Internal audit is the institution's third line: independent of the business that uses AI and the risk functions that oversee it, and answerable directly to the audit committee. AI now runs through the processes internal audit is charged with examining: investment decisions, valuations, client advice, operations and reporting. Yet most audit methods were built for software and IT general controls, not for systems that reason, act and run on infrastructure the institution does not own. The question is no longer whether internal audit will examine AI, but whether it has a method capable of testing control over it.

Boards now expect internal audit to report on AI. Most audit programs answer with what they know how to test: policies, inventories, model documentation. That is governance evidence. It is not control evidence.
Governance is policy. Control is evidence.
The exposures that matter sit where current methods do not reach:
Deep. Below the model: the data centers, computing and power on which it runs, often rented, often in another jurisdiction, under someone else's key custody.
Wide. Beyond the institution: inside the asset managers, servicers and providers to whom it has delegated work, but not liability.
An audit that stops at the model layer, or at the institution's own walls, reports on the part of AI that is easiest to see.

Institutional AI equips internal audit functions with the 5×5 Control Matrix™, the instrument behind our research on eighty of the world's leading financial institutions.
The Matrix reads the five ecosystems of the Institutional AI Stack™ (Power, Computing, Data Centers, Models and Agentic Applications) against five pillars of control: Jurisdictional, Logical, Technical, Operational and Contractual. That makes twenty-five intersections, each tested on its own terms and never collapsed into a single score.
Every intersection is classified by one standard: evidenced, assumed or absent.

Institutional AI does not issue audit opinions, attestations or certifications. Your internal audit function retains ownership of its work, its conclusions and its reporting line to the audit committee.
Institutional AI maintains no hyperscaler alliances, no model-provider partnerships and no resale economics with technology vendors. The method has no product to protect.
The AI Control Assessment™ and the 5×5 Control Matrix™ are proprietary instruments developed by Institutional AI, LLC ("Institutional AI"). Test programs, control classifications and recommendations are produced through Institutional AI's methodology and reflect its analytical interpretation of institutional inputs as of the date of completion. Classifications of evidenced, assumed or absent describe the completeness of demonstrable, evidenced control; they are not assurances about an institution's actual internal controls. Institutional AI is not a certified public accounting firm and does not perform audits, attestations or certifications, or issue audit opinions of any kind.
The 5×5 Control Matrix™ reading shown on this page is a hypothetical illustration developed to demonstrate the methodology. Any resemblance to specific institutions is incidental.
Institutional AI's methodology is intended to support internal audit functions, which retain sole responsibility for the scope, performance, conclusions and reporting of their audit work. Outputs do not constitute legal, regulatory, accounting, audit, investment, tax or fiduciary advice. Institutions should consult appropriate professional advisors before acting on findings.
AI is a given. Control is not.™
© 2026 Institutional AI. All Rights Reserved.