In this episode of The Third Party Risk Institute Podcast, host Linda Tuck Chapman speaks with Dasha Gorovenco, Executive Director in EY Ireland’s audit practice, about what effective artificial intelligence governance looks like through an external auditor’s lens.
Dasha explains why documentation is not the same as evidence, why AI ownership must exist in practice rather than only on paper, and why organizations need to know which AI systems are actually operating across their networks not simply which tools were approved or listed in a vendor contract.
Together, Linda and Dasha discuss AI audit evidence, third-party and fourth-party AI risk, SOC and ISO compliance, AI inventories, model testing, regulatory readiness, data sovereignty, cybersecurity risk, and operational resilience.
What we cover in this episode:
• What external auditors assess when reviewing an AI governance program
• Why policies, contracts, meeting invitations, and process documents do not necessarily prove that controls are operating effectively
• How to define practical AI ownership across business teams, technology, risk, compliance, users, and senior leadership
• Why one Chief AI Officer or AI Risk Officer cannot own every aspect of AI risk
• How organizations can identify approved and unapproved AI within third-party products, software, cloud environments, and business processes
• How functionality-based questions can help identify AI embedded within vendor products and services
• Why SOC reports may not provide sufficient assurance over AI-specific controls
• The growing need for AI inventories, AI Bills of Materials, monitoring, and fourth-party visibility
• Why dynamic AI systems, large language models, algorithms, and automated decisions require ongoing testing
• How organizations can assess AI-generated errors, model bias, inconsistent outputs, and control failures
• What the EU AI Act, DORA, GDPR, and data-sovereignty requirements mean for global organizations
• How AI governance, cybersecurity risk, regulatory compliance, and operational resilience are connected
This episode is perfect for:
• Board members, Chief Risk Officers, Chief Audit Executives, CISOs, CIOs, and AI governance leaders
• Internal Audit, IT Audit, Risk, Compliance, GRC, and Assurance Professionals
• Third-Party Risk Management and Vendor Risk Management Professionals
• Procurement, Cybersecurity, Privacy, Data Governance, and Model Risk Teams
• Professionals responsible for AI controls, regulatory compliance, operational resilience, and third-party oversight
• Organizations implementing or purchasing AI-enabled products and services
🎧 Enjoying the podcast?
Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com
📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd.
📬 Have a question or topic you'd like us to cover?
Email us at: [email protected]