93% of Audit Teams Use AI. 60% Have No Strategy For It.
Gartner surveyed 161 chief audit executives in May 2026 and found 93% of audit functions already use AI in some form — but 60% have no formal strategy governing that use. Only 38% of CAEs report having a strategy in place; 39% are still building one, and 23% have none at all. More than half, 54%, haven’t started measuring the return on their AI investment.
James Bourke, a Director Analyst in Gartner’s Risk & Audit Practice, frames this as a governance problem rather than an access problem: “many CAEs are still navigating a confusing landscape of hype, high expectations and uncertainty about how best to deliver AI’s value.” The technology is already in daily use. The oversight structure meant to direct it isn’t.
That gap tracks a pattern Gartner has flagged elsewhere. In an August briefing on AI agents specifically, Gartner analyst Alex Levine told CFOs to treat their first agent deployment as a governance pilot, not an ROI showcase, warning that “early pilots are most likely to fail due to unclear controls, not poor technology.” His prescription — explicit permission boundaries, mandatory human review points, and full failure logs before scaling — is the same fix the audit-function data implies: write the rules before the rollout, not after.
For organizations further along than a pilot, the audit numbers are the more uncomfortable read. This isn’t a caution about early experiments — it’s evidence that adoption has already outrun governance in a function built specifically to catch that kind of gap. An audit team that can’t yet measure its own AI’s ROI, using AI it adopted ahead of any formal policy, is the control function itself proving the point it exists to make elsewhere in the business.