00:00:02 The IIA
The Institute of Internal Auditors presents All Things Internal Audit Tech.
00:00:06 The IIA
In this companion episode to Internal Auditor Magazine's Human Capital Risk in an AI World article, Tom Diamante talks with Manuel London and Richard Chan about how AI can help organizations identify behavioral, cultural, operational, and decision-making risks earlier, while also creating concerns around bias, surveillance, and employee trust
00:00:30 The IIA
and misuse.
00:00:31 The IIA
The conversation explores internal audit's role in auditing AI, supporting responsible implementation and helping organizations balance risk mitigation with innovation.
00:00:43 Tom Diamante
So maybe to get started, gentlemen, if it's okay, how would you define human capital risk and fold in, if you can, how that really is affecting how AI is being used today?
00:00:56 Manuel London
Richard, do you want to go or you want me to begin?
00:00:57 Tom Diamante
Please go ahead.
00:00:58 Manuel London
Okay, well, the human capital risk is the risks that are incurred due to individuals or teams in organization that are creating those risks.
00:01:10 Manuel London
They may be evident from other data like financial data, operational data, or directly from evidence of behaviors, whether it's misuses or in some cases fraud, bias, mistrust, and other factors that are high risk and high stakes for the organization.
00:01:34 Manuel London
And the advantage of AI
00:01:37 Manuel London
is that, of course, we know it's statistical methods for analyzing, integrating vast amounts of data that really could never have been done without it, at least not in terms of the amount of data that's possible.
00:01:52 Manuel London
And this could be financial data, it can be operations data, or indeed it can be behavioral data of different sorts, whether it's from emails or records of conversations, texts,
00:02:04 Manuel London
and so forth across the organization, not necessarily pinpointing one individual, but AI can pick up those risks early as an early warning system and provide a tracking mechanism to ensure that or to identify any unusual patterns as they are emerging before they become detrimental to the organization.
00:02:26 Tom Diamante
Thank you, Manny.
00:02:27 Tom Diamante
Richard, do you like to weigh in on that?
00:02:29 Richard Chan
Yeah, I think I definitely agree with Manny because
00:02:32 Richard Chan
Human capital risks cover various aspects as long as there are human elements of the organization where it creates uncertainties or potential risk aspects.
00:02:43 Richard Chan
And AI can certainly help providing analytical tool sets.
00:02:48 Richard Chan
At the same time, management scholars have really emphasized on the importance of
00:02:52 Richard Chan
the machine-human interaction, right, the conjoint agency, rather than using AI as a passive toolset to analyze it, but managers should really incorporate this toolset actively to prevent potential risk and enhance organizational performance.
00:03:10 Tom Diamante
Would you both agree that human capital risk really speaks to behavior in an organization that somehow is a threat to the business or the execution of that business?
00:03:21 Tom Diamante
Would that be a simple way to state it?
00:03:23 Manuel London
Right.
00:03:24 Manuel London
It also may reflect that the organization is not doing as well as it could do.
00:03:29 Manuel London
And it also can pinpoint, of course, positive aspects of when decisions are made well and they are good decisions and processes are outstanding that might not be evident unless they are brought forth from data that are analyzed on a regular basis.
00:03:46 Tom Diamante
So the organization's not performing at the level that it could be, is what you're saying, right?
00:03:51 Tom Diamante
Even though there's a level of success, maybe there's room for enhancement.
00:03:55 Manuel London
Right.
00:03:55 Manuel London
And of course, on the negative side, are decisions made too quickly?
00:03:58 Manuel London
Are they not aligned with what the organization's goals are or indeed its values?
00:04:04 Manuel London
Do they not consider socially responsible criteria?
00:04:08 Manuel London
You know, these are things we have written about in our article in the IA magazine.
00:04:14 Tom Diamante
AI seems to be getting mixed pressed, if you will, but there certainly isn't a lot of conversation these days around how AI is totally a value add to work and life in general.
00:04:26 Tom Diamante
Would you like to kind of just...
00:04:28 Tom Diamante
to talk a little bit about how AI might be something that contributes to risk or has some negative implications if misused or improperly used, or how as a management tool, which is, as you know, is often being deployed as a management tool, can lead to maybe some concerns if misused or improperly used.
00:04:50 Richard Chan
So it really depends on how the AI is being trained, right?
00:04:54 Richard Chan
So essentially,
00:04:55 Richard Chan
If it's being trained on biased data, the derivation or its recommended solution could be biased as well.
00:05:03 Richard Chan
So that's one aspect where AI can result in, whether it's biased hiring decision, performance feedback, performance evaluation, et cetera.
00:05:11 Richard Chan
So that's one aspect we need to pay close attention to.
00:05:15 Manuel London
Yeah.
00:05:16 Manuel London
And that happens because AI is trained on decisions that are made by the organization or by many organizations.
00:05:24 Manuel London
And often it's biased because the input is biased.
00:05:27 Manuel London
And so the results are like that.
00:05:29 Manuel London
But another factor is that people can mistrust AI or be concerned that it's going to take away their jobs or won't be used correctly.
00:05:39 Manuel London
And so that can lead to dissension in the organization or fear or people not adopting it as quickly as they could or using it as effectively as they could.
00:05:50 Manuel London
So those are potential negatives that can occur.
00:05:54 Tom Diamante
Well, on that issue, can you speak a little bit to the data on willingness or openness to actually use AI as an employee?
00:06:02 Tom Diamante
Because my understanding is that sometimes there's some reluctance for employees to use AI because
00:06:09 Tom Diamante
There's a concern that one's manager might view that as a negative, not a positive, meaning it's showing a lack of judgment or the kind of reliance on AI to do your job for you.
00:06:22 Manuel London
Yeah, or lack of competence.
00:06:24 Manuel London
You know, and what do we need you for if you're just going to use AI to generate the results?
00:06:29 Manuel London
or whatever they're working on.
00:06:31 Manuel London
Let's say it's a marketing presentation or something like that, or they're putting together a presentation on whatever topic.
00:06:37 Manuel London
And so they're using AI to do it for them.
00:06:40 Manuel London
And so they say, well, what are we paying you for if all I had to do is press up and then they could have done it.
00:06:45 Manuel London
But I think we should be thinking about AI as tools.
00:06:49 Manuel London
Just like Excel is a tool, Excel has become a very important tool, I'm sure, for auditors and certainly people in finance and in many fields, because it does so many things so well and keeps track of data and provides analytic tools.
00:07:03 Manuel London
So of course, we're using it.
00:07:05 Manuel London
So AI is really very similar.
00:07:08 Manuel London
There are a variety of AI tools and large language models that have been applied and could be used in different ways to make the organization more effective and efficient.
00:07:18 Manuel London
And so we should be using it.
00:07:20 Manuel London
Organizations should welcome it, and employees should learn how to use it as a tool that enhances their field of expertise.
00:07:27 Tom Diamante
So as one tool, and Richard, please chime in, but as one way of using this tool, or one way this tool has been used, has been to monitor behavior inside the organization.
00:07:39 Tom Diamante
Would either one of you like to kind of lean in on that a little bit?
00:07:42 Tom Diamante
Is that a good thing?
00:07:43 Tom Diamante
Is that a bad thing?
00:07:44 Tom Diamante
Are there concerns?
00:07:45 Tom Diamante
What are your thoughts on that?
00:07:47 Richard Chan
That's a very good question, right?
00:07:49 Richard Chan
So in terms of when it comes to monitoring, it really depends on individual's perception, right?
00:07:54 Richard Chan
Depending how, it also depends on how organization is utilizing the monitoring mechanism.
00:08:01 Richard Chan
So although AI monitoring can create some kind of surveillance cultures, they really diminish morale, increase stress, and will result in attritions.
00:08:12 Richard Chan
And in fact, in more recent Pew Research survey in 2025, what they have found that after surveying around 5,000 U.S.
00:08:23 Richard Chan
workers, over half, 52% of them, they worry the usage of AI in the workforce.
00:08:30 Richard Chan
And earlier research also found that 61% against
00:08:35 Richard Chan
using invasive AI application tracking physical movement and digital activities of employees.
00:08:42 Richard Chan
So there are certain list of concerns.
00:08:45 Richard Chan
But ultimately, it really depends on employees' perception, right?
00:08:49 Richard Chan
How these mechanism is being used, whether they actually use to improve performance, organization really use it as a reward or punishment mechanism.
00:08:59 Richard Chan
That will change how the AI monitor would be perceived.
00:09:04 Manuel London
Right.
00:09:04 Manuel London
It's not unusual for organizations to monitor employees' behavior.
00:09:08 Manuel London
Certainly, it's not new.
00:09:11 Manuel London
And some organizations have been doing it for many years in areas of manufacturing and delivery and things of that sort.
00:09:18 Manuel London
Probably less so in office kind of work in terms of monitoring emails or monitoring conversations, looking at how much time people are spending on the computer and different types of software and so forth.
00:09:33 Manuel London
And that's something people aren't necessarily used to.
00:09:36 Manuel London
And it's not necessarily good, but how is it related to the performance of those individuals and the outcomes of the organization?
00:09:44 Manuel London
So it may not be, and it may be that that's part of their job too.
00:09:47 Manuel London
So it just varies.
00:09:50 Manuel London
But as Richard points out, people are very leery about that and concerned that they don't have agency themselves.
00:09:57 Manuel London
to determine what they need to do on their jobs and how they're going to do it to produce the outcomes that the organization expects.
00:10:04 Tom Diamante
So context really matters here when you're talking about data, its use, and its interpretation, correct?
00:10:10 Manuel London
Oh, absolutely.
00:10:11 Manuel London
You know, it's used in different ways, different approaches, not just one.
00:10:14 Manuel London
And I think auditors can put together systems
00:10:19 Manuel London
that help them identify what's going on in the organization, take advantage of AI, but do it in a way that makes sense for that organization in various departments.
00:10:28 Tom Diamante
So I'm glad you touched upon that.
00:10:29 Tom Diamante
So in terms of audit, if you will, as a profession, what thoughts might you have in terms of the responsibility or the, if you will, of the mission of internal audit as it relates to the use of AI in their organizations?
00:10:45 Tom Diamante
Do they own it?
00:10:46 Tom Diamante
Should they have a leadership role?
00:10:49 Tom Diamante
What's your view of the role of the function of internal audit in the use and perhaps management or mitigation of misuse of AI?
00:10:59 Manuel London
I would say that they have a valuable role and they do it using non-financial as well as financial data.
00:11:08 Manuel London
So it provides additional input.
00:11:11 Manuel London
and identifies problems that may not have been evident as early on as they are.
00:11:17 Manuel London
So, I think internal auditors especially should understand the various AI tools that are available to them, how the organization can incorporate them into their processes, and then work with leadership to discuss this and determine what the internal audit role should be, what results are being identified, and have a discussion.
00:11:38 Manuel London
So essentially, they can take a
00:11:41 Manuel London
a role along with the leaders of the organization to understand how the heads of the different disciplines or areas within the organization in the C-suite, if you will, as well as the head of the organization, the CEO, and be part, be at the table to provide those data and discuss how best they may be used.
00:12:02 Richard Chan
Yeah, that's a very good point because internal auditory can also not only need to understand all these frontier models,
00:12:10 Richard Chan
and its potential application.
00:12:12 Richard Chan
Having this understanding, it will allow them to become integrated, right?
00:12:16 Richard Chan
Really incorporate these AI toolset into the business practice, whether it's HR function, accounting, finance, marketing, et cetera.
00:12:25 Richard Chan
For example, what happened in recent years is that a lot of major large companies, often they really want to catch the AI wave.
00:12:34 Richard Chan
They essentially don't have any rule or regulation.
00:12:37 Richard Chan
They just tell
00:12:39 Richard Chan
and force their employees to ask them to use these AI tools without understanding how these usage can help them to enhance their workforce productivities.
00:12:50 Richard Chan
So I was talking to one of the major Fortune 500 firms, one of the director in technology.
00:12:58 Richard Chan
What he has shared is that oftentimes without understanding how these AI tool set could help them to
00:13:06 Richard Chan
perform their day-to-day functions, employees simply use it on various purposes.
00:13:11 Richard Chan
It's not very effective usage of AI tools.
00:13:14 Richard Chan
So internal auditors can really become more effective integrators, ensuring there's a strong alignment with AI tool and how they can accomplish.
00:13:24 Tom Diamante
So essentially, audit should audit AI?
00:13:28 Tom Diamante
Would you agree with that?
00:13:30 Manuel London
Sure, that's absolutely a way of looking at it.
00:13:33 Manuel London
Are the tools being used effectively and how, certainly.
00:13:37 Manuel London
But also the auditor can have a role with leadership in understanding how well the organization is operating.
00:13:44 Manuel London
Are decisions being made?
00:13:45 Manuel London
Are costs being overrun?
00:13:47 Manuel London
Let's say they're implementing a new
00:13:49 Manuel London
system are people working together effectively from the different departments to do the integration that's necessary, essentially focusing on organizational dynamics and how well they're working.
00:14:00 Manuel London
So that may be a broader role than internal auditors are used to, provide some expansive value to create that value and maintain it in the organization.
00:14:11 Tom Diamante
So are there any principles or rule of thumb or something that you might advise internal auditors or leadership in general in terms of deploying AI as a management tool?
00:14:22 Tom Diamante
Are there any kind of do's and don'ts or any guidance comes to mind to make sure that it's deployed in a value-add way and then doesn't bleed into becoming, you know, like a surveillance type of a culture, you know, which everyone is concerned about?
00:14:39 Tom Diamante
how can that be done, or what assurances, or what role can internal audit play to make sure that when and if you deploy AI, it's done in a way that is, you know, have a...
00:14:50 Tom Diamante
a positive influence and not contribute to, or added to, unwanted, unhealthy risk.
00:14:57 Manuel London
Yeah, well, I suppose identifying how it's being used and track that, track out potential outcomes that portend problems like lower morale or people leaving the organization, attrition that results from that, evidence of stress, people not coming into work when they're supposed to, or being online when they're supposed to, depending upon if they're working hybrid or whatever.
00:15:18 Manuel London
they're working, are they identifying those potential problems that are essentially conflicts that can occur or culture risks, if you will, that can emerge?
00:15:29 Manuel London
And so the internal auditor can have a role in thinking about that and helping leadership think about that.
00:15:36 Tom Diamante
Would you agree that the leadership should be able to explain to their employees what data they actually are collecting and perhaps even
00:15:45 Tom Diamante
statewide that's so, if that's a problem or if that's problematic, would you say that maybe we haven't thought this through?
00:15:53 Richard Chan
Yeah, I think it's very important for the managers or the leadership to be transparent in the type of data being collected.
00:16:02 Richard Chan
And furthermore, how these data would be utilized, right?
00:16:05 Richard Chan
One of the reasons why people have these type of fear of being a monetary, being surveillance all the time is simply because
00:16:13 Richard Chan
they really do a lot of uncertainty, right?
00:16:15 Richard Chan
People don't know what type of data are being collected and how these data will be used to, whether these data will fundamentally change their performance evaluation or promotion opportunity, et cetera.
00:16:27 Richard Chan
So having clarity and showing responsible usage and transparency would be helpful.
00:16:34 Tom Diamante
Because that would erode trust, would it not?
00:16:36 Richard Chan
Yep, definitely.
00:16:37 Tom Diamante
And not just trust in the tool, but I think guilty by association, as they say.
00:16:42 Tom Diamante
But if your manager is using a monitoring system to manage you, then your monitoring isn't necessarily the same as management, correct?
00:16:51 Manuel London
Well, certainly it's a balance.
00:16:52 Manuel London
The idea of using AI to control and monitor is to avoid risk, of course, or to identify it as it's emerging.
00:17:01 Manuel London
But at the same time, the systems can promote
00:17:05 Manuel London
effective working relationships that can promote.
00:17:08 Tom Diamante
Social identification of high potentials, identifying positive outliers, right?
00:17:14 Tom Diamante
Special events, things that have occurred that might get under the radar if the radar wasn't on.
00:17:18 Tom Diamante
Very often we think about early warning systems or in terms of identifying a negative event, right?
00:17:25 Tom Diamante
But Manny, what you're saying is that, hey, we can also identify really unusual positive things that have taken place and take note of that as well.
00:17:33 Tom Diamante
right.
00:17:33 Manuel London
Exactly.
00:17:34 Manuel London
This is what we mean by a healthy risk culture in the AI world.
00:17:38 Manuel London
And the internal auditor and the staff can help promote this and understand its value to the organization.
00:17:46 Tom Diamante
Right, which might contribute directly to things like product development and reducing cycle times and just an innovation in general, right?
00:17:53 Tom Diamante
So identifying when things go right, when things go efficiently, and
00:18:00 Tom Diamante
product development comes to market very rapidly, products are commercialized more rapidly than expected, ahead of budget, under budget, ahead of time, like delivery is there, and taking notice of these things and be able to share that enterprise-wide, which also might be something that may not have happened unless AI was involved.
00:18:20 Richard Chan
Right.
00:18:20 Richard Chan
So that's a very good point as well, because in terms of research, people actually have found that the use of AI toolset is actually
00:18:28 Richard Chan
result in more creative ideas.
00:18:31 Richard Chan
One of the reasons is because humans tend to be biased and utilize their own judgment experience when you come up formulate with creative ideas.
00:18:40 Richard Chan
But AI would be able to enable...
00:18:43 Richard Chan
workers to look beyond their comfort zone, right, and resulting in more creative solutions.
00:18:49 Richard Chan
However, it's also very important to ensure that there's some way to safeguard somehow blind acceptance.
00:18:56 Richard Chan
Innovation is great, but internal auditors or employees also need to look at whether such innovations will result in useful result.
00:19:07 Richard Chan
Otherwise, it's just
00:19:10 Richard Chan
random combination of wild ideas, right?
00:19:12 Tom Diamante
So it's a great way to overcome just traditional silos or organizational barriers.
00:19:17 Tom Diamante
So this is a good example of technology kind of coming through bureaucratic impediments, if you will, by use of technology.
00:19:25 Tom Diamante
You know, another thing I've come across use in practice is that no one is ever against innovation, right?
00:19:30 Tom Diamante
The innovation word.
00:19:32 Tom Diamante
So AI is always put forward typically as, new innovation and they anthropomorphize, the AI agent, give it a name.
00:19:40 Tom Diamante
They do all these sorts of things to speed implementation.
00:19:43 Tom Diamante
Often that it makes it more difficult culturally for anyone in the organization, perhaps including internal audit, to tap the brakes and say, hold on a second.
00:19:52 Tom Diamante
You know, what are we doing?
00:19:53 Tom Diamante
Why are we doing this?
00:19:55 Tom Diamante
What data is being collected?
00:19:57 Tom Diamante
What if we're wrong?
00:19:58 Tom Diamante
what if everyone uses this data as a validated output when really it's just input for decision making?
00:20:06 Tom Diamante
Have you seen or what advice would you have based upon your experience and research in it where how it's implemented and the mechanisms used to implement it can kind of get in the way of doing it correctly, you know, for the sake of innovation and speed and kind of, you know, bringing in the, you know, the next best thing?
00:20:23 Tom Diamante
You know, there's such a rush
00:20:25 Tom Diamante
to implement AI.
00:20:26 Tom Diamante
And it's, probably, most people would probably agree that you don't want to get in the way of new technology and certainly don't want to get in the way of AI coming in to make us, more efficient and to improve operations.
00:20:41 Tom Diamante
Like nobody wants to do that.
00:20:42 Tom Diamante
You don't want to be accused of the person tapping the brakes.
00:20:46 Tom Diamante
But in fact, someone needs to ask these difficult questions.
00:20:49 Tom Diamante
You know, should we do it?
00:20:50 Tom Diamante
Why are we doing it?
00:20:51 Tom Diamante
What data are we collecting?
00:20:53 Tom Diamante
Who is making
00:20:55 Tom Diamante
decisions based upon that data, right?
00:20:57 Tom Diamante
All of that.
00:20:58 Tom Diamante
And one of the implications of all of that.
00:21:00 Tom Diamante
So I guess, what I'm trying to, the question I'm trying to pose here is, what are the cultural impediments or what are the cultural considerations that need to be taken into, you know, into consideration before AI is fully deployed?
00:21:16 Tom Diamante
And how can AI maybe, how can internal audit play a role
00:21:22 Tom Diamante
in making sure that when it is implemented, timing is right, the outcomes are anticipated, and there are checkpoints or guideposts or guardrails in place so that if a fix is necessary, they actually have the capacity to improve it and make it better.
00:21:40 Tom Diamante
Big question, I know.
00:21:42 Manuel London
Yeah, that was going to say, that's a very big question.
00:21:45 Manuel London
Generally, I think what you're saying is that the internal audit staff can work together with people who are responsible for major operations.
00:21:55 Manuel London
Let's say integrating a new software system that cuts across departments and disciplines and doing it in a way that is going to be effective and efficient.
00:22:04 Manuel London
As data are collected, let's say relative to the goals, the per chart they have for
00:22:12 Manuel London
what's supposed to happen when, understanding not just the data and where problems are occurring, but helping to pinpoint why they occur and what can be done to improve the situation or avoid it in the future?
00:22:24 Tom Diamante
In terms of value to the board and leadership in general, kind of high level, where do you see the value of AI that contributes directly to improve governance or to the efficacy of the board?
00:22:38 Tom Diamante
What would they become aware of?
00:22:40 Tom Diamante
Maybe it's early warning systems, maybe risk escalation, competitive issues.
00:22:46 Tom Diamante
where do you see AI being as influential in terms of being useful for board decision making and board efficacy and governance in general?
00:22:56 Manuel London
Of course, it's all of those things.
00:22:58 Manuel London
And one can sit down and look at how AI is being used across the organization or within each area of the organization.
00:23:05 Manuel London
What's being done in the financial area, for example, to ensure risks are being avoided, let's say fraud is being identified or avoided, of course, how this is affecting the reputation of the organization.
00:23:19 Manuel London
They can identify
00:23:22 Manuel London
irregularities of things going on.
00:23:24 Manuel London
The same thing in operations in terms of safety, in terms of quality, all sorts of quality controls.
00:23:31 Manuel London
And how is AI being used to implement those controls?
00:23:35 Manuel London
Are those being done in ways that are effective rather than making people wary of what's going on and so reticent to move forward with innovation?
00:23:45 Manuel London
and being active.
00:23:47 Manuel London
Customer relationships, another area, of course, where there are all sorts of data that are being collected and provide early warning systems for a whole host of potential problems.
00:23:59 Manuel London
And then as we've been discussing a lot about organizational dynamics and the way decisions are being made, people are interacting with each other, whether it's they're doing so collaboratively or conflicts are emerging.
00:24:11 Manuel London
And so AI can help identify those
00:24:15 Manuel London
issues as well and try to fine-tune and improve communications.
00:24:20 Manuel London
So really, AI has potential value across the organization in each department.
00:24:28 Manuel London
Internal auditors will be using the results of AI to pinpoint problems as they occur, but also to show how it can be of value and then to work with leadership throughout the C-suite
00:24:40 Manuel London
to improve the way it's being used and ensure it's being used effectively in finding areas where it should be used and where it can do more for the organization where it's not being used perhaps right away.
00:24:53 Richard Chan
Yeah, that's a great point.
00:24:54 Richard Chan
And also, essentially, how organization should treat AI is ensured there will be human in the loop, right?
00:25:02 Richard Chan
Internal auditors or top management teams should really be integrators.
00:25:06 Richard Chan
And while at the same time, not only understanding the latest technology and how they can effectively improve performance, at the same time, they also need to safeguard against blind acceptance.
00:25:19 Richard Chan
Otherwise, garbage in, garbage out, right?
00:25:21 Richard Chan
We all know the what type data we receive will dictate what type of output we generate.
00:25:27 Richard Chan
So it's important for internal attitudes to have a practical checklist.
00:25:33 Richard Chan
understanding what tools are being implemented and how these tools will impact the different functional areas, and also understanding where the data are coming from and whether these data will be objective and non-biased, et cetera.
00:25:49 Richard Chan
And all those to ensure that they are human in the loop, human in the AI loops.
00:25:55 Richard Chan
That would be important.
00:25:57 Tom Diamante
And so what in your mind is the perhaps one or two things that an organization must attend to?
00:26:03 Tom Diamante
in order to ensure that AI is implemented in a positive way and not necessarily a negative way.
00:26:09 Tom Diamante
So how can we make sure that AI is something that mitigate risks and doesn't irritate risk?
00:26:16 Tom Diamante
What comes to mind?
00:26:17 Manuel London
I'll just repeat what I've said a few minutes ago, and which we have written about in this concept of the internal auditor thinking about what constitutes a healthy risk culture for the organization generally, and AI contributes to that.
00:26:32 Manuel London
It doesn't mean that whatever the audit
00:26:35 Manuel London
staff has been doing has got to change.
00:26:39 Manuel London
But how does AI facilitate that as a tool that can guard against bad risk and move toward a more effective and innovative organization?
00:26:49 Tom Diamante
So you want to get rid of the bad risk, but also nurture, if you will, the entrepreneurial positive risk and not do one for the sake of compromising the other.
00:26:59 Tom Diamante
I think that's probably a
00:27:01 Tom Diamante
difficult balance.
00:27:03 Tom Diamante
Richard.
00:27:04 Richard Chan
Yeah, that's exactly what I thought as well.
00:27:06 Richard Chan
I totally agree with Juan.
00:27:08 Richard Chan
Both of you have to mention.
00:27:09 Tom Diamante
In terms of wrapping this up, you know, I appreciate the time of both of you.
00:27:13 Tom Diamante
And again, obviously it was a pleasure working with both of you to produce the article.
00:27:18 Tom Diamante
I just kind of think we all agree that AI, like you said earlier, is a very valuable tool.
00:27:23 Tom Diamante
But like any other tool, how you use it really matters.
00:27:26 Tom Diamante
One thing we touched upon is that if an organization cannot explain what data it is collecting and why it's collecting that data and how it will use that data to the workforce, then they probably haven't thought it through and probably should kind of go circle back and get the answers to those questions so that when they do implement it, Mandy, as kind of you put it, we're encouraging the innovation and the entrepreneurial behavior
00:27:51 Tom Diamante
while also using the tool to mitigate and prevent unwanted, unhealthy risk.
00:27:58 Manuel London
Right, and to think about human capital risk in particular as perhaps an area that internal auditors have not thought as much about.
00:28:06 Tom Diamante
Right, and perhaps they should play a role there.
00:28:10 Tom Diamante
one thing, interesting, and I know we're trying to wrap it up, but, and without backgrounds, most of us come out of HR kind of types of backgrounds.
00:28:18 Tom Diamante
No, HR typically kind of owns the human capital space.
00:28:22 Tom Diamante
So maybe one thing we've touched upon here, even though lightly, is that maybe AI should not be, if you will, completely owned by HR.
00:28:32 Tom Diamante
but maybe should share the wealth and internal audit should play a role in the use and ensure guidance and navigation of how AI is being used effectively with HR.
00:28:42 Tom Diamante
Would you agree?
00:28:44 Manuel London
Absolutely.
00:28:44 Manuel London
And especially in times of change and in organizations that are going through change, let's say a merger or acquisition of some sort, where they can really identify human capital risk and try to understand how that's influencing decisions.
00:28:59 Manuel London
and to ensure that risks are not incurred unnecessarily.
00:29:02 Tom Diamante
Well, thank you both.
00:29:04 Tom Diamante
I think that wraps it up.
00:29:06 Tom Diamante
I appreciate your time, and I look forward to our next research article together.
00:29:12 Manuel London
Absolutely.
00:29:13 Manuel London
Thanks, Tom.
00:29:14 Manuel London
It's Richard.
00:29:16 The IIA
If you like this podcast, please subscribe and rate us.
00:29:19 The IIA
You can subscribe wherever you get your podcasts.
00:29:21 The IIA
You can also catch other episodes on YouTube or at theia.org.
00:29:26 The IIA
That's THEIIA.org.