Jul 23 / Briefings

The Shadow in the Machine: Surprising Realities of AI and the Future of Risk

Executive Summary

The rapid integration of Artificial Intelligence (AI) into enterprise operations has fundamentally shifted the internal audit and risk management landscape. This briefing synthesizes core insights, speaker quotes, and audience poll data from the webinar session Embedded Intelligence: Using AI to Transform the Risk Lifecycle and Audit Readiness .

The analysis demonstrates that AI does not merely change the methodology of auditing; it radically alters the nature of the processes being audited. While business operations move at machine speed, traditional risk frameworks remain bound to static, paper-based oversight.

Critical Takeaways:
The Document-Reality Gap: AI creates a widening divergence between documented procedures and actual running processes as adaptive logic evolves faster than policy manuals.
Shadow AI & Behavioral Exposure: Unsanctioned AI use by "well-intentioned, misguided people" (WIMPS) poses severe data exposure risks that static corporate policies cannot solve.
Third-Party Transparency: A major enterprise threat stems from "trusted" long-term vendors embedding AI into established products without new procurement cycles or legal reviews.
Methodological Evolution: Internal audit is transitioning away from retrospective sampling (e.g., checking 25 transactions twice a year) toward continuous, full-population testing—shifting the auditor’s role from assurance provider to strategic advisor.


1. The Paradigm Shift: From Auditing Processes to Auditing Intelligence

In the traditional corporate landscape, the audit function served as a steady anchor, verifying that established protocols were followed. However, the integration of AI has fundamentally altered the internal audit mandate. As Dirk Schrader argues, AI is not merely changing the "how" of auditing through better analytics; it is fundamentally transforming the "what." We are moving away from auditing static workflows and toward auditing active, evolving intelligence.

"Audit may be producing technically correct findings about a process that no longer fully exists."Dirk Schrader, Global VP of Security Research, Netwrix

The strategic danger lies in the growing divergence between three versions of any given business process:
1. The Designed Process: The theoretical ideal envisioned by leadership.
2. The Documented Process: The version recorded in manuals and compliance frameworks.
3. The Actually Running Process: The reality on the ground, which is increasingly shaped by AI agents that adapt continuously without appearing in process narratives.

When AI-enabled processes migrate tasks from human hands to automated logic, they create a "silent divergence." Traditional audit methods fail to detect subtle changes in decision thresholds or model weights, leading to "technically correct findings" for processes that no longer exist in reality. Furthermore, autonomous agents break traditional identity-based access controls—the entity accessing sensitive data is no longer a human employee but an automated logic loop without a traditional evidence trail.


2. The Inventory Illusion & Industry Readiness

A comprehensive AI inventory is the baseline for enterprise risk management, yet a massive gap exists between adoption speed and oversight maturity. As Mike Levy notes, partial lists focus dangerously on software names rather than workflows, leaving leadership completely blind to underlying data exposure.

"Partial lists are fundamentally dangerous because they focus on software names rather than application. A list of tools provides zero visibility into the actual logic or data exposure occurring within an enterprise workflow."Mike Levy, CEO of Cherry Hill Advisory.

Audience survey results confirm that the vast majority of organizations are operating with incomplete visibility into their AI footprint:
POLL: How complete is your organization's inventory of AI use cases? Total votes: 304
B. Partial - enterprise tools only (151 votes) 50%
D. We do not have one (53 votes) 17%
A. Comprehensive - enterprise, embedded vendor, and shadow AI (50 votes) 16%
C. Drafted but not validated (50 votes) 16%
Key Finding: Only 16% of organizations maintain a comprehensive inventory covering enterprise, embedded vendor, and shadow AI workflows.


3. Managing Shadow AI, Data Sovereignty, and Employee Behavior

Shadow AI is fundamentally a workflow and visibility problem, not a policy problem. Mandates and policy announcements fail when employees are under intense productivity pressure.

"Shadow AI is driven by 'WIMPS'—Well-Intentioned, Misguided People. These are high-performing employees who use unsanctioned AI tools or enter sensitive data into public models simply to keep pace with workload demands, completely unaware of the data privacy or intellectual property risks."Colin Whittaker, Founder of Informed Risk Decisions

Survey data confirms that multi-faceted exposures and unrestricted data inputs represent the core operational risks facing internal audit teams today:
POLL: In your opinion, which AI-related exposure creates the biggest audit risk in your organization today? Total votes: 284
E. All of the above are creating meaningful audit risk in my organization (95 votes) 33%
C. Sensitive data being entered into AI tools without clear restrictions or monitoring (66 votes) 23%
A. Employees using unsanctioned AI tools outside approved governance (60 votes) 21%
B. Third-party vendors embedding AI into products or services without sufficient transparency (49 votes) 17%
D. Lack of clear ownership for AI approvals/oversight & lack of explainability (14 votes) 5%
Transitional & Tertiary Data Exposures:
A critical area of concern involves "tertiary" and "transitional" data services. As proprietary data is processed, it leaves intermediate cache trails used by vendors to optimize Large Language Models (LLMs). Without explicit contractual restrictions, enterprise intellectual property can unwittingly become a training asset for a vendor's other commercial clients.


4. The Third-Party Trojan Horse in Long-Term Vendor Contracts

Third-party risk management (TPRM) has historically focused on new procurements. However, Dr. Maria Azua Himmel highlights a unique threat: the "trusted" long-term vendor. Because these relationships are established, they often bypass new risk assessments, yet vendors are actively embedding AI capabilities into legacy products.

"The board-level concern is that AI is being added to existing products without new procurement cycles or legal reviews. These 'silent' additions can influence enterprise decisions—such as pricing logic or legal workflows—bypassing traditional risk and audit teams entirely."Dr. Maria Azua Himmel, Independent Board Director; Pam-American Life Insurance Group

Core Contract Interrogation Questions:
To close this gap, TPRM teams must actively interrogate existing vendors on:
1. Have you embedded AI or trained a proprietary LLM within the service provided to us?
2. What specific datasets were used to train or fine-tune that model?
3. Are our proprietary inputs or transitional metadata used to train models accessible to other clients?


5. Technical Integrity: Technical Drift vs. "World Drift"

While engineering teams focus on "Technical Model Drift" (the mathematical decay of accuracy), Dirk Schrader highlights the more insidious threat of "World Drift."

Technical Model Drift: Historical training data becomes statistically stale over time, causing measurable drops in precision.
World Drift: A model remains technically valid and performs exactly as engineered, yet delivers the wrong answer because external business context, regulations, or strategic priorities have shifted.

When asked where AI will create the biggest internal audit challenge over the next 2–3 years, respondents identified **auditing AI usage across the business** as their primary concern:
POLL: Where do you think AI will create the biggest challenge for internal audit over the next 2–3 years? Total votes: 325
B. Auditing AI usage across the business (102 votes) 31%
A. Validating AI-generated audit findings (74 votes) 23%
D. Governing data access, privacy, and model risk (70 votes) 22%
C. Understanding changing business processes and controls (50 votes) 15%
E. Translating AI-related risk into board-level assurance (29 votes) 9%

6. Visibility-Based Governance & Board-Level Oversight

Effective governance requires shifting from "Human-in-the-loop" (manual approval of every transaction) to "Human-on-the-loop" oversight (automated monitoring of system trends and telemetry). This allows governance to scale at machine speed while flagging weak signals of model failure.

Board Audit Committee Requirements:
The Audit Committee must move from asking "Are we using AI?" to "Do we have a consolidated, cross-functional view of our AI exposure?" Board reporting should include:
Consolidated Enterprise View: Integrated exposure reporting across finance, IT, and operations.
Escalation Thresholds: Clear policy triggers defining when an AI anomaly or near-miss requires board notification.
Operational Resilience Standards: Protocols to ensure decision-making remains defensible even when AI models operate in degraded crisis states.


7. Strategic Roadmap: Transforming Governance into a Competitive Asset

A forward-looking enterprise strategy treats risk management as an enabler for innovation:
1. Inventory Use Cases, Not Just Tools: Evaluate application context. Using AI to draft internal memos is low-risk; using it for financial forecasting or legal analysis carries existential risk.
2. Adopt Continuous Auditing: Transition from small, periodic sample testing to real-time, full-population automated monitoring.
3. Ensure Explainability & Transparency: Ground AI oversight in established frameworks (such as COSO AI guidelines) to maintain defensible, explainable audit findings.

"Governance is not a barrier to innovation; it is the foundation for responsible transformation. What we permit, we sponsor."Mike Levy, CEO of Cherry Hill Advisory, Wolters Kluwer TeamMate ambassador

Explore these dynamics further by accessing the full webinar recording: Embedded Intelligence: Using AI to Transform the Risk Lifecycle and Audit Readiness .