Skip to main content
    Why ReignFor Chief Audit Executives

    The third line needs a population it did not have to ask for.

    Internal audit plans on a cycle and reports on a period. AI systems act continuously, and the population you would sample from is generated faster than a plan can anticipate it. The harder problem is not volume. It is that the evidence is assembled, on request, by the people you are reviewing.

    A single-tenant dedicated instance, in your own AWS or Azure account or in infrastructure iTmethods operates. Both available today; Google Cloud is planned for 2027. Air-gapped and sovereign are in development.

    Where evidence comes from design target
    Assembled on request Written as it happened You ask They assemble You receive Independence is the cost the population was produced by the people under review, after they knew what you asked for PCAOB AS 1105 .10 makes that a thing you have to test as each call is authorized each one linked to the one before Write-once, your account your retention, your Object Lock Nobody had to cooperate and removing one from the middle is a thing the chain shows Material for a human review. Not a verdict, not an audit opinion.
    The record is written by the boundary as it authorizes each call, not by the team you are reviewing once you have asked for it.
    The decision you are actually making

    Independence is easier to hold when the evidence was already there.

    Every audit of an AI-enabled process runs into the same question: where did this population come from, and who produced it. The answer decides how much of the engagement is testing the control and how much is testing the data about the control.

    01Evidence produced on request is evidence someone chose to produce
    The population was assembled by the function under review, after it knew what you had asked for.

    PCAOB AS 1105 .10 makes that a thing you have to work on rather than around: test the accuracy and completeness of information produced by the company, or test the controls over it, including IT general controls and automated application controls.

    02A control tested once a year is evidenced once a year
    Where the control sits in the path, every action it governed is a test of it.

    The IIA’s GTAG on Continuous Auditing and Monitoring, third edition, issued 25 September 2025, is the current guidance on building an audit approach around that rather than around the annual sample.

    03The third line is being asked about AI before it is ready to answer
    The Internal Audit Foundation and AuditBoard surveyed 373 senior internal audit leaders in North America in Q4 2025 and published in February 2026.

    Four in ten believed their function was adequately prepared to detect or respond to AI-enabled fraud. The top barriers were technology, then skills, then budget — in that order.

    04Planning needs to know what ran, not what was expected to run
    Volume, refusals and routing behaviour are visible while the work happens rather than in a report assembled afterwards.

    That is a planning input before it is an evidence one. It changes which populations are worth an engagement this quarter.

    Three lines, one estate

    What the third line gets that it did not have to request.

    The IIA replaced its Three Lines Model position paper on 8 July 2026 with a Statement of Position aimed at the board. The distinction it holds — that the third line reviews the first and second and is independent of both — is exactly the distinction that a self-assembled population erodes.

    Plan

    Risk-based planning

    What actually ran, at what volume, with what refusals and what routing behaviour. Visible while the work happens rather than in a report assembled after you asked for one.

    The question under it. What would you plan around this quarter?
    Available today What the record carries →
    Monitor

    Continuous control monitoring

    Where the control sits in the path, every action it governed is a test of it. A record per call is the population, not a sample of it.

    The question under it. Which controls could you monitor continuously?
    Rely

    Evidence you did not have to request

    Records are written as the work happens and hash-linked as they are written, then exported write-once into storage you hold under your own retention and Object Lock. What you read does not depend on anyone having cooperated after the fact.

    The question under it. How much of your evidence is produced on request?
    Available today Monitoring and records →
    Follow

    A claim you can walk

    Scope, then requirement, then check, then evidence and coverage, and only then a claim — with the gap recorded beside the evidence rather than in a release note. A check that cannot decide goes to a named person.

    The question under it. Could a reviewer walk it without us?
    Co-design development Reign Assurance →
    What produces it

    The record is written by the boundary, not by the team you are reviewing.

    That is the whole of the independence argument, and it rests on one product that exists today rather than on the one that is still in co-design.

    Reign GatewayA record per model call, hash-linked, exported write-once to your account. Available today. Reign OpsThe substrate and its log pipeline, operated to your change control. Available today. Reign AssuranceScope to requirement to check to evidence. Co-design development, not sold.

    Hash-linking is the property that matters most to a third line: a record cannot be removed from the middle of the chain without the chain showing it. Export is write-once into storage under your retention and your Object Lock, which means iTmethods cannot go back and change it either.

    The edge of it

    Reign prepares. Your people decide.

    This is the page where the boundary matters most, because the market usually claims the opposite of what is true here.

    iTmethods does not issue an audit opinion.

    It does not certify, does not attest, does not issue an audit opinion and does not provide independent assurance, in any tense. Nothing on this page is independent assurance of anyone’s controls.

    The record is material for a review, not a conclusion.

    Internal audit reaches the assessment, with whatever advisers it chooses to involve, and nothing here substitutes for that judgment. What changes is the quality and the availability of the evidence that judgment draws on.

    Coverage reaches the systems in scope and no further.

    Work that happens outside those systems is outside the record. A tool that reports on what it cannot see is not producing evidence; the unreachable parts are stated alongside the reachable ones.

    Reign Assurance is not shipping.

    It is being designed with the control functions that will have to rely on it. The record described on this page is produced by Reign Gateway, which is available today.

    The IIA has issued four Topical Requirements — Cybersecurity, Third-Party, Organizational Behavior and Organizational Resilience. None of them is about AI, and none is in consultation. We mention it because the absence is the point: there is no mandatory internal audit requirement to comply with here, only an evidence problem to solve.

    Before the scoping call

    The questions that arrive before the scoping call.

    Is this internal audit software?
    No. It is the infrastructure the work runs on, which happens to produce a record as a by-product of authorizing each call. The audit judgment, the planning and the opinion stay with you and with whatever tooling you already use for them.
    How do I know the record has not been edited?
    Records are hash-linked as they are written, so a record removed from the middle of the chain is detectable. The export is write-once into storage in your own account, under your retention period and your Object Lock — which means iTmethods cannot edit it either. What the record carries →
    Does this let me test a full population instead of sampling?
    It gives you a record of every call the boundary authorized within the systems in scope. Whether that constitutes a testable population for a given engagement is your determination, not ours, and it depends on scope — which is why coverage is stated on the face of the evidence rather than assumed.
    What about the systems that are not in scope?
    They are outside the record and they are listed as such. Work that happens outside the deployment is recorded as not assessed, with the reason. The gap sits beside the evidence rather than in a release note. Evidence and coverage →
    AWS Advanced Tier Services Partner SOC 2 Type II on Reign Ops
    AWS Advanced Tier Services Partner and Validated Managed Service Provider. Twenty-one years operating critical infrastructure for regulated enterprises.
    Next step

    Bring us a control you have to opine on.

    We will look at what evidence exists for it today, how it was produced, and who would have had to cooperate to produce it. That last question is usually the one that decides how much of the engagement is testing the control and how much is testing the data about it.