Like furlough, algorithms are a concept that became firmly a part of national consciousness in the wake of the COVID pandemic: a concept with significance previously understood largely by academics, scientists and digital technologists, which publicly impacted so many student lives with the dilemma of exam grading.
Within the world of internal audit and risk, algorithms have been a matter of discussion for some time as we have explored the development and consequences of digital disruption and the impact this has for the organisations we serve. Much has been written on Artificial Intelligence including the risks, and the challenges inherent in auditing these tools.
I am not an expert in the issues associated with the A-level crisis and the application of algorithms in this context. However, to an educated observer it appears that many of the recommendations incorporated in so many internal audit and risk articles were not practiced, with devastating consequences not only for students and universities, but also for those involved in the discredited education and qualification system.
So, when we apply hindsight what do we learn? AI relies on algorithms to predict future patterns and outcomes. It enables sophisticated analysis of huge quantities of data to derive analysis that simply would not otherwise be possible. However, it can only be valuable and successful if the underlying algorithms are free from bias of all forms.
If we consider the A-level algorithms, we can now see the danger of a system that allows teacher predicted grades to have greater prominence when class sizes are smaller, given that private schools have smaller class sizes than the state sector. We can also predict that teachers will, for good reason, set mock exams that differ depending on whether they want to build confidence in their students, or provide a “shock” to encourage harder work. And it is possible that teachers will make stretching predictions of grades to encourage their students to push themselves (particularly where small class sizes mean the teachers can provide more on-to-one support).
Those charged with developing algorithms within AI tools search for patterns and create hypothesis with embedded assumptions. The algorithms simplify the patterns amongst multi-dimensional and complex information. Inevitably the architects of these algorithms cease to be independent of the hypothesis they are creating. Only an independent review and check, by someone with the appropriate behavioural understanding and professional skepticism to challenge, will identify where bias may have crept in.
As auditors, all too often we focus on systems and process risks, particularly in a digital environment. These risks can seem hardest to penetrate or understand, so we employ specialists to make sure they are minimised to an acceptable level. The insight we gain from the exam experience is that behavioural risks associated with algorithmic bias are at least as significant, yet more far more subjective. We need to focus at least as much time and attention on the behavioural and phycological biases if we are to provide the level of insight our stakeholders expect.
AI, and its inherent algorithms, will continue to be a feature of all aspects of our lives, determining not only which universities our children have access to, but what medical care might be available, and what benefits or work opportunities we might be able to access. We must have the foresight to recognise that bias will creep in – it is human nature – and, as auditors and risk professionals, insist that we play our part in mitigating this risk. Our organisations, and their customers, beneficiaries, suppliers and employees, need our independent advice, assurance and recommendations. We must ensure we deliver this with credibility, empathy, and impact to influence change. Now is the time for Heads of Audit and Risk to look forward and ensure we have the capabilities to meet this challenge.