How frontier AI companies could implement an internal audit function

📅 2025-12-16
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Leading AI enterprises lack internal audit mechanisms calibrated to catastrophic and systemic risks. Method: This paper introduces the first four-dimensional integrated framework that tightly couples the Institute of Internal Auditors (IIA) standards with AI safety governance—systematically defining audit scope, resource models, execution frequency, and sensitive information access protocols. It synthesizes risk-based assurance theory, AI governance literature, and real-world operational case studies. Contribution/Results: The framework establishes, for the first time, organizational safety trade-off boundaries, thereby addressing a critical gap in endogenous risk assurance. It delivers an actionable internal audit capability roadmap, enabling boards and regulators to obtain high-confidence, system-level evidence for risk control. By embedding audit rigor into AI safety governance, the framework strengthens the safety governance feedback loop and advances institutional accountability in high-stakes AI development.

Technology Category

Philosophy and Ethics of AI: Safety, Robustness & TrustworthinessNatural Language Processing: Safety and RobustnessHumans and AI: AI for Accessibility

Application Category

Responsible Web: Audits of web technologies, standards, platforms, and applicationsSecurity and Privacy: Security and privacy of machine learning and AI applicationsSearch and Retrieval-Augmented AI: Web evaluation methodologies and metrics
📝 Abstract
Frontier AI developers operate at the intersection of rapid technical progress, extreme risk exposure, and growing regulatory scrutiny. While a range of external evaluations and safety frameworks have emerged, comparatively little attention has been paid to how internal organizational assurance should be structured to provide sustained, evidence-based oversight of catastrophic and systemic risks. This paper examines how an internal audit function could be designed to provide meaningful assurance for frontier AI developers, and the practical trade-offs that shape its effectiveness. Drawing on professional internal auditing standards, risk-based assurance theory, and emerging frontier-AI governance literature, we analyze four core design dimensions: (i) audit scope across model-level, system-level, and governance-level controls; (ii) sourcing arrangements (in-house, co-sourced, and outsourced); (iii) audit frequency and cadence; and (iv) access to sensitive information required for credible assurance. For each dimension, we define the relevant option space, assess benefits and limitations, and identify key organizational and security trade-offs. Our findings suggest that internal audit, if deliberately designed for the frontier AI context, can play a central role in strengthening safety governance, complementing external evaluations, and providing boards and regulators with higher-confidence, system-wide assurance over catastrophic risk controls.
Problem

Research questions and friction points this paper is trying to address.

Designing internal audit functions for frontier AI companies
Assessing practical trade-offs in audit scope and sourcing arrangements
Providing system-wide assurance over catastrophic risk controls
Innovation

Methods, ideas, or system contributions that make the work stand out.

Design internal audit for frontier AI safety governance
Analyze four core dimensions: scope, sourcing, frequency, information access
Provide system-wide assurance over catastrophic risk controls
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
F
Francesca Gomez
Arcadia Impact - AI Governance Taskforce, London, United Kingdom
A
Adam Buick
Arcadia Impact - AI Governance Taskforce, London, United Kingdom; Ulster University, Northern Ireland
L
Leah Ferentinos
Arcadia Impact - AI Governance Taskforce, London, United Kingdom
H
Haelee Kim
Arcadia Impact - AI Governance Taskforce, London, United Kingdom
E
Elley Lee
Arcadia Impact - AI Governance Taskforce, London, United Kingdom