Skip to main content
Image coming soon

The Risk Partner's AI Workpaper Defence Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Risk Partner's AI Workpaper Defence Playbook

Defend AI-augmented Risk Services workpapers to QMR and external inspection with a chain from prompt to partner sign-off.

The internal QMR finding that flagged an AI-generated walkthrough with no traceable prompt history is the finding a Risk partner cannot repeat. The next inspection wants the same artefact. A defensible, partner-signed chain of evidence from prompt to sign-off.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Risk Services partners are running engagements where teams are quietly using generative tools to draft walkthroughs, summarise interview notes, code-review client systems, and pre-fill control matrices. The work product looks fine. The workpaper file does not show the prompt, the model response, the reviewer challenge, or the partner judgement on residual risk. Internal Quality Management Review picks this up first. The PCAOB-style external inspection picks it up second. The client Audit Committee, briefed on AI use in their engagement, asks the third version of the question. By the time three of those land in a single quarter, the partner book carries an unacceptable defensibility gap and the partner personally carries the sign-off exposure. The fix is not banning AI use on engagements. The fix is the artefact, partner-signed, that proves the chain from prompt to conclusion holds up under challenge.

What you walk away with

  • Produce a partner-signed prompt log, reviewer challenge record, and residual judgement memo for every AI-augmented workpaper on the file.
  • Pass internal Quality Management Review on AI use in Risk Services engagements without remediation findings.
  • Brief the client Audit Committee on AI use in their engagement with a defensible, plain-English summary of what was used, why, and what reviewers changed.
  • Respond to a regulator or PCAOB-style inspection request on generative tool use in audit-adjacent work with a complete response pack in days, not weeks.
  • Set a Risk Services engagement-level AI use policy that survives a national leader review and an external inspection without rewrites.
  • Carry the partner sign-off on AI-augmented deliverables with documented evidence of judgement, not a blanket disclosure.

The 12 modules

Module 1. The QMR finding that broke the file
Reconstructs the realistic QMR finding pattern landing on Risk Services files this cycle. Walks the partner through what reviewers actually wrote, what the file did and did not contain, and what the partner sign-off memo failed to address. Names the four reviewer questions that have to be answered on the file before sign-off, not after the finding. Sets the bar for every subsequent module.
Module 2. The prompt log artefact
Specifies the prompt log artefact for a Risk Services engagement: prompt text, model and version, date and time, engagement role of the user, source documents passed in, model output retained verbatim, reviewer challenge, partner judgement on the residual. Includes a worked example for an SOX walkthrough, an ITGC control narrative, and a third-party risk summary. Templates are in the playbook for direct drop into workpaper.
Module 3. Reviewer challenge form for AI-augmented workpapers
Builds the reviewer challenge form that sits one level above the prompt log. Reviewer reads the model output, marks what they changed, what they retained as is, and what they escalated to partner. The form ties to the file index so QMR can trace any conclusion back to the prompt and the challenge. Includes the four challenge categories every QMR panel expects to see on file.
Module 4. Partner sign-off memo on AI use
The single most important artefact in the file: the partner memo that documents what AI was used for, what reviewers challenged, what the partner accepted as residual judgement, and why. Written in plain English for a future inspector, not in firm-internal shorthand. Includes the three-paragraph template, the standing judgement language, and the client-engagement-specific addendum that QMR will look for.
Module 5. Engagement-level AI use policy
The partner-signed policy that sits at the top of the engagement file and governs what AI may and may not be used for on this client. Covers in-scope tool list, prohibited use cases for this engagement, data handling and retention requirements, client consent or notification status, and the escalation path when the team wants to use a tool outside the policy. Built to survive a national leader read and an external inspection.
Module 6. Client Audit Committee read-out on AI use
The plain-English briefing the partner gives to the client Audit Committee or equivalent governance body on AI use in their engagement. Names the tools, names the use cases, names the controls, names what the firm retains and for how long. Includes the standing Q-and-A for the three questions every Audit Committee currently asks, and a one-page handout the client can take into their own board meeting.
Module 7. QMR self-assessment for the partner book
The self-assessment the Risk partner runs across their own portfolio before the formal QMR cycle opens. Identifies which files have AI-augmented workpapers, which carry the partner sign-off memo and which do not, and which need remediation before review. Includes the prioritisation rubric, the remediation playbook for files mid-engagement, and the documented decision log when a file is closed without remediation.
Module 8. Regulator and inspection response pack
The pre-built response pack the partner releases when a regulator letter or PCAOB-style inspection request lands asking about generative tool use. Covers the engagement inventory, the per-engagement prompt log extract, the partner sign-off memos, the policy on file, and the residual-risk register. Designed to ship within five business days of the request, not five weeks.
Module 9. Retention, privilege, and discoverability of prompt logs
Resolves the question every Risk partner asks: do the prompt logs and reviewer challenge records survive retention rules, attract privilege, and what is the discoverability exposure in a future client dispute. Walks the partner through the firm-retention rule, the client engagement letter language that should be added, the privilege overlay where applicable, and the litigation-hold posture. Built with general-counsel input embedded in the templates.
Module 10. Cross-engagement consistency across the partner book
Builds the standing position the partner takes across every file in their book: same policy, same artefacts, same reviewer challenge structure, same sign-off memo shape. Includes the team briefing the partner gives at engagement kick-off, the deliverable templates the team uses end to end, and the quarterly self-audit checklist that catches drift before the next QMR cycle. Removes the file-by-file variation that QMR penalises.
Module 11. National leader and risk function escalation paths
Maps when the partner escalates to the national Risk leader, the firm Risk Management function, or the Office of General Counsel. Covers the three triggering events on a live engagement, the documentation that has to accompany the escalation, and the standing position to take when a client pushes back on the firm AI use policy. Includes a written escalation template ready to send.
Module 12. Twelve-month partner book readiness plan
Stitches the prior eleven modules into a twelve-month plan for the partner book. Covers the policy roll-out across live engagements, the back-file remediation sequence, the team training cadence, the client Audit Committee briefing schedule, the QMR self-assessment milestones, and the inspection readiness drill. Built as a calendar of artefacts, not a strategy deck.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

QMR cycle opens and a file with AI-augmented workpapers is selected for review.
Client Audit Committee asks how generative tools were used in their engagement and what the firm retains.
Regulator letter or PCAOB-style inspection request lands asking about AI use in audit-adjacent work.
National Risk leader asks the partner for evidence the policy is enforced consistently across the book.

What you get with this course

  • Twelve written modules covering prompt log, reviewer challenge, partner sign-off memo, engagement policy, Audit Committee read-out, QMR self-assessment, inspection response pack, retention and privilege overlay, cross-engagement consistency, escalation paths, and the twelve-month readiness plan.
  • Downloadable templates for every artefact named above, in editable formats, ready for direct drop into the engagement file.
  • Worked examples for SOX walkthroughs, ITGC control narratives, third-party risk summaries, and regulatory assurance reports.
  • Hand-built implementation playbook configured for a Risk Services portfolio, delivered alongside course access.
  • Standing Q-and-A for client Audit Committee briefings and the three questions currently asked.
  • Account access in the Art of Service learning environment with the full written module library.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

Modules one through four cover the foundation artefacts (prompt log, reviewer challenge, partner sign-off memo, residual judgement).

Modules five through eight cover engagement policy, client Audit Committee briefing, QMR self-assessment, and inspection response.

Modules nine through twelve cover retention and privilege, cross-engagement consistency, national leader escalation, and the twelve-month partner book plan.

Before and after

Before

AI is used quietly across engagements in the partner book. Workpapers carry conclusions the model contributed to with no prompt log on file, no reviewer challenge record, and a partner sign-off memo that does not address AI use. The next QMR finding is a matter of which file gets pulled first. The client Audit Committee question on AI use is answered ad hoc each time. A regulator request would take weeks to assemble.

After

Every AI-augmented workpaper in the book carries a prompt log, a reviewer challenge record, and a partner sign-off memo that documents the residual judgement in plain English. The engagement-level AI use policy sits on the file. The client Audit Committee read-out is standing copy. The QMR self-assessment is run before the formal cycle opens. A regulator or inspection request is answered with a pre-built pack within five business days.

What happens if you do not address this

The QMR finding lands on a partner-signed file. The Audit Committee question is answered inconsistently across engagements. A regulator or PCAOB-style inspection request takes weeks to assemble and the response carries gaps. The partner personally carries the sign-off exposure when the inspector points to a workpaper conclusion the model contributed to and there is no chain on file from prompt to judgement.

Who it is for

A Risk Services partner or principal carrying portfolio responsibility for client engagements that touch internal controls, SOX, ICFR, IT general controls, third-party assurance, regulatory assurance reports, or risk advisory deliverables. Reports into a national Risk leader, sits on internal QMR review panels, signs off opinion and advisory deliverables, fronts client Audit Committee presentations on engagement quality and AI use, and is personally accountable when an inspection or QMR finding lands on a file they signed.

Who this is NOT for. Junior managers and senior associates who do not personally sign deliverables. Risk consultants in advisory-only roles with no opinion sign-off responsibility. Tax and Deals partners whose work is not subject to QMR on assurance-adjacent files. Anyone running a fully manual practice with no AI tool use across engagements, current or planned.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Two to three hours per module if read end to end. Most partners work through the templates over a four to six week roll-out across the book, with the QMR self-assessment and the engagement-level policy as the first two artefacts that land on live files.

Why $199 is the right number

Firm-internal Risk Management guidance currently provides the policy language but stops short of the engagement-file artefacts. PCAOB and IAASB consultations describe the expectations but do not give you the prompt log template, the reviewer challenge form, or the partner sign-off memo shape. Vendor AI governance courses cover model risk at the enterprise level but do not address the partner sign-off exposure on a client engagement file. This course is the file-level artefact set, built for the partner carrying the sign-off.

FAQ

Is this firm-specific?
No. The artefacts are designed to sit alongside firm-internal Risk Management guidance, not replace it. Any Big4 or large independent assurance firm partner can use the templates against their own internal policy as the governing document.
Does the course tell me which AI tools are acceptable to use on engagements?
No. That is a firm-internal decision driven by your Risk Management function and your client engagement letters. The course teaches you how to document the use of whatever tools your firm permits, in a form that survives QMR and external inspection.
Is the prompt log template aligned to a specific regulator standard?
It is aligned to the documentation expectations emerging across PCAOB consultation papers, IAASB AI in assurance discussions, and the audit-adjacent expectations of major prudential regulators. It is built to be regulator-neutral and inspectable across jurisdictions.
What does the implementation playbook contain?
A partner-book-specific configuration of the twelve module artefacts: prompt log starter, reviewer challenge form, partner sign-off memo template, engagement policy, Audit Committee read-out, QMR self-assessment, inspection response pack, retention overlay, escalation templates, and a twelve-month roll-out calendar.
Can my team work through this with me?
Yes. The course is licensed to the buyer but the templates are intended to be rolled out across the engagements the partner signs. The team briefing slide deck and the engagement kick-off script are in the playbook.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.