Artificial intelligence (AI) offers opportunities for the federal administration, but also presents new challenges. The development and use of AI systems require substantial investment in infrastructure, data and expertise. These costs must be offset by demonstrable benefits within a foreseeable timeframe. At the same time, the complexity of many AI processes makes it difficult to understand how they work and can entail risks – such as the reinforcement of societal prejudices or the lack of explainability of automated decisions.
A risk-based audit must therefore take technical, organisational, legal and ethical aspects into account in equal measure. By addressing the three risk dimensions of ‘trustworthiness’, ‘cost-effectiveness’ and ‘skills’, the Swiss Federal Audit Office’s (SFAO) guidelines on the assessment of AI take these diverse risks into account. The choice of risk dimensions is based on the Federal Chancellery’s sub-strategy on AI. Thirteen risk areas are assigned to these three risk dimensions.

The life cycle of an AI application differs fundamentally from that of conventional IT systems: AI models are developed, trained and adapted dynamically and iteratively, enabling them to develop new patterns and capabilities over the course of their life cycle that can be difficult to predict. The guide takes the temporal aspect into account by dividing the AI application’s lifecycle into the planning, development and operational phases. Furthermore, the guide highlights the phases in which the individual risk areas may be relevant. In this way, it helps auditors to systematically identify and assess risks throughout the entire lifecycle of an AI application.