Good morning {{name}},
I’m Tim Buckley, founder of Beyond the Lines™.
Beyond the Lines™ helps internal audit leaders turn insight into decisions, ownership and outcomes, building the trust, judgement and future-ready capability needed to lead in a Human + AI world.
Less control theatre. More decisions, ownership and outcomes.
AI Use Cases Are Not Your Audit Strategy
A subscriber recently asked how internal audit should approach AI governance and implementation in the audit process, but with one important challenge: How do we step beyond specific use cases and look more holistically at changing our approach with AI?
That is exactly the right question.
Because many audit functions are still asking:
Where can we use AI?
The better question is:
What should now change in how the function operates?
That is a very different conversation.
The BtL position is simple:
AI drafts. Humans decide.
AI organises. Humans validate.
AI speeds up mechanics. Humans sign off.
But that only works if the operating model is clear.
The practical argument
AI governance in internal audit cannot just be a policy note, a list of approved tools or a use case register.
Those things matter, but they are not enough.
The real governance question is:
How does the function preserve judgement, evidence quality, independence, confidentiality and credibility while changing how work gets done?
That means AI needs to be considered across the audit lifecycle.
Planning.
Scoping.
Risk assessment.
Fieldwork.
Evidence analysis.
Exception identification.
Report drafting.
Quality review.
Action tracking.
Audit committee reporting.
Methodology updates.
Team capability.
CAE oversight.
If AI is only applied to isolated tasks, it may make the function faster without making it better.
That is the trap.
Speed is useful. But it’s not the strategy.
The Human + AI Operating Model Review
I’ve summarised this week’s Human + AI framework in a practical cheat sheet below. Screenshot it or save it for your next AI governance, methodology or audit leadership discussion. The full explanation follows underneath, but the visual is designed to help you quickly test whether AI is changing the function responsibly, or just adding tools to old ways of working.
Use this six-part review to assess whether your AI approach is genuinely changing the function or simply adding tools to old ways of working.
1. Governance
Ask:
Who approves AI use in audit?
What data can and cannot be used?
What tools are permitted?
What needs documenting?
Who reviews exceptions?
What would trigger escalation?
The governance model should be practical enough for teams to use and senior enough for the CAE to stand behind.
A good test:
Could you explain your AI approach to the audit committee without sounding either reckless or vague?
2. Methodology
Ask: Where does AI change the audit lifecycle?
This should not be limited to report drafting.
Consider:
Planning: AI can help scan prior findings, policies, risk registers, external trends and committee papers.
Scoping: AI can help identify risk themes, duplicated coverage and gaps in control design.
Fieldwork: AI can structure testing steps, compare evidence and highlight inconsistencies.
Reporting: AI can draft, summarise and test clarity, but humans must own judgement, tone and conclusion.
Follow-up: AI can help compare action evidence against original risk exposure.
The methodology should be explicit about where AI helps and where human judgement is mandatory.
3. Evidence
Ask: What can AI analyse, and what evidence still requires human validation?
AI can help process large volumes of documents, transactions, meeting notes, policies and control evidence.
But audit still needs to know:
What was the source?
Was the data complete?
Was the interpretation reasonable?
Were exceptions validated?
Was the conclusion independently reviewed?
Can the work be reperformed or explained?
Evidence credibility cannot be outsourced to a tool.
4. Quality
Ask: What are the review points?
A Human + AI audit process needs quality gates.
For example:
Prompt or task design reviewed for sensitive work.
Outputs checked against source evidence.
Exceptions validated before discussion with management.
Draft wording reviewed for fairness and accuracy.
Final conclusions signed off by accountable audit leadership.
The principle is simple:
AI can support the work, but it should not create unreviewed audit judgement.
5. Capability
Ask: What skills do audit leaders now need?
Not everyone needs to become technical.
But audit leaders do need to understand enough to ask better questions.
Can the team challenge AI output?
Can managers spot weak prompts, poor assumptions or unsupported conclusions?
Can senior leaders explain where AI was used and why?
Can the CAE defend the function’s approach to the audit committee?
Capability is not just tool training. It is judgement training.
6. Oversight
Ask: What should the CAE and audit committee see?
AI use should not create a hidden operating layer.
At a minimum, oversight should cover:
Approved use cases.
Restricted use cases.
Key risks and mitigations.
Quality review approach.
Data and confidentiality guardrails.
Lessons learned.
Impact on methodology, capability and reporting.
The audit committee does not need a demo reel. It needs confidence that the function is moving responsibly.
Quick baseline check
If you want to step back and look beyond AI use cases, the free Board-Trusted CAE Scorecard is a useful starting point.
It will help you assess where your internal audit function may already be strong, and where trust, decision-readiness, follow-through or future-ready capability may need more attention.
Use it as a quick baseline before deciding what to change next.
Before and after: use case thinking vs operating model thinking
Use case thinking
“We can use AI to summarise meeting notes.”
Useful, but narrow.
Operating model thinking
“How should audit capture, validate and use meeting evidence so that AI improves consistency without weakening professional judgement?”
That creates a better question.
Use case thinking
“We can use AI to draft audit reports.”
Useful, but risky if unmanaged.
Operating model thinking
“How should AI support report drafting while preserving audit tone, fairness, evidence alignment and accountable sign-off?”
That is the real governance question.
Use case thinking
“We can use AI to analyse transactions.”
Potentially powerful.
Operating model thinking
“How do we confirm data completeness, validate exceptions, evidence the analysis and explain the conclusion to management and the audit committee?”
That is where AI becomes audit-relevant.
Use this this week
Pick one AI use case your function is currently considering. Then don’t only ask whether the use case works. Ask what needs to change around it.
Complete this review:
Use case
What task are we trying to improve?
Audit lifecycle point
Where does this sit: planning, scoping, fieldwork, evidence review, reporting, follow-up or oversight?
Operating change
Does this change the way the audit process should work, or is it just speeding up one task?
Human judgement point
What judgement must remain visible and human-owned?
Evidence requirement
What source material supports the AI output, and how will it be validated?
Quality gate
Who reviews the output before it is relied on?
Governance guardrail
What rule, review or escalation prevents poor use?
Capability need
What does the team need to understand to challenge the output, not just use the tool?
Oversight
What does the CAE need to know, and what would the audit committee need to see if asked?
The test is simple.
If the use case cannot be connected to methodology, evidence, quality, capability and oversight, it is not yet operating model change.
It is still a tool experiment.
BtL Leadership Signals webinar with Trent Russell
This is exactly why the next BtL Leadership Signals session matters.
AI and analytics rarely fall short because the tools are weak.
They fall short because too many audit functions treat them as isolated use cases, rather than part of a bigger change in how the function should operate.
In this live session, I’ll be joined by Trent Russell, founder of Greenskies Analytics and Host of The Audit Podcast to explore what audit leaders should genuinely be rethinking if they want AI and analytics to improve the function in a meaningful way.
We’ll discuss where audit leaders are still getting this wrong, the difference between point solutions and real operating model change, and what CAEs and senior audit leaders should be reviewing now across capability, methodology, stakeholder expectations and ways of working.
Register for the BtL Leadership Signals session with Trent Russell:
Toolkit founding cohort and the September Studio
The Board-Trusted CAE Toolkit is now available at the £195 founding price.
It is built for audit leaders who want to take one live audit leadership challenge and make it more decision-ready, committee-ready and implementation-ready.
The promise is simple:
One live issue. Better message. Clearer ownership. Stronger follow-through.
The Toolkit helps you work through:
Baseline and live issue selection.
Decision-ready reporting.
Audit committee narrative.
Ownership and follow-through.
Stakeholder movement.
Human + AI judgement.
30-day implementation sprint.
The Implementation Studio is the next layer.
The Implementation Studio is a practical group implementation environment for internal audit leaders who want to turn ideas, frameworks and toolkit outputs into real change inside their function. It combines structured sprints, peer challenge, live working sessions and focused hot seats to help CAEs, Heads of Internal Audit and senior audit leaders improve decision-ready reporting, audit committee relevance, management ownership, follow-through and Human + AI ways of working.
The Studio is designed for leaders who do not just want more content. They want a supported rhythm for applying the work, testing their thinking, strengthening execution and building a more board-trusted, future-ready internal audit function.
It opens in September and Toolkit founding buyers will get first access and will receive a preferential founding offer.
If you want to be part of the early group helping shape Beyond the Lines™ through feedback, use cases and practical application, the Toolkit is the right place to start. It gives you the core frameworks and operating mechanics. The Implementation Studio is where those mechanics get tested, applied and embedded, through structured sprints, peer challenge and live implementation support.
Closing reflection
AI in internal audit is not just a productivity question.
It is a leadership question.
The functions that benefit most will not be the ones with the longest use case list.
They will be the ones that redesign the work carefully enough to protect judgement, improve quality and create better outcomes.
Less control theatre. More decisions, ownership and outcomes.
Best,
Founder Beyond the Lines™ | Integral Assurance
Share with a colleague
Forward this to one audit leader who is trying to make reporting more useful, more senior and harder to ignore.
Save 10+ Hours a Week With 37 Claude Prompts
Every manager faces the same situations before lunch: a message to land, a meeting to run, a hiring call, a report due. The AI Report built 37 Claude prompts for exactly those moments, organised by the situations every manager faces.
Copy the prompt, fill the brackets, run it in Claude, and get back 10+ hours a week. Oh, and it's free.
All you have to do is subscribe to The AI Report, a 5-minute daily AI brief read by 400,000+ business leaders at IBM, AWS and Microsoft, and the full prompt pack lands in your welcome email. The newsletter and the prompts, both free. Subscribe and grab both





