The third line needs a population it did not have to ask for.
Internal audit plans on a cycle and reports on a period. AI systems act continuously, and the population you would sample from is generated faster than a plan can anticipate it. The harder problem is not volume. It is that the evidence is assembled, on request, by the people you are reviewing.
A single-tenant dedicated instance, in your own AWS or Azure account or in infrastructure iTmethods operates. Both available today; Google Cloud is planned for 2027. Air-gapped and sovereign are in development.
Independence is easier to hold when the evidence was already there.
Every audit of an AI-enabled process runs into the same question: where did this population come from, and who produced it. The answer decides how much of the engagement is testing the control and how much is testing the data about the control.
PCAOB AS 1105 .10 makes that a thing you have to work on rather than around: test the accuracy and completeness of information produced by the company, or test the controls over it, including IT general controls and automated application controls.
The IIA’s GTAG on Continuous Auditing and Monitoring, third edition, issued 25 September 2025, is the current guidance on building an audit approach around that rather than around the annual sample.
Four in ten believed their function was adequately prepared to detect or respond to AI-enabled fraud. The top barriers were technology, then skills, then budget — in that order.
That is a planning input before it is an evidence one. It changes which populations are worth an engagement this quarter.
What the third line gets that it did not have to request.
The IIA replaced its Three Lines Model position paper on 8 July 2026 with a Statement of Position aimed at the board. The distinction it holds — that the third line reviews the first and second and is independent of both — is exactly the distinction that a self-assembled population erodes.
Risk-based planning
What actually ran, at what volume, with what refusals and what routing behaviour. Visible while the work happens rather than in a report assembled after you asked for one.
Continuous control monitoring
Where the control sits in the path, every action it governed is a test of it. A record per call is the population, not a sample of it.
Evidence you did not have to request
Records are written as the work happens and hash-linked as they are written, then exported write-once into storage you hold under your own retention and Object Lock. What you read does not depend on anyone having cooperated after the fact.
A claim you can walk
Scope, then requirement, then check, then evidence and coverage, and only then a claim — with the gap recorded beside the evidence rather than in a release note. A check that cannot decide goes to a named person.
The record is written by the boundary, not by the team you are reviewing.
That is the whole of the independence argument, and it rests on one product that exists today rather than on the one that is still in co-design.
Hash-linking is the property that matters most to a third line: a record cannot be removed from the middle of the chain without the chain showing it. Export is write-once into storage under your retention and your Object Lock, which means iTmethods cannot go back and change it either.
Reign prepares. Your people decide.
This is the page where the boundary matters most, because the market usually claims the opposite of what is true here.
It does not certify, does not attest, does not issue an audit opinion and does not provide independent assurance, in any tense. Nothing on this page is independent assurance of anyone’s controls.
Internal audit reaches the assessment, with whatever advisers it chooses to involve, and nothing here substitutes for that judgment. What changes is the quality and the availability of the evidence that judgment draws on.
Work that happens outside those systems is outside the record. A tool that reports on what it cannot see is not producing evidence; the unreachable parts are stated alongside the reachable ones.
It is being designed with the control functions that will have to rely on it. The record described on this page is produced by Reign Gateway, which is available today.
The IIA has issued four Topical Requirements — Cybersecurity, Third-Party, Organizational Behavior and Organizational Resilience. None of them is about AI, and none is in consultation. We mention it because the absence is the point: there is no mandatory internal audit requirement to comply with here, only an evidence problem to solve.
The questions that arrive before the scoping call.
Is this internal audit software?
How do I know the record has not been edited?
Does this let me test a full population instead of sampling?
What about the systems that are not in scope?
The same estate, three other questions.
Whoever else is in the room is reading a different page about the same infrastructure. These are theirs.
Bring us a control you have to opine on.
We will look at what evidence exists for it today, how it was produced, and who would have had to cooperate to produce it. That last question is usually the one that decides how much of the engagement is testing the control and how much is testing the data about it.