Salvato in:
Dettagli Bibliografici
Autori principali: Gomez, Francesca, Buick, Adam, Ferentinos, Leah, Kim, Haelee, Lee, Elley
Natura: Recurso digital
Lingua:inglese
Pubblicazione: Zenodo 2025
Soggetti:
Accesso online:https://doi.org/10.5281/zenodo.17962267
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866901846740697088
author Gomez, Francesca
Buick, Adam
Ferentinos, Leah
Kim, Haelee
Lee, Elley
author_facet Gomez, Francesca
Buick, Adam
Ferentinos, Leah
Kim, Haelee
Lee, Elley
contents <p>Frontier AI developers operate at the intersection of rapid technical progress, extreme risk<br>exposure, and growing regulatory scrutiny. While a range of external evaluations and safety<br>frameworks have emerged, comparatively little attention has been paid to how internal<br>organizational assurance should be structured to provide sustained, evidence-based oversight<br>of catastrophic and systemic risks. This paper examines how an internal audit function could<br>be designed to provide meaningful assurance for frontier AI developers, and the practical<br>trade-offs that shape its effectiveness. Drawing on professional internal auditing standards,<br>risk-based assurance theory, and emerging frontier-AI governance literature, we analyze four<br>core design dimensions: (i) audit scope across model-level, system-level, and governance-<br>level controls; (ii) sourcing arrangements (in-house, co-sourced, and outsourced); (iii)<br>audit frequency and cadence; and (iv) access to sensitive information required for credible<br>assurance. For each dimension, we define the relevant option space, assess benefits and<br>limitations, and identify key organizational and security trade-offs.<br>We show that while model-level audits offer the most direct insight into dangerous capabili-<br>ties, system-level and governance-level audits provide broader and more durable coverage<br>as frontier risks increasingly depend on organizational controls rather than isolated model<br>failures. We further demonstrate that hybrid sourcing models anchored by an internal Chief<br>Audit Executive allow greater flexibility for tiered information access while preserving inde-<br>pendence and external credibility. Finally, we argue that differentiated audit frequencies and<br>carefully governed information access regimes are necessary to sustain assurance value in<br>environments where both technical capabilities and organizational structures evolve rapidly.<br>Our findings suggest that internal audit, if deliberately designed for the frontier AI context,<br>can play a central role in strengthening safety governance, complementing external evalua-<br>tions, and providing boards and regulators with higher-confidence, system-wide assurance<br>over catastrophic risk controls.</p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_17962267
institution Zenodo
language eng
publishDate 2025
publisher Zenodo
record_format zenodo
spellingShingle How frontier AI companies could implement an internal audit function
Gomez, Francesca
Buick, Adam
Ferentinos, Leah
Kim, Haelee
Lee, Elley
Artificial Intelligence/ethics
<p>Frontier AI developers operate at the intersection of rapid technical progress, extreme risk<br>exposure, and growing regulatory scrutiny. While a range of external evaluations and safety<br>frameworks have emerged, comparatively little attention has been paid to how internal<br>organizational assurance should be structured to provide sustained, evidence-based oversight<br>of catastrophic and systemic risks. This paper examines how an internal audit function could<br>be designed to provide meaningful assurance for frontier AI developers, and the practical<br>trade-offs that shape its effectiveness. Drawing on professional internal auditing standards,<br>risk-based assurance theory, and emerging frontier-AI governance literature, we analyze four<br>core design dimensions: (i) audit scope across model-level, system-level, and governance-<br>level controls; (ii) sourcing arrangements (in-house, co-sourced, and outsourced); (iii)<br>audit frequency and cadence; and (iv) access to sensitive information required for credible<br>assurance. For each dimension, we define the relevant option space, assess benefits and<br>limitations, and identify key organizational and security trade-offs.<br>We show that while model-level audits offer the most direct insight into dangerous capabili-<br>ties, system-level and governance-level audits provide broader and more durable coverage<br>as frontier risks increasingly depend on organizational controls rather than isolated model<br>failures. We further demonstrate that hybrid sourcing models anchored by an internal Chief<br>Audit Executive allow greater flexibility for tiered information access while preserving inde-<br>pendence and external credibility. Finally, we argue that differentiated audit frequencies and<br>carefully governed information access regimes are necessary to sustain assurance value in<br>environments where both technical capabilities and organizational structures evolve rapidly.<br>Our findings suggest that internal audit, if deliberately designed for the frontier AI context,<br>can play a central role in strengthening safety governance, complementing external evalua-<br>tions, and providing boards and regulators with higher-confidence, system-wide assurance<br>over catastrophic risk controls.</p>
title How frontier AI companies could implement an internal audit function
topic Artificial Intelligence/ethics
url https://doi.org/10.5281/zenodo.17962267