Salvato in:
| Autori principali: | , , , , |
|---|---|
| Natura: | Recurso digital |
| Lingua: | inglese |
| Pubblicazione: |
Zenodo
2025
|
| Soggetti: | |
| Accesso online: | https://doi.org/10.5281/zenodo.17962267 |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866901846740697088 |
|---|---|
| author | Gomez, Francesca Buick, Adam Ferentinos, Leah Kim, Haelee Lee, Elley |
| author_facet | Gomez, Francesca Buick, Adam Ferentinos, Leah Kim, Haelee Lee, Elley |
| contents | <p>Frontier AI developers operate at the intersection of rapid technical progress, extreme risk<br>exposure, and growing regulatory scrutiny. While a range of external evaluations and safety<br>frameworks have emerged, comparatively little attention has been paid to how internal<br>organizational assurance should be structured to provide sustained, evidence-based oversight<br>of catastrophic and systemic risks. This paper examines how an internal audit function could<br>be designed to provide meaningful assurance for frontier AI developers, and the practical<br>trade-offs that shape its effectiveness. Drawing on professional internal auditing standards,<br>risk-based assurance theory, and emerging frontier-AI governance literature, we analyze four<br>core design dimensions: (i) audit scope across model-level, system-level, and governance-<br>level controls; (ii) sourcing arrangements (in-house, co-sourced, and outsourced); (iii)<br>audit frequency and cadence; and (iv) access to sensitive information required for credible<br>assurance. For each dimension, we define the relevant option space, assess benefits and<br>limitations, and identify key organizational and security trade-offs.<br>We show that while model-level audits offer the most direct insight into dangerous capabili-<br>ties, system-level and governance-level audits provide broader and more durable coverage<br>as frontier risks increasingly depend on organizational controls rather than isolated model<br>failures. We further demonstrate that hybrid sourcing models anchored by an internal Chief<br>Audit Executive allow greater flexibility for tiered information access while preserving inde-<br>pendence and external credibility. Finally, we argue that differentiated audit frequencies and<br>carefully governed information access regimes are necessary to sustain assurance value in<br>environments where both technical capabilities and organizational structures evolve rapidly.<br>Our findings suggest that internal audit, if deliberately designed for the frontier AI context,<br>can play a central role in strengthening safety governance, complementing external evalua-<br>tions, and providing boards and regulators with higher-confidence, system-wide assurance<br>over catastrophic risk controls.</p> |
| format | Recurso digital |
| id | zenodo_https___doi_org_10_5281_zenodo_17962267 |
| institution | Zenodo |
| language | eng |
| publishDate | 2025 |
| publisher | Zenodo |
| record_format | zenodo |
| spellingShingle | How frontier AI companies could implement an internal audit function Gomez, Francesca Buick, Adam Ferentinos, Leah Kim, Haelee Lee, Elley Artificial Intelligence/ethics <p>Frontier AI developers operate at the intersection of rapid technical progress, extreme risk<br>exposure, and growing regulatory scrutiny. While a range of external evaluations and safety<br>frameworks have emerged, comparatively little attention has been paid to how internal<br>organizational assurance should be structured to provide sustained, evidence-based oversight<br>of catastrophic and systemic risks. This paper examines how an internal audit function could<br>be designed to provide meaningful assurance for frontier AI developers, and the practical<br>trade-offs that shape its effectiveness. Drawing on professional internal auditing standards,<br>risk-based assurance theory, and emerging frontier-AI governance literature, we analyze four<br>core design dimensions: (i) audit scope across model-level, system-level, and governance-<br>level controls; (ii) sourcing arrangements (in-house, co-sourced, and outsourced); (iii)<br>audit frequency and cadence; and (iv) access to sensitive information required for credible<br>assurance. For each dimension, we define the relevant option space, assess benefits and<br>limitations, and identify key organizational and security trade-offs.<br>We show that while model-level audits offer the most direct insight into dangerous capabili-<br>ties, system-level and governance-level audits provide broader and more durable coverage<br>as frontier risks increasingly depend on organizational controls rather than isolated model<br>failures. We further demonstrate that hybrid sourcing models anchored by an internal Chief<br>Audit Executive allow greater flexibility for tiered information access while preserving inde-<br>pendence and external credibility. Finally, we argue that differentiated audit frequencies and<br>carefully governed information access regimes are necessary to sustain assurance value in<br>environments where both technical capabilities and organizational structures evolve rapidly.<br>Our findings suggest that internal audit, if deliberately designed for the frontier AI context,<br>can play a central role in strengthening safety governance, complementing external evalua-<br>tions, and providing boards and regulators with higher-confidence, system-wide assurance<br>over catastrophic risk controls.</p> |
| title | How frontier AI companies could implement an internal audit function |
| topic | Artificial Intelligence/ethics |
| url | https://doi.org/10.5281/zenodo.17962267 |