A focused course, tailored for you
The Risk Partner's AI Workpaper Defence Playbook
Defend AI-augmented Risk Services workpapers to QMR and external inspection with a chain from prompt to partner sign-off.
The internal QMR finding that flagged an AI-generated walkthrough with no traceable prompt history is the finding a Risk partner cannot repeat. The next inspection wants the same artefact. A defensible, partner-signed chain of evidence from prompt to sign-off.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
Risk Services partners are running engagements where teams are quietly using generative tools to draft walkthroughs, summarise interview notes, code-review client systems, and pre-fill control matrices. The work product looks fine. The workpaper file does not show the prompt, the model response, the reviewer challenge, or the partner judgement on residual risk. Internal Quality Management Review picks this up first. The PCAOB-style external inspection picks it up second. The client Audit Committee, briefed on AI use in their engagement, asks the third version of the question. By the time three of those land in a single quarter, the partner book carries an unacceptable defensibility gap and the partner personally carries the sign-off exposure. The fix is not banning AI use on engagements. The fix is the artefact, partner-signed, that proves the chain from prompt to conclusion holds up under challenge.
What you walk away with
- Produce a partner-signed prompt log, reviewer challenge record, and residual judgement memo for every AI-augmented workpaper on the file.
- Pass internal Quality Management Review on AI use in Risk Services engagements without remediation findings.
- Brief the client Audit Committee on AI use in their engagement with a defensible, plain-English summary of what was used, why, and what reviewers changed.
- Respond to a regulator or PCAOB-style inspection request on generative tool use in audit-adjacent work with a complete response pack in days, not weeks.
- Set a Risk Services engagement-level AI use policy that survives a national leader review and an external inspection without rewrites.
- Carry the partner sign-off on AI-augmented deliverables with documented evidence of judgement, not a blanket disclosure.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- Twelve written modules covering prompt log, reviewer challenge, partner sign-off memo, engagement policy, Audit Committee read-out, QMR self-assessment, inspection response pack, retention and privilege overlay, cross-engagement consistency, escalation paths, and the twelve-month readiness plan.
- Downloadable templates for every artefact named above, in editable formats, ready for direct drop into the engagement file.
- Worked examples for SOX walkthroughs, ITGC control narratives, third-party risk summaries, and regulatory assurance reports.
- Hand-built implementation playbook configured for a Risk Services portfolio, delivered alongside course access.
- Standing Q-and-A for client Audit Committee briefings and the three questions currently asked.
- Account access in the Art of Service learning environment with the full written module library.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.
Modules one through four cover the foundation artefacts (prompt log, reviewer challenge, partner sign-off memo, residual judgement).
Modules five through eight cover engagement policy, client Audit Committee briefing, QMR self-assessment, and inspection response.
Modules nine through twelve cover retention and privilege, cross-engagement consistency, national leader escalation, and the twelve-month partner book plan.
Before and after
AI is used quietly across engagements in the partner book. Workpapers carry conclusions the model contributed to with no prompt log on file, no reviewer challenge record, and a partner sign-off memo that does not address AI use. The next QMR finding is a matter of which file gets pulled first. The client Audit Committee question on AI use is answered ad hoc each time. A regulator request would take weeks to assemble.
Every AI-augmented workpaper in the book carries a prompt log, a reviewer challenge record, and a partner sign-off memo that documents the residual judgement in plain English. The engagement-level AI use policy sits on the file. The client Audit Committee read-out is standing copy. The QMR self-assessment is run before the formal cycle opens. A regulator or inspection request is answered with a pre-built pack within five business days.
What happens if you do not address this
The QMR finding lands on a partner-signed file. The Audit Committee question is answered inconsistently across engagements. A regulator or PCAOB-style inspection request takes weeks to assemble and the response carries gaps. The partner personally carries the sign-off exposure when the inspector points to a workpaper conclusion the model contributed to and there is no chain on file from prompt to judgement.
Who it is for
A Risk Services partner or principal carrying portfolio responsibility for client engagements that touch internal controls, SOX, ICFR, IT general controls, third-party assurance, regulatory assurance reports, or risk advisory deliverables. Reports into a national Risk leader, sits on internal QMR review panels, signs off opinion and advisory deliverables, fronts client Audit Committee presentations on engagement quality and AI use, and is personally accountable when an inspection or QMR finding lands on a file they signed.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Two to three hours per module if read end to end. Most partners work through the templates over a four to six week roll-out across the book, with the QMR self-assessment and the engagement-level policy as the first two artefacts that land on live files.
Why $199 is the right number
Firm-internal Risk Management guidance currently provides the policy language but stops short of the engagement-file artefacts. PCAOB and IAASB consultations describe the expectations but do not give you the prompt log template, the reviewer challenge form, or the partner sign-off memo shape. Vendor AI governance courses cover model risk at the enterprise level but do not address the partner sign-off exposure on a client engagement file. This course is the file-level artefact set, built for the partner carrying the sign-off.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.