-

New ISACA Publications Highlight Machine Learning Technology and Compliance Risk for Auditors

SCHAUMBURG, Ill.--(BUSINESS WIRE)--The increased use of machine learning (ML) worldwide has created a greater need for IT auditors to understand the technology. ISACA's new white paper series, Audit Practitioner's Guide to Machine Learning, Part 1: Technology and Audit Practitioner's Guide to Machine Learning, Part 2: Compliance Risk, provides auditors with guidelines on the opportunities, risks and compliance requirements associated with the technology.

Through these resources, auditors can better understand the complex and sometimes challenging process involved with building machine learning applications, as well as related considerations involving the data pipeline and software development lifecycle.

The Part 1 paper outlines the roadmap that ML application follows, as well as the related key risk factors that auditors should investigate, including:

  • Data governance
  • Data engineering
  • Feature engineering
  • Model training
  • Model evaluation
  • Model deployment/prediction

Part 2 explores the key laws, regulations and industry standards involved in data compliance for ML auditing, including:

  • Lawfulness, fairness and transparency of personal data used in ML
  • Data minimization and data security
  • Accountability and governance
  • Consumer’s Right to Know

“Having a solid background in machine learning allows auditors to better comprehend the development cycle from technical as well as business perspectives,” says Robin Lyons, Principal, IT Audit Professional Practices at ISACA. “This enables IT auditors to evaluate ML risk exposures and provides management with direction for actionable procedures to mitigate risk and support compliance.”

To download complimentary copies of both parts 1 and 2 of the Audit Practitioner's Guide to Machine Learning, visit https://store.isaca.org/s/store#/store/browse/detail/a2S4w000005Gu72EAC and https://store.isaca.org/s/store#/store/browse/detail/a2S4w000005Gu6dEAC. Additional resources from ISACA around IT audit can be found at http://www.isaca.org/resources/it-audit.

About ISACA

For more than 50 years, ISACA® (www.isaca.org) has equipped individuals and enterprises with the knowledge, credentials, education, training and community to progress their careers, transform their organizations, and build a more trusted and ethical digital world. ISACA is a global professional association and learning organization that leverages the expertise of its more than 165,000 members who work in digital trust fields such as information security, governance, assurance, risk, privacy and quality. It has a presence in 188 countries, including 225 chapters worldwide. Through its foundation One In Tech, ISACA supports IT education and career pathways for underresourced and underrepresented populations.

Contacts

Emily Van Camp, +1.847.385.7217, communications@isaca.org
Kristen Kessinger, +1.847.660.5512, kkessinger@isaca.org

ISACA


Release Versions
Hashtags

Contacts

Emily Van Camp, +1.847.385.7217, communications@isaca.org
Kristen Kessinger, +1.847.660.5512, kkessinger@isaca.org

Social Media Profiles
More News From ISACA

Four Ways to Incorporate AI into Threat Intelligence Programs

SCHAUMBURG, Ill.--(BUSINESS WIRE)--Threat environments have become more complex, especially with the rise of generative AI and the rapid commercialization of the cybercrime ecosystem. Enterprises have also long struggled to realize meaningful value from traditional cyberthreat intelligence programs. However, there are steps that cybersecurity professionals can take to improve the effectiveness of their threat intelligence programs, as outlined in ISACA’s new white paper, Building a Threat-Led C...

AI-Driven Cyber Threats Are the Biggest Concern for Cybersecurity Professionals Going Into 2026, Finds New ISACA Research

LONDON--(BUSINESS WIRE)--Over half (51%) of European IT and cybersecurity professionals fear AI-driven cyber threats and deepfakes will keep them up at night next year, according to new ISACA research. What’s driving this concern is a lack of preparedness for AI-related risks across the industry. Only 14% of respondents feel their organisation is very prepared to manage the risks associated with generative AI solutions in 2026. The majority (82%) feel they are only somewhat prepared, not very p...

From Ransomware to AI Risk: New ISACA Research Identifies What Will Keep Tech Pros Up at Night in 2026

SCHAUMBURG, Ill.--(BUSINESS WIRE)--As they look ahead to 2026, more than half of digital trust professionals (59 percent) are expecting that AI-driven cyber threats and deepfakes will keep them up the most at night next year, according to ISACA’s 2026 Tech Trends & Priorities Pulse Poll. Also anticipated to keep them up at night are thoughts of irreparable harm caused by failure to detect/respond to a breach (36 percent) and insider threats and human error (35 percent), finds the inaugural...
Back to Newsroom