The 2025 GAO Green Book and AI: Why Strong Internal Controls Matter More Than Ever
- John C. Blackshire, Jr.

- 2 days ago
- 5 min read
Artificial Intelligence is transforming government operations at every level.
Federal agencies, state governments, municipalities, educational institutions, healthcare organizations, and nonprofit entities are rapidly adopting AI to automate workflows, improve citizen services, detect fraud, analyze spending, and strengthen decision-making. At the same time, these technologies introduce new risks involving cybersecurity, data integrity, privacy, model governance, and accountability.
As government operations become increasingly digital, one thing has not changed:
Strong internal controls remain the foundation of effective governance.
That is precisely why the 2025 revision of the GAO Green Book (Standards for Internal Control in the Federal Government) is so important. The updated standards place greater emphasis on fraud risk, improper payments, information security, preventive controls, and accountability, helping organizations address today's rapidly changing risk environment.
The GAO Green Book Standards CPE program from Corporate Compliance Seminars helps government professionals, auditors, compliance officers, grant administrators, and internal control specialists understand how to implement these updated standards while preparing their organizations for the challenges created by Artificial Intelligence and digital transformation.
What Is the GAO Green Book?
The GAO Green Book, formally titled Standards for Internal Control in the Federal Government, provides the framework federal agencies use to design, implement, operate, and continuously improve effective systems of internal control. This is the GAO improved edition of the COSO framework. The GAO has done an excellent job of improving the documentation of an effective internal control framework compared to the COSO documentation.
Although written for the federal government, the Green Book is widely used by:
State governments
County governments
Municipal governments
School districts
Universities
Tribal governments
Healthcare organizations
Nonprofits
Government contractors
Organizations managing federal grants
The framework helps management achieve three fundamental objectives:
Effective and efficient operations
Reliable reporting
Compliance with laws and regulations
These objectives are as relevant to AI-enabled organizations as they were before the rise of intelligent technologies.
Why the 2025 Green Book Matters
Government programs are becoming more complex.
Agencies increasingly manage:
Artificial Intelligence initiatives
Cloud computing
Cybersecurity risks
Large grant programs
Digital citizen services
Data analytics
Automated financial systems
Third-party service providers
Recognizing these changes, GAO updated the Green Book in 2025 to strengthen guidance in several important areas, including:
Fraud risk
Improper payments
Information security
Preventive controls
Risk documentation
Accountability across all organizational levels
Managing new and significantly changed programs
These updates reflect the reality that modern internal control systems must evolve as technology and risks evolve.
AI Is Creating New Internal Control Challenges
Artificial Intelligence improves productivity.
It also creates entirely new categories of risk.
Organizations now need internal controls over:
AI-generated decisions
Machine learning models
Automated workflows
Data quality
Prompt management
AI access controls
Human review of AI outputs
Model monitoring
AI cybersecurity
Regulatory compliance
Internal auditors increasingly ask questions such as:
Who approved the AI model?
What data trained the model?
How are AI outputs validated?
Can management override AI decisions?
Are AI activities logged?
How are changes monitored?
Who is accountable when AI produces incorrect results?
The Green Book's principles of governance, risk assessment, control activities, information and communication, and monitoring provide an excellent framework for answering these questions—even though AI itself did not exist when earlier versions of the framework were developed.
The Five Components Still Drive Effective Governance
The Green Book organizes internal control into five integrated components:
1. Control Environment: Leadership establishes integrity, ethical values, accountability, and organizational culture.
Organizations implementing AI need executives who clearly define acceptable AI use and establish governance over emerging technologies.
2. Risk Assessment: Management identifies risks that could prevent achievement of organizational objectives.
Today those risks include:
AI bias
Cybersecurity
Privacy
Data quality
Fraud
Third-party vendors
Automated decision-making
3. Control Activities: Management designs controls to mitigate identified risks.
Examples include:
Approval workflows
Access controls
Segregation of duties
Preventive controls
Automated validations
AI governance reviews
4. Information and Communication: Reliable information must reach decision makers in a timely manner.
As organizations increasingly depend on AI-generated insights, controls over data accuracy and communication become even more important.
5. Monitoring: Internal control systems require continuous monitoring and improvement.
Organizations should regularly evaluate whether both traditional controls and AI-related controls remain effective as technology changes.
These five components continue to provide one of the strongest governance frameworks available for public-sector organizations.
Fraud Prevention Begins with Strong Internal Controls
Government agencies manage billions of taxpayer dollars every year.
Without effective internal controls, organizations become more vulnerable to:
Fraud
Improper payments
Procurement abuse
Grant misuse
Payroll fraud
Cybercrime
Financial reporting errors
Asset misappropriation
The updated Green Book places increased emphasis on identifying and preventing these risks through proactive internal control systems rather than relying solely on detective controls after losses occur.
AI Will Improve Internal Auditing—Not Replace Internal Auditors
Internal Audit departments are rapidly adopting AI to improve efficiency.
Today's auditors use AI to:
Analyze large transaction populations
Review contracts
Summarize policies
Identify unusual transactions
Draft audit programs
Prepare workpapers
Generate executive summaries
Research regulations
Assist with risk assessments
These tools save time.
However, AI cannot replace:
Professional judgment
Ethical decision-making
Risk prioritization
Governance oversight
Board communication
Independent assurance
Those responsibilities remain firmly with experienced audit and compliance professionals.
What You'll Learn in the GAO Green Book Standards CPE Program
The GAO Green Book Standards course from Corporate Compliance Seminars is built around the 2025 revision of the Green Book and provides practical guidance for implementing effective internal control systems. Participants learn how to:
Understand the five components, 17 principles, and 52 attributes of the Green Book
Apply the framework to operational, compliance, fraud, and information security risks
Evaluate internal control effectiveness using maturity concepts
Align Green Book principles with COSO
Strengthen risk assessment and monitoring processes
Support compliance with Uniform Guidance and federal grant requirements
Build a stronger culture of accountability and continuous improvement
Apply Green Book concepts to modern AI-enabled business processes and government operations
The course focuses on translating the Green Book from a compliance document into a practical management framework that improves organizational performance and governance.
Who Should Attend?
This program is ideal for professionals responsible for governance, compliance, and accountability, including:
Internal Auditors
Government Auditors
Compliance Officers
Federal Managers
State and Local Government Officials
Grant Administrators
Inspectors General Staff
Risk Managers
Financial Managers
Program Managers
School District Administrators
Government Contractors
Whether your organization is implementing new AI tools, managing federal grants, or strengthening enterprise risk management, the Green Book provides a proven framework for building resilient internal controls.
The Future of Government Accountability
Artificial Intelligence will continue transforming public-sector operations.
Digital services will expand.
Cyber threats will evolve.
Federal funding programs will become increasingly complex.
The organizations that succeed will not simply adopt new technologies—they will implement strong governance structures that ensure those technologies operate responsibly, transparently, and effectively.
The GAO Green Book provides exactly that foundation.
If you are responsible for internal controls, government auditing, compliance, enterprise risk management, or federal grant oversight, the GAO Green Book Standards CPE program from Corporate Compliance Seminars provides practical, immediately applicable guidance for implementing one of the most respected internal control frameworks in government while preparing your organization for the AI-driven future.
Comments