The Next AI Failure Will Be a Control Failure, Not a Model Failure
- information9255
- Jul 7
- 5 min read
Updated: 7 days ago

The key governance challenge is not whether the AI model works, but whether management understands where and how AI is being used within the organization.
While AI enables value creation, this value is only protected when the organization knows which processes depend on AI, who is responsible for each use case, what data the system accesses, mitigation of shadow AI, how it influences decisions, when exceptions should be escalated, and whether independent verification of controls is possible.
The primary risk is not the algorithm itself, but unmanaged adoption, unclear accountability, weak oversight, and the unchecked expansion of AI into critical decisions before governance catches up.
The next significant AI failure is more likely to result from a hidden control lapse within procurement, finance, information technology, compliance, operations, or customer workflows than from a rogue model. This shift is driving the evolution from AI governance to AI assurance.
Organizations that will earn trust are not those with the most refined AI principles, but those that can demonstrate to boards, regulators, customers, and auditors a comprehensive inventory of material AI use cases, risk tiering, human override, traceability, vendor dependency mapping, test results, and incident reporting.
Responsible AI without auditable evidence will be seen as reputation management rather than governance.
Why it Matters Now
The context has shifted. AI is no longer an emerging technology issue that Leadership, with the blessing of the boards, can delegate to innovation teams.
Regulatory requirements are increasing while operational use expands.
The EU AI Act is in force, with prohibited practices and rules for general-purpose AI models.
Transparency obligations begin in August 2026, and high-risk system requirements will follow on a staged timeline.
Boards recognize the strategic importance of AI: NACD found that 95% of directors expect AI to impact their business, yet only 28% report regular board discussions on the topic. This gap is not only a governance issue but also a future liability concern.
Internal audit’s preparedness data is the clearest warning signal.
In a 2026 joint study by The IIA and AuditBoard, fewer than 40% of internal audit leaders believed their functions were adequately prepared to detect or respond to AI-enabled fraud.
Yet 57% said they are already assessing control weaknesses that enable fraud, 51% are advising management on AI governance or policy updates, and 88% identified AI-powered phishing as a top concern.
This represents a classic assurance gap: high exposure, incomplete action, and limited confidence.
NIST’s Generative AI Profile makes the same point from a controls perspective.
It identifies a broad risk set that goes far beyond bias and hallucination: confabulation, data privacy, information integrity, information security, intellectual property, harmful content, value-chain opacity, overreliance in human-AI configurations, and third-party integration risks.
NIST’s implication is clear: organizations need updated risk tiering, pre-deployment and in-context testing, documentation of third-party components and plugins, formal incident disclosure, and defined decommissioning protocols when systems exceed risk tolerance.
This is not merely an ethics statement; it is a control architecture.
Incident data is trending negatively.
OECD analysis shows media-reported AI incidents rising from 92 per month in 2022 to 324 per month in 2025.
Synthetic-media risks increased 2.5 times and now represent over 14% of incidents; cyberattacks and fraud nearly tripled; election interference and geopolitical spikes, while event-driven, are severe.
The key point for boards is not the reliability of every media report, but that incident frequency is increasing faster than most corporate assurance models can accommodate.
Financial authorities share concerns about concentration, dependency, and fragility.
The FSB warns that AI can amplify third-party dependencies, concentration, cyber risk, and weaknesses in model and data governance.
The ECB notes that widespread AI use and concentrated suppliers may increase operational risk, cyber risk, herding behavior, and systemic fragility.
The Federal Reserve emphasizes that AI falls within existing frameworks and raises familiar issues in model risk, data governance, third-party risk, privacy, and compliance.
This is important because boards can no longer treat AI as a separate ethics issue. AI is becoming integral to the enterprise control environment.
Standards are evolving to address these challenges.
ISO/IEC 42001, the first AI management system standard, formalizes an AI governance approach that includes policy, risk assessment and treatment, oversight, traceability, and continuous improvement.
COSO also frames AI as an enterprise risk management and oversight issue, not just a technical deployment matter.
As standards are integrated into management systems, assurance expectations typically follow.
The organizations most exposed to AI risk may not be those developing advanced models, but those embedding third-party AI into routine business processes without updating controls. A mediocre model with strong controls is manageable; a powerful model within a weak process is dangerous.
This shifts the board’s focus. Instead of asking,
“Do we have an AI policy?”
Boards should ask, “Can management prove where AI influences a material decision, who owns that risk, what evidence exists that controls work, and how fast the system can be challenged, overridden, or shut down?”
If management cannot answer these questions clearly, the organization lacks true AI governance. Optimism alone will not protect the organization when control failures occur.
For both internal and external audits, the implications are significant.
AI cannot be audited effectively as an isolated technology topic annually.
It must be audited within its operational context, including decision rights, data lineage, model change management, vendor governance, exception handling, access control, and evidence reliability.
The control objective has shifted from simply 'using AI responsibly' to 'ensuring AI-influenced decisions are explainable, attributable, testable, and defensible.'
A practical approach is to treat every material AI use case as a decision system that must be inventoried, tiered, controlled, logged, challenged, and assured.
This requires linking AI to business materiality and decision implications.
The initial focus should not be on 'which models do we have?
Instead, it should be 'which decisions, disclosures, transactions, judgments, customer outcomes, or compliance obligations are influenced by AI, directly or indirectly?

A practical agenda starts with eight key actions, each straightforward to state but challenging to implement
Build a live inventory of all AI use cases.
Classify each use case by decision materiality.
Assign a named executive owner to every material use case.
Require human override for high-impact decisions.
Monitor and log prompts, outputs, changes, and exceptions.
Test third-party models before and after deployment.
Establish AI incident reporting with escalation thresholds.
Put AI assurance on the annual audit plan now, before control gaps become material failures.
Sources:
Jonathan Ngah, CIA, CISA, CFE, is a GRC professional with 17+ years of combined leadership experience in advisory and industry-specific roles and a contributor to Synergy-IA.

Comments