What an AI audit actually finds

Iceberg tip above water with a much larger mass hidden below, symbolizing shadow AI

The fastest way to get CISSP Certified. Join our bootcamp 


Image of masterclass video - Destination Certification

Most organizations doing their first AI security audit expect to find shadow AI. Employees using ChatGPT when they shouldn't. Unauthorized tools slipping past IT.

That's rarely the biggest problem.

The real findings tend to show up in places nobody thought to look. Here's what a real AI security audit actually examines, and what it typically uncovers.

Start with inventory, not policy.

The first step isn't reviewing your AI usage policy. It's finding out what AI is actually running in your environment. Not what's approved. What's running.

This means cataloguing every AI tool across every team, including the ones embedded in software you already use. Grammarly. Notion. Slack. Microsoft 365. Zoom. These tools added AI features in updates. Most organizations don't have them on an AI inventory because they weren't installed as AI tools.

What auditors consistently find: organizations think they have five AI tools. They have forty.

Then map the data flows.

For each tool, you need to know what data it touches and where that data goes. Not what the vendor's privacy policy says. What actually happens when an employee pastes a document into the tool.

Does the data get sent to external servers for processing? Does it get used for model training? Is it retained, and for how long? Is the enterprise version configured differently from the consumer version employees might be using on personal devices?

Most organizations find they can answer these questions for their intentionally deployed AI tools. They can't answer them for the tools that got AI features in updates.

Check the governance controls.

An AI system that processes sensitive data needs controls around it. Who can access it? Who approved it? What happens when it produces incorrect output? Is there a human review step for consequential decisions?

The audit question isn't whether these controls exist on paper. It's whether they actually function in practice.

Auditors regularly find AI tools that were approved through a standard software review process designed for traditional software. Nobody asked the AI-specific questions: What happens when the model drifts? How do you detect if outputs start changing? What's the incident response plan if the tool is compromised or manipulated?

Test for AI-specific vulnerabilities.

Traditional vulnerability assessments look for known software flaws. AI systems have additional attack surfaces: prompt injection, model poisoning, data extraction through crafted inputs.

A basic test: Can you get the AI tool to produce outputs it's not supposed to produce through carefully worded inputs? Can you extract information about other users? Can you manipulate the tool's behavior through content it processes?

Most organizations have never tested their AI tools for any of these. They assumed their standard security testing covered it. It doesn't.

What you do with the findings.

A completed AI audit gives you a risk picture most organizations genuinely don't have. Which tools are high risk. Where the data governance gaps are. Which controls are missing. What needs to be fixed before someone else finds it first.

That's the foundation of an AI security program. Not policy documents. An accurate picture of what's actually running, what it's doing with your data, and where the controls are missing.

AAISM teaches you how to build and run this kind of program. How to scope an AI audit, assess the findings, and implement controls that work for systems that learn and adapt rather than just execute fixed code.

Our next AAISM Bootcamp runs October 5-7. Three days with Joseph Zefrani covering everything ISACA tests. Full year of access to all course materials, plus four implementation tools for real-world AI security work.


Best,
The DestCert Team

P.S. Can't make the bootcamp? Our AAISM MasterClass covers the same material at your own pace.

Thumbnail image for CISM mindmap 4.4 - Destination Certification

Free CISM MindMap: Incident Handling


We put together a free MindMap video covering the key concepts in Domain 4, a quick, clear way to get the big picture before you dive into studying. Free to watch, no strings attached. Plus you'll get downloadable audio files and printable PDFs.

The CAT is almost out of the bag.


We've been building something. You'll see it soon.

Image of a group of people who are searching for a mountain top - Destination Certification

Free AAISM Exam Strategies Guide


Master the mindset and techniques top candidates use to pass the AAISM exam with confidence. Learn how to approach scenario-based questions, avoid common traps, manage your time effectively, and think like an AI security leader.

Background image of CCSP MasterClass - Destination Crtification

Destination CCSP just got a major update


We've refreshed the guidebook to match the latest exam outline, with AI/ML security now woven through all six domains. Same clear explanations that have helped thousands pass, updated for what ISC2 tests today.

Would you like to receive the DestCert Weekly via email?

Your information will remain 100% private. Unsubscribe with 1 click.

Page [tcb_pagination_current_page] of [tcb_pagination_total_pages]