The landscape of internal audit is undergoing a rapid, albeit often undirected, transformation with the widespread adoption of Artificial Intelligence (AI). A recent survey by Gartner reveals that a staggering 93% of internal audit leaders are now incorporating AI into their workflows, yet a significant majority – 62% – admit to lacking a defined AI strategy. This divergence between usage and strategic planning presents a critical challenge for the profession, potentially hindering the realization of AI’s full potential and increasing organizational risk. Concurrently, a separate report from the UK’s Financial Conduct Authority (FCA) highlights concerning deficiencies in the wealth management sector regarding client fund source verification, a cornerstone of anti-money laundering (AML) efforts. These findings, coupled with an analysis by Flashpoint indicating a surge in ransomware attacks despite a decrease in victim payouts, paint a complex picture of evolving threats and evolving defenses across the financial and corporate governance spheres.
Internal Audit’s AI Paradox: Widespread Adoption, Strategic Deficit
The Gartner survey, which polled 743 audit professionals, underscores the pervasive integration of AI into audit practices. Generative AI, in particular, is being deployed for a variety of tasks, primarily focused on enhancing productivity and streamlining processes. Sixty percent of respondents indicated using AI for pre-engagement planning, drafting audit issues, and generating ratings and reports. Another 40% are leveraging it for engagement planning and reviewing draft documents. These applications suggest a pragmatic, task-oriented approach to AI adoption, aimed at immediate efficiency gains.
However, the application of AI for more complex and strategic audit functions remains comparatively limited. Only about a third of audit leaders are utilizing GenAI for performing actual audit testing (30%). Furthermore, its use in writing or editing code/scripts for audits stands at 27%, while finding information accounts for 26%. More in-depth analytical tasks such as root cause analysis are being supported by AI by only 22% of respondents, and a mere 12% are employing it for quality assurance reviews. This indicates that while AI is becoming a common tool, its role is largely confined to augmenting existing processes rather than fundamentally transforming audit methodologies or enabling new levels of insight.
James Bourke, Director of Analyst in Gartner’s Risk and Audit practice, commented on these findings, stating, "Audit’s current use of GenAI concentrates less on strategic audit use cases and more on moderate productivity improvements." This observation points to a potential disconnect between the perceived benefits of AI and the ability of audit functions to strategically embed it within their broader risk management and assurance frameworks. The lack of a clear strategy means that AI implementation might be ad-hoc, potentially leading to siloed applications, suboptimal resource allocation, and an inability to fully capitalize on AI’s transformative capabilities. Without a strategic roadmap, organizations risk missing opportunities to enhance audit effectiveness, improve risk identification, and proactively address emerging threats.
UK Wealth Management Firms Under Scrutiny for KYC Weaknesses
In parallel to the AI adoption trends in internal audit, the FCA’s survey of approximately 400 UK wealth management firms has exposed significant gaps in crucial compliance procedures. The report reveals that a concerning 10% of these firms are failing to adequately verify the sources of their clients’ wealth. This oversight is particularly alarming given the heightened global focus on combating financial crime, including money laundering and terrorist financing.
The FCA’s findings indicate that nearly 40 firms are not conducting thorough due diligence on the origins of client funds. This lack of verification is a fundamental breach of Know Your Customer (KYC) principles, which are designed to prevent illicit actors from integrating their criminal proceeds into the legitimate financial system. Beyond source of wealth checks, the survey unearthed further compliance deficiencies. More than a quarter (26%) of firms do not maintain records of expected transaction frequencies for their clients, and 13% fail to document expected investment amounts. These omissions hinder a firm’s ability to identify unusual or suspicious transaction patterns that could signal illicit activity.
Compounding these issues, approximately 6% of firms are not verifying if their clients are Politically Exposed Persons (PEPs), a category of individuals who may be more susceptible to bribery and corruption due to their position. Furthermore, around 7% of firms are not conducting sanctions screening, a critical measure to ensure compliance with international sanctions regimes and prevent financial dealings with prohibited entities or individuals.
While the FCA noted that firms have improved in the frequency of refreshing KYC checks, these identified gaps highlight persistent weaknesses in the fight against financial crime. Nick Henderson-Mayo, Head of Compliance at VinciWorks, a compliance training and risk management software provider, commented on the survey’s implications: "Verifying sources of wealth and evidence of funds is critically important, especially because failing to do so can present a significant sanctions risk these days." His statement underscores the severe implications of non-compliance, extending beyond regulatory penalties to reputational damage and potential involvement in sanctions breaches.
Interestingly, the FCA survey also touched upon AI adoption within the wealth management sector, revealing a more nascent stage of integration compared to internal audit. Only 13% of firms reported using AI, with another 40% considering its implementation. This suggests that while AI is recognized as a potential tool, its adoption in this sector is still in its early phases, potentially lagging behind the broader industry trends observed in internal audit. The wealth management sector’s current compliance challenges, coupled with a slower uptake of AI, could create a vulnerability that sophisticated financial criminals might exploit.
Ransomware Attacks Intensify as AI Fuels Cybercrime
The threat of cybercrime continues to evolve at an alarming pace, with a recent analysis by threat intelligence platform Flashpoint revealing a troubling paradox: while fewer ransomware victims are paying ransoms, the overall number of attacks is on the rise. The company’s Global Threat Intelligence Report for the first half of 2026 indicates a 45% increase in ransomware victims compared to the same period in the previous year. Despite this surge in attacks, the proportion of victims choosing to pay ransoms has fallen to a historic low of 28%.
This trend of increased attacks and decreased payouts can be attributed to several factors, including improved resilience and backup strategies among organizations, as well as a growing reluctance among law enforcement agencies and cybersecurity experts to encourage ransom payments, which can fuel further criminal activity. However, the underlying threat remains potent.
A significant driver behind the escalating cyberattacks is the rapid advancement and deployment of AI by malicious actors. Flashpoint’s report highlights that AI is accelerating the pace and sophistication of cyberattacks. The intelligence gathered from illicit forums and marketplaces revealed 22 million discussions involving criminal AI toolkits. These discussions underscore how cybercriminals are increasingly utilizing locally hosted, safeguard-free AI models to generate phishing campaigns, malware, exploit code, and social engineering content at "machine speed." This democratization of advanced cyberattack capabilities means that even less sophisticated actors can now deploy highly effective and personalized attacks.
The report also draws a stark connection between geopolitical instability and escalating cyber risks. The early part of 2026 saw military conflicts in the Middle East coincide with a wave of cyber campaigns targeting critical infrastructure, supply chains, financial institutions, and industrial systems. This trend illustrates how geopolitical events can rapidly create operational risks for organizations far beyond the immediate conflict zones. Nation-state actors and affiliated groups are leveraging cyber capabilities as a tool of modern warfare and political leverage, creating a more volatile and unpredictable global threat landscape.
Implications and Future Outlook
The confluence of these reports paints a picture of organizations navigating a complex and rapidly evolving risk environment. The widespread adoption of AI in internal audit, while promising for efficiency, carries the inherent risk of strategic misalignment. Without clear objectives and governance, AI could become a superficial tool rather than a transformative force for enhanced assurance and risk management. Organizations must prioritize developing comprehensive AI strategies that define use cases, ethical considerations, data governance, and the necessary upskilling of audit professionals. The focus needs to shift from mere productivity gains to leveraging AI for more sophisticated risk identification, predictive analytics, and proactive threat mitigation.
In the financial sector, particularly wealth management, the FCA’s findings serve as a critical warning. The identified gaps in KYC and AML procedures expose firms to significant regulatory penalties, reputational damage, and, more importantly, an increased risk of facilitating financial crime. The slow adoption of AI in this sector might further exacerbate these vulnerabilities. Firms need to accelerate their investment in robust compliance technologies, including AI-powered solutions, to automate and enhance due diligence processes, identify suspicious activities more effectively, and ensure adherence to evolving regulatory requirements. The imperative is to move beyond tick-box compliance to a proactive and intelligence-driven approach to financial crime prevention.
The escalating ransomware threat, fueled by AI, demands a multi-faceted response. Organizations must bolster their cybersecurity defenses, implement robust incident response plans, and prioritize employee training to counter sophisticated social engineering tactics. Beyond individual organizational efforts, there is a growing need for enhanced public-private partnerships to share threat intelligence, develop collective defense strategies, and disrupt the financial incentives for ransomware actors. The geopolitical dimension of cyber threats underscores the importance of international cooperation and robust national security strategies to address state-sponsored cyber activities.
Ultimately, the insights from Gartner, the FCA, and Flashpoint highlight a critical juncture for businesses and regulatory bodies. The rapid integration of powerful technologies like AI, coupled with persistent compliance gaps and an increasingly volatile threat landscape, necessitates a proactive, strategic, and collaborative approach to risk management and governance. The future of corporate integrity and security will depend on the ability of organizations to not only adopt new technologies but to do so with foresight, strategic intent, and a clear understanding of the evolving risks they face.
