Scoping an AI Audit: System, Process or Whole Programme
The scope of an AI audit determines what you test and how deep you go. You have three main options: you can audit a single system end-to-end, you can audit a specific process that touches multiple systems (like model approval), or you can audit the whole AI programme for governance maturity. Each scope requires different planning and produces different findings. Understanding which scope fits your audit objective prevents wasted effort and ensures you capture the right evidence.
System-Level Audits
A system-level audit focuses on one AI system from conception to production. You trace how hiring AI was built, what data it uses, how it was tested, who has access, how decisions are logged, and how performance is monitored. This audit is deep and narrow. You will understand that specific system very well, but you will not know whether other AI systems have the same governance gaps. System-level audits work well when you are investigating a complaint, testing your audit procedures on a known system, or providing evidence to support a regulatory inquiry. They also work well when a system is so critical or immature that it demands focused attention. The downside is that system audits require significant time investment and do not give you a picture of risk across the organisation.
Process-Level Audits
A process-level audit cuts across multiple systems and focuses on one stage of the life cycle or one governance process. You might audit “how AI systems are approved” by reviewing the approval process, sampling approved systems to check they followed it, and identifying where the process is not being followed. Or you might audit “model validation” across all systems that use external models, checking whether validation happened and whether test evidence was reviewed. Process audits are broader and often surface systemic issues that affect many systems at once. A broken approval process is more important than individual system failures because it means many systems could be in the same state. The downside is that process audits may not go deep enough into any single system to find subtle failures.

Programme-Level Audits
A programme-level audit assesses the maturity of your entire AI governance function. You review AI policy, governance structures, the existence of registers and controls, and the effectiveness of oversight across all systems. You typically do not audit individual systems deeply, but you do sample enough to form a view of whether governance is working in practice or just on paper. Programme audits are useful in the early stages of building AI governance, when you want to establish a baseline of maturity and identify the biggest gaps. They are also useful when you want to report to the board on governance status. The downside is that programme audits may miss system-specific risks that do not show up in a high-level review.
Mixed Scopes
Most audit plans use all three scopes at different times. You might conduct a programme-level audit in year one to assess maturity, then follow up with system-level audits of the highest-risk systems in year two, and process-level audits in year three to address cross-system issues you have identified.
Defining Audit Scope Clearly
Whatever scope you choose, document it explicitly in your audit plan and engagement letter. State which system or process you are auditing, what stage of the life cycle you are covering (or which programme elements), and what you are not covering. This prevents scope creep and sets clear expectations with management about what findings you will deliver.
