategic simplification, coupled with rigorous internal training to guarantee clarity at all staff levels, addresses the common frustration among board members who often find audit discussions overly technical and inaccessible.
The evolving risk landscape, shaped by rapid technological advances, AI proliferation, cyber threats, and geopolitical volatility, demands that internal audit not only keep pace but also anticipate future challenges. As Stacey Schabel, the IIA’s Global Chair in June 2026, emphasizes, internal auditors must transition from traditional backward-looking assurance roles to strategic partners offering foresight and insight. This evolution requires embracing AI readiness, adopting new methodologies, and cultivating skills that align audit functions with emerging risks such as operational resilience and third-party vulnerabilities, thereby closing the widening gap between where risk resides and where audit traditionally focuses.
Talent development and mentorship have emerged as cornerstone priorities for building a future-ready internal audit profession. The IIA’s initiatives like Vision University underscore the importance of nurturing mid-career professionals and newcomers alike, inspiring them to appreciate the strategic value and career potential within internal audit. Schabel’s leadership vision, articulated in late June 2026, stresses that fostering confidence in addressing emerging risks and strengthening integrated assurance frameworks will empower internal auditors to become influential strategic partners, thereby sustaining enterprise resilience amid complex governance and compliance challenges.
Effective governance and integrated assurance models are pivotal to sustaining enterprise resilience in an AI-driven risk environment. The IIA’s forthcoming 2027 strategic plan, as announced by Schabel, places risk front and center, supported by a new GRC Council designed to guide members through evolving governance, risk, and compliance complexities. This structural evolution, combined with advancing AI readiness and strengthening trust and credibility through clear communication, equips internal audit to build influence and navigate the increasingly intricate risk terrain with confidence and strategic foresight.





