[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"article-body-the-verification-gap":3},"\n[Workiva's 2026 midyear benchmark](https://www.workiva.com/resources/executive-benchmark-survey-verification-gap)\nsurveyed 2,272 finance, risk and sustainability professionals,\nincluding 847 C-level executives, and produced the statistic this\nprofession should sit with: one in four executives say internal\naudits have detected AI-generated errors that reached external\naudiences or board members. In the same study, only 11% said their\norganisation's data quality is sufficient for AI use.\n\nPut the two findings together and the situation states itself.\nMachine-produced numbers are flowing into the most consequential\ncommunications an organisation makes, drawn from data the\norganisation itself does not trust, and the error rate is no longer\nhypothetical. The verification gap, in Workiva's phrase, is not\ncoming. It is reporting to the audit committee.\n\n## Assurance demand is outrunning assurance capacity\n\nInternal audit has seen this movie once before, with cyber.\n[Gartner's 2026 audit planning research](https://www.gartner.com/en/newsroom/press-releases/2025-11-13-gartner-says-internal-auditors-to-focus-on-cybersecurity-data-governence-and-regulatory-compliance-in-2026-2),\nsurveying 160 chief audit executives, found 96% with cyber assurance\nactivities planned, while only 48% expressed high confidence in\ntheir ability to actually provide that assurance. It took a\ndecade for cyber to travel from emerging topic to universal audit\nplan item, and the confidence still has not caught up with the\ncoverage.\n\nAI assurance is starting the same journey with less runway. Boards\nthat have watched an AI error reach them will ask, at the next\ncommittee, a version of: who is assuring these outputs? The chair\ndoes not care that the methodology is immature. And the function\nfielding the question is already stretched. Audit budgets have\ntightened while the profession absorbs new global standards and\nmost audit leaders carry duties beyond audit itself.\n\n## Why the traditional toolkit cannot cover this\n\nThe deeper problem is not capacity but method. Internal audit's core\ninstrument is periodic, sampled testing. Select a quarter, pull 25\nitems, examine them, conclude. Against an AI estate this instrument\nfails on every axis:\n\n- **Volume.** A model producing thousands of outputs daily makes a\n  quarterly sample of a few dozen items statistically decorative.\n- **Drift.** A model that was accurate in March can be quietly wrong\n  by June. Point-in-time conclusions expire faster than the audit\n  cycle that produced them.\n- **Provenance.** Auditing an output requires knowing which model\n  version produced it, trained on what data, approved by whom. In\n  most estates that record does not exist, so the audit stalls at\n  the first question.\n\n> You cannot sample your way to assurance over a system that never\n> stops producing. The assurance has to be as continuous as the\n> thing assured.\n\n## What assurable AI actually requires\n\nThe encouraging news is that the requirements are knowable, and they\nare infrastructure, not heroics:\n\n1. **Provenance as a record, not a recollection.** Every production\n   model carries an immutable passport: version, owner, frozen\n   training data, backtest with misses, approvals. Audit's first\n   three questions become lookups.\n2. **Continuous monitoring of the outputs themselves.** Calibration\n   tracked against outcomes every cycle, drift detected when it\n   happens, exceptions routed to named owners; the control operates\n   over the whole population, always, and audit assures the\n   monitoring rather than re-performing it quarterly.\n3. **Determinism where numbers are made.** An output that cannot be\n   regenerated from its inputs cannot be audited at all. Same\n   inputs, same number is the precondition for everything above.\n\nAudit leadership should also note the upside. The function that\narrives at the committee with a working answer to \"who assures the\nAI?\" is having the trusted-advisor conversation the profession keeps\nsaying it wants. The one that arrives with a sampling plan is having\nthe other conversation.\n\nThe committee question is coming either way. The difference is\nwhether audit meets it with a sampling plan or with standing\ninfrastructure. Continuous output monitoring, model passports,\ndeterministic recomputation. The Prophesee Audit module is the\nsecond answer. [Make the AI estate auditable](/contact).\n",1786833838624]