0% found this document useful (0 votes)
7 views5 pages

AI Risk Control Test Matrix User Manual

The AI Risk-Control-Test Audit Matrix user manual outlines a structured approach for internal and IT audits related to AI governance, aligning with IIA and ISACA standards. It provides a seven-step method for engagement, a scoring system for assessing risks, and a matrix for documenting AI risks and controls. The manual emphasizes the importance of tailoring the workbook to specific organizational contexts and maintaining it regularly to ensure relevance and compliance.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views5 pages

AI Risk Control Test Matrix User Manual

The AI Risk-Control-Test Audit Matrix user manual outlines a structured approach for internal and IT audits related to AI governance, aligning with IIA and ISACA standards. It provides a seven-step method for engagement, a scoring system for assessing risks, and a matrix for documenting AI risks and controls. The manual emphasizes the importance of tailoring the workbook to specific organizational contexts and maintaining it regularly to ensure relevance and compliance.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

User Manual : AI Risk-Control-Test Audit Matrix

2026-2027

Aligned to IIA AI Auditing Framework and ISACA ITAF / CISA-oriented practice


Table of Contents
1. Why this tool was chosen................................................................................................................................................ 2
2. Workbook architecture................................................................................................................................. 2
3. Seven-step operating method....................................................................................................................... 3
4. How to read the Matrix columns................................................................................................................. 3
5. Scoring method................................................................................................................................................ 3
6. Alignment with professional standards...................................................................................................... 3
7. Maintenance rules........................................................................................................................................... 4
8. Quick field guide............................................................................................................................................. 4
Deliverables Excel workbook + this manual

Primary audience Internal audit, IT audit, AI governance, and control functions

Designed from IIA framework, ITAF 5th edition, and the uploaded program / roadmap artefacts

Recommended use Scoping, workpaper preparation, control testing, and evidence requests

1. Why this tool was chosen


 The roadmap and the awareness journey, explicitly recommends a reusable deliverable that links AI risks to controls,
audit tests, and expected evidence. The same roadmap also stresses that; A clear reusable support is more valuable
than a long theoretical contribution.
 The program documentation reinforces this direction by structuring the journey around AI risk registers, AI policy
templates, AI audit workpapers, and practical audit artefacts that can be adopted by multiple entities.
 To align those two practical documents with professional standards, the workbook anchors its control and testing
logic on the IIA AI Auditing Framework, and the 2026 ISACA IT Audit Framework (ITAF).

2. Workbook architecture

 Dashboard: quick counts by domain and priority.


 Tailoring: records engagement context and scoping signals before you test.
 Matrix: core library of AI risks, control objectives, test of design, test of operating effectiveness, and expected
evidence.
 Evidence Catalog: reusable document request list.
 Standards Crosswalk : shows where the workbook aligns to IIA and ITAF concepts.
 Sources: explains the design basis.
3. Seven-step operating method

Step 1 - Define the engagement on the Tailoring sheet and select the AI category.
Step 2 - Answer the scoping questions honestly; they help identify whether you need a targeted, focused, or enhanced
review.
Step 3 - Move to Matrix and filter by AI category, lifecycle, and risk domain.
Step 4 - Keep only relevant rows and adjust impact, likelihood, residual risk, owner, and status.
Step 5 - Convert the selected rows into your engagement program or workpaper.
Step 6 - Request evidence using the Evidence Catalog and the Expected Evidence column.
Step 7 - Use Standards Crosswalk when you draft the scope, methodology, and report language.

4. How to read the Matrix columns

1. Risk Statement explains what can go wrong.


2. Typical Cause / Scenario explains how the risk can materialize.
3. Control Objective states the control result management should achieve.
4. Example Key Controls gives practical control ideas, not mandatory wording.
5. Test of Design verifies whether the control was designed properly.
6. Test of Operating Effectiveness checks whether the control actually operated during the period.
7. Expected Evidence lists the documents, system records, or artefacts auditors should request.
8. Primary Criteria / Assertion Focus helps the auditor connect testing to auditable criteria such as completeness,
accuracy, transparency, explainability, confidentiality, or reliability.

5. Scoring method

 Impact and Likelihood are editable on a 1-5 scale.


 Inherent Risk Score is calculated automatically as Impact x Likelihood.
 Priority is derived automatically: 20-25 Critical, 12-19 High, 6-11 Medium, 1-5 Low.
 Residual Risk is intentionally manual because auditors should apply professional judgment after considering the
actual control environment.
6. Alignment with professional standards

 IIA alignment: the tool follows the IIA framing across Governance, Management, and Internal Audit, and uses
the framework checklist themes such as AI inventory, accountability, data security, bias, explainability, third-
party oversight, and board reporting.
 ISACA / CISA alignment: the tool applies ITAF concepts for risk-based planning, suitable criteria, assertions,
evidence sufficiency, technology-generated evidence, documentation, reporting, and follow-up.
 Practical implication: the workbook is not just a risk register; it is a scoping and evidence-backed audit
workpaper starter.

7. Maintenance rules

 Review the matrix at least annually or when the AI governance framework, regulations, or major use cases change.
 Add entity-specific controls rather than replacing the base library unless the base row is no longer relevant.
 Preserve the standards references so that future updates remain auditable and defensible.
 If direct testing is limited because a vendor or system is opaque, document the limitation and supplement with
independent corroboration or third-party assurance.

8. Quick field guide

When to use Main sheet Expected output

Scoping Tailoring A clearly documented AI use case and relevant risk focus.

Control design review Matrix Selected control objectives and design tests.

Operating effectiveness Matrix + Evidence Catalog Requested evidence and sample-based tests.

Methodology memo Standards Crosswalk Aligned wording for scope, criteria, and evidence basis.

Reporting Dashboard + Matrix Priority view and status-backed observations.

Version note: this manual describes the base library delivered with the workbook. Tailor it to the entity context,
legal perimeter, and AI maturity before issuing assurance conclusions.

You might also like