LLM Security Risks in Internal Audit: A Vendor Due-Diligence Checklist
Assess prompt injection, data exposure, access boundaries, subprocessors, retention, model training, and human approval before using AI with audit evidence.
IABuddy · 4 min read
Topic collection
Review LLM security questions, multi-client access boundaries, AI governance, evidence repositories, and human approval controls.
Start with the information that will enter the workflow and who may access it. The guides below organize vendor questions, client separation, evidence handling, and human review. Product security claims should be checked against current documentation and agreed contract terms.
Assess prompt injection, data exposure, access boundaries, subprocessors, retention, model training, and human approval before using AI with audit evidence.
IABuddy · 4 min read
Design multi-client audit workflows with clear workspaces, least-privilege access, isolated retrieval, controlled sharing, and tested offboarding practices.
IABuddy · 4 min read
Assess AI agents that affect financial reporting with a practical checklist for ownership, access, approvals, change management, evidence, and monitoring.
IABuddy · 4 min read
Design AI audit review gates for scope, evidence quality, proposed results, exceptions, and sign-off, with clear ownership and a record of human decisions.
IABuddy · 4 min read
Organize audit evidence with stable identifiers, useful metadata, version history, permissions, retention rules, and tested links to workpapers and conclusions.
IABuddy · 4 min read