Fieldwork from NexNith Fieldwork · Agents pathway · Briefs
Agents pathway · Brief

Scoping an assurance engagement over an AI agent

By Nitin Tyagi, CISA, CISSP, CIPT · Founder, NexNith · Published 2026-08-18

Key points

The scoping conversation determines the value of everything that follows, and it is settled early, in a meeting whose purpose is presented as an introduction rather than as a decision.

The characteristic opening move from a business owner is generous in tone and reasonable on its face: it is a chatbot, so a documentation review should be enough, we will walk you through it, and we would rather not tie up engineering. Accepting costs nothing on the day it is agreed, which is what makes it easy to agree to. What it costs is the ability to opine, because a documentation review over an agent produces a report about a design, and the design is not the system.

State what cannot be concluded

The pushback that works is not a demand for access, because a demand invites a decision about whose convenience prevails. It is a plain statement of what the report will and will not be able to say. From documentation the committee can be told what the agent was designed to do; what it can do is a different question, and where a member has been harmed by an action the organization cannot account for it is the question being asked.

That formulation works for three reasons that generalize beyond this conversation. It is true, so it survives being repeated to anyone the owner consults. It comments on what the evidence can support rather than on anyone’s competence, so there is nothing in it to defend against. And it hands the scope decision to the person accountable for the consequence, which is where the decision belongs.

It also creates the record needed if access is refused. A scope limitation stated at the front of the report, in terms of the conclusions that could not be reached, is a respectable second outcome, because it leaves the organization holding a decision it took knowingly rather than a report that overstates its own basis.

Access negotiated late costs more than access negotiated early

Two weeks in, the same request is a different request. It implies that the work done so far was insufficient. It lands on an engineering team whose sprint is already committed. It requires re-approval from someone who understood the question to be settled. And it arrives with a reporting deadline behind it, which removes the option of waiting for a convenient moment.

The practical consequence is that every access request is made at once, at the start. The kickoff meeting is the cheapest moment available to ask for the effective permissions export, the platform console, the logs, and the configuration. Asking for all four at once, as a list with a one-line reason against each, gives the owner a single decision to take, where asking for them one at a time as each becomes necessary gives them four opportunities to decline.

Five questions that scope an agent engagement

An agent review can be scoped from these five, and they are worth writing into the engagement letter as the questions the review will answer.

  1. What can this agent do without a person in the loop?
  1. What is the worst outcome reachable through its tools, and what bounds it?
  1. Who can influence its inputs, including indirectly through retrieved content?
  1. If it did something harmful, could that be established from the logs afterwards, per member?
  1. Who approved each of its capabilities, and against what documented use case?

They are framed as questions rather than as controls to test, and the framing is deliberate. An organization that has put a system in front of its customers should be able to answer all five, so an organization that cannot answer them has a finding before any control has been tested.

Keep the boundary between assessing and fixing

At some point in the fieldwork an engineer may offer to correct something while it is still under examination. The offer is well meant, and the instinct to accept is strong, because a risk reduced is a risk reduced. Accepting produces two consequences, neither of which is visible at the moment the offer is made. The evidence then describes a system that no longer exists, so the finding has to be argued from a configuration that cannot be re-examined. And the practitioner has directed a remediation they will later be asked to assess.

The boundary holds without delaying the fix, because preserving evidence requires a copy of the configuration rather than a postponement. Management decides what is corrected and when, since management carries the operational consequence of the correction. The practitioner establishes the current state, preserves a copy of it as evidence, reports it accurately, and ensures the decision is taken by somebody with the authority to accept the risk if they choose not to act.

AAIA D3AAAIR 3AAAISM D1DAIGP I.B
Fieldwork is independent educational material produced by NexNith. It is not affiliated with, endorsed by, or connected to ISACA or the International Association of Privacy Professionals (IAPP). AAIA, AAISM, AAIR, CISA, CISM, and CRISC are trademarks of ISACA. AIGP and CIPT are trademarks of the IAPP. No examination content is reproduced. Every organization and person named in this material is fictional.