
Saudi Arabia has named 2026 the Year of Artificial Intelligence, and this decision changes the internal audit agenda for every regulated entity in the Kingdom. Boards now expect internal audit to move beyond traditional financial and operational reviews and to build real capability in Internal Audit AI Governance. This shift is not optional. Regulators, standard-setters, and audit committees now treat AI oversight as a core assurance responsibility, not a side project for the IT team.
Saudi Arabia’s AI regulatory landscape stands today, how the IIA’s Global Internal Audit Standards are moving toward a formal AI Topical Requirement, and how Chief Audit Executives (CAEs) in KSA can prepare their functions now.
Why Internal Audit AI Governance Has Become a Board-Level Priority
Saudi organizations are deploying AI faster than most governance functions can absorb it. Globally, 83% of audit functions are already piloting or using AI, and another 12% plan to follow within the year, according to a Gartner survey of chief audit executives published in early 2026. That leaves almost no audit function on the sidelines. Yet adoption does not equal maturity: a separate 2026 Gartner poll of 743 audit professionals found that generative AI use in internal audit still concentrates on isolated tasks such as engagement pre-planning, drafting issues, and reviewing drafts, with less than a third of teams using AI for audit testing.
This gap between adoption and strategic control is exactly where Internal Audit AI Governance earns its place on the audit committee agenda. Internal audit does not only need to use AI tools responsibly; it must also independently assure the board that the organization’s own AI systems are governed, explainable, and compliant with Saudi regulations.
The stakes are high nationally as well. Saudi Arabia expects government AI adoption alone to generate roughly $56 billion annually in productivity gains, based on SDAIA figures reported in 2025. Internal audit sits at the center of ensuring that this scale of investment does not outpace control.
Saudi Arabia’s AI Regulatory Landscape: The Building Blocks of Internal Audit AI Governance
Saudi Arabia does not yet have a single, standalone AI law. Instead, AI oversight runs through a layered set of authorities, and internal audit functions must map their Internal Audit AI Governance programs against all of them.
- SDAIA (Saudi Data & AI Authority) issued a mandatory AI Adoption Framework in November 2025 covering five pillars: data governance, model accountability, transparency, human oversight, and risk management. The framework applies to every public sector entity in the Kingdom and is aligned with the Personal Data Protection Law (PDPL).
- In 2026, SDAIA moved further and published ten regulatory documents covering the ethical and responsible use of AI, including AI ethics principles and generative AI principles for government entities.
- In April 2026, SDAIA opened public consultation on a draft Responsible AI Policy. Industry analysis describes it as a risk-tiering framework that classifies AI systems into four levels: critical, high, limited, and low risk, with obligations around documentation, testing, and monitoring that scale with each tier. The consultation closed in May 2026, and organizations should treat the direction of this policy as effectively confirmed, even before the final text is issued.
- SAMA (Saudi Central Bank) regulates banks, insurance companies, and finance companies. SAMA does not run a separate AI law, but its IT governance and risk frameworks already expect AI-driven decisions such as credit scoring to remain explainable, fair, and auditable, with clear customer disclosure when AI drives a financial decision.
- The NCA (National Cybersecurity Authority) adds a further layer through its cybersecurity controls, which apply whenever AI systems touch sensitive infrastructure or data.
For internal audit functions, the practical result is that a single AI system can sit under SDAIA’s national framework, PDPL, SAMA (for financial entities), and NCA controls at the same time. Internal Audit AI Governance therefore requires a mapping exercise before any testing begins, so the audit team knows exactly which obligations apply to which system.
Saudi Arabia’s Key AI Governance Authorities and Their Focus Areas
| Authority | Primary Focus | Status as of Mid-2026 | Relevance to Internal Audit |
| SDAIA | National AI Adoption Framework, Responsible AI Policy, AI ethics principles | Framework mandatory for public sector (Nov 2025); draft Responsible AI Policy consultation closed May 2026 | Sets the governance baseline auditors must test against |
| PDPL (enforced via SDAIA) | Data protection underpinning AI training and deployment | Fully implemented in 2025 | Governs data inputs and outputs used by AI models |
| SAMA | Banking and financial sector IT governance, AI-driven credit decisions | Ongoing supervisory expectations, no separate AI law | Requires explainability and fairness testing for AI in finance |
| NCA | Cybersecurity controls for AI infrastructure | Applies where AI touches critical systems or sensitive data | Covers resilience and security testing of AI platforms |
The IIA’s Global Internal Audit Standards: The Road Toward an AI Topical Requirement
The Institute of Internal Auditors (IIA) reshaped the profession’s rulebook through its 2024 Global Internal Audit Standards, and it added a new mechanism called Topical Requirements. These requirements set a mandatory minimum scope for internal audit work on specific high-risk topics, and they sit above general professional judgment.
The IIA has already issued a Cybersecurity Topical Requirement, which was published in February 2025 and takes effect on 5 February 2026. An Anti-Corruption Topical Requirement followed a public consultation window from 8 June to 23 July 2026, with final publication expected later in 2026. Artificial intelligence has not yet received its own dedicated Topical Requirement, but the IIA has clearly signaled that it is next in line. In June 2026, the IIA released a full suite of AI Risk Engagement documents, including a Board AI Governance Questionnaire, a Management AI Risk and Control Questionnaire, and an ERM AI Risk Assessment Questionnaire designed to help internal auditors build a structured understanding of how management identifies, assesses, manages, monitors, and reports on AI risks.
These tools give CAEs in Saudi Arabia a practical head start. Building Internal Audit AI Governance capability now, using the IIA’s existing AI Risk Engagement questionnaires, means the audit function will already have working papers, risk taxonomies, and board-reporting templates in place once the formal AI Topical Requirement arrives.
IIA Topical Requirements Timeline (2025 – 2026)
| Topical Requirement | Consultation / Publication | Effective Date | Current AI Relevance |
| Cybersecurity | Published February 2025 | 5 February 2026 | Covers AI-related infrastructure and model security controls |
| Anti-Corruption | Consultation 8 June–23 July 2026 | Expected later in 2026 | Touches AI used in fraud and corruption monitoring |
| Artificial Intelligence | Not yet a formal Topical Requirement | Supported by AI Risk Engagement documents issued 16 June 2026 | Directly governs model risk, data integrity, and board oversight |
| Organisational Behaviour & Resilience | Public consultation expected 2025/2026 | Not yet finalized | Indirectly covers human oversight of automated decisions |
Only 45% of respondents in a KPMG survey on the Global Internal Audit Standards said their internal auditors largely or fully cover the required skills and knowledge for Topical Requirements. That leaves a real skills gap, and it is one that Saudi audit committees should ask about directly, especially given how fast AI adoption is moving inside their own organizations.
Why Internal Audit AI Governance Cannot Wait for a Formal Mandate
Audit leaders sometimes wait for a standard to become mandatory before they invest in it. With AI, that approach carries real risk. Internal Audit’s Risk in Focus 2026 research shows digital disruption climbing sharply on risk registers, and more than half of North American respondents placed digital disruption among their top five risks, up seventeen points in two years, driven primarily by the rapid spread of AI. Saudi organizations, many of which are adopting AI as fast as or faster than global peers under Vision 2030 momentum, face the same exposure.
Governance maturity has not kept pace with deployment. McKinsey’s 2026 AI Trust Maturity research found that only about 30% of organizations reach a mature level of strategy, governance, and agentic AI controls, and the same analysis notes that regulated sectors such as banking, insurance, and government adopt AI more cautiously precisely because of audit, explainability, and accountability concerns. Internal audit functions that build strong Internal Audit AI Governance practices now position their organizations to move faster, not slower, because assurance clears the path for confident deployment.
Building an AI Governance Audit Framework: A Practical Roadmap for KSA Audit Functions
CAEs preparing for the next Topical Requirement should build their programs around four practical pillars, each grounded in what SDAIA and the IIA already expect.
- Map every AI system against Saudi regulatory layers. Internal audit should catalogue each AI use case and record which of SDAIA’s framework, PDPL, SAMA rules, and NCA controls apply, before scoping any engagement.
- Adopt the IIA’s AI Risk Engagement questionnaires now. These tools already exist for board, management, and ERM-level assessment, and they translate directly into audit programs even before a formal Topical Requirement takes effect.
- Test explainability and fairness, not just security. SAMA’s supervisory expectations already require that AI-driven credit and financial decisions remain explainable and free of embedded bias, so internal audit must test model outputs, not only IT controls.
- Close the skills gap directly. With less than half of surveyed audit functions confident in Topical Requirement readiness, internal audit leaders should invest in AI literacy training and bring in specialist support where internal capability is thin.
Key Risks Internal Audit Must Address Inside AI Systems
A mature Internal Audit AI Governance program covers several risk clusters that go beyond generic IT audit checklists.
- Model accountability and explainability: Can the organization explain why an AI system produced a specific output, especially for credit, hiring, or compliance decisions?
- Data governance and PDPL alignment: Does the data feeding the model meet Saudi data protection and localization requirements?
- Bias and fairness: Has management tested the model for discriminatory outcomes across customer segments?
- Human oversight: Does a qualified human retain the ability to override or halt an automated decision?
- Third-party and vendor risk: Where the organization licenses AI models from external providers, does the contract preserve audit rights and transparency?
- Resilience and security: Do NCA-aligned controls protect the AI system from manipulation, data poisoning, or outage?
How Insights KSA Can Help You?
Building Internal Audit AI Governance capability from scratch is demanding, and few internal audit teams in the Kingdom have spare capacity to do it alone. Insights KSA works alongside CAEs and audit committees to close that gap in a structured, practical way.
- Regulatory mapping: Insights KSA maps your AI systems against SDAIA’s AI Adoption Framework, PDPL, SAMA expectations, and NCA controls, so your audit universe reflects the real regulatory picture.
- Topical Requirement readiness: Insights KSA benchmarks your function against the IIA’s existing Cybersecurity Topical Requirement and the emerging AI Risk Engagement toolkit, so you are not caught unprepared when the AI Topical Requirement becomes mandatory.
- AI audit methodology: Insights KSA helps you build testable audit programs for model accountability, bias, explainability, and human oversight, grounded in the same questionnaires the IIA has already published.
- Capability building: Insights KSA delivers targeted training that closes the skills gap identified across the profession, so your internal auditors gain confidence testing AI systems, not just documenting them.
- Board and audit committee reporting: Insights KSA helps you translate technical AI risk findings into clear, decision-useful reporting that boards can act on.
Saudi organizations that engage early gain a real advantage: they enter the formal Topical Requirement period with working papers, trained staff, and a tested methodology already in place, rather than starting from zero under regulatory pressure.
FAQs
What is Internal Audit AI Governance?
Internal Audit AI Governance is the practice of independently assuring that an organization’s artificial intelligence systems are properly controlled, explainable, fair, and compliant with applicable regulation. It covers model risk, data governance, human oversight, and board reporting on AI.
Does Saudi Arabia have a dedicated AI law?
Not yet as a single standalone statute. AI oversight in the Kingdom runs through SDAIA’s AI Adoption Framework and draft Responsible AI Policy, the PDPL, SAMA’s supervisory expectations for financial institutions, and NCA cybersecurity controls.
Has the IIA issued a formal AI Topical Requirement?
Not yet. The IIA has issued a Cybersecurity Topical Requirement, effective 5 February 2026, and opened consultation on an Anti-Corruption Topical Requirement in mid-2026. For AI specifically, the IIA has released a suite of AI Risk Engagement questionnaires (June 2026) that internal auditors can use now, ahead of a formal requirement.
Why should internal audit act before an AI Topical Requirement becomes mandatory?
AI adoption is already outpacing governance maturity. Roughly 83% of audit functions are piloting or using AI, yet only a minority apply it to strategic audit work, and only about 30% of organizations reach mature AI governance overall. Acting early reduces exposure and builds the working papers auditors will need later.
Who does SAMA’s AI-related guidance apply to?
SAMA’s expectations apply to banks, insurance companies, finance companies, and other licensed financial institutions in Saudi Arabia. AI-driven decisions such as credit scoring must remain explainable, fair, and disclosed to customers where relevant.
How can Insights KSA support our internal audit function?
Insights KSA maps AI systems against Saudi regulatory requirements, benchmarks Topical Requirement readiness, builds testable AI audit methodologies, trains audit staff, and helps translate findings into clear board reporting.
