Skip to Content

All Things Internal Audit: AI Regulation Is Here: What Internal Auditors Need to Know Now

AI regulation is no longer on the horizon. It’s here. In this episode, Ernest Anunciacion talks with Marco Horvat about how global AI regulations are reshaping governance, risk management, and the role of internal audit. They discuss why regulators are prioritizing risk to individuals and how AI governance spans the full system life cycle.

Host:

Ernest Anunciacion, CIA

Head of Product Marketing, MindBridge AI

Guests:

Marko Horvat, CPA

Senior Vice President of Business Transformation, ELB Learning

Key points

  • Introduction and episode overview [00:00:01 – 00:00:28]
  • Why AI regulation is accelerating globally [00:00:56 – 00:01:26]
  • How regulators are redefining risk as harm to individuals [00:01:35 – 00:02:18]
  • EU-style risk tiering and prohibited vs. high-risk AI use cases [00:02:37 – 00:03:36]
  • Human-in-the-loop expectations and judgment-based AI decisions [00:03:36 – 00:04:11]
  • What regulators expect organizations to demonstrate [00:04:31 – 00:05:32]
  • Internal audit’s expanding role across the AI life cycle [00:05:38 – 00:06:39]
  • Readiness assessments and the challenge of locating AI use [00:06:59 – 00:07:27]
  • AI literacy skills auditors need today [00:07:43 – 00:09:29]
  • Explainable AI, hallucinations, and model drift [00:08:21 – 00:09:29]
  • Common audit gaps: shadow AI, monitoring, and third-party risk [00:09:44 – 00:12:00]
  • Why vendor AI does not transfer accountability [00:12:02 – 00:12:21]
  • What internal audit teams should be doing right now [00:12:32 – 00:14:28]
  • Balancing continuous monitoring with new risk exposure [00:13:48 – 00:14:20]
  • Partnering with legal and compliance on AI governance [00:14:40 – 00:15:10]
  • Final takeaways: AI regulation is no longer theoretical [00:15:28 – 00:16:31]