by Jerrad Bartczak, IT Audit Manager – AI & Special Projects
How to Think About AI in Your Compliance Program
We hear a version of this question a lot lately: “We’re starting to use AI across our technology environment. How do we think about that from a compliance perspective?”
It’s a fair question, and the honest answer is simpler than most people expect.
For many organizations, that includes everything from AI-powered coding assistants and workflow automation to customer-facing AI features and productivity tools.
Using AI is fine
There’s nothing inherently disqualifying about using AI tools in your technology environment or your control environment. It’s not a red flag by default, and it doesn’t automatically put your compliance posture at risk. Frameworks like SOC 2 and ISO 27001 aren’t written to penalize the use of new technology. They’re written around how you manage risk and adhere to specific requirements; that extends to the technology, people & processes you’re using to run your business.
So if you’re evaluating AI tools, or already have some in your control environment, that alone isn’t the problem.
Using AI isn’t a free pass
AI introduces real trade-offs. It can process large amounts of data, faster, and with less manual oversight than the tools it’s replacing. That’s the appeal. It’s also a risk. When a system can act, decide, or generate output faster than a human is reviewing it, gaps in oversight become gaps in your control environment.
None of this is hypothetical. It’s the same category of risk compliance programs have always had to manage: who has access, what changes have a low enough risk level where they can proceed with less frequent reviews, and how you’d know if something went wrong after the fact. AI just changes the speed and scale at which those questions matter.
What doesn’t change: someone still has to mind the shop
This is the core of it. AI can help you move faster and do more. It shouldn’t be treated as something you turn on and stop thinking about.
You still own your controls. You still own your environment. That doesn’t go away because a tool is doing more of the work. Whatever you introduce, whether it’s an AI-powered feature, a new integration, or a workflow automation, someone needs to be watching it: monitoring outputs, reviewing changes, and catching the things that go wrong before they become bigger problems.
That’s not a reason to avoid AI. It’s a reason to be deliberate about how you bring it in.
Where this shows up in practice
This idea, technology helps but people still own the outcome, isn’t abstract. It shows up in specific, everyday parts of a compliance program: how you manage changes to your systems, how you handle access and provisioning, how you approach code reviews, and how you run internal audits. We’re seeing more and more practical uses of AI woven into how our clients are managing their own compliance programs.
Over the next few posts, we’re going to walk through what that looks like in each of those areas, starting with change management: what it actually means to keep humans in the loop when AI is part of how changes get made and reviewed. We’re excited to share our perspectives and how we can advise on the risks, benefits and considerations of this emerging technology and its impact on data security.
Like this kind of content? Look for Part 2 coming soon.


