[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"article-body-the-verification-gap":3},"\nOne in four executives say internal audits have caught AI-generated\nerrors that reached external audiences or board members. Only 11%\nsay their organisation's data quality is good enough for AI use.\nBoth come from\n[Workiva's 2026 midyear benchmark](https://www.workiva.com/resources/executive-benchmark-survey-verification-gap),\nwhich surveyed 2,272 finance, risk and sustainability\nprofessionals, including 847 C-level executives.\n\nPut the two together. Machine-produced numbers are flowing into the\nmost consequential communications an organisation makes, on data it\ndoes not itself trust. The errors have started arriving.\n\n## The demand is outrunning the capacity\n\nInternal audit has seen this movie before, with cybersecurity.\n[Gartner's 2026 audit planning research](https://www.gartner.com/en/newsroom/press-releases/2025-11-13-gartner-says-internal-auditors-to-focus-on-cybersecurity-data-governence-and-regulatory-compliance-in-2026-2),\nsurveying 160 heads of internal audit, found 96% planning to provide\nassurance over cyber risk, while only 48% expressed high confidence\nthey could deliver it. Cyber took a decade to become a universal\naudit plan item.\n\nAI is starting the same journey with less runway. A board that has\nwatched an AI error reach it will ask who is checking these outputs.\nThe chair does not care that the methods are young.\n\n## Sampling cannot cover it\n\nThe deeper problem is method, not headcount. Internal audit's core\ninstrument is the periodic sample. Pick a quarter, pull 25 items,\nexamine them, conclude. Against AI systems that fails three ways at\nonce.\n\nThe volume is wrong. A model producing thousands of outputs a day\nmakes a quarterly look at a few dozen decorative.\n\nThe target moves. A model that was accurate in March can be quietly\nwrong by June, so a point-in-time conclusion expires faster than the\naudit cycle.\n\nAnd the paper trail is missing. To audit an output you need to know\nwhich version of which model produced it, on what data, approved by\nwhom. In most organisations that record does not exist.\n\nYou cannot sample your way to confidence in a system that never\nstops producing.\n\n## What auditable AI requires\n\nThe requirements are infrastructure, not heroics.\n\n1. **A standing record for every model.** Which version is running,\n   who owns it, what it was trained on, how it performed before\n   launch including the predictions it got wrong, and who approved\n   it. A [Model Passport](/insights/the-model-passport) holds\n   exactly this, and turns audit's first three questions into\n   lookups.\n2. **Continuous checking of every output.** Each output is scored\n   against what actually happened, so a model whose stated odds stop\n   matching reality is caught when it drifts, not at year-end. Audit\n   then verifies that the watching works, instead of re-performing\n   it quarterly.\n3. **Numbers that can be recomputed.** An output that cannot be\n   regenerated from its inputs cannot be audited at all. Same\n   inputs, same number, every time.\n\nThe committee question is coming either way. The function that\narrives with a working answer gets the trusted-advisor conversation\nthe profession keeps saying it wants. The one with a sampling plan\ngets the other conversation.\n\nContinuous output checking, a passport per model and numbers that\nrecompute identically are what\n[the Prophesee Compliance Suite](/solutions/compliance/audit)\nprovides, built into how the platform runs rather than bolted on.\n[Make the AI estate auditable](/contact).\n",1786984937868]