Artificial Intelligence and Internal Control Systems: A Theoretical Examination of Risk Detection, Monitoring, Compliance, and Organizational Accountability in Businesses
DOI:
https://doi.org/10.3390/wk2cxc21Abstract
Internal control systems exist to give organizations reasonable assurance that operations are effective, financial reporting is reliable, and applicable laws and regulations are followed — an assurance that has historically rested on periodic testing performed by people who can be asked, directly, why a particular control judgement was made. Artificial intelligence (AI) is now performing a growing share of the risk-detection and monitoring work internal control systems depend on, and this paper offers a theoretical examination of what that shift means for the control environment as a whole, not merely for the efficiency of individual control activities. Integrating the COSO Internal Control framework, agency theory, the Institute of Internal Auditors' Three Lines Model, and the NIST AI Risk Management Framework with recent empirical evidence on AI-enabled monitoring, automation, and algorithmic decision authority, the paper argues that AI strengthens two of internal control's traditional components — risk assessment and monitoring activities — more reliably than it strengthens a third, less often theorized requirement: organizational accountability for control failures. Because AI systems increasingly perform the detection and monitoring work that control frameworks assume a human occupies, the traditional assumption that a specific, identifiable person can explain why a control operated as it did becomes harder to satisfy exactly as detection and monitoring become more comprehensive and more automated. Drawing on the distinction between post-hoc explanation and interpretability by design, the paper proposes that this accountability gap is not simply a communication problem to be solved with better explanation tools, but a structural design choice organizations make when they select complex, opaque models over simpler, inherently interpretable ones for control-relevant decisions. The paper develops a four-dimensional theoretical model, compares the governance vocabulary of COSO, the Three Lines Model, and the NIST framework directly, and considers what the resulting account implies for how internal control systems, and the professionals who operate them, need to adapt.




