AI Output: Responsible Use
Blogs Nancy Hom, CISA Aug 18, 2026

Have you seen the recent headlines about a few well-known accounting firms publishing data that was actually artificial intelligence (AI) hallucinations? I won’t rehash the details, but the broader takeaway is a useful reminder: AI output verification steps need to be practical, consistent, and effective. In some cases, sources cited by AI turned out not to exist, and the human review process did not catch the issue. These headlines are a good reminder of how easily AI-generated content can appear convincing.
So, How Much Do I Trust AI?
Here's how I think about it: Trusting AI is a lot like trusting a driver. When my trust is low, I'm the backseat driver, second-guessing every turn because I believe I know the best path to the destination. When it's medium, I'm more like an experienced passenger (who knows how to drive.) I am relaxed but still watching the road and speaking up when something looks off. When trust is high, I'm basically dozing in the passenger seat, relying on the driver to get me there. That last one might be fine for a quick trip around town, but it gets risky fast if the road changes or the destination matters.
I don't think the answer is to zone out completely, and it's not great to be an unbearable backseat driver controlling the wheel either. What I strive for is knowing when to ease off, when to lean in, and when to take over (if warranted.) That middle ground is where I try to operate. AI models do change, and their performance can swing better or worse over time because of their probabilistic nature. It is this unpredictability that can be delightful and nerve-wracking at the same time.
So, How Much Should I Check?
This isn't meant to be a technical deep dive, so I'm going to skip over things like model selection or input quality because they affect how good the AI output is. I’ll assume you've nailed all of that. What's left is figuring out whether the output is usable.
So, how much checking is enough? For me, it comes down to what's at stake. For lower-stakes internal work, such as summarizing a team discussion, brainstorming a first pass at audit scope, and suggesting testing procedures, a quick check usually does the job. For anything higher stakes — something going to a stakeholder or feeding into a key decision or final audit report — I always give it a careful, hands-on review and validation. Every single time.
Three Simple Checks I Use
Language models have limitations, and knowing what they are helps me focus my review and catch hallucinations before they cause problems.
- AI can invent sources, quotes, page numbers, and links that sound completely legitimate but don't exist or don't say what the AI claims. So, I always ask for sources and open them myself to confirm.
- AI can deliver a wrong answer just as confidently as a right one. So, I ask it what assumptions it made, what it's unsure about, and what I should double-check before I rely on it. Sometimes I run the same task or goal in a few AI tools and compare the answers. Reviewing the output with a trusted subject matter expert also helps validate the answer.
- AI can miscalculate totals, percentages, and multi-step date math — so if a number is going into a decision, a report, or anything compliance-related, I verify it myself.
Where This is Headed
I don't think GenAI is ready to run an audit, start to finish, on its own yet. It is strongest when it is supporting specific tasks, not replacing the whole job. Audit work needs a combination of routine execution, critical thinking, context setting, and professional judgment. Over time, I expect AI will help us move faster, work through problems, spot better insights, and support us in making better decisions. The real opportunity is being intentional about where it fits: which decisions it can support, which it might eventually own, and which should always stay with people. That shift isn't going to happen overnight in some big agentic leap. It'll happen gradually, as we test, learn, and build AI into the work with discipline.
Looking out toward 2030 and beyond, I think AI will keep sliding closer to the driver's seat. My goal is to stay as an experienced passenger when I choose to be along for the ride, diligently watching the road and exercising the agency to make sure we safely and reliably reach the desired destination. More importantly, I am ready and capable to take over the steering wheel, too, if that is ever needed.
The views and opinions expressed in this blog are those of the author and do not necessarily reflect the official policy or position of The Institute of Internal Auditors (The IIA). The IIA does not guarantee the accuracy or originality of the content, nor should it be considered professional advice or authoritative guidance. The content is provided for informational purposes only.