Bank strengthens oversight of 1,000+ AI initiatives without slowing innovation
7
AI governance domains now under active audit coverage
100+
production AI use cases with governance oversight validated
1000+
AI initiatives governed under a framework strengthened for emerging AI risks
At a glance
Client
Global financial services company
Industry
Banking
Our role
AI governance lifecycle audit advisor
Our solution
Agentic AI audit readiness
Scenario
A mature audit function meets autonomous AI
A large global financial services organization had made significant investments in AI and had the governance infrastructure to match: a strong model risk management function, mature AI governance capabilities, alignment to regulatory obligations, compliance audits already completed, and thousands of AI initiatives inventoried and routed through an enterprise governance platform.
However, emerging technology and infrastructure landscape continued to impact the company, and the portfolio of AI tools in use across the company was continuously changing.
As adoption accelerated, the client’s internal audit leadership could see AI systems evolving from predictive models and chat-based assistants into autonomous systems: agents that invoke tools, access enterprise data, execute workflows and make decisions with increasing levels of independence. These systems introduced risk considerations that differed from earlier models and control environments. Where traditional AI governance assumes risk can be managed before deployment through policies, reviews and approvals, agentic AI systems work differently. They make decisions in runtime, in response to new conditions. Oversight had to move at that speed.
The team wanted to understand how emerging technologies such as agentic AI and open-source models with complex AI workflows, and their net-new risks, could be evaluated. At the same time, they sought alignment with regulatory expectations, the NIST AI Risk Management Framework and enterprise governance objectives.
They needed an audit approach built to properly oversee these new conditions, without repeating work already being done by existing model risk management and compliance programs. They aimed to add value to the innovation already underway without slowing it down.
Key agentic AI risks the team sought to evaluate
- Agent autonomy and decision-making
- Tool invocation and excessive permissions
- Unauthorized actions
- Prompt manipulation and model abuse
- Data privacy and information leakage
- Human oversight and accountability
- Operational resilience
- Model drift and continuous monitoring
- Third-party AI risk management
- Open-source AI risks
- Auditability and evidence generation
Approach
Auditing more than the model
The bank's internal audit function already had strong AI governance coverage, but it didn’t yet have an approach built for autonomous systems going live across the enterprise.
Grant Thornton was engaged to support the client’s internal audit team with specialized AI governance and risk expertise for its first AI lifecycle audit.
A traditional audit would have concentrated on the AI model itself: performance, validation activities, documentation and regulatory compliance. This audit followed the AI lifecycle instead, identifying risks and control points at each phase from development through deployment, monitoring and decommissioning. That structure made the scope easier to explain to the teams being audited: this was an AI lifecycle audit, testing controls that model risk management didn’t cover.
| Traditional AI audit and model risk management programs focus on: | An AI lifecycle audit covers: |
|---|---|
|
|
Building from internal audit leaders’ existing AI audit knowledge and operations, Grant Thornton identified key questions to help them evaluate their existing AI governance and risk assessment inputs and processes. They also facilitated knowledge-sharing in emerging areas of audit focus, including AI red teaming, runtime governance, human-in-the-loop accountability and agent orchestration. These sessions helped the team gain confidence that they could assess emerging autonomous AI technologies with the same rigor applied to other enterprise risks.
Result
An AI audit plan ready to scale for the future
With its first AI lifecycle audit complete, the client’s internal audit team was equipped with a more structured approach to evaluating emerging AI technologies. The audit spanned seven AI governance domains and roughly 40 governance requirements, validating controls behind thousands of AI initiatives and hundreds of production AI use cases, all documented to the standard examiner review requires.
Additionally, the internal audit team operated with a clearer understanding of generative AI, open-source models, foundation models and agentic AI as distinct risk profiles rather than a single category. Controls testing improved as the teams better understood underlying processes: where the controls changed, and which controls business leaders internally responsible and accountable for and how it impacted their business processes. They gained clearer visibility into governance effectiveness, human accountability, lifecycle risks and platform workflow controls.
As a result, the internal audit function emerged better prepared to support ongoing AI innovation while maintaining independence with effective risk oversight and readiness for future agentic AI audits.
Connect with our team
Partner, Cyber & Risk Advisory
Grant Thornton Advisors LLC
Vikrant Rai is an Advisory leader in Grant Thornton’s Cyber and Risk practice delivering IT, Cybersecurity and AI risk management solution.
Edison, New Jersey
Industries
- Banking
- Healthcare
- Life Sciences
- Manufacturing
- Private Equity
- Technology
- Transportation & Distribution
Content disclaimer
This Grant Thornton Advisors LLC content provides information and comments on current issues and developments. It is not a comprehensive analysis of the subject matter covered. It is not, and should not be construed as, accounting, legal, tax, or professional advice provided by Grant Thornton Advisors LLC. All relevant facts and circumstances, including the pertinent authoritative literature, need to be considered to arrive at conclusions that comply with matters addressed in this content.
Grant Thornton Advisors LLC and its subsidiary entities are not licensed CPA firms.
For additional information on topics covered in this content, contact a Grant Thornton Advisors LLC professional.
Ready to talk? We’re ready to listen.
Request a meeting and a member of our team will be in touch to see what we can do to meet your needs.
Want to submit an RFP? Please submit your request through our RFP submission page.