Search

 
 

Bank strengthens oversight of 1,000+ AI initiatives without slowing innovation

 

7

AI governance domains now under active audit coverage

 

100+

production AI use cases with governance oversight validated

 

1000+

AI initiatives governed under a framework strengthened for emerging AI risks

 
 

At a glance

 

Client

Global financial services company

 

Industry

Banking

 

Our role

AI governance lifecycle audit advisor

 

Our solution

Agentic AI audit readiness

 
 
 

A repeatable way to audit autonomous AI

 
folder icon

Scenario

Internal audit needed a practical way to evaluate agentic AI risks without duplicating existing oversight or slowing innovation already underway.

gears icon

Approach

Grant Thornton helped the team build a repeatable approach to evaluating AI systems, developing questions and validating controls for net-new risks.

graph icon

Result

The client completed its first AI lifecycle audit and improved readiness for future agentic AI assessments.

 
 

Scenario

 
 

A mature audit function meets autonomous AI

 

A large global financial services organization had made significant investments in AI and had the governance infrastructure to match: a strong model risk management function, mature AI governance capabilities, alignment to regulatory obligations, compliance audits already completed, and thousands of AI initiatives inventoried and routed through an enterprise governance platform.

 

However, emerging technology and infrastructure landscape continued to impact the company, and the portfolio of AI tools in use across the company was continuously changing.

 

As adoption accelerated, the client’s internal audit leadership could see AI systems evolving from predictive models and chat-based assistants into autonomous systems: agents that invoke tools, access enterprise data, execute workflows and make decisions with increasing levels of independence. These systems introduced risk considerations that differed from earlier models and control environments. Where traditional AI governance assumes risk can be managed before deployment through policies, reviews and approvals, agentic AI systems work differently. They make decisions in runtime, in response to new conditions. Oversight had to move at that speed.

 

The team wanted to understand how emerging technologies such as agentic AI and open-source models with complex AI workflows, and their net-new risks, could be evaluated. At the same time, they sought alignment with regulatory expectations, the NIST AI Risk Management Framework and enterprise governance objectives.

 

They needed an audit approach built to properly oversee these new conditions, without repeating work already being done by existing model risk management and compliance programs. They aimed to add value to the innovation already underway without slowing it down.

 

Key agentic AI risks the team sought to evaluate

 
  • Agent autonomy and decision-making
  • Tool invocation and excessive permissions
  • Unauthorized actions
  • Prompt manipulation and model abuse
  • Data privacy and information leakage
  • Human oversight and accountability
  • Operational resilience
  • Model drift and continuous monitoring
  • Third-party AI risk management
  • Open-source AI risks
  • Auditability and evidence generation
 
 
 

Approach

 
 

Auditing more than the model

 

The bank's internal audit function already had strong AI governance coverage, but it didn’t yet have an approach built for autonomous systems going live across the enterprise.

 

Grant Thornton was engaged to support the client’s internal audit team with specialized AI governance and risk expertise for its first AI lifecycle audit.

 

A traditional audit would have concentrated on the AI model itself: performance, validation activities, documentation and regulatory compliance. This audit followed the AI lifecycle instead, identifying risks and control points at each phase from development through deployment, monitoring and decommissioning. That structure made the scope easier to explain to the teams being audited: this was an AI lifecycle audit, testing controls that model risk management didn’t cover.

 

 

Traditional AI audit and model risk management programs focus on:An AI lifecycle audit covers:
  • Model performance
  • Validation activities
  • Documentation
  • Regulatory compliance
  • AI governance: Strategy, use case and risk classification are developed
  • Design and build: AI systems and security and privacy programs are designed, data is prepared, models are selected and/or developed, trained, and workflows are orchestrated
  • Test and deploy: Models are evaluated, validated, deployed and integrated
  • Monitor: Evaluates model drift, observability, third-party oversight, KPIs, analytics and audit evidence generation

Building from internal audit leaders’ existing AI audit knowledge and operations, Grant Thornton identified key questions to help them evaluate their existing AI governance and risk assessment inputs and processes. They also facilitated knowledge-sharing in emerging areas of audit focus, including AI red teaming, runtime governance, human-in-the-loop accountability and agent orchestration. These sessions helped the team gain confidence that they could assess emerging autonomous AI technologies with the same rigor applied to other enterprise risks.

 

How we can help you

 
 

INDUSTRY

Banking -->

 

 

Ready to talk? We’re ready to listen.

Request a meeting -->
 
 

Result

 
 

An AI audit plan ready to scale for the future

 

With its first AI lifecycle audit complete, the client’s internal audit team was equipped with a more structured approach to evaluating emerging AI technologies. The audit spanned seven AI governance domains and roughly 40 governance requirements, validating controls behind thousands of AI initiatives and hundreds of production AI use cases, all documented to the standard examiner review requires.

 

Additionally, the internal audit team operated with a clearer understanding of generative AI, open-source models, foundation models and agentic AI as distinct risk profiles rather than a single category. Controls testing improved as the teams better understood underlying processes: where the controls changed, and which controls business leaders internally responsible and accountable for and how it impacted their business processes. They gained clearer visibility into governance effectiveness, human accountability, lifecycle risks and platform workflow controls.

 

As a result, the internal audit function emerged better prepared to support ongoing AI innovation while maintaining independence with effective risk oversight and readiness for future agentic AI audits.

 
 

Connect with our team

 

Edison, New Jersey

Industries

  • Banking
  • Healthcare
  • Life Sciences
  • Manufacturing
  • Private Equity
  • Technology
  • Transportation & Distribution
 
 
 

Content disclaimer

This Grant Thornton Advisors LLC content provides information and comments on current issues and developments. It is not a comprehensive analysis of the subject matter covered. It is not, and should not be construed as, accounting, legal, tax, or professional advice provided by Grant Thornton Advisors LLC. All relevant facts and circumstances, including the pertinent authoritative literature, need to be considered to arrive at conclusions that comply with matters addressed in this content.

Grant Thornton Advisors LLC and its subsidiary entities are not licensed CPA firms.

For additional information on topics covered in this content, contact a Grant Thornton Advisors LLC professional.

 

Ready to talk? We’re ready to listen.

 

Request a meeting and a member of our team will be in touch to see what we can do to meet your needs.

 

Want to submit an RFP? Please submit your request through our RFP submission page.

 
 
 

Trending topics

 

Follow us