Somewhere in your organization, an algorithm is making a decision that used to belong to a person. It may be scoring a loan application, flagging a transaction, screening a job candidate, drafting a customer response, or summarizing a contract for an executive who will act on the summary. Caribbean organizations crossed a threshold over the past two years, largely without ceremony: artificial intelligence moved from pilot to production — and generative AI moved from novelty to daily habit, often through tools no one formally approved. The governance question this raises is the subject of this ninth article in The Internal Audit Imperative™: when systems stop merely computing decisions and start making them, who provides assurance over how well they decide?

Why AI Has Entered the Audit Universe

AI earns its place on the audit plan the same way any subject does: consequence. Models now influence outcomes with direct customer, financial, and regulatory impact — credit and underwriting decisions, fraud flags that freeze accounts, pricing, collections prioritization, hiring screens. Alongside these sit the generative AI risks that have arrived with startling speed: confidential data pasted into public tools, convincingly wrong output acted upon without verification, intellectual property ambiguity, prompt injection against AI-enabled applications, and — most pervasive of all — shadow AI: staff adopting tools the organization has never assessed, producing work the organization cannot trace. None of this argues against AI; the productivity case is real and the region should capture it. It argues for what every consequential technology eventually requires: governance that is designed, and assurance that is independent.

The Governance Anchor: ISO/IEC 42001

Until recently, an auditor asked to assess AI governance had no benchmark to assess it against. That has changed. ISO/IEC 42001 — the first certifiable international standard for an AI management system (AIMS) — gives organizations, and their auditors, a structured definition of what managed AI looks like: leadership accountability and policy; an inventory of AI systems and their intended uses; AI risk assessment and, critically, AI impact assessment — evaluating effects on the people subject to the system’s decisions, not merely on the organization; lifecycle controls from data and development through deployment, monitoring, and retirement; and management of third-party and supplier AI. Complementary frameworks such as the NIST AI Risk Management Framework supply additional depth on trustworthy-AI characteristics.

The practical significance for Caribbean boards is not certification — few regional organizations need the certificate yet. It is that the benchmark now exists. An internal audit function can assess AI governance against a recognized standard rather than an improvised checklist; a board can ask “how do we compare to ISO 42001?” and receive a structured answer; and an organization that later chooses certification — as regulated institutions and government suppliers increasingly will — starts from a mapped position rather than a blank page.

The New Audit Universe: Seven AI Entries

 

Translated into audit-plan language, AI adds seven recurring entries to the universe:

  1. The AI inventory — and shadow AI discovery. You cannot govern what you have not found. The first engagement is a census: sanctioned systems, embedded AI inside vendor products, and the unsanctioned tools in daily use.
  2. Governance and accountability. Policy existence and adequacy, named ownership for each system, human oversight for consequential decisions, and board reporting.
  3. Data governance. What data trains, feeds, and leaves each system — privacy compliance, confidentiality boundaries, and data quality, because a model is an opinion about its data.
  4. Model lifecycle controls. Validation before deployment, performance and drift monitoring after, documented change control, and retirement criteria — the model-risk disciplines banking has known for years, now needed everywhere.
  5. Generative AI use controls. Acceptable-use rules, confidential-data boundaries, output verification for anything consequential, and disclosure norms — tested against actual behaviour, not the policy PDF.
  6. Third-party AI. The Caribbean reality again: most AI arrives embedded in vendor platforms. Due diligence, contractual terms on data use and model behaviour, and the right to audit — or at least the right to answers.
  7. Impact assessment for high-stakes uses. Where systems decide about people — credit, employment, claims — has anyone formally assessed fairness, explainability, and recourse? Under ISO 42001, someone must.

Both Sides of the Ledger: AI as Audit Tool

Internal audit is not only AI’s examiner; it is one of its most natural beneficiaries. The same Standards that push functions toward data analytics (Article 10 takes this up in full) make AI-assisted auditing — document review at scale, anomaly detection, control-testing copilots, fieldwork summarization — an obvious capability investment. The discipline is symmetry: a function that uses AI must govern its own use by the same rules it audits in others — approved tools, confidentiality boundaries, human review of anything that reaches a conclusion, and transparency with the audit committee about where AI touched the work. Nothing would damage the function’s credibility faster than being found to preach standards it does not practise.

A model is an opinion about its data, delivered with confidence. Assurance exists to test the opinion before the organization acts on the confidence.

A Pragmatic First-Year AI Assurance Plan

For most Caribbean organizations, credible AI assurance is a four-step first year, not a moonshot. Step one: the inventory — a full census of AI in use, sanctioned and shadow, with each use case risk-tiered by consequence. Step two: the governance review — policy, ownership, human oversight, and board reporting assessed against ISO 42001’s management-system requirements. Step three: two deep dives — the highest-consequence model (often credit, fraud, or pricing) audited for lifecycle controls, and generative AI usage audited against actual staff behaviour. Step four: the board report — one integrated view: where AI is, what it decides, how it is governed, what was tested, and what the organization has consciously chosen not to allow. Four steps, one year, and the organization moves from “we think people are using it” to governed adoption with independent assurance.

Five AI Questions for the Next Board Meeting

  1. Do we have a complete inventory of AI in use — including the tools staff adopted without asking?
  2. Which of our decisions about people — credit, hiring, claims — involve a model, and who formally assessed the impact?
  3. For our highest-consequence model: who validated it, who monitors it, and when did anyone last check it still works?
  • What are our rules for generative AI — and does anyone test behaviour against them?
  1. Which of our vendors embed AI in what they sell us — and what have they told us about it?

The Dawgen Perspective

Every transformative technology passes through the same three phases: enthusiasm, incident, and governance. The organizations that fare best are those that build the third phase before the second finds them. The Caribbean has a rare timing advantage here — AI adoption is accelerating regionally just as the governance benchmarks have matured globally — which means boards can adopt with guardrails from the outset rather than retrofitting them after a headline. That is precisely the posture this series has urged on every risk: assurance positioned before the risk matures, not after it announces itself.

Dawgen Global’s AI Governance & Assurance practice supports both sides of the ledger across 15+ Caribbean territories: AI inventories and shadow-AI discovery, ISO/IEC 42001 readiness assessments and AIMS design, model lifecycle and GenAI usage audits delivered under our internal audit methodology, and AI-enablement of audit functions themselves — governed by the same standards we assess, and reported under TRUST360™ in the board’s language.

Next in the series: “Continuous Auditing and Data Analytics: Moving Beyond the Annual Audit Plan” — the technology mandate inside the Standards, and how full-population assurance changes what a board can know.

 

Govern the Algorithms Before They Make the News

Dawgen Global’s AI Assurance Programme delivers the first-year plan end to end: AI inventory and shadow-AI discovery, ISO/IEC 42001 readiness assessment, deep-dive audits of your highest-consequence model and GenAI usage, and one integrated board report under TRUST360™.

Governed adoption — with independent assurance.

Email us |[email protected]  |  dawgen.global  |

Big Firm Capabilities. Caribbean Understanding.

 

About Dawgen Global

Dawgen Global is an independent, integrated multidisciplinary professional services firm headquartered at 47 Trinidad Terrace, New Kingston, Jamaica, serving more than 15 territories across the Caribbean. Founded and led by Dr. Dawkins Brown, Executive Chairman, the firm is independent and not affiliated with any international network. It delivers a full suite of professional services under one roof: audit and assurance; tax advisory; IT and digital transformation; risk management; cybersecurity; actuarial and insurance regulatory advisory; HR advisory; mergers and acquisitions; corporate recovery; business advisory and strategy; accounting BPO and virtual CFO services; and legal process outsourcing.

The proposition is simple: big-firm capability without the big-firm price. Dawgen Global’s integrated approach is built for the specific complexities and opportunities of the Caribbean market, helping organizations make sharper, better-informed decisions that drive measurable progress.

To explore a partnership, reach out:

 

by Dr Dawkins Brown

Dr. Dawkins Brown is the Executive Chairman of Dawgen Global , an integrated multidisciplinary professional service firm . Dr. Brown earned his Doctor of Philosophy (Ph.D.) in the field of Accounting, Finance and Management from Rushmore University. He has over Twenty three (23) years experience in the field of Audit, Accounting, Taxation, Finance and management . Starting his public accounting career in the audit department of a “big four” firm (Ernst & Young), and gaining experience in local and international audits, Dr. Brown rose quickly through the senior ranks and held the position of Senior consultant prior to establishing Dawgen.

https://www.dawgen.global/wp-content/uploads/2023/07/Foo-WLogo.png

Dawgen Global is an integrated multidisciplinary professional service firm in the Caribbean Region. We are integrated as one Regional firm and provide several professional services including: audit,accounting ,tax,IT,Risk, HR,Performance, M&A,corporate recovery and other advisory services

Where to find us?
https://www.dawgen.global/wp-content/uploads/2019/04/img-footer-map.png
Dawgen Social links
Taking seamless key performance indicators offline to maximise the long tail.
https://www.dawgen.global/wp-content/uploads/2023/07/Foo-WLogo.png

Dawgen Global is an integrated multidisciplinary professional service firm in the Caribbean Region. We are integrated as one Regional firm and provide several professional services including: audit,accounting ,tax,IT,Risk, HR,Performance, M&A,corporate recovery and other advisory services

Where to find us?
https://www.dawgen.global/wp-content/uploads/2019/04/img-footer-map.png
Dawgen Social links
Taking seamless key performance indicators offline to maximise the long tail.

© 2023 Copyright Dawgen Global. All rights reserved.

© 2024 Copyright Dawgen Global. All rights reserved.