Employees are an organization’s greatest asset, but when mismanaged, they can also be a source of risk. Human capital risk encompasses a wide swath of issues, such as employee misconduct, unfair employment practices, leadership that acts in unnecessarily authoritarian or inappropriate ways, or corporate dynamics that undermine governance, sustainability, and controls.
Artificial intelligence (AI) offers internal auditors new ways to zero in on human capital risk. There are many possibilities to deploy AI as an early warning system, depending on the business or organizational priorities. AI can monitor and flag risks related to customer relationship management, fraud, physical safety, bullying, cultural issues, and organizational dynamics that threaten performance.
AI can also identify organizational ineffectiveness that is a consequence of what leaders fail to do, such as neglecting to escalate risk, provide feedback to underperforming employees, or identify gaps in talent management.
Used within emails or chats to analyze sentiment, or alongside data analytics, AI can find patterns of risk. However, there is a caveat: Overuse of AI monitoring can veer into what feels like a surveillance culture, resulting in diminished morale, stress, and attrition. Further, organizations must exercise the utmost care where AI is used in decision-making, as algorithmic discrimination could result in unfair employment practices.
With the right controls, the organization can balance the use of AI without making employees fearful or paranoid. Internal audit can advise senior management on AI’s impact on people, processes, and outcomes to help reduce risk and build competitive advantage.
Individual Risks
The use of AI cybersecurity tools for risk management is now a booming industry, with software to monitor emails, chat interactions, keystrokes, and performance analytics. These tools can be used to analyze content in messaging platforms to get ahead of bullying and incivility issues, thereby preventing sexual harassment lawsuits and protecting morale. One example of this is the AI-based SafeChat+ feature used by DoorDash to safeguard drivers. The app monitors customer messages to identify potentially violent or conflict-prone interactions, enabling drivers to cancel orders without penalty.
A more long-term method involves analyzing anonymous email content by department and over time to uncover problems. For instance, an analysis of words used in email and text exchanges that suggests conflict and disagreement could reveal a particularly authoritative or punitive leadership style.
In looking at procurement, AI can unmask unusual buying patterns and messages that signal inappropriate arrangements like off-ledger payments with suppliers. AI tools can also be used to uncover conflicts between purchasing decisions and vendors, such as contracts that reward self-interest.
AI can even be used to identify AI misuse by employees. The rate of misuse is troubling, with 44% of employees admitting to inappropriate use of AI, which could expose trade secrets or sensitive financial information, according to KPMG’s Trust, Attitudes and Use of Artificial Intelligence: A Global Study 2025.
Systemic Risks
Looking for risk within organizational practices or everyday operations is another application for AI. The technology can be used to root out stalled initiatives that absorb funds, dissect high volumes of customer or user complaints to pinpoint root causes, and identify excessive time spent in meetings.
On the human resources (HR) front, AI can identify actions that affect hiring and promotion rates for protected classes, such as women and minorities. Seemingly neutral policies can produce disparate outcomes for these groups because of biases that hiring managers do not recognize or would not admit. Auditors can track these patterns by region or department to strengthen talent acquisition, promotion, and retention practices, while reducing legal risk.
AI can also see trends in employee complaints against management, including illegal actions such as sexual harassment and financial misconduct. Used by internal auditors, AI can complement whistleblowing programs by surfacing issues that employees may be reluctant to raise through traditional channels.
As a culture risk diagnostic, AI gives organizations an ear to the ground, providing a powerful means to strengthen risk culture. That said, because AI lacks intentionality and moral judgment, leaders must be cautious: Leaning too heavily on algorithmic findings can undermine the relationships and trust a healthy culture requires.
Organizational Dynamics
AI can also alert internal auditors to patterns of behavior or decision-making that point to risk. Behavioral patterns are easier to detect in the aggregate, making them well suited to AI.
Specifically, internal auditors can use AI systems to reveal problematic signs of behavior among leaders, especially for teams under stress. For instance, AI can analyze group discussions and leader communication patterns to identify actions that impede rational decision-making. One indication of this is groupthink, where team members agree with each other without discussing alternative points of view. A more subtle demonstration of ineffective group behavior when stress is high is a tendency to make riskier decisions, as groups under stress tend toward less cautious decisions than individuals would reach on their own.
Other, more nuanced applications would be the identification of decisions by senior leaders that are misaligned with organizational values or ignore socially responsible criteria that are important to the board and stakeholders. Such decision-making patterns can inform the HR, risk, and governance professionals guiding the organization.
AI can help internal auditors uncover high-stakes human capital issues — intentional or unintentional disruptions, subversive actions, and passive aggression. By scrutinizing AI-assisted decision-making, auditors can see who gets heard, how conflicting priorities interact, where incentives distort oversight, and how frontline pressure shapes behavior. This enables internal audit to detect organizational dynamics that signal failure, including:
- Behavioral drift — gaps in actions, decisions, and follow-through.
- Control failures — unintentional or deliberate breakdowns of procedure.
- Systemic cracks — misaligned incentives, weak performance management, and ineffective leadership.
AI can also reveal emerging vulnerabilities: information hoarding, workarounds, inconsistent customer treatment, bypassed controls, unexplained role changes, disempowered teams, unsustainable workloads, and eroding customer trust. These are all indicators of misbehavior that can threaten organizational performance.
Monitoring Is Not Management
AI-driven management systems, cloaked as data-based management or evidence-driven behavior and performance tools, can easily create a surveillance culture. With such early-warning systems, employees may learn to distrust management, growing fearful of being watched, measured, and criticized for every stroke of the keyboard (see “A Slippery Slope Into Surveillance Culture”). Yet, enabling technology to touch employees in such a way that it captures productive and counter-productive behavior is fast becoming commonplace.
In a 2025 Pew Research Center survey of more than 5,000 employees, U.S. Workers Are More Worried Than Hopeful About Future AI Use in the Workplace, 52% of participants report being worried about the future use of AI at their company. Only a small fraction say they expect it to improve their own opportunities. Roughly one-third anticipate fewer long-term job prospects because of AI.
A 2023 Pew survey, AI in Hiring and Evaluating Workers: What Americans Think, suggested that realizing efficiencies at the expense of employee trust and morale would be counterproductive, with workers showing skepticism about the use of AI for workplace monitoring and evaluation. Indeed, 61% of survey respondents say they oppose more invasive AI applications such as physical movement tracking and digital activities, 81% say AI monitoring would lead to workers feeling “inappropriately watched,” and 66% worry the data would be misused.
Organizations must balance between preventing bad risks through controls and monitoring with nurturing the collaboration and innovation that enable good risks. A healthy risk culture in the AI world guards against harmful risk and supports good risk-taking. Wrongdoing averted; innovation sparked.
To support innovation while avoiding unnecessary risk, internal auditors should:
Think like an integrator. Diffused responsibility for AI often leads to a lack of accountability. As an integrator, internal audit can help the organization align AI use across the organization through controls. In addition, assuming accountability for monitoring the impact of AI on people, processes, and outcomes would enable the profession to advise the C-suite on how best to use the technology to accelerate execution and build competitive advantage.
Inspect AI output to guard against blind acceptance. Internal audit can ensure that useful metrics are in place to assess AI’s value. By focusing on business and employee outcomes and asking the right questions, internal audit can assure management that controls are in place to reduce unwanted human capital risk.
Internal audit should help create guardrails to reduce AI-related human capital risk. However, leadership must own the risk. Internal audit can assure executives that they are engaged in the right activities to thwart unwanted, unhealthy, AI-related human capital risk by offering a structured checklist of tasks and safeguards:
- Inventory all AI tools that have been used for monitoring and managing human capital.
- Assess whether AI tools have a documented business purpose, legal basis, and business rationale.
- Test data flows by examining data sources, storage, usage, retention periods, and disclosure.
- Advise on employee transparency practices.
- Flag the trust and morale risk explicitly in reporting.
- Challenge management to demonstrate that metrics derived from AI monitoring predict performance.
- Question any personnel decision where AI output was created without a human review.
- Verify human-in-the-loop controls operate as designed for high-stakes decisions, such as hiring, firing, and promoting employees.
- Ensure employee challenges to AI decisions are tracked, resolved, and fed back into model governance.
Toward a Healthy Risk Culture
Internal auditors should use culture stress testing not only to fortify internal controls, but to assess how people respond to organizational change. Transitions such as software implementations, increased monitoring, mergers, acquisitions, and initial public offerings generate emotional and behavioral reactions that manifest as measurable risks — employee turnover risk, diminished productivity, distrust, fear, miscommunication, and battles over conflicting priorities.
These are not soft issues; they are early warning signs of a control breakdown. AI can help surface and monitor these human factors in ways traditional risk frameworks often miss.