How We Used AI to Review the Proposed TUSD Internal Audit Function Charter
- John C. Blackshire, Jr.

- Aug 16
- 11 min read
Updated: Aug 23
A Practical Case Study in Using AI for Governance, Internal Control, and Internal Audit Analysis
Artificial intelligence is frequently discussed as a tool for writing emails, summarizing documents, or generating presentations.
That barely scratches the surface of what AI can do for an auditor.
One of the more powerful applications is using AI as an analytical assistant in evaluating the design of an entity-level control.
We recently applied that approach to a proposed Tucson Unified School District (TUSD) Internal Audit Function Charter.
The project was not simply:
“Upload the charter to AI and ask whether it is good.”
That would have produced little more than a generic opinion.
Instead, the proposed charter was treated as a governance control, the requirements surrounding that control were broken into individual components, and AI was used to help compare the proposed design against multiple professional governance criteria.
The result was a substantially deeper review.
The final analysis identified 20 governance findings: 5 Critical, 8 High, and 7 Moderate.
More importantly, the AI-assisted process helped expose a central governance issue that would have been easy to miss in a conventional document review:
The charter was considerably stronger at explaining what the Internal Auditor could do than at explaining how the Governing Board and Audit Committee would govern the Internal Audit function.
That distinction became the foundation of the entire review.
The Document We Started With
TUSD's proposed charter was not an empty or fundamentally defective document.
It contained a number of important elements.
The charter stated that the Internal Audit activity had been re-established by the Governing Board and provided that both the charter and audit plan would be approved annually by the Board. It described Internal Audit's mission as providing independent and objective assurance and consulting services intended to improve District operations.
It also provided the Internal Auditor with broad authority, including unrestricted access to District functions, records, property, and personnel, as well as authority to allocate audit resources, determine scope, and obtain specialized assistance when necessary.
The charter contained other positive provisions.
It prohibited Internal Audit from taking operational responsibilities that could impair judgment, established direct reporting to the Governing Board, and required consultation with the Audit Committee in developing the annual audit plan.
It also required a risk-based audit plan, reporting of significant findings to the Audit Committee, follow-up of unresolved findings, a Quality Assurance and Improvement Program, external quality assessments at least every five years, and continuing professional education.
Those are meaningful strengths.
The AI-assisted review did not begin with an assumption that the charter was bad.
It began with a more disciplined audit question:
Is the charter designed well enough to create a sustainable, independent, accountable, and professionally governed Internal Audit function?
Step One: Define What the Control Is Supposed to Accomplish
This is where audit methodology matters.
Before asking AI to evaluate anything, we first needed to understand the control objective.
The objective was not:
“TUSD should have an Internal Audit Charter.”
TUSD already had one.
The actual objective was whether the charter established a governance structure capable of supporting Internal Audit with sufficient:
Independence
Authority
Resources
Accountability
Professional competence
Governing Board oversight
Audit Committee oversight
That distinction appears directly in the final review. The stated purpose was not merely to determine whether a charter existed, but whether the charter established the governance structure necessary for a modern public-sector Internal Audit function.
This is the same discipline auditors should apply to any internal control:
Objective → Risk → Control → Design Effectiveness
AI becomes considerably more useful once the auditor first establishes what the control is supposed to accomplish.
Step Two: Break the Charter Into Individual Governance Components
A charter is written as prose.
Auditors need to think in controls.
AI was useful in breaking the document into individual governance concepts.
For example:
Organizational Independence: Who does the Internal Auditor report to?
Functional Oversight: Who protects Internal Audit independence throughout the year?
Audit Planning: Who approves the risk-based audit plan?
Resources: Who determines whether the Internal Audit budget and staffing are adequate?
Performance: Who evaluates the Internal Auditor?
Appointment and Removal: Who controls employment decisions affecting the Internal Auditor?
Quality: Who oversees the QAIP and reviews external assessments?
Corrective Action: Who monitors significant unresolved findings?
This decomposition is important.
A five-page charter can contain dozens of distinct governance assertions.
AI makes it much easier to extract, categorize, and compare them systematically.
Step Three: Separate What the Charter Says From What It Does Not Say
This was one of the most valuable uses of AI.
Auditors are naturally good at reading what a document contains.
AI can help systematically identify what is missing.
For example, the charter explicitly stated:
“To ensure independence, the Internal Auditor shall report to the Governing Board.”
That is a strong provision.
But the analysis then asked:
What else must exist for organizational independence to work?
The review identified several responsibilities that were not explicitly assigned, including responsibility for safeguarding independence, reviewing organizational placement and resources, periodically evaluating Internal Audit effectiveness, overseeing the QAIP, reviewing external assessments, and monitoring management actions that could impair independence.
This illustrates an important AI audit technique:
Do not ask only, “What does the document say?” Ask, “What would I expect to find here that is absent?”
That turns AI from a summarization tool into a gap-analysis tool.
Step Four: Compare the Charter Against Multiple Governance Frameworks
A useful professional review requires criteria.
The project did not rely upon one generic model charter.
The analysis used a broader governance lens that included:
The 2025 Global Internal Audit Standards
The IIA Model Internal Audit Charter
COSO Internal Control—Integrated Framework
GAO Green Book
Government Auditing Standards, or Yellow Book
Government Finance Officers Association governance practices
The review's criteria explicitly incorporated these sources across findings.
This is an area where AI can significantly accelerate the auditor's work.
Instead of manually comparing the charter paragraph-by-paragraph with multiple frameworks, AI can help create a comparison matrix:
Governance Requirement | TUSD Charter Provision | Gap | Significance
The auditor then evaluates whether the apparent gap is real.
That final point is critical.
AI can identify a potential difference.
The auditor determines whether it constitutes a finding.
Step Five: Ask AI to Look Beyond the Reporting Line
This produced one of the project's most significant insights.
At first glance, TUSD appeared to have addressed independence reasonably well because the charter required the Internal Auditor to report directly to the Governing Board.
But independence is more than an organizational chart.
The review concluded that a complete functional relationship should also address activities such as:
Charter approval
Risk-based audit-plan approval
Resource sufficiency
Performance evaluation
Protection against interference
QAIP oversight
External quality assessments
The first Critical finding therefore concluded that the functional reporting relationship was not fully defined.
This is precisely where AI can make an auditor better.
A traditional review could easily stop at:
“Reports to Governing Board—good.”
The AI-assisted analysis pushed the next question:
What does reporting to the Governing Board actually mean operationally and functionally?
That deeper question exposed the governance gap.
Step Six: Examine the Audit Committee's Actual Authority
The same process was applied to the Audit Committee.
The proposed charter involved the Audit Committee in development of the annual audit plan and the annual independence declaration.
But AI-assisted gap analysis helped identify what was not clearly assigned to the Committee.
The review found that the charter did not explicitly establish Audit Committee authority for
activities such as monitoring Internal Audit independence, reviewing resource adequacy, monitoring implementation of the audit plan, reviewing significant findings, overseeing the QAIP, reviewing external quality assessments, evaluating Internal Audit effectiveness, meeting privately with the Internal Auditor, or participating in significant employment decisions affecting the Internal Auditor.
That became another Critical finding.
The real question was not:
“Does the charter mention the Audit Committee?”
It does.
The better question was:
“Does the charter give the Audit Committee enough defined responsibility to function as the Governing Board's continuous oversight mechanism for Internal Audit?”
The review concluded that it did not yet do so adequately.
Step Seven: Turn Governance Gaps Into Structured Audit Findings
AI was also useful for moving from a list of observations to a formal audit-finding structure.
Each significant issue was organized around:
Condition
What does the proposed charter currently provide?
Criteria
What should leading governance practice provide?
Cause
Why does the gap appear to exist?
Consequence
What could happen if it remains unresolved?
Risk
How important is the issue?
Recommendation
What should be changed?
Value Created
How would the organization benefit from fixing it?
Suggested Charter Language
What might an improved provision actually look like?
This structure matters because there is a large difference between saying:
“The charter doesn't discuss the Internal Auditor's evaluation.”
and developing a governance finding showing that the charter establishes many responsibilities for the Internal Auditor but does not identify who evaluates whether those responsibilities were effectively performed.
The final recommendation called for a formal annual evaluation by the Audit Committee, with recommendations presented to the Governing Board, using criteria such as audit-plan achievement, quality, communication, independence, QAIP results, stakeholder feedback, and standards compliance.
AI helped organize the analysis.
Professional judgment determined whether the issue merited a Critical risk classification.
Step Eight: Develop Actual Replacement Charter Language
This is another area where generative AI can create substantial efficiency.
It is easy to tell management:
“The charter should be improved.”
It is much harder—and much more valuable—to demonstrate what improvement could look like.
For the resource-governance finding, for example, the proposed language called for the Audit Committee to annually review Internal Audit staffing, budget, organizational placement, competencies, CPE, technology, data analytics, and access to specialized expertise. It also required the Internal Auditor to communicate resource limitations that could impair completion of the audit plan.
Similarly, proposed language surrounding appointment and removal would give the Governing Board authority over appointment, reappointment, compensation, and removal, with the Audit Committee assisting through recruitment, evaluation, compensation review, and recommendations.
This is a strong use of AI:
Identify Gap → Define Requirement → Draft Possible Language → Human Review
AI is particularly good at producing a first draft.
But the draft still requires review for:
Legal authority
Board policy
Organizational structure
Professional standards
Practicality
Unintended consequences
AI should draft.
Humans should approve.
Step Nine: Risk-Rank the Findings
Not every deficiency deserves the same attention.
The review ultimately categorized the issues into:
5 Critical
8 High
7 Moderate
for a total of 20 governance findings.
The five Critical areas were:
Functional reporting responsibilities
Audit Committee oversight
Internal Audit budget and resource oversight
Performance evaluation of the Internal Auditor
Appointment, reappointment, compensation, and removal authority
These issues were considered foundational because they affect the mechanisms that sustain Internal Audit independence and accountability.
The High findings moved into the next layer of Internal Audit maturity, including audit-universe governance, risk-assessment methodology, QAIP reporting, corrective-action follow-up, coordination with External Audit, fraud responsibilities, ERM integration, and cybersecurity auditing.
This prioritization made the analysis much more useful to governance.
Step Ten: Convert 70 Pages of Analysis Into a Governance Dashboard
One danger of AI is that it can generate too much information.
The final review ran approximately 70 pages.
An Audit Committee or Governing Board cannot govern effectively if the important issues are buried inside 70 pages of narrative.
So the detailed analysis was also converted into a Governance Dashboard.
The dashboard summarized the 20 findings by:
Priority
Finding
Governance Area
Risk Rating
The first five priorities were all Critical; the next eight were High; and the remaining seven were Moderate.
This illustrates another important AI use:
Use AI not only to expand analysis, but also to compress it for decision-makers.
The detailed report serves the auditor.
The dashboard serves governance.
Both are necessary.
Step Eleven: Force the AI to Identify Strengths
A governance review should not become an exercise in finding fault.
AI prompts can accidentally create that bias.
If you ask:
“Find everything wrong with this charter,”
AI will find things wrong with it.
That is not necessarily an objective audit methodology.
The review therefore also identified positive control features that should be preserved.
These included:
Direct Governing Board reporting
Broad audit authority
Protection of objectivity
Risk-based planning
QAIP requirements
External assessment
Professional development
The report specifically concluded that these provisions showed that TUSD had already incorporated many elements of a modern Internal Audit function.
This balanced analysis was important because the ultimate conclusion was not:
“The charter is a failure.”
Instead, the assessment was that it established a credible foundation, but not yet a leading-practice governance framework.
That is a much more defensible conclusion.
Step Twelve: Ask AI the Bigger Governance Question
Once the detailed findings were assembled, the analysis stepped back from individual provisions.
The key question became:
What pattern do all these findings reveal?
This is where AI is particularly strong.
It can look across dozens of issues and identify a recurring theme.
The final review characterized the charter as a basic-to-developing Internal Audit governance framework rather than a mature leading-practice framework.
The central governance conclusion was even clearer:
TUSD had established an Internal Audit function, but had not yet established a complete governance framework for governing that function.
The proposed charter was strongest where it discussed the Internal Auditor's authority and responsibilities.
It was weakest where it discussed the responsibilities of the people charged with governing the Internal Auditor.
That is the kind of pattern recognition that makes AI particularly useful in governance analysis.
AI Did Not Make the Audit Conclusion
This needs to be emphasized.
AI can:
Read
Compare
Categorize
Search for gaps
Develop questions
Organize findings
Draft language
Summarize results
Challenge conclusions
But AI does not possess professional accountability.
The auditor remains responsible for deciding:
Whether the criteria are appropriate
Whether the AI correctly interpreted the charter
Whether an apparent omission is actually a weakness
Whether other policies or laws address the issue
Whether the risk rating is supportable
Whether a recommendation is practical
Whether the final conclusion is fair
An AI-generated sentence is not audit evidence.
A professionally worded AI finding is not automatically a valid finding.
The auditor owns the conclusion.
AI Should Also Be Used to Attack the Auditor's Own Findings
One of the most valuable AI techniques is red teaming.
After developing a finding, ask the AI:
“Assume you are TUSD management and strongly disagree with this finding. Develop the strongest argument against it.”
Then ask:
“What evidence would be required to rebut that argument?”
Or:
“Identify assumptions in this finding that are not directly supported by the charter.”
This is a powerful safeguard against confirmation bias.
Auditors should not use AI only to prove themselves right.
They should also use it to discover where they might be wrong.
The Difference Between AI Writing and AI Auditing
There is an important distinction.
The least sophisticated use of AI is:
“Write me an audit report.”
A considerably more sophisticated workflow is:
Understand the Objective
↓
Provide the Source Document
↓
Define Authoritative Criteria
↓
Decompose the Control
↓
Compare Requirements
↓
Identify Potential Gaps
↓
Validate Each Gap
↓
Risk-Rank Findings
↓
Develop Corrective Actions
↓
Draft Suggested Language
↓
Red-Team the Findings
↓
Prepare Governance Reporting
That is not simply AI-assisted writing.
That is AI-assisted audit methodology.
What Did the Review Ultimately Find?
The review did not conclude that TUSD lacked the foundations for Internal Audit.
Quite the opposite.
The charter provided a useful structural base, including direct Board reporting, broad access authority, risk-based planning, quality assurance, external assessments, and professional development.
The major weakness was the governance architecture surrounding those provisions.
The report concluded that structural improvements were needed in five foundational areas: functional oversight, Audit Committee governance, resource sufficiency, Internal Auditor evaluation, and authority over appointment, compensation, and removal.
The objective was therefore not simply to rewrite some paragraphs.
It was to move the charter from an operational Internal Audit document toward a comprehensive Internal Audit governance framework.
What Other Internal Auditors Can Learn From This Project
The methodology is not limited to TUSD.
It could be used to review:
Internal Audit Charters
Audit Committee Charters
Enterprise Risk Management policies
SOX governance documents
Cybersecurity policies
Procurement policies
Delegations of authority
Fraud programs
Ethics policies
The underlying method remains the same:
Don't ask AI whether the document is good.
Ask:
What objective is this control supposed to accomplish?
What authoritative criteria apply?
What does the document require?
What is missing?
What risk does the gap create?
What would a stronger control look like?
Those are audit questions.
AI simply allows the auditor to ask them against much larger bodies of information, much faster.
The Bottom Line
The TUSD Internal Audit Function Charter project demonstrated an important lesson about artificial intelligence and auditing.
AI's greatest value is not that it can write faster.
Its greater value is that it can help auditors think more broadly, compare more systematically, challenge assumptions, identify patterns, and communicate complicated governance issues more effectively.
But that requires disciplined use.
The TUSD review began with a five-page proposed charter. That charter contained substantial strengths, including direct Governing Board reporting, broad audit authority, a risk-based plan, QAIP, external assessments, and professional-development requirements.
AI-assisted analysis helped transform that relatively short governance document into a much deeper examination of the system surrounding the Internal Audit function.
The final result identified 20 governance issues, prioritized them according to risk, developed detailed findings and possible charter language, and reduced the overall analysis to one central conclusion:
TUSD had established the operational foundation for an Internal Audit function. The next challenge was establishing the governance system necessary to protect and sustain it.
That is exactly the type of work where AI can make an experienced auditor considerably more effective.
Let AI process the information.
Let AI identify potential patterns and gaps.
Let AI challenge the analysis.
Let AI help communicate the results.
But keep the most important responsibility exactly where it belongs:
Professional judgment remains with the auditor.
Comments