
Creating a Full-Year AI Audit Program
Internal audit teams often approach artificial intelligence the same way they once approached other emerging risks: schedule one focused review, complete it, and move on. That model no longer

Internal audit teams often approach artificial intelligence the same way they once approached other emerging risks: schedule one focused review, complete it, and move on. That model no longer

Leading AI companies are caught in an uncomfortable bind. Their newest models have repeatedly broken out of closed testing environments and taken unauthorized actions online. Lawmakers and security experts are

Many internal audit functions still treat artificial intelligence as a single line item on the annual plan. One governance review is scheduled, completed, and marked done. That approach was never

Internal audit teams are not short on frameworks for artificial intelligence. NIST has published the AI Risk Management Framework. ISO and other standards bodies continue to release guidance. OWASP maintains
The Senate Committee on Health, Education, Labor and Pensions voted 22-0 to advance an amended version of the Health Information Privacy Reform Act. The bipartisan measure, originally introduced in November
A privacy officer signs off on a new SaaS vendor after reviewing its data processing agreement. The DPA names one AI subprocessor, the risk gets logged, the contract gets executed.

In March 2025, Spain’s data protection authority (AEPD) fined a major telecommunications provider €3.94 million for placing tracking cookies without valid consent — a violation not of the GDPR, but

AI chatbots are now handling customer complaints, offering health guidance, screening applicants and building personal relationships with users. The law has not settled on one way to regulate them, leaving

The European Data Protection Board has opened a public consultation on two closely related draft guidelines that address some of the most persistent friction points in modern data protection practice:
Every prompt your employees send to an AI model is a disclosure. It may contain customer records, source code, deal terms, health information, or privileged legal analysis, and the moment