Stay connected: follow us on LinkedIn and explore more at
www.CherryHillAdvisory.com.

Subscribe now to join the Risk Register community:

Source: GlobeNewswire
Summary: Alation expanded its Intelligence Operating System with six products that strengthen governance across enterprise data, context, and AI agents. Enhancements include AI Governance, Semantic Model Mastering, and agent-aware integrations that automatically let agents read updated source documents and propagate context when those sources change. The release underscores enterprise data cataloging, lineage, context propagation, and agent coordination. The capabilities are available now to Alation users. For internal audit, this is about traceability of what data and documents were used, by whom and when, and ensuring evidence remains current and controlled.
How Internal Audit Can Deploy This: Treat this update as a control surface for audit evidence integrity and AI risk governance. Practical uses: 1) Continuous evidence currency. Subscribe internal audit to cataloged “authoritative sources” (policies, SOX narratives, data dictionaries). When a source changes, context propagation alerts signal that dependent reports, models, or agents must be retested before reuse. Tie the alert to your risk register for reassessment of operational risk where controls depend on the changed asset. 2) ICFR/SOX control testing. Use Semantic Model Mastering to anchor data lineage and business meaning of fields used in key reports. When semantic definitions change, trigger a re-performance or reperformance waiver decision for the affected SOX 404 test and document rationale. 3) Agent oversight. If your audit team uses agents for evidence gathering, the agent-aware integrations provide a governed path to ensure agents read the latest approved sources, reducing stale-evidence risk and supporting risk governance. Pilot steps this quarter: pick two high-impact assets (e.g., revenue recognition policy; GL-to-report mapping) and tag them as audit-relevant in the catalog. Enable change alerts to the audit mailbox. Define an approval workflow so any downstream audit work reusing impacted artifacts is paused until a human reviewer clears it. Safeguards: grant internal audit read-only access; ensure agent permissions are scoped to approved sources; require human review of agent outputs before they enter workpapers; store alerts and acknowledgements in the audit file to evidence oversight.
✎ Try it yourself — Build recipe
Build recipe: Govern audit-relevant sources and agent access in Alation AIOS 1) Trigger and scope: Identify authoritative sources that drive audit work (e.g., policies, process narratives, data dictionaries, GL mapping docs). Add an “audit-evidence” tag in the data catalog to mark these assets as in-scope for change monitoring. 2) Access model: Grant the internal audit group read-only access to tagged assets. Confirm data owners retain write privileges; no public write access. 3) AI Governance policy: Create a governance rule for “audit-evidence” assets: when a tagged source changes, flag dependent datasets, reports, and registered agents as “review required.” 4) Context propagation: Enable context propagation so change notices appear on dependent objects’ pages and are visible to agents that interact with them. Route notifications to the audit mailbox or ticket queue. 5) Agent permissions: Limit agent scopes to approved, tagged sources and read-only interactions. Disallow agents from using untagged sources in audit workflows. 6) Human approval gate: Require a human reviewer to clear the “review required” flag before dependent artifacts can be reused in control testing or continuous monitoring. 7) Test procedure: Make a non-material update to a sandboxed copy of a tagged source. Verify: a) audit mailbox receives the alert; b) dependent objects display review-required status; c) agents attempting to read the outdated artifact are pointed to the updated source. 8) Go/no-go: Proceed if alerts arrive within 15 minutes, all dependencies are flagged, and read-only/agent scopes are enforced. Otherwise, remediate gaps and retest.

Source: Public/PR distribution (Acrisure press release)
Summary: Acrisure announced Auris AI, an AI operating system for the insurance industry offered to Acrisure clients. The platform is positioned to standardize AI across underwriting, risk scoring, claims automation, and customer engagement, and integrates with Acrisure’s advisory and technology stack. Availability and commercial terms are via Acrisure sales channels; no per-seat pricing was disclosed. For internal audit, Auris represents a centralized AI layer spanning high-judgment, high-volume processes—prime ground for risk assessment, governance checks, and validation of AI-enabled underwriting and claims controls.
How Internal Audit Can Deploy This: Treat Auris as a shared control environment for underwriting and claims automation. Start by defining what you will test, not how it works. Two immediate workflows: 1) Underwriting risk scoring: Obtain read-only access to decision logs and input artifacts (applications, third-party data). For a pilot line of business, perform full-population analytics on rule/score thresholds and exception handling, then sample borderline cases for human override consistency. Map results to operational risk in the risk register and adjust the audit plan accordingly. 2) Claims automation: Review straight-through processing versus routed claims and the triggers for manual review. Test whether flagged fraud-risk patterns reliably route to investigation and whether approvals are recorded with time/user stamps suitable for evidence gathering. Pilot steps this quarter: coordinate with the business owner to collect architecture diagrams, data flow maps, and control objectives defined for Auris-enabled workflows. Request a data extract of decision logs (inputs, model/logic version, output, user/agent identifier, timestamp) for one underwriting product and one claims flow. Define pass/fail criteria: traceability of decisions, completeness of logs, and clear reprocessing paths when models or rules change. Safeguards: enforce role-based, read-only access for internal audit; ensure protected data stays within enterprise boundaries; require human review for material decisions; align tests with the organization’s AI governance policy and vendor risk requirements. Document any gaps in change management or logging as control deficiencies and track remediation.
✎ Try it yourself — Checklist
Pre-implementation and pilot audit checklist for Auris AI (underwriting and claims) 1) Scope defined (Pass/Fail): Line(s) of business, products, and processes covered by Auris are documented and approved by management. 2) Decision logging (Pass/Fail): Logs capture input fields, data sources, model/logic version, output/score, agent or user ID, and timestamp. 3) Traceability (Pass/Fail): Each decision can be re-performed using logged inputs and the recorded model/logic version. 4) Change management (Pass/Fail): A formal process exists to review/approve updates to models, rules, and data connectors, with effective dates and rollback. 5) Access control (Pass/Fail): Role-based access is enforced; internal audit has read-only access; admin access is restricted and monitored. 6) Exception handling (Pass/Fail): Criteria for manual review/overrides are defined; overrides are documented with rationale, user, and timestamp. 7) Data governance (Pass/Fail): Data sources used by Auris are inventoried with ownership, quality checks, and retention rules aligned to policy. 8) Operational monitoring (Pass/Fail): KPIs exist for underwriting and claims (e.g., exception rates, straight-through rates, turnaround times) with thresholds and alerts. 9) Risk governance alignment (Pass/Fail): Auris controls are mapped to the organization’s AI governance policy and vendor risk requirements; residual risks are in the risk register. 10) Evidence readiness (Pass/Fail): Reporting extracts and logs are exportable and suitable for audit workpapers without exposing unnecessary PII.

Source: Superintelligence News
Summary: Meta’s Muse personal AI agent is now available as a native Mac app after earlier mobile and web launches. On macOS, Muse can interact with local files, Mail, Notes, Messages, and Calendar, but requires explicit user permission before taking sensitive actions. The desktop app is opt-in, with free and paid tiers noted in earlier releases. For internal audit, a desktop agent that can act on user files and applications is a new control surface that must be governed for data access, action logging, and reviewability of agent-assisted evidence collection.
How Internal Audit Can Deploy This: Handle Muse as a privileged local helper that must be contained. Three immediate workflows: 1) Evidence gathering: Allow read-only access to a dedicated audit folder so Muse can inventory files and summarize contents for workpaper drafting; require human review before filing. 2) Communications timeline: With explicit permission, let Muse read Mail and Calendar for a defined period to extract a chronology of approvals or meetings relevant to a control testing window. 3) Continuous monitoring support: Have Muse list new or modified files in the audit folder weekly, aiding operational risk monitoring without touching production data. Pilot this quarter: deploy Muse on a managed Mac enrolled in MDM. Configure macOS permissions to restrict Muse to specified folders and to read-only interactions with Mail, Notes, Messages, and Calendar. Disable any integrations that transmit content externally. Establish a logging procedure (macOS unified logs plus an agent action log maintained by the user) and require screenshots or file path citations for every output used as evidence. Safeguards: least-privilege access; explicit approvals for each sensitive action; no deletion or sending of emails/messages; store outputs locally; maintain a human-in-the-loop review before inclusion in workpapers; align use with the organization’s AI governance and IT risk policies. Document actions and approvals to ensure repeatability and oversight.
✎ Try it yourself — Agent skill
Agent skill: Internal Audit desktop assistant scope for Meta Muse (macOS) Role: Read-only internal audit research and evidence assistant running on a managed Mac. Tools (macOS): Files, Mail, Notes, Messages, Calendar. Do not use any external connectors or cloud sharing. Procedure: 1) Before any action, ask the user to confirm the allowed folder(s) and date range. Operate only within those constraints. 2) Files: List and read files in the allowed folder(s). Create inventories, summaries, and citations (file path + last-modified timestamp). 3) Mail/Calendar: With explicit permission each session, read messages/events within the approved date range to construct timelines of approvals and meetings. 4) Notes/Messages: Read content only as authorized to extract facts relevant to defined audit procedures; never send messages. Hard constraints: - Read-only. Never modify, move, delete, or create files, emails, notes, messages, or calendar entries. - No external sharing, uploads, or links. Work locally only. - Require explicit user confirmation for each new data source or app access request. - Log every action in-session: action, data source, file path or mailbox, timestamp. Human escalation triggers: - Any request to send a message or email, change a file, or access data outside the approved folders/date range. - Detection of sensitive data beyond scope. Output format: - Provide: a) objectives; b) steps performed; c) inventories/timelines with citations; d) gaps or missing items; e) user approvals captured; f) action log. Flag any ambiguities and never invent content.
Disclaimer: This content is provided for general informational purposes only and does not constitute legal, accounting, tax, investment, or other professional advice. Portions were generated using AI tools from public web sources and may contain errors or omissions — verify important details against the primary sources linked above before relying on them. Any example prompts, scripts, templates, or other artifacts are provided “as is” without warranty of any kind, express or implied; test them on non-production data and apply your own professional judgement before use. Cherry Hill Advisory disclaims all liability for any loss or damage arising from the use of, or reliance on, this content or any artifact it contains.
Subscribe now to join the Risk Register community: