Enregistré dans:
| Auteurs principaux: | , , , , |
|---|---|
| Format: | Recurso digital |
| Langue: | anglais |
| Publié: |
Zenodo
2025
|
| Sujets: | |
| Accès en ligne: | https://doi.org/10.5281/zenodo.17962267 |
| Tags: |
Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
|
Table des matières:
- <p>Frontier AI developers operate at the intersection of rapid technical progress, extreme risk<br>exposure, and growing regulatory scrutiny. While a range of external evaluations and safety<br>frameworks have emerged, comparatively little attention has been paid to how internal<br>organizational assurance should be structured to provide sustained, evidence-based oversight<br>of catastrophic and systemic risks. This paper examines how an internal audit function could<br>be designed to provide meaningful assurance for frontier AI developers, and the practical<br>trade-offs that shape its effectiveness. Drawing on professional internal auditing standards,<br>risk-based assurance theory, and emerging frontier-AI governance literature, we analyze four<br>core design dimensions: (i) audit scope across model-level, system-level, and governance-<br>level controls; (ii) sourcing arrangements (in-house, co-sourced, and outsourced); (iii)<br>audit frequency and cadence; and (iv) access to sensitive information required for credible<br>assurance. For each dimension, we define the relevant option space, assess benefits and<br>limitations, and identify key organizational and security trade-offs.<br>We show that while model-level audits offer the most direct insight into dangerous capabili-<br>ties, system-level and governance-level audits provide broader and more durable coverage<br>as frontier risks increasingly depend on organizational controls rather than isolated model<br>failures. We further demonstrate that hybrid sourcing models anchored by an internal Chief<br>Audit Executive allow greater flexibility for tiered information access while preserving inde-<br>pendence and external credibility. Finally, we argue that differentiated audit frequencies and<br>carefully governed information access regimes are necessary to sustain assurance value in<br>environments where both technical capabilities and organizational structures evolve rapidly.<br>Our findings suggest that internal audit, if deliberately designed for the frontier AI context,<br>can play a central role in strengthening safety governance, complementing external evalua-<br>tions, and providing boards and regulators with higher-confidence, system-wide assurance<br>over catastrophic risk controls.</p>