Internal Audit's AI Say-Do Gap Now Has Numbers, practitioner guidance from TheAICommand
← AI News
Analysis

Internal Audit's AI Say-Do Gap Now Has Numbers

Two 2026 surveys put hard numbers on something internal audit has felt for a year: adoption is racing ahead of capability. Gartner has 83 per cent of audit functions piloting or using AI, while only a small share feel able to embed it. The IIA and AuditBoard have 85 per cent alert to AI-enabled fraud and fewer than 40 per cent ready to detect it. For an Australian function, the gap is a benchmark to self-assess against, not a headline to read past.

·TheAICommand

Quick answer

Two 2026 surveys put numbers on internal audit's AI say-do gap. Gartner finds 83 per cent of audit functions piloting or using AI, but only a small share confident they can embed it. The IIA and AuditBoard find 85 per cent alert to AI-enabled fraud, yet fewer than 40 per cent ready to detect it. Score your function honestly.

Internal audit has an AI say-do gap, and two 2026 surveys now put numbers on it: stated adoption has roughly doubled, but the share of functions actually embedding the technology, or ready for the fraud it enables, has not kept pace. Audit is talking about AI far faster than it is using it.

The numbers, from two 2026 surveys

Gartner's survey, published on 27 January 2026 and based on 119 chief audit executives polled in August 2025, found 83 per cent of audit functions are now piloting or using AI, with another 12 per cent planning to within the year. Set that against Gartner's March 2024 survey, where 41 per cent said they used or planned to use generative AI, and the trajectory is clear: adoption has roughly doubled in under two years. More than 70 per cent of chief audit executives now rate building a culture of innovation and better use of data analytics and generative AI as important or extremely important for 2026, and 80 per cent want to lift the impact of data analytics in their function.

That is the "say", and it is loud.

Where the doing lags

The same research names the gap. Despite the interest, Gartner reports that only a small number of chief audit executives are confident in their function's ability to effectively embed generative AI into audit workflows and methodologies, and about 70 per cent of those already using the tools say they need outside help. Gartner's benchmarking of how audit actually uses generative AI puts most functions in the early stages, still exploring or piloting individual use cases rather than running them as embedded, day-to-day practice. Progress is held back, it notes, by poor data quality, a shortage of technical development skills, and in some cases access to the technology itself.

The distance between "83 per cent piloting or using" and "a small number confident they can embed it" is the say-do gap in one line. A pilot is not an embedded practice, a licence is not a capability, and intent is not a completed audit that used AI in a defensible step.

The same gap, with stakes

A second survey shows what the gap costs when the pressure is real. The Internal Audit Foundation and AuditBoard, in a report released on 17 February 2026 based on more than 370 senior internal audit leaders in North America, found 85 per cent consider AI-enabled fraud a moderate-to-high risk, yet fewer than 40 per cent feel their function is adequately prepared to detect it. "While the awareness of AI-enabled fraud is high, the 'readiness gap' remains a significant vulnerability for most organisations," said Richard Chambers, senior advisor for risk and audit at AuditBoard.

The reasons auditors gave are practical, not philosophical: a lack of appropriate technology or tools (57 per cent), too few staff with the relevant skills (55 per cent), limited budget (46 per cent) and competing priorities (43 per cent). It is the same shape as the Gartner data at higher stakes. Awareness is not the bottleneck. Tools, skills and time are.

Why this is a benchmark, not just news

These are North American surveys, so treat the exact percentages as a mirror, not a local statistic. The value for an Australian function is the self-assessment: hold it against the same two questions. On adoption, are you in the 83 per cent that has at least piloted, or still deciding? On capability, are you in the small group confident it can embed AI in an actual audit, or is your "adoption" a stalled pilot and a subscription nobody has operationalised?

That distinction matters more than the raw figures, because internal audit is the third line of defence, and in APRA-regulated entities it carries named obligations under prudential standards on governance and the operational-risk expectations of CPS 230. A function that has "adopted AI" on paper but cannot evidence how it uses or governs that AI has a say-do gap its own board and regulator could one day ask about. The site's companion piece on what still counts as evidence covers the assurance half of that question; this is the adoption half.

Score your own function

A mid-sized Australian internal audit team of six runs one AI subscription, bought eight months ago after a board push to "use AI". Scored honestly against the surveys, it sits in the 83 per cent that has piloted and the majority that cannot yet embed. Two auditors use the tool to summarise documents and draft sections of reports; nobody uses it in testing, and there is no written standard for when AI output can support a finding. On the fraud question, the team rates AI-enabled fraud a high risk in its own audit universe but has run no procedure to detect a synthetic identity or a deepfaked approval.

The head of audit records the position as it is, with no real names, no live engagement references and no vendor account details, then sets three targets: a written AI-use standard within the quarter, one auditor trained to embed the tool inside a real audit, and one fraud-detection procedure piloted before year-end. The gap does not close by buying more tools. It closes by turning a subscription into practice.

Draft it with these prompts

Use these to run the self-assessment and build the plan, keeping inputs generic so nothing confidential leaves your environment.

Prompt
You are helping [ORGANISATION]'s internal audit function run an honest AI
say-do self-assessment. Our function has [TEAM_SIZE] auditors. We currently
use AI for [CURRENT_USE_CASES] and hold [NUMBER] AI subscriptions or tools.
We do or do not have a written standard for AI use in audit work: [YES_OR_NO].

Assess us against two questions: (1) adoption, have we piloted or embedded AI,
and (2) capability, can we evidence AI used inside a completed audit. Rate each
as Not started, Piloting or Embedding, and explain the rating in one line.
Flag the single biggest blocker from these categories: tools, skills, budget,
time, governance. Mark anything you cannot judge from the inputs as NEEDS INPUT.
Prompt
You are helping [ORGANISATION]'s head of internal audit turn a stalled AI
pilot into embedded practice over one quarter. Inputs: current use
[CURRENT_USE_CASES]; biggest blocker [BLOCKER]; team skills level [SKILL_LEVEL];
top AI-enabled fraud risk in our audit universe [FRAUD_RISK].

Produce three concrete, sequenced targets for the next quarter, each with an
owner role, a done-looks-like test, and one measure of success. Include one
target that closes the AI-enabled fraud readiness gap specifically. Keep every
target achievable with our current headcount. Do not recommend buying new tools
unless you first show the current tool cannot meet the target.

Do this Monday

  1. List every AI tool your audit function holds and how it is actually used today, engagement by engagement, not subscription by subscription.
  2. Score the function against the two survey questions: have we piloted, and can we evidence AI used inside a completed audit. Be honest about pilots that stalled.
  3. Name your single biggest blocker from tools, skills, budget, time or governance, using the first prompt, and stop treating "we have a licence" as adoption.
  4. Draft or update a one-page standard for when AI output can support audit work and when a human must verify it, so adoption has a rule behind it.
  5. Pick one real, upcoming audit and commit to embedding AI in a defined, documented step of it, with a named auditor accountable.
  6. Add AI-enabled fraud to your audit universe and pilot one detection procedure this quarter, using the second prompt to sequence it.
  7. Record the whole assessment, dated, so your next review measures movement rather than restating intent.

A self-assessment checklist

Work down this list and mark each as present, partial or absent. Anything absent is your say-do gap, in order.

  • Adoption that is embedded, not just licensed: at least one completed audit used AI in a defined, documented step.
  • A written standard for when AI output can support a finding and when a human must verify it.
  • At least one auditor skilled enough to embed the tool in testing, not only in drafting.
  • AI-enabled fraud named in the audit universe, with at least one detection procedure piloted.
  • A named owner for AI governance inside the function, and a date the position was last reviewed.
  • Evidence you could show a board or regulator of how the function uses and controls its own AI, not just that it bought some.

Hype check

The percentages are North American and largely self-reported, and the headline adoption figure counts piloting, which flatters the intent side of the ledger. Do not import them as Australian facts. Equally, do not wave the gap away. Two independent 2026 surveys, one on general adoption and one on fraud readiness, describe the same shape: audit is aware and interested well ahead of being capable and ready. The measured reading is that the say-do gap is real, it is named by auditors themselves, and it closes with skills and standards rather than another subscription.

Bottom line

Internal audit's AI adoption has roughly doubled on paper, but confidence in actually embedding the technology, and readiness for the fraud it enables, has not followed. Gartner puts 83 per cent piloting or using AI while only a small number feel able to embed it. The IIA and AuditBoard put 85 per cent alert to AI-enabled fraud while fewer than 40 per cent feel prepared for it. For an Australian function, the numbers are a mirror: score yourself honestly, name the blocker, and turn intent into evidenced practice before your board asks you to.

Do this Monday:

  • Score your function against two questions: have you piloted AI, and can you evidence it used inside a completed audit.
  • Name your single biggest blocker, tools, skills, budget, time or governance, and stop counting a licence as adoption.
  • Write a one-page standard for when AI may support a finding and when a human must verify it.
  • Add AI-enabled fraud to your audit universe and pilot one detection procedure this quarter.

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

What is internal audit's AI "say-do gap"?
It is the distance between stated AI adoption and actual embedded use. Gartner's January 2026 survey found 83 per cent of audit functions piloting or using AI, up from 41 per cent using or planning to in 2024, yet only a small number of chief audit executives feel confident they can effectively embed the technology in real audit workflows. Interest has raced ahead of capability.
What did the IIA and AuditBoard find about AI-enabled fraud?
Their report, released on 17 February 2026 and based on more than 370 senior internal audit leaders in North America, found 85 per cent consider AI-enabled fraud a moderate-to-high risk, but fewer than 40 per cent feel their function is adequately prepared to detect it. The top barriers were a lack of appropriate tools (57 per cent) and too few skilled staff (55 per cent).
Do these North American numbers apply to Australian audit teams?
Treat them as a mirror, not a local statistic. The value is the self-assessment: hold your own function against the same two questions, whether you have genuinely embedded AI in a completed audit, and whether you are ready for AI-enabled fraud. Internal audit's obligations under prudential standards such as CPS 230 make an unevidenced "we adopted AI" a gap worth closing.
How do you close the gap without just buying more tools?
The surveys name skills, standards and time, not more software, as the binding constraints. Turn one stalled pilot into embedded practice: write a standard for when AI output can support a finding, train at least one auditor to use the tool inside real testing, and pilot one AI-enabled fraud detection procedure. Adoption becomes real when it produces evidence, not when a licence is bought.

Tags

internal auditIIAAuditBoardGartnerAI adoptionAI governanceAI-enabled fraudCPS 230
← Back to AI News