Deliverable 4c · People, Culture & Training
Role-Based Playbooks
Every role gets a plain-language playbook for using AI safely — what to do, what never to do, the approved tools, and exactly when to escalate. The framework meets people where they work.
Auditor
Auditors may use approved AI tools to accelerate drafting, research, and summarization, but must exercise independent professional judgment on all findings, risk ratings, and recommendations.
- Use PL-001 and PL-007 to draft initial finding summaries and memos, then edit to reflect your professional judgment
- Verify every dollar figure, citation, and regulatory reference in AI output against primary source documents
- Classify all AI-assisted work products at TLP:AMBER or higher until cleared by the engagement supervisor
- Document AI tool usage in your workpaper as part of the evidence trail
- Do not use AI-generated risk ratings as final without independent corroboration of the underlying condition and criteria
- Do not input full unredacted audit evidence into any model not approved for TLP:RED data
- Do not share AI outputs outside the audit team before supervisor review
- Do not rely on AI for legal interpretation of audit standards — route to OIG Counsel
- • Azure OpenAI GPT-4o (TLP:AMBER and below)
- • Internal RAG (standards corpus)
- • Databricks DBRX (code and data tasks)
- • Microsoft Copilot for Government (drafting support)
Escalate to the Supervisory Auditor and RISC AI Governance Lead if AI output contains unexplained factual discrepancies, appears to have hallucinated citations, or if a finding relies materially on AI analysis without independent corroboration.