Jamie Ontiveros – Assurance
Assurance Blog
Independence Was Always a Proxy

We have spent years signing off on internal audit's use of the word "independence." Here is the uncomfortable part: internal auditors are not independent in the sense the word carries, and AI is about to make that impossible to keep saying. The word was always a proxy for the thing we actually wanted, objectivity you can prove. On what the Standards really claim, how the IIA has quietly half-conceded, and the receipt-based architecture that should replace a borrowed word. #internalaudit #AI #IIA

Assurance Blog
One Auditor, Two Tribes

My internal audit team's training budget splits in half every year: half to the IIA, half to ISACA. Two memberships, two certifications, two of everything, for a job that has fused into one while the institutions stayed split. Why does the profession still run two tribes? On how the split made sense once, why AI is ending the case for it, the four futures ahead, and who really holds the power to change it. #internalaudit #IIA #ISACA #AI #GRC

Assurance Blog
Curated, not algorithmic — even when it's YouTube

Assurcast's promise is "curated, not algorithmic." This month I taught it to bring in YouTube, the most algorithmic medium there is. Audit and assurance videos now embed and play in the feed, the AI summarizes the video description, sharing uses the real thumbnail, and every "Watch on YouTube" button points back to the creator. A dozen tracked slices about keeping the content and leaving the recommendation engine at the door. #assurcast #howiai #claudecode #indiehacker

Assurance Blog
The Prompt Is Not a Security Boundary

Most AI privacy stories start with the prompt. TeachMetrics' AI features assume the opposite: the model is an untrusted SQL author. It can only see 24 aggregate views with no student PII by construction. Its SQL passes an allow-list validator, runs in a read-only transaction, and every answer shows exactly what was sent. Prompt injection's blast radius shrinks to 'a different aggregate query ran.' The prompt is UX. The boundary is code.

Assurance Blog
The Correction of Error

Every system makes mistakes. What separates a trustworthy one is what it does next. A Correction of Error is a structured, no-blame admission: what broke, why the system allowed it, and what changes so the whole class of bug can't return. In our harness the AI files them unprompted, against a written standard, including failures nobody would have caught. Prevention isn't maturity. Honest correction is.

Assurance Blog
Humanity in the loop

We talk a lot about “humans in the loop.” But humans get tired. Humans rubber-stamp. Humans become bottlenecks. The real challenge is preserving humanity in the loop: truthfulness, accountability, craftsmanship, humility, and trust. I explore how a single AI agent can build and review its own work when guided by shared tenets and honest retrospection.

I help modern audit and risk professionals embrace data analytics and AI to transform assurance. I also build software products in the social, grc, and analytics domains.

Subscribe

By email

Get the latest news and updates in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and tag.

View all feeds →
Feeds
Subscribe by email

Get the latest news and updates in your inbox.