Auditing Governance: Policy, Roles and Approval Records

Governance failures are the easiest wins for internal audit because they are the quickest to spot and often signal deeper control problems. When an organisation has no AI policy, no documented roles and responsibilities, and no approval process, then everything that follows is built on sand. This lesson shows you how to audit governance elements: policy, roles, and approval, which form the foundation for all other AI controls.

Policy and Standards

Start by asking whether your organisation has documented AI governance policy. Good policy includes principles (what the organisation believes about AI safety, fairness and transparency), scope (which AI systems the policy applies to), roles (who is responsible for what), and decision gates (when human review is required). Policy should be written at a level that applies across the business, not just in one department. The policy should address the EU AI Act compliance requirements, internal risk tolerance, and key decision points like what risk thresholds trigger escalation.

Audit steps here are straightforward. Request the AI policy. If it does not exist, that is finding one. If it does exist, check whether it has been approved by the board or audit committee, whether it has been communicated to everyone who needs to follow it, and whether it is up to date with current regulatory requirements. The EU AI Act Article 4 AI literacy requirements came into force on 2 August 2026, and your policy should address them. Check whether policy is available to everyone and whether new starters receive it as part of onboarding.

Roles and Responsibilities

Document who holds each responsibility in your AI governance structure. Common roles include: Chief AI Officer or equivalent, model owner, data governance lead, compliance lead, audit lead, and ethics champion. Each role should have documented responsibilities, decision rights, and accountability. A control without a clear owner is not a control.

Audit for clarity and gaps. Ask management to produce an RACI matrix (responsible, accountable, consulted, informed) for key AI governance decisions. Can you trace who approved each high-risk system? Is there a clear escalation path when issues are found? If someone leaves, would knowledge walk out the door, or is their role documented well enough for someone else to step in?

Lesson concept diagram

Approval Gates and Records

The strongest AI policies are useless if they are not enforced. Test the approval process by sampling decisions. Pull approval records for five to ten AI systems deployed in the past twelve months. For each, check: Was there an approval? Did it happen before deployment, not after? Who approved it? Were they authorised to? Was the approval recorded? What criteria did they check against? Did they confirm that data governance was done, that testing was adequate, and that regulatory risks were assessed?

You will often find that approvals are missing, or that they happened but were not documented. A conversation with a model owner about an approval is not an approval record. An email thread without a clear approval statement is ambiguous. Audit records, not recollections.

Policy and Roles in Practice

The final test is whether governance on paper matches governance in practice. Shadow a model approval decision. Sit in the meeting where a new hiring AI tool is presented for approval. Are the governance questions asked? Are risks challenged? Or does the approval feel like a formality? If governance exists in policy but not in practice, then the control is ineffective and needs strengthening.