é É « » à è ù ç ô é

The CAE's AI Moment: Lead From the Front, or Watch From the Sidelines

Nikki Young
July 24, 2026
| 13 min read

This is Part 5 of Achieving Audit Leadership Through Analytics and AI, a six-part series produced with The Internal Audit Collective and Supervizor, tracking how audit functions move from reporting issues to being accountable for outcomes.

Coming in mid-series? The previous installments are listed below.

Here's the series so far:

  • Part 1: Going from zero to one: launching an audit analytics program that actually sticks

  • Part 2: From Point-in-Time Audits to Continuous Auditing: Choosing What to Run Repeatedly and Why

  • Part 3: The Handoff: Moving from Continuous Auditing to Continuous Monitoring Owned by the Business
  • Part 4: The Audit Report Is Not the Product Anymore 
  • Part 5: Where Audit Analytics Programs Break

Everything in this series has been building toward one moment, and it's the one sitting on your desk right now: what do you actually do about AI?

Your audit committee chair has probably already asked some version of the question. Your CFO has a working group. Your board wants a roadmap. It feels urgent and new. It isn't. You've been here before.

We've Seen This Movie Before

Tom O'Reilly, founder of the Internal Audit Collective, draws the analogy directly:

"It's similar to how internal audit teams adopted analytics. When it first became prominent around 2005 to 2010 – there was a small subset that led from the front of not only their organization, but our industry, and they leaned into data analytics. We're seeing the same thing happen with AI."

The CAEs who moved slower on data analytics didn't fall out of the race – plenty are still building that case today, and there's nothing wrong with being mid-journey. But the ones who started earlier generally spent less time explaining sample sizes to skeptical audit committees, and negotiated from a slightly stronger position than peers still building the track record. That's the real cost of moving later – not irrelevance, just a smaller head start..

The CAEs who get remembered for AI implementation won't be the ones with the best AI vendor. They'll be the ones who recognized early that this was a test they'd already taken once, and knew how to study for it this time. A CAE who has already built a real analytics reputation is in exactly that position now.

The Data Says You Already Have a Head Start

Here's the strange part: almost nobody has actually built the foundation yet, even though almost everybody has started experimenting.

Gartner's most recent audit-department survey found 83% of internal audit functions are already piloting or using AI in some form, with another 12% planning to start within the year. On paper, that looks like universal adoption. ISACA's 2026 AI Pulse Poll, which surveyed more than 3,400 digital trust professionals, tells the story underneath that number: only 38% of organizations have comprehensive AI policies in place despite AI use already being pervasive, and only 11% of practitioners strongly agree their organizations are giving adequate attention to the ethics of how it's deployed. Adoption is outrunning governance almost everywhere.

That gap is the opening. ISACA's own research draws the same conclusion: effective AI governance is downstream of data governance, and organizations that haven't mastered their data first have no real way to manage AI risk, build trust in outputs, or capture lasting value from the investment. Most functions racing to pilot AI right now haven't done that work. If you've spent the past few years building a real analytics program – clean data pipelines, defined exception logic, a track record the business trusts – you're not entering this moment from zero. You're entering it with the one thing 89% of practitioners admit their organizations don't yet have confidence in: a disciplined foundation underneath the tool.

Think about what that means competitively. Most of your peers are going to spend the next eighteen months discovering, the hard way, that the model was never the hard part – the data underneath it was. You already learned that once, back when you built your first analytics test instead of your first AI pilot. The lesson transfers directly; you're just not footing the bill twice.

Data Analytics and AI Were Never Two Different Journeys

Here's the reframe that matters: data analytics and AI are not sequential projects on your roadmap. They're the same discipline at different levels of maturity.

Treating data analytics like an application instead of an approach to work is a categorization error. High-performing audit teams use it to bolster the value of their assurance work, not as a tool they deploy once and set aside. That distinction is exactly why a strong analytics program should translate into more value from AI, not less – the overlap in skill and mindset is the whole point. Technical fluency was only ever half the equation. The strategy is what closes the rest of the gap – and it's the same one you've already been building, one deliberate step at a time.

Celia Viguier, US General Manager at Supervizor, frames the stakes from the other side of the equation:

Clean data is now the top prerequisite finance teams cite before they'll let agentic AI anywhere near a process, because an agent built on top of inconsistent data doesn't just repeat old mistakes – it makes them at machine speed and at scale.”

That's the version of "garbage in, garbage out" that should actually worry a CAE in 2026: it isn't a data-quality footnote anymore, it's an operational risk multiplier.

That reframes what success should even look like. A program that reports its win by the number of exceptions it surfaces every quarter is measuring a symptom count, not a scorecard. The better measure is how many of the underlying processes actually got fixed, and how much cleaner the data is after the program than it was before. That distinction matters even more with AI in the picture, because clean, trustworthy data is the real deliverable – financial integrity, not a longer exception list. Detection is a mechanism, not an end state – the point was always to get the business to a place where its own data, and its own agents, could be trusted.

Finance-grade AI has three non-negotiable requirements, and they map directly onto what a mature analytics program already produces: repeatability (the same input reliably produces the same output), transparency (you can explain why the model reached a conclusion), and safety (enterprise data doesn't leak out and isn't used to train someone else's model). None of that is new territory for an audit function that has already built repeatable routines and governed handoffs. It's the same rigor, pointed at a faster tool. Supervizor's own MCP integration exists precisely so that a structured analytics foundation can plug into whatever AI tools finance or audit already use, rather than becoming one more disconnected pilot competing for attention.

Picture what that foundation actually enables once AI sits on top of it: an auditor typing a plain-English question and getting back a prioritized action plan in seconds – ranked by risk, cutting across entities, controls, and time periods that would otherwise have taken days to assemble manually:

ai-xplore

The Opportunity Is Yours to Take

There's a version of this moment where internal audit waits to be invited into the AI conversation. That version is a mistake, and it's worth naming why out loud.

Audit is supposed to be the risk-focused function, which makes it the natural technology driver too – the one that jumps first into new practices and pulls the rest of the organization forward, not the one that waits to be invited. That's not a stretch of the mandate – it's closer to the mandate's original intent than most audit charters currently reflect.

Taking that opportunity does ask something of you personally, and it's worth being honest about the cost: courage, a degree of vulnerability, and the willingness to add a genuinely new competency to a workload that was never going to shrink to make room for it. That's the real trade-off, not a hypothetical one. The CAEs who get there first won't be the ones with the most spare capacity. They'll be the ones who decided the cost was worth paying before the decision was made for them.

The Three-Step Playbook for Leading This Moment

Getting out ahead of this doesn't mean pitching a company-wide transformation on day one. It means running the same sequence that worked for analytics, compressed into three deliberate moves.

Step One: Build the Muscle on Your Own Team First


Start with your own function before you advise anyone else's. Internal audit's first move should be its own team, not someone else's – working out the bugs and learning what actually holds up before any of it gets exported elsewhere. That responsibility sits with the CAE specifically: getting personally fluent in AI, building a change management plan for the team, and holding people accountable to actually use it rather than treat it as a side project.

One internal audit team ran into this directly when they were assigned an AI governance audit. Partway in, the team stopped and asked an uncomfortable question: who are we to audit this if we haven't done it ourselves first? Instead of pushing forward with the assignment as written, they built their own internal AI policy, ran their own team through it, and used what they learned – where the friction was, where compliance was genuinely hard – before taking that experience anywhere near finance or the broader enterprise. The governance audit got better because the team had already lived the problem.

You don't need an AI governance audit to run the same play. Point AI at your own function's analysis work, your own reporting, your own risk assessments – the places where a wrong output costs you an internal afternoon, not a client relationship. That's where you learn what the tool actually gets wrong before you're vouching for it to someone else.

Step Two: Finance Is Your Natural First Partner


Don't go straight to the enterprise. Go to finance, because finance is already moving on this with or without you. Shared-services and finance organizations are actively deploying agentic AI for accounts-payable automation right now – agents that read invoices, execute three-way matching, resolve exceptions, and manage supplier communications with minimal human review. You already know this process. You know where duplicate payments hide, where approval workflows get bypassed, where vendor master data goes stale.

That's the leverage point. Between the process knowledge, the risk-and-controls knowledge, and now a working knowledge of AI, audit is arguably better positioned to help finance through this than anyone else at the table. The pitch to finance isn't "let audit slow this down." It's "before you automate this, the foundation needs to be right" – then you walk them through the same repeatability, transparency, and safety criteria you'd apply to any control. Finance's plate hasn't gotten any lighter either, which means a partner who arrives with a working framework rather than a checklist gets a warmer reception than you'd expect.

Push on what "resolve exceptions autonomously" actually means before finance signs off on it, because that's where the real control question lives. An agent that can independently decide a mismatched invoice is close enough to approve is an agent making a judgment call that used to require a human signature. That's not a reason to block the project. It's the reason audit needs to be in the room while the exception-handling logic is designed, not after it's already live and generating a monthly reconciliation surprise.

Step Three: Let the Enterprise Come to You

Once you've built credibility with your own team and then with finance, you stop being the function asking for a seat at the table and become the function other departments start asking to borrow.

That pattern is already visible outside of audit. One convenience-retail internal audit team recently posted about its internal AI work on LinkedIn – nothing more than a description of what they'd built and learned – and the company's CFO asked them to present it to the entire finance organization. That kind of story is arguably the single KPI internal audit should be tracking: how often it happens. The credibility that gets you invited into marketing, sales, operations, and compliance conversations isn't built by asking. It's built by having already done good work, with a partner who benefited from it, that the story travels on its own.

What that invitation actually unlocks is worth being specific about. It's not a courtesy seat at a steering committee. It's budget conversations you'd otherwise be excluded from, visibility into AI projects before the control gaps get built in rather than after, and a CFO or CTO who calls you before the rollout instead of after the incident. That's the difference between being informed about the enterprise's AI strategy and helping to shape it.

Don't Miss It Twice

Building an analytics foundation from zero. Deciding what deserves to run continuously. Handing that work to the business once it's proven. Treating advisory relationships as the real product instead of the report. Knowing exactly where these programs break. Every one of those moves has been pointing at this exact moment – the one where audit either leads on AI or explains, again, why it didn't.

The organizations that get AI right will have clean data, tested controls, and someone in the room who already knows exactly where things break. That someone is the CAE – but only for the ones who decide that now, not later.

The commitment that matters here: if you do nothing else, commit to incorporating more analytics – and now more AI – into your work, because you owe that much to yourself and to the profession. A CAE just starting this journey should go back to where the foundation gets built and hand it to whoever on the team is going to own this next. A CAE who has already done that work knows exactly what's being asked now – lead again, on purpose, before the decision gets made without them.

Tom puts it this way:

"The correlation between audit leadership and data analytics maturity isn't really up for debate anymore – the leaders who build their reputation on this now are the ones who'll still be relevant in five years. The Internal Audit Collective has always tried to be the place practitioners come for the 'how-to,' not just the 'why should you care,' and our thought leadership work with Supervizor is exactly that culmination. Getting to do it alongside people like Celia Viguier and the team at Supervizor, who care as much about internal auditors actually succeeding as we do, is what makes this collaboration worth being proud of."

If you're still building the analytics foundation underneath all of this, book a demo with Supervizor to start that conversation. If what you want is the peer network to compare notes with CAEs living through the same AI moment, that's exactly what the Internal Audit Collective exists for.

The leadership decisions behind a program that sticks matter more than the tooling ever did. What tends to matter after that gets more tactical: the specific analytics plays that work, transaction type by transaction type, told by the practitioners who ran them. Anyone who finds that useful should stay close to both organizations for what's next.

 

Nikki Young
Nikki is a freelance writer, editor, proofreader, and general word-nerd. Nikki has a 20+ year career background in internal audit, risk, and fraud, and now applies that knowledge in her writing and editorial work, rather than in daily practice. She holds her Certified Internal Auditor (CIA), Certification in Risk Management Assurance (CRMA), and Certified Fraud Examiner (CFE) designations. She is also an active member of both the Institute of Internal Auditors (IIA) and the Associated of Certified Fraud Examiners (ACFE).
See more