Hael
Book a meeting

AI GOVERNANCE INTERNAL AUDIT

Internal audit that tests how AI governance operates in practice.

Hael provides objective, evidence-based internal audit across AI governance frameworks, management systems and regulatory programmes.

We assess whether responsibilities, controls and review processes are appropriately designed, implemented and effective, then present clear findings for management action.

OBJECTIVE ASSURANCE

A reliable view of whether the governance system is working.

Internal audit gives leadership an objective assessment of whether agreed governance arrangements are operating as intended. It examines the evidence behind the system, not simply whether the required documents exist.

A well-run audit identifies weaknesses early, supports management oversight and provides a disciplined basis for corrective action and continual improvement.

Independent challenge

Test governance and control operation through an appropriately independent review rather than relying solely on those responsible for the work.

Clear management findings

Distinguish material nonconformities and control weaknesses from observations and opportunities for improvement.

Stronger external readiness

Resolve weaknesses before certification, customer review or regulatory scrutiny exposes them under greater pressure.

An annual requirement, not a one-off

The internal audit is required before certification and again every year for as long as the certificate is held. It is not a stage of the implementation project. It is a standing obligation that arrives on the same schedule as the surveillance audit.

Companies that treat it as a formality tend to meet the same findings again at surveillance, and a missing or superficial internal audit is a common finding at certification.

OUR APPROACH

One audit from agreed criteria to management-ready findings.

Hael plans and conducts internal audit against a defined scope and set of criteria. We review the management system, the operation of controls and the quality of evidence, while preserving the objectivity required of the audit process.

Define scope, criteria and independence

We agree the frameworks, entities, systems, processes and reporting period to be covered, together with the audit criteria and intended audience.

We also confirm how appropriate independence will be maintained, particularly where Hael or another adviser has supported implementation.

Test design and operation

We review policies, responsibilities, assessments, controls, evidence and management oversight. Testing may include document review, interviews, sampling and tracing decisions back to their supporting records.

The audit considers both whether arrangements are suitably designed and whether they operate consistently in practice.

Report findings and support action

We present findings clearly, explain the evidence behind them and distinguish nonconformities from observations and improvement opportunities.

Management receives a practical view of root causes, priorities and the corrective action needed.

APPROPRIATE INDEPENDENCE

Objective assurance, with responsibilities kept clear.

Internal audit must be conducted with sufficient objectivity and impartiality. The people responsible for designing or operating an activity should not audit their own work.

Where Hael has supported implementation, we establish whether an appropriately separate practitioner can perform the audit without compromising objectivity. Where that is not appropriate, we will recommend an independent alternative rather than blur the boundary.

Management remains responsible for the governance system, the treatment of findings and the decision to accept or remediate identified risks. Hael’s role is to provide a clear and evidence-based audit conclusion.

PLANNING THE WORK

An audit programme based on scope, risk and management need.

The audit scope depends on the framework or requirements involved, the boundaries of the management system, the maturity of implementation and the assurance leadership needs. A focused audit may test a particular process or AI system. A full management-system audit may cover governance, risk, lifecycle controls, evidence, management review and continual improvement.

Before work begins, we agree the audit criteria, scope, sampling approach, information request, interviews, timetable, reporting format and fee. Where the audit supports an external certification or examination, we plan it early enough for corrective action to be completed and evidenced before independent assessment.

WHY HAEL

Specialist AI governance advice, led by experienced practitioners.

Hael is the specialist AI governance and compliance practice within Buckingham Group, drawing on fifteen years of work across governance, risk and compliance. Our focus is deliberately specific: helping organisations put credible governance around the AI they develop, provide and use.

We advise AI providers preparing for enterprise scrutiny, as well as established and regulated organisations introducing AI across complex operating environments. We understand that these organisations have different commercial, regulatory and operational priorities. The scope and delivery model are designed accordingly.

Our work can cover readiness, scope, governance design, policy and control implementation, AI inventory, risk and impact assessment, evidence, internal audit, management review, certification preparation and ongoing improvement. We can lead the complete programme or work alongside your existing legal, risk, security, product and engineering teams.

Every engagement has a named practitioner and an agreed scope, timetable and fee. Where the Hael platform supports an engagement, it maintains the underlying systems, controls, evidence, decisions and review record. It supports practitioner judgement and operational continuity; it does not replace either.

CONNECTED SERVICES

Use internal audit as part of a complete assurance programme.

Readiness and gap assessment

Establish the current position and define the work required before implementation or formal audit.

AI governance implementation

Design and embed the governance, controls and evidence that internal audit will later assess.

Certification readiness and audit support

Use internal-audit findings to strengthen readiness for independent certification or examination.

Continuous governance and assurance

Maintain a risk-based audit and review cycle as systems, controls and requirements change.

Why it cannot come from your certification body

ISO/IEC 17021-1 prevents a certification body from providing internal audit services to the organisations it certifies. The requirement is that the auditor is competent in the standard and independent of the work being examined.

In a company of thirty people, the person who built the management system is usually the only person who understands it, and they cannot audit their own work. That is why the audit is normally carried out externally.

DISCUSS YOUR INTERNAL AUDIT

Start with a clear view of the assurance management needs.

In an initial scoping call, a Hael practitioner will review the framework or requirements involved, the boundaries of the governance system, the implementation work completed and the reason for commissioning the audit.

We will then set out the recommended scope, audit criteria, method, independence arrangements, timetable and fee. You will know how the audit will be conducted before deciding whether to proceed.