Your Next Cyber Security Audit Will Ask About AI. Ready?

Somewhere in your next audit, after the familiar questions about access rights and backup tests, a newer one will land: which AI tools are your people using, and who approved them? In most companies the room goes quiet at that point. Not because the answer is embarrassing, but because nobody is sure whose job it was to know.

A cyber security audit is an independent check that your security measures actually exist, actually work, and can be shown to work with evidence. Auditors don't take your word for anything. They ask for the access review, the backup log, the record of who signed off on that exception. That part hasn't changed. What has changed, quickly, is the evidence list.

For years, businesses have prepared their answers on firewalls, passwords and phishing training. Those answers are usually ready, filed, and reasonably good. The AI questions are different. They arrived in the last two years, they touch every department rather than just IT, and in most organisations no one owns them. Staff paste customer text into chatbots that were never assessed. Copilot reads every file its permissions allow, including the folders nobody remembered were open. Automated agents hold credentials that no leaver process will ever revoke, because no one ever hired them.

The scale of the gap is on record. In IBM's 2025 Cost of a Data Breach report, 63% of organisations said they had no AI governance policy at all, and among those that suffered an AI-related security incident, 97% lacked proper access controls on their AI tools. The tools arrived. The oversight didn't.

So it's worth walking through what auditors are now asking, what a good answer sounds like, and who in your business should be able to give it before the meeting where the room goes quiet.

Why AI moved into audit scope

Auditors follow risk, and the risk has moved. When a fifth of your workforce is quietly using unapproved AI tools, the biggest unreviewed data flows in your company are no longer email attachments. IBM's report put a price on this: organisations with high levels of shadow AI, meaning staff using AI tools nobody sanctioned, paid an average of $670,000 more per breach. And 13% of organisations surveyed had already experienced attacks that compromised their AI models or applications directly. This is no longer a future risk to note in the appendix.

Regulation is following the same path, just more slowly. The EU AI Act's headline obligations for high-risk systems were due in August 2026, and the EU has since agreed to push that deadline back to December 2027. Some businesses read the delay as permission to relax. Auditors read it differently: deferred is not cancelled, and the rules already in force on prohibited practices and general-purpose AI haven't moved. Meanwhile the parties that don't wait for regulators, your cyber insurer and your largest customers, have already added AI questions to their renewal forms and vendor reviews. Whether or not the law is ready, the questionnaires are.

The questions your auditor will ask

The exact wording varies by framework, but the substance is converging. Expect versions of these:

  • Do you have an inventory of the AI tools in use across the business, including the ones nobody approved?
  • What company data leaves your environment through AI tools, and where does it go?
  • Who approved each AI deployment, and who owns it now?
  • What can your AI agents and assistants actually access, and who reviews those permissions, on what schedule?
  • How are AI outputs checked before they reach customers or decisions?
  • What do your AI vendors do with the data you send them, and does the contract say so?
  • If an AI tool misbehaves, who can switch it off, and how fast?

Read that list again and notice something reassuring: there is nothing exotic in it. Inventory, data flows, ownership, access, review, contracts. These are the same disciplines audits have always tested, pointed at a new class of software. The businesses that struggle are not the ones lacking AI expertise. They are the ones that never applied their existing discipline to the new tools.

What a good answer sounds like

Audit-ready doesn't mean perfect. Auditors distinguish sharply between a business that knows its gaps and a business that discovers them in the meeting.

A good answer to the inventory question is a register: every AI tool in use, what it touches, who owns it, when it was last reviewed. A good answer on shadow AI is not 'we've banned it', which auditors rarely believe, but 'we survey for it quarterly, here's what we found, here's what we did'. A good answer on agent access treats a piece of software with credentials the way you treat a contractor with a badge: listed, scoped to the minimum, reviewed on a schedule, removed when the work ends.

If you want a structure to hang this on, ISO/IEC 42001, the management system standard for AI, is the reference auditors increasingly reach for, and it slots alongside ISO 27001 rather than replacing it. You don't need to certify against it tomorrow. You do need the habits it describes: know what you run, name who owns it, write down what you decided and why.

The old questions haven't gone anywhere

None of this replaces the classic audit scope. The findings that sink most reports are still the unglamorous ones: accounts belonging to people who left last year, backups that were never test-restored, admin rights that outlived their project. If those basics are shaky, fix them first. An AI governance register sitting on top of an unpatched server impresses nobody.

The point is that the bar has been raised, not moved. You now need the old answers and the new ones.

Who can actually run this audit?

Here the market has a problem. Auditors who genuinely understand AI systems are scarce, and consultancies charge accordingly. That scarcity is also an opening, on both sides of the table.

If you're building the capability in-house, or you're an IT professional deciding where to specialise, the path runs through audit fundamentals first. CISA remains the recognised foundation for IT audit, and it has become the doorway to something newer: ISACA's Advanced in AI Audit (AAIA) credential, which requires an active CISA (or an equivalent audit qualification) and tests AI governance, AI operations and AI audit techniques specifically. For the systems side, the ISO 27001 Lead Auditor course teaches you to plan and run management system audits over four days, the same machinery that ISO 42001 borrows. And if your AI questions are mostly Microsoft-shaped, because Copilot and its agents are what your auditor will actually point at, SC-500 covers securing exactly those.

For teams that need more than one person carrying this, Unlimited Security Training covers the security and audit courses under one subscription, which suits the reality that audit readiness is a team property, not an individual's.

FAQ

Is shadow AI really an audit issue, or just an HR one?

Audit, firmly. Unapproved tools move company data outside your controls without assessment or contract. The $670,000 figure above is the measured cost of treating it as a people problem instead of a security one.

Does ISO 27001 already cover AI?

Partly. Its controls on access, suppliers and data handling apply to AI tools like any other software. What it doesn't give you is AI-specific governance: model behaviour, output checking, the register of AI decisions. That's the gap ISO 42001 fills.

The EU AI Act deadline moved to 2027. Can this wait?

The legal deadline moved. The commercial ones didn't. Insurers, enterprise customers and auditors are asking now, and the controls take months to build, not weeks. Starting early also costs less, because you're building a register, not running a remediation project.

How often should AI use be audited?

Treat it like access reviews: a full look annually, a lighter check quarterly. AI tools appear in a business far faster than servers ever did, so an annual-only rhythm guarantees your inventory is fiction by month six.

Where to start this week

You don't need a framework project to get ready. You need a list. Write down every AI tool you know about, ask each department head what they would add, and put a name next to every entry. Then book the review: an hour, next month, in the diary now. That one page answers more of the auditor's questions than most businesses can manage today.

After that, work the list in order of what touches customer data first. Close the access nobody needs, add the AI clause at the next vendor renewal, and send whoever owns the register on the training that lets them defend it in the room. Do it now, while it's a preparation job with your name on the plan, rather than after the first audit turns it into a findings list with a deadline on it.

Written by:

Frank Hojgaard

Frank Højgaard is the Founder and CEO of Readynez, where he focuses on how organisations build the skills and capabilities needed to succeed with AI. With more than 15 years in IT training and workforce development, he writes about AI adoption, Copilot enablement, skills intelligence, role-based learning, and how companies can move from traditional course consumption to measurable workforce readiness and business impact.

Two people monitoring systems for security breaches

Unlimited Security Training

Get Unlimited access to ALL the LIVE Instructor-led Security courses you want - all for the price of less than one course. 

  • 60+ LIVE Instructor-led courses
  • Money-back Guarantee
  • Access to 50+ seasoned instructors
  • Trained 50,000+ IT Pro's

Basket

{{item.CourseTitle}}

Price: {{item.ItemPriceExVatFormatted}} {{item.Currency}}