top of page
Search

How We Used AI to Review the Proposed TUSD Internal Audit Function Charter

Aug 16
11 min read

Updated: Aug 23

A Practical Case Study in Using AI for Governance, Internal Control, and Internal Audit Analysis

Artificial intelligence is frequently discussed as a tool for writing emails, summarizing documents, or generating presentations.


That barely scratches the surface of what AI can do for an auditor.


One of the more powerful applications is using AI as an analytical assistant in evaluating the design of an entity-level control.


We recently applied that approach to a proposed Tucson Unified School District (TUSD) Internal Audit Function Charter.


The project was not simply:

“Upload the charter to AI and ask whether it is good.”

That would have produced little more than a generic opinion.


Instead, the proposed charter was treated as a governance control, the requirements surrounding that control were broken into individual components, and AI was used to help compare the proposed design against multiple professional governance criteria.


The result was a substantially deeper review.


The final analysis identified 20 governance findings: 5 Critical, 8 High, and 7 Moderate.


More importantly, the AI-assisted process helped expose a central governance issue that would have been easy to miss in a conventional document review:

The charter was considerably stronger at explaining what the Internal Auditor could do than at explaining how the Governing Board and Audit Committee would govern the Internal Audit function. 

That distinction became the foundation of the entire review.


The Document We Started With

TUSD's proposed charter was not an empty or fundamentally defective document.


It contained a number of important elements.


The charter stated that the Internal Audit activity had been re-established by the Governing Board and provided that both the charter and audit plan would be approved annually by the Board. It described Internal Audit's mission as providing independent and objective assurance and consulting services intended to improve District operations.


It also provided the Internal Auditor with broad authority, including unrestricted access to District functions, records, property, and personnel, as well as authority to allocate audit resources, determine scope, and obtain specialized assistance when necessary.


The charter contained other positive provisions.


It prohibited Internal Audit from taking operational responsibilities that could impair judgment, established direct reporting to the Governing Board, and required consultation with the Audit Committee in developing the annual audit plan.


It also required a risk-based audit plan, reporting of significant findings to the Audit Committee, follow-up of unresolved findings, a Quality Assurance and Improvement Program, external quality assessments at least every five years, and continuing professional education.  


Those are meaningful strengths.


The AI-assisted review did not begin with an assumption that the charter was bad.


It began with a more disciplined audit question:

Is the charter designed well enough to create a sustainable, independent, accountable, and professionally governed Internal Audit function?

Step One: Define What the Control Is Supposed to Accomplish

This is where audit methodology matters.


Before asking AI to evaluate anything, we first needed to understand the control objective.

The objective was not:

“TUSD should have an Internal Audit Charter.”

TUSD already had one.


The actual objective was whether the charter established a governance structure capable of supporting Internal Audit with sufficient:

  • Independence

  • Authority

  • Resources

  • Accountability

  • Professional competence

  • Governing Board oversight

  • Audit Committee oversight


That distinction appears directly in the final review. The stated purpose was not merely to determine whether a charter existed, but whether the charter established the governance structure necessary for a modern public-sector Internal Audit function.


This is the same discipline auditors should apply to any internal control:


Objective → Risk → Control → Design Effectiveness


AI becomes considerably more useful once the auditor first establishes what the control is supposed to accomplish.


Step Two: Break the Charter Into Individual Governance Components

A charter is written as prose.


Auditors need to think in controls.


AI was useful in breaking the document into individual governance concepts.


For example:

Organizational Independence: Who does the Internal Auditor report to?


Functional Oversight: Who protects Internal Audit independence throughout the year?


Audit Planning: Who approves the risk-based audit plan?


Resources: Who determines whether the Internal Audit budget and staffing are adequate?


Performance: Who evaluates the Internal Auditor?


Appointment and Removal: Who controls employment decisions affecting the Internal Auditor?


Quality: Who oversees the QAIP and reviews external assessments?


Corrective Action: Who monitors significant unresolved findings?


This decomposition is important.


A five-page charter can contain dozens of distinct governance assertions.


AI makes it much easier to extract, categorize, and compare them systematically.


Step Three: Separate What the Charter Says From What It Does Not Say

This was one of the most valuable uses of AI.


Auditors are naturally good at reading what a document contains.


AI can help systematically identify what is missing.


For example, the charter explicitly stated:

“To ensure independence, the Internal Auditor shall report to the Governing Board.”

That is a strong provision.


But the analysis then asked:

What else must exist for organizational independence to work?

The review identified several responsibilities that were not explicitly assigned, including responsibility for safeguarding independence, reviewing organizational placement and resources, periodically evaluating Internal Audit effectiveness, overseeing the QAIP, reviewing external assessments, and monitoring management actions that could impair independence.


This illustrates an important AI audit technique:

Do not ask only, “What does the document say?” Ask, “What would I expect to find here that is absent?”

That turns AI from a summarization tool into a gap-analysis tool.


Step Four: Compare the Charter Against Multiple Governance Frameworks

A useful professional review requires criteria.


The project did not rely upon one generic model charter.


The analysis used a broader governance lens that included:

  • The 2025 Global Internal Audit Standards

  • The IIA Model Internal Audit Charter

  • COSO Internal Control—Integrated Framework

  • GAO Green Book

  • Government Auditing Standards, or Yellow Book

  • Government Finance Officers Association governance practices


The review's criteria explicitly incorporated these sources across findings.


This is an area where AI can significantly accelerate the auditor's work.


Instead of manually comparing the charter paragraph-by-paragraph with multiple frameworks, AI can help create a comparison matrix:


Governance Requirement | TUSD Charter Provision | Gap | Significance


The auditor then evaluates whether the apparent gap is real.


That final point is critical.


AI can identify a potential difference.


The auditor determines whether it constitutes a finding.


Step Five: Ask AI to Look Beyond the Reporting Line

This produced one of the project's most significant insights.


At first glance, TUSD appeared to have addressed independence reasonably well because the charter required the Internal Auditor to report directly to the Governing Board.


But independence is more than an organizational chart.


The review concluded that a complete functional relationship should also address activities such as:

  • Charter approval

  • Risk-based audit-plan approval

  • Resource sufficiency

  • Performance evaluation

  • Protection against interference

  • QAIP oversight

  • External quality assessments


The first Critical finding therefore concluded that the functional reporting relationship was not fully defined.


This is precisely where AI can make an auditor better.


A traditional review could easily stop at:

“Reports to Governing Board—good.”

The AI-assisted analysis pushed the next question:

What does reporting to the Governing Board actually mean operationally and functionally?

That deeper question exposed the governance gap.


Step Six: Examine the Audit Committee's Actual Authority

The same process was applied to the Audit Committee.


The proposed charter involved the Audit Committee in development of the annual audit plan and the annual independence declaration.


But AI-assisted gap analysis helped identify what was not clearly assigned to the Committee.


The review found that the charter did not explicitly establish Audit Committee authority for

activities such as monitoring Internal Audit independence, reviewing resource adequacy, monitoring implementation of the audit plan, reviewing significant findings, overseeing the QAIP, reviewing external quality assessments, evaluating Internal Audit effectiveness, meeting privately with the Internal Auditor, or participating in significant employment decisions affecting the Internal Auditor.


That became another Critical finding.


The real question was not:

“Does the charter mention the Audit Committee?”

It does.


The better question was:

“Does the charter give the Audit Committee enough defined responsibility to function as the Governing Board's continuous oversight mechanism for Internal Audit?”

The review concluded that it did not yet do so adequately.


Step Seven: Turn Governance Gaps Into Structured Audit Findings

AI was also useful for moving from a list of observations to a formal audit-finding structure.


Each significant issue was organized around:

  • Condition

    • What does the proposed charter currently provide?

  • Criteria

    • What should leading governance practice provide?

  • Cause

    • Why does the gap appear to exist?

  • Consequence

    • What could happen if it remains unresolved?

  • Risk

    • How important is the issue?

  • Recommendation

    • What should be changed?

  • Value Created

    • How would the organization benefit from fixing it?

  • Suggested Charter Language

    • What might an improved provision actually look like?


This structure matters because there is a large difference between saying:

“The charter doesn't discuss the Internal Auditor's evaluation.”

and developing a governance finding showing that the charter establishes many responsibilities for the Internal Auditor but does not identify who evaluates whether those responsibilities were effectively performed.


The final recommendation called for a formal annual evaluation by the Audit Committee, with recommendations presented to the Governing Board, using criteria such as audit-plan achievement, quality, communication, independence, QAIP results, stakeholder feedback, and standards compliance.


AI helped organize the analysis.


Professional judgment determined whether the issue merited a Critical risk classification.


Step Eight: Develop Actual Replacement Charter Language

This is another area where generative AI can create substantial efficiency.

It is easy to tell management:

“The charter should be improved.”

It is much harder—and much more valuable—to demonstrate what improvement could look like.


For the resource-governance finding, for example, the proposed language called for the Audit Committee to annually review Internal Audit staffing, budget, organizational placement, competencies, CPE, technology, data analytics, and access to specialized expertise. It also required the Internal Auditor to communicate resource limitations that could impair completion of the audit plan.


Similarly, proposed language surrounding appointment and removal would give the Governing Board authority over appointment, reappointment, compensation, and removal, with the Audit Committee assisting through recruitment, evaluation, compensation review, and recommendations.


This is a strong use of AI:


Identify Gap → Define Requirement → Draft Possible Language → Human Review


AI is particularly good at producing a first draft.


But the draft still requires review for:

  • Legal authority

  • Board policy

  • Organizational structure

  • Professional standards

  • Practicality

  • Unintended consequences

AI should draft.


Humans should approve.


Step Nine: Risk-Rank the Findings

Not every deficiency deserves the same attention.


The review ultimately categorized the issues into:

  • 5 Critical

  • 8 High

  • 7 Moderate

for a total of 20 governance findings.


The five Critical areas were:

  1. Functional reporting responsibilities

  2. Audit Committee oversight

  3. Internal Audit budget and resource oversight

  4. Performance evaluation of the Internal Auditor

  5. Appointment, reappointment, compensation, and removal authority


These issues were considered foundational because they affect the mechanisms that sustain Internal Audit independence and accountability.


The High findings moved into the next layer of Internal Audit maturity, including audit-universe governance, risk-assessment methodology, QAIP reporting, corrective-action follow-up, coordination with External Audit, fraud responsibilities, ERM integration, and cybersecurity auditing.


This prioritization made the analysis much more useful to governance.


Step Ten: Convert 70 Pages of Analysis Into a Governance Dashboard

One danger of AI is that it can generate too much information.


The final review ran approximately 70 pages.


An Audit Committee or Governing Board cannot govern effectively if the important issues are buried inside 70 pages of narrative.


So the detailed analysis was also converted into a Governance Dashboard.


The dashboard summarized the 20 findings by:

  • Priority

  • Finding

  • Governance Area

  • Risk Rating


The first five priorities were all Critical; the next eight were High; and the remaining seven were Moderate.


This illustrates another important AI use:

Use AI not only to expand analysis, but also to compress it for decision-makers.

The detailed report serves the auditor.


The dashboard serves governance.


Both are necessary.


Step Eleven: Force the AI to Identify Strengths

A governance review should not become an exercise in finding fault.


AI prompts can accidentally create that bias.


If you ask:

“Find everything wrong with this charter,”

AI will find things wrong with it.


That is not necessarily an objective audit methodology.


The review therefore also identified positive control features that should be preserved.


These included:

  • Direct Governing Board reporting

  • Broad audit authority

  • Protection of objectivity

  • Risk-based planning

  • QAIP requirements

  • External assessment

  • Professional development


The report specifically concluded that these provisions showed that TUSD had already incorporated many elements of a modern Internal Audit function.


This balanced analysis was important because the ultimate conclusion was not:

“The charter is a failure.”

Instead, the assessment was that it established a credible foundation, but not yet a leading-practice governance framework.


That is a much more defensible conclusion.


Step Twelve: Ask AI the Bigger Governance Question

Once the detailed findings were assembled, the analysis stepped back from individual provisions.


The key question became:

What pattern do all these findings reveal?

This is where AI is particularly strong.


It can look across dozens of issues and identify a recurring theme.


The final review characterized the charter as a basic-to-developing Internal Audit governance framework rather than a mature leading-practice framework.


The central governance conclusion was even clearer:

TUSD had established an Internal Audit function, but had not yet established a complete governance framework for governing that function.

The proposed charter was strongest where it discussed the Internal Auditor's authority and responsibilities.


It was weakest where it discussed the responsibilities of the people charged with governing the Internal Auditor.


That is the kind of pattern recognition that makes AI particularly useful in governance analysis.


AI Did Not Make the Audit Conclusion

This needs to be emphasized.


AI can:

  • Read

  • Compare

  • Categorize

  • Search for gaps

  • Develop questions

  • Organize findings

  • Draft language

  • Summarize results

  • Challenge conclusions


But AI does not possess professional accountability.


The auditor remains responsible for deciding:

  • Whether the criteria are appropriate

  • Whether the AI correctly interpreted the charter

  • Whether an apparent omission is actually a weakness

  • Whether other policies or laws address the issue

  • Whether the risk rating is supportable

  • Whether a recommendation is practical

  • Whether the final conclusion is fair


An AI-generated sentence is not audit evidence.


A professionally worded AI finding is not automatically a valid finding.


The auditor owns the conclusion.


AI Should Also Be Used to Attack the Auditor's Own Findings

One of the most valuable AI techniques is red teaming.


After developing a finding, ask the AI:

“Assume you are TUSD management and strongly disagree with this finding. Develop the strongest argument against it.”

Then ask:

“What evidence would be required to rebut that argument?”

Or:

“Identify assumptions in this finding that are not directly supported by the charter.”

This is a powerful safeguard against confirmation bias.


Auditors should not use AI only to prove themselves right.


They should also use it to discover where they might be wrong.


The Difference Between AI Writing and AI Auditing

There is an important distinction.


The least sophisticated use of AI is:

“Write me an audit report.”

A considerably more sophisticated workflow is:


Understand the Objective

Provide the Source Document

Define Authoritative Criteria

Decompose the Control

Compare Requirements

Identify Potential Gaps

Validate Each Gap

Risk-Rank Findings

Develop Corrective Actions

Draft Suggested Language

Red-Team the Findings

Prepare Governance Reporting


That is not simply AI-assisted writing.


That is AI-assisted audit methodology.


What Did the Review Ultimately Find?

The review did not conclude that TUSD lacked the foundations for Internal Audit.


Quite the opposite.


The charter provided a useful structural base, including direct Board reporting, broad access authority, risk-based planning, quality assurance, external assessments, and professional development.


The major weakness was the governance architecture surrounding those provisions.


The report concluded that structural improvements were needed in five foundational areas: functional oversight, Audit Committee governance, resource sufficiency, Internal Auditor evaluation, and authority over appointment, compensation, and removal.


The objective was therefore not simply to rewrite some paragraphs.


It was to move the charter from an operational Internal Audit document toward a comprehensive Internal Audit governance framework.


What Other Internal Auditors Can Learn From This Project

The methodology is not limited to TUSD.


It could be used to review:

  • Internal Audit Charters

  • Audit Committee Charters

  • Enterprise Risk Management policies

  • SOX governance documents

  • Cybersecurity policies

  • Procurement policies

  • Delegations of authority

  • Fraud programs

  • Ethics policies


The underlying method remains the same:

Don't ask AI whether the document is good.

Ask:

What objective is this control supposed to accomplish?
What authoritative criteria apply?
What does the document require?
What is missing?
What risk does the gap create?
What would a stronger control look like?

Those are audit questions.


AI simply allows the auditor to ask them against much larger bodies of information, much faster.


The Bottom Line

The TUSD Internal Audit Function Charter project demonstrated an important lesson about artificial intelligence and auditing.


AI's greatest value is not that it can write faster.


Its greater value is that it can help auditors think more broadly, compare more systematically, challenge assumptions, identify patterns, and communicate complicated governance issues more effectively.


But that requires disciplined use.


The TUSD review began with a five-page proposed charter. That charter contained substantial strengths, including direct Governing Board reporting, broad audit authority, a risk-based plan, QAIP, external assessments, and professional-development requirements.  

AI-assisted analysis helped transform that relatively short governance document into a much deeper examination of the system surrounding the Internal Audit function.


The final result identified 20 governance issues, prioritized them according to risk, developed detailed findings and possible charter language, and reduced the overall analysis to one central conclusion:

TUSD had established the operational foundation for an Internal Audit function. The next challenge was establishing the governance system necessary to protect and sustain it. 

That is exactly the type of work where AI can make an experienced auditor considerably more effective.

  • Let AI process the information.

  • Let AI identify potential patterns and gaps.

  • Let AI challenge the analysis.

  • Let AI help communicate the results.


But keep the most important responsibility exactly where it belongs:

Professional judgment remains with the auditor.



Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page