User Manual : AI Risk-Control-Test Audit Matrix
2026-2027
Aligned to IIA AI Auditing Framework and ISACA ITAF / CISA-oriented practice
Table of Contents
1. Why this tool was chosen................................................................................................................................................ 2
2. Workbook architecture................................................................................................................................. 2
3. Seven-step operating method....................................................................................................................... 3
4. How to read the Matrix columns................................................................................................................. 3
5. Scoring method................................................................................................................................................ 3
6. Alignment with professional standards...................................................................................................... 3
7. Maintenance rules........................................................................................................................................... 4
8. Quick field guide............................................................................................................................................. 4
Deliverables Excel workbook + this manual
Primary audience Internal audit, IT audit, AI governance, and control functions
Designed from IIA framework, ITAF 5th edition, and the uploaded program / roadmap artefacts
Recommended use Scoping, workpaper preparation, control testing, and evidence requests
1. Why this tool was chosen
The roadmap and the awareness journey, explicitly recommends a reusable deliverable that links AI risks to controls,
audit tests, and expected evidence. The same roadmap also stresses that; A clear reusable support is more valuable
than a long theoretical contribution.
The program documentation reinforces this direction by structuring the journey around AI risk registers, AI policy
templates, AI audit workpapers, and practical audit artefacts that can be adopted by multiple entities.
To align those two practical documents with professional standards, the workbook anchors its control and testing
logic on the IIA AI Auditing Framework, and the 2026 ISACA IT Audit Framework (ITAF).
2. Workbook architecture
Dashboard: quick counts by domain and priority.
Tailoring: records engagement context and scoping signals before you test.
Matrix: core library of AI risks, control objectives, test of design, test of operating effectiveness, and expected
evidence.
Evidence Catalog: reusable document request list.
Standards Crosswalk : shows where the workbook aligns to IIA and ITAF concepts.
Sources: explains the design basis.
3. Seven-step operating method
Step 1 - Define the engagement on the Tailoring sheet and select the AI category.
Step 2 - Answer the scoping questions honestly; they help identify whether you need a targeted, focused, or enhanced
review.
Step 3 - Move to Matrix and filter by AI category, lifecycle, and risk domain.
Step 4 - Keep only relevant rows and adjust impact, likelihood, residual risk, owner, and status.
Step 5 - Convert the selected rows into your engagement program or workpaper.
Step 6 - Request evidence using the Evidence Catalog and the Expected Evidence column.
Step 7 - Use Standards Crosswalk when you draft the scope, methodology, and report language.
4. How to read the Matrix columns
1. Risk Statement explains what can go wrong.
2. Typical Cause / Scenario explains how the risk can materialize.
3. Control Objective states the control result management should achieve.
4. Example Key Controls gives practical control ideas, not mandatory wording.
5. Test of Design verifies whether the control was designed properly.
6. Test of Operating Effectiveness checks whether the control actually operated during the period.
7. Expected Evidence lists the documents, system records, or artefacts auditors should request.
8. Primary Criteria / Assertion Focus helps the auditor connect testing to auditable criteria such as completeness,
accuracy, transparency, explainability, confidentiality, or reliability.
5. Scoring method
Impact and Likelihood are editable on a 1-5 scale.
Inherent Risk Score is calculated automatically as Impact x Likelihood.
Priority is derived automatically: 20-25 Critical, 12-19 High, 6-11 Medium, 1-5 Low.
Residual Risk is intentionally manual because auditors should apply professional judgment after considering the
actual control environment.
6. Alignment with professional standards
IIA alignment: the tool follows the IIA framing across Governance, Management, and Internal Audit, and uses
the framework checklist themes such as AI inventory, accountability, data security, bias, explainability, third-
party oversight, and board reporting.
ISACA / CISA alignment: the tool applies ITAF concepts for risk-based planning, suitable criteria, assertions,
evidence sufficiency, technology-generated evidence, documentation, reporting, and follow-up.
Practical implication: the workbook is not just a risk register; it is a scoping and evidence-backed audit
workpaper starter.
7. Maintenance rules
Review the matrix at least annually or when the AI governance framework, regulations, or major use cases change.
Add entity-specific controls rather than replacing the base library unless the base row is no longer relevant.
Preserve the standards references so that future updates remain auditable and defensible.
If direct testing is limited because a vendor or system is opaque, document the limitation and supplement with
independent corroboration or third-party assurance.
8. Quick field guide
When to use Main sheet Expected output
Scoping Tailoring A clearly documented AI use case and relevant risk focus.
Control design review Matrix Selected control objectives and design tests.
Operating effectiveness Matrix + Evidence Catalog Requested evidence and sample-based tests.
Methodology memo Standards Crosswalk Aligned wording for scope, criteria, and evidence basis.
Reporting Dashboard + Matrix Priority view and status-backed observations.
Version note: this manual describes the base library delivered with the workbook. Tailor it to the entity context,
legal perimeter, and AI maturity before issuing assurance conclusions.