Ask any internal auditor in Maldives what “using AI” means at work, and you’ll probably hear the same answer: summarising a policy document, drafting audit findings, or asking a chatbot to explain a regulation in plain English. That’s Generative AI, and it’s genuinely useful. It writes faster than we do.
But while most of us have been getting comfortable with the chatbot, the profession globally has already moved on to something bigger. It’s called agentic AI, and it doesn’t just answer your questions. It goes and does the work, pulling data, testing controls, flagging exceptions, and following up, largely on its own.
In my first article on this site, I argued that internal auditing in the Maldives must evolve from a compliance function into a strategic partner. Agentic AI is, quite possibly, the single biggest test of whether we actually mean that. Here are the takeaways from the global research that every Maldivian audit committee, CAE, and internal auditor should sit with.
1. “Generative” and “Agentic” are not the same species of AI
This distinction matters more than it sounds. Generative AI creates content, a summary, a draft memo, a explanation of a standard. It waits for you to ask, gives you an answer, and stops. It doesn’t act on anything.
Agentic AI is different. It can plan a sequence of steps, use tools, pull data from multiple systems, make a decision, and carry an action through to completion, with only occasional human check-ins. One industry comparison put it simply: generative AI provides information, while agentic AI gets things done.
Think of the difference this way: a generative tool might draft an email flagging a control breakdown. An agentic system might actually send that email, log the exception, and update three related registers, all before anyone reviews it. That’s a much bigger leap in capability, and in risk.
A recent industry playbook on agentic AI for internal audit laid the distinction out plainly:
| Generative AI | Agentic AI | |
|---|---|---|
| What it does | Describes and summarises | Executes and documents |
| Auditor’s role | Operator | Reviewer |
| Output | A draft to build on | A completed workpaper to review |
| Where it saves time | Prep and documentation | Execution itself |
| What it doesn’t change | Headcount requirements | Auditor judgment |
That last row is the one worth sitting with. Generative AI makes an audit team faster at the same amount of work. Agentic AI is the first credible way to expand coverage without a proportional increase in headcount, which matters enormously in a market as talent-constrained as ours.
2. Adoption is not creeping — it’s doubling
The numbers coming out of the profession globally are striking. One industry survey found that nearly 8 in 10 internal auditors (77%) are already using or experimenting with some form of AI, but a much smaller group, 47% of governance, risk, and compliance leaders, are using or planning to use agentic AI specifically. Separately, one industry tracking report found that agentic AI deployment in audit and finance functions grew from roughly 11% to 25% in a single year, more than doubling. Other analysis suggests three in four companies plan to invest in agentic AI capability by the end of 2026.
This is the part that should genuinely concern anyone still treating AI as a “someday” agenda item. When a capability doubles in a year, “we’ll look at it next year” quietly becomes “we’re now a year behind.”
3. The world’s largest professional body for internal auditors is already calling this a governance issue, not an IT project
When the U.S. National Institute of Standards and Technology asked for feedback on its AI risk management framework, the global Institute of Internal Auditors didn’t respond with a list of tools. It responded by insisting that AI risk be managed through the Three Lines Model, the same governance structure we already use for every other kind of enterprise risk, rather than being carved off into a separate, siloed “AI committee” that nobody else understands.
That’s a deliberate signal. AI oversight isn’t a specialist add-on bolted onto governance. It’s meant to run through the same accountability structure that governs everything else: the governing body setting direction, management owning the risk, and internal audit providing independent assurance over the whole thing.
4. The risk agentic AI creates is a different kind of risk
With generative AI, the worst-case failure is usually a bad answer, wrong facts, a hallucinated citation, an awkward summary. Embarrassing, but contained, because a human reads it before anything happens.
With agentic AI, the worst-case failure is a bad action. The system doesn’t just draft the wrong recommendation; it can execute it, approving a payment, closing a case, updating a record, notifying a regulator, before a human ever sees it. That shifts the entire risk conversation from “is this accurate?” to “what did it actually do, and can we reverse it?”
This is exactly why frameworks now call for human-in-the-loop thresholds: clear rules about which actions an agent can take entirely on its own, and which ones must wait for a human sign-off. Low-value, reversible actions can run automatically. High-value or irreversible ones cannot.
5. Cybersecurity and AI have pushed past the traditional risks — and it happened fast
The IIA’s Risk in Focus 2026 report, drawing on responses from thousands of chief audit executives across more than 130 countries, shows digital disruption and AI climbing to third place among global risk priorities, up from fourth the year before. In North America specifically, over half of audit leaders now place AI-driven digital disruption in their top five risks, a jump of 17 percentage points in just two years.
The report’s own guidance to audit leaders is blunt: push for internal audit representation on AI councils, audit the AI workflows and the data behind them, and don’t assume management will invite internal audit to the table, ask for the seat.
6. The Maldives is actually not starting from zero — but internal audit specifically is behind the curve
This is the part that surprised me most while researching this piece, and it should reframe how we think about “AI in the Maldives.”
The Maldives became the first country in South Asia to complete UNESCO’s AI Readiness Assessment, launched in mid-2025. A National AI Masterplan (2025–2035) is being developed by the National Centre for Information Technology to guide adoption across sectors, alongside supporting legislation on cybercrime, digital identity, and data protection. At the national level, this is real institutional momentum, not just talk.
But that momentum has been concentrated in government digital services and national infrastructure, not in internal audit functions inside SOEs, banks, councils, or private companies. If national government can move fast enough to roll out a digital identity platform integrating health, business, and family records in a short span, there is no structural reason internal audit departments in the Maldives should be years behind. The gap isn’t capability. It’s attention.
7. Small, resource-constrained audit teams have the most to gain — and the most to lose
One commentary on Maldivian AI strategy made an observation that applies directly to our profession: adopted with intent, AI can reduce the structural disadvantages of operating in a small, dispersed market. Adopted passively, it risks deepening dependence on foreign platforms and leaving local capability behind.
“Perhaps the greatest risk for the Maldives is delay.”
That line was written about the country’s broader AI strategy, but it applies with unusual precision to internal audit here. Our functions are already thin, small teams, dispersed across islands, competing for scarce technical talent. Agentic AI, deployed carefully, is a genuine force multiplier for exactly this kind of resource-constrained environment: one auditor with a well-governed agent can cover more ground than five without one. Deployed carelessly, or not at all, it becomes one more way we fall further behind organisations that do adopt it.
8. This isn’t about replacing auditors — it’s about promoting them
The most senior voices in the profession are framing this the same way. One veteran audit leader, reflecting on decades of change, from checklists, to risk-based planning, to data analytics, described agentic AI as the most consequential shift internal audit has seen. His reasoning: if agents take over the repetitive execution of testing, the auditor’s role moves from operating the procedure to reviewing and interpreting its result. That’s a promotion, not a demotion, but only for auditors who build the judgment to challenge what an agent produces rather than simply accept it.
The workforce data backs this up. In one survey of audit leaders, 51% expected reductions in purely transactional, data-processing roles; 40% anticipated hiring shifting toward higher-skill profiles; and 32% predicted reduced reliance on contractors and outsourced staff for routine testing. For the Maldives, where co-sourcing and outsourced testing capacity is already scarce and expensive, that last figure is worth paying close attention to, it points toward relying less on external capacity and building more of it in-house, governed by better tools.
“Our value will be determined not by what we check, but by how we enable others to succeed.”
9. “Digital teammates” is the phrase the profession is converging on — and it changes how we plan work
One major advisory firm now describes the direction of travel for internal audit as agents that sense risk, initiate action, and execute entire workflows inside human-defined guardrails, describing them as:
“digital teammates operating alongside auditors.”
That framing matters because it changes what an audit plan looks like. Instead of a fixed annual schedule of discrete audits, the profession is moving toward continuous, always-on monitoring where agents watch for risk signals in real time and the audit plan flexes around what they find. For a small Maldivian audit shop that currently manages to cover only a fraction of its universe each year because of headcount constraints, that shift in model, not just tooling, is the real opportunity.
A Governance Structure for Adopting Agentic AI — Not Just a Tool Rollout
Buying an AI tool is easy. Governing what it’s allowed to do is the hard part, and it’s the part that determines whether internal audit ends up trusted with agentic AI or locked out of it. A sensible structure for a Maldivian organisation, SOE, bank, council, or private company, should cover four layers:
Oversight layer (the governing body / board or audit committee)
- Approves the organisation’s overall risk appetite for autonomous AI action, not just AI use in general.
- Requires a standing report on what agents are deployed, what they’re authorised to do, and what they’ve done.
- Ensures internal audit has an assigned seat, not just an invitation, on any AI governance or steering committee.
Management layer (first and second lines)
- Owns a clear inventory: every agentic AI deployment, its purpose, its data sources, and the systems it can touch.
- Sets explicit human-in-the-loop thresholds: which actions an agent may complete unsupervised (low value, reversible) versus which require sign-off (high value, irreversible, regulatory, or reputational).
- Maintains audit trails and logs for every autonomous action, not just every generated output.
Assurance layer (internal audit — the third line)
- Builds enough technical fluency to test an agent’s logic, not just its output, this is a new competency requirement, not an optional one.
- Audits the guardrails themselves: are the human-in-the-loop thresholds actually being respected in practice, or quietly bypassed for speed?
- Confirms every autonomous action is logged with full traceability back to source evidence, an agent’s conclusion is only as defensible as the trail behind it. Traceability is what makes autonomous output reviewable, and reviewability is what makes it auditable.
- Checks that every autonomous output has a named human owner who signed off on it, not just a system log showing the agent ran.
- Evaluates data governance feeding the agents, poor data quality becomes poor autonomous action, at scale and speed.
- Uses agentic AI in its own work where appropriate continuous control testing, exception monitoring, while maintaining independent oversight of its use elsewhere in the organisation.
Policy and culture layer
- A written AI use policy, understood by staff who are not technologists, this is a governance document, not an IT manual.
- Defined escalation paths when an agent acts unexpectedly or incorrectly.
- Ongoing training so audit staff can question an agent’s reasoning, not just accept its conclusions.
A Practical Roadmap for Maldivian Internal Audit Functions
Given the realities of our market, small teams, limited specialist AI talent, and organisations at very different starting points, a phased approach makes more sense than a single leap.
Phase 1 — Foundation (0–6 months): Get literate, get honest
- Build basic organisational literacy on the difference between generative and agentic AI at board, management, and audit committee level.
- Take an honest inventory: is anyone in the organisation already using agentic tools informally, without governance? (This happens more often than most CAEs assume.)
- Run a “repetition audit” across your current testing cycles, walk through your existing compliance and controls-testing workflows and identify exactly where auditor time is trapped in high-volume, low-judgment, repetitive work. External benchmarks suggest fieldwork execution can account for as much as 70% of total audit hours in a typical testing cycle. Whatever the true figure is in your own function, it’s almost certainly your biggest automation opportunity.
- Add AI governance as a formal line item in the annual risk assessment and audit plan, even if the answer today is “we don’t have any yet.”
Phase 2 — Pilot with guardrails (6–12 months)
- Choose one low-risk, high-volume, reversible internal audit process for a controlled proof of concept, a standard monthly user-access review or a routine reconciliation is a good candidate, run first on non-production evidence. Avoid anything customer-facing or irreversible for this first run.
- Benchmark your current baseline hours for that manual test before the pilot starts. Those numbers become the yardstick for whether the pilot actually worked.
- Define human-in-the-loop thresholds before the pilot starts, not after something goes wrong.
- Document everything: what the agent did, what evidence it read, what a human reviewed, and what was overridden and why.
Phase 3 — Governance formalisation (12–18 months)
- Formalise the four-layer governance structure above into policy.
- Secure internal audit’s seat on any organisation-wide AI steering group.
- Begin building the technical competency of the audit team, this doesn’t require every auditor to become a data scientist, but every auditor should be able to ask an agent intelligent questions about its own logic.
Phase 4 — Scale with assurance (18 months and beyond)
- Expand agentic AI use across more of the audit universe, guided by what the pilot proved out.
- Shift parts of the audit plan from periodic, point-in-time reviews toward continuous, real-time monitoring for the areas where agents have proven reliable.
- Benchmark progress against regional and global peers, IIA chapters across Asia are already publishing adoption data; there is no need to reinvent this from scratch.
The Real Question
Generative AI made us faster writers. Agentic AI is offering something else entirely, the chance for internal audit to move from reviewing what already happened to sensing what’s about to happen. Organisations in the Maldives are already building the national infrastructure for AI at a pace that outpaces much larger countries. Internal audit’s job now is to decide whether it will help govern that shift from a position of informed authority, or explain, after the fact, why it wasn’t in the room when the decisions were made.
The question isn’t whether agentic AI is coming to Maldivian organisations. It already is. The real question is the one I keep coming back to:
Will internal audit in the Maldives help write the rules for agentic AI, or will it be the last function to find out an agent broke one?
Leave a Reply