Internal Controls for AI

Internal Controls for AI

Internal Controls for AI, in Plain English

I'm an accounting professor and a CPA, and everything I do with AI runs on one old habit: process thinking. What is the process? Where can it fail? How do we know the result is trustworthy? Who checks the work, and who checks the checker? Accountants have been asking those questions for over a century. AI just made them everybody's questions.

What is COSO?

COSO is the framework organizations use to design and evaluate internal control, and it describes five things every trustworthy operation has. In plain words:

Control environment. The tone and the rules of the place. Does anyone actually care about doing this right?

Risk assessment. Sitting down and naming what could go wrong before it does.

Control activities. The specific safeguards: approvals, reconciliations, separation of duties, locked cabinets.

Information and communication. Writing things down and making sure the right people see them.

Monitoring. Checking that the checks still work.

None of this was invented for computers. A shopkeeper a hundred years ago ran a version of it with a ledger, a locked drawer, and a rule about who counts the cash. That's the point: these are old habits, and they transfer.

My version, for working with AI

In Where AI Fits: Part 1, I compress control thinking into three words anyone can use: prevent, detect, mitigate.

Prevent. Set the rules before the work starts. My house rules: never overwrite, never delete, private stays private. Give the AI written context, state what's off limits, and make it ask before acting.

Detect. Make checking part of the routine. The AI restates the task before it starts, so misunderstandings surface early. Versions are numbered and dated, so any change is visible. Trust is fine. Verification is policy.

Mitigate. Assume something will eventually go wrong, and make wrongness cheap. New versions never replace old ones, so any mistake can be rolled back. A lessons file turns every error into a one-line rule, so each mistake only ever costs you once.

If you know the classic vocabulary, you'll recognize everything here: authorization, segregation of duties, audit trail, documentation, exception handling. The technology is new. The questions are ours.

Where this gets serious

That's the household version. The moment AI agents start doing real work inside organizations, working in the same systems, handing tasks to each other, and reporting on their own performance, the same questions get sharper and the stakes get real. Who authorizes an agent? Who verifies its work? What happens when two agents disagree about what the truth is?

That's my current research. My paper, Who Audits the Agent?, on agentic AI, internal control, and assurance, is under review at Accounting Horizons, and the preprint is available now on SSRN: read the SSRN preprint

And if you are working through these questions right now, send me a note through Ask a Question. Choose the topic that fits best; I read every message.

The everyday version of all of this, taught step by step, is in the book: Where AI Fits: Part 1, $9.99 on Amazon.