Hello World
First post! Welcome to the first instance of SignalKit and my personal broadcast platform. More here soon. #signalkit
First post! Welcome to the first instance of SignalKit and my personal broadcast platform. More here soon. #signalkit
Compliance value isn't fixed. It peaks at trigger events like an IPO, a new regulation, or an M&A deal, then drifts without deliberate leadership. The best audit leaders know the difference between a gate and a habit.
We have spent years signing off on internal audit's use of the word "independence." Here is the uncomfortable part: internal auditors are not independent in the sense the word carries, and AI is about to make that impossible to keep saying. The word was always a proxy for the thing we actually wanted, objectivity you can prove. On what the Standards really claim, how the IIA has quietly half-conceded, and the receipt-based architecture that should replace a borrowed word. #internalaudit #AI #IIA
My internal audit team's training budget splits in half every year: half to the IIA, half to ISACA. Two memberships, two certifications, two of everything, for a job that has fused into one while the institutions stayed split. Why does the profession still run two tribes? On how the split made sense once, why AI is ending the case for it, the four futures ahead, and who really holds the power to change it. #internalaudit #IIA #ISACA #AI #GRC
Assurcast's promise is "curated, not algorithmic." This month I taught it to bring in YouTube, the most algorithmic medium there is. Audit and assurance videos now embed and play in the feed, the AI summarizes the video description, sharing uses the real thumbnail, and every "Watch on YouTube" button points back to the creator. A dozen tracked slices about keeping the content and leaving the recommendation engine at the door. #assurcast #howiai #claudecode #indiehacker
Most AI privacy stories start with the prompt. TeachMetrics' AI features assume the opposite: the model is an untrusted SQL author. It can only see 24 aggregate views with no student PII by construction. Its SQL passes an allow-list validator, runs in a read-only transaction, and every answer shows exactly what was sent. Prompt injection's blast radius shrinks to 'a different aggregate query ran.' The prompt is UX. The boundary is code.
Every system makes mistakes. What separates a trustworthy one is what it does next. A Correction of Error is a structured, no-blame admission: what broke, why the system allowed it, and what changes so the whole class of bug can't return. In our harness the AI files them unprompted, against a written standard, including failures nobody would have caught. Prevention isn't maturity. Honest correction is.
We talk a lot about “humans in the loop.” But humans get tired. Humans rubber-stamp. Humans become bottlenecks. The real challenge is preserving humanity in the loop: truthfulness, accountability, craftsmanship, humility, and trust. I explore how a single AI agent can build and review its own work when guided by shared tenets and honest retrospection.
This is the welcome video to my course on cRisk Academy. Check it out.
For decades we've measured control maturity by one yardstick: more automation, more prevention. But a perfectly optimized control can stay "effective" right up until it fails catastrophically. A 70-year-old theory, cybernetics, points to what comes next in the age of AI.
I help modern audit and risk professionals embrace data analytics and AI to transform assurance. I also build software products in the social, grc, and analytics domains.
By email
Get the latest news and updates in your inbox.
By feed reader
We publish RSS, Atom, and JSON feeds sliced by category and tag.
View all feeds →Get the latest news and updates in your inbox.