Auditing AI and Machine Learning Systems
A model learns its rules from data. The audit follows the data, the validation and the decisions.
Machine learning systems are trained, not programmed line by line. A credit-scoring model at an NBFC or an invoice-matching model in a shared services centre learns its rules from historical data. That shifts the auditor's attention from 'is the code correct?' to 'was the data fit for purpose, is the model still performing, and can anyone explain a given decision?'
DISA Module 6 covers AI's types, uses in finance, impact on audit, risks and governance. Two roles need to be kept apart: auditing an AI system the client uses, and using AI as an audit tool. This page is mostly about the first.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
Risks Across the Model Lifecycle
Use case approval
Typical risk
Model used for a decision it was never designed for
What the auditor looks for
Documented purpose, owner, risk rating and sign-off
Training data
Typical risk
Bias, unrepresentative or stale data, personal data used without a lawful basis
What the auditor looks for
Data lineage, quality checks, consent or other legal ground for personal data
Model development
Typical risk
Overfitting, untested edge cases
What the auditor looks for
Validation by someone independent of the developer, test results, acceptance criteria
Deployment
Typical risk
Unapproved model version in production
What the auditor looks for
Change management and version control over models, not only code
Operation
Typical risk
Drift: accuracy degrades as real-world data changes
What the auditor looks for
Ongoing performance monitoring, thresholds, retraining triggers
Decisions
Typical risk
No explanation for an adverse outcome; no human review
What the auditor looks for
Explainability approach, override and escalation logs, complaint handling
| Stage | Typical risk | What the auditor looks for |
|---|---|---|
| Use case approval | Model used for a decision it was never designed for | Documented purpose, owner, risk rating and sign-off |
| Training data | Bias, unrepresentative or stale data, personal data used without a lawful basis | Data lineage, quality checks, consent or other legal ground for personal data |
| Model development | Overfitting, untested edge cases | Validation by someone independent of the developer, test results, acceptance criteria |
| Deployment | Unapproved model version in production | Change management and version control over models, not only code |
| Operation | Drift: accuracy degrades as real-world data changes | Ongoing performance monitoring, thresholds, retraining triggers |
| Decisions | No explanation for an adverse outcome; no human review | Explainability approach, override and escalation logs, complaint handling |
Frameworks Current in 2026
The background material (revised edition, 2020) predates these, so it describes AI governance in general terms.
- NIST AI Risk Management Framework 1.0
- Released by NIST on 26 January 2023 for voluntary use. Organised around four functions: Govern, Map, Measure and Manage. A Generative AI Profile (NIST AI 600-1) followed on 26 July 2024.
- ISO/IEC 42001
- The international management system standard for AI. Like ISO 27001 for information security, it is a framework an organisation can implement and be audited against.
- DPDP Act 2023
- Where a model is trained on or decides about individuals' digital personal data, India's data protection law applies. ICAI's AI chapter still refers to the earlier Personal Data Protection Bill, which was replaced by this Act.
The Auditor's Role, per ICAI's Material
- check_circleInclude AI in the risk assessment and in the risk-based audit plan.
- check_circleGet involved early in AI projects as an adviser, but do not take responsibility for implementing AI processes, policies or procedures. That would impair independence and objectivity.
- check_circleGive assurance on the reliability of the algorithms and of the data they rely on.
- check_circleOperational managers own and manage AI risk day to day; the auditor assesses whether their policies and controls are adequate and working.
Quick practice on audit concepts. No signup.
A Model Is Not a Black Box Exemption
A client saying 'the vendor's model decides' does not move accountability to the vendor. The entity that uses the output to approve a loan or post an accrual owns the decision, and the controls around it are in scope like any other application control.
How the DISA Assessment Test Tests This
No ICAI question bank is public; these patterns follow from the syllabus.
- check_circleClassification MCQs from the material: narrow (weak) AI vs general AI vs super AI, and the functional types (reactive machines, limited memory, theory of mind, self-awareness). Only narrow AI exists in practice.
- check_circleIndependence: whether the auditor should design or implement the client's AI controls. No.
- check_circleRisk identification: a model trained on past approvals that disadvantages a group of applicants is algorithm bias, not a processing error.
- check_circleLearning types: supervised (labelled data) vs unsupervised (finding patterns without labels). Anomaly detection in journal entries is a common unsupervised example.
FAQs
How do you audit an AI system?expand_more
Treat it as an application with a lifecycle: check the approved purpose, training data quality and lawful basis, independent validation, version control over models, ongoing performance monitoring and the human review of adverse decisions.
What is the NIST AI Risk Management Framework?expand_more
A voluntary framework NIST released on 26 January 2023, organised around four functions: Govern, Map, Measure and Manage.
Can auditors use AI in an audit?expand_more
Yes. ICAI's material gives fraud detection examples such as data mining, expert systems, machine learning and neural networks. The auditor still owns the conclusions and must document how the tool's output was evaluated.
What is model drift?expand_more
The gradual loss of a model's accuracy as real-world data moves away from the data it was trained on. It is why one-time validation is not enough.
Next steps
Take a full DISA mock testAssessment Test format, timed and scored.
