One in four executives say internal audits have caught AI-generated errors that reached external audiences or board members. Only 11% say their organisation's data quality is good enough for AI use. Both come from Workiva's 2026 midyear benchmark, which surveyed 2,272 finance, risk and sustainability professionals, including 847 C-level executives.
Put the two together. Machine-produced numbers are flowing into the most consequential communications an organisation makes, on data it does not itself trust. The errors have started arriving.
The demand is outrunning the capacity
Internal audit has seen this movie before, with cybersecurity. Gartner's 2026 audit planning research, surveying 160 heads of internal audit, found 96% planning to provide assurance over cyber risk, while only 48% expressed high confidence they could deliver it. Cyber took a decade to become a universal audit plan item.
AI is starting the same journey with less runway. A board that has watched an AI error reach it will ask who is checking these outputs. The chair does not care that the methods are young.
Sampling cannot cover it
The deeper problem is method, not headcount. Internal audit's core instrument is the periodic sample. Pick a quarter, pull 25 items, examine them, conclude. Against AI systems that fails three ways at once.
The volume is wrong. A model producing thousands of outputs a day makes a quarterly look at a few dozen decorative.
The target moves. A model that was accurate in March can be quietly wrong by June, so a point-in-time conclusion expires faster than the audit cycle.
And the paper trail is missing. To audit an output you need to know which version of which model produced it, on what data, approved by whom. In most organisations that record does not exist.
You cannot sample your way to confidence in a system that never stops producing.
What auditable AI requires
The requirements are infrastructure, not heroics.
- A standing record for every model. Which version is running, who owns it, what it was trained on, how it performed before launch including the predictions it got wrong, and who approved it. A Model Passport holds exactly this, and turns audit's first three questions into lookups.
- Continuous checking of every output. Each output is scored against what actually happened, so a model whose stated odds stop matching reality is caught when it drifts, not at year-end. Audit then verifies that the watching works, instead of re-performing it quarterly.
- Numbers that can be recomputed. An output that cannot be regenerated from its inputs cannot be audited at all. Same inputs, same number, every time.
The committee question is coming either way. The function that arrives with a working answer gets the trusted-advisor conversation the profession keeps saying it wants. The one with a sampling plan gets the other conversation.
Continuous output checking, a passport per model and numbers that recompute identically are what the Prophesee Compliance Suite provides, built into how the platform runs rather than bolted on. Make the AI estate auditable.