Date: 2026/08/13
Author: Irakli Lomidze
President of ISACA Tbilisi Chapter
Introduction: what audit quietly assumes
Every assurance framework rest on a picture of what it assures, even when the picture is never drawn explicitly. For the entire history of IT audit, that picture has been deterministic: a system, given the same input under the same conditions, produces the same output, and a process, executed according to its definition, yields the outcome the definition promises. The property is so fundamental that the profession has never needed to name it.
Determinism is what justifies the auditor's core techniques. Re-performance works because running the transaction, or walking the process through again, reproduces the result the auditee obtained. Sample-based testing works because a control's behavior is a stable function of its configuration or its documented procedure, which is why change management rather than continuous observation is the anchor control. Root cause analysis works because an anomaly implies a discoverable cause. And behind all three stands a second, even older assumption: the record. Events leave persistent, copyable traces, an approval leaves a signature, a transaction a log entry, and evidence can be extracted without damaging the original, duplicated into working papers, and examined by a second reviewer who will see what the first one saw. Information, in the classical world, is a substance that can be read without being consumed.
Stochastic systems, of which large language models are the prominent case, break determinism: the same input, under nominally identical conditions, yields different outputs, and behavior ceases to be a stable function of anything an auditor can inspect. This challenge is serious but tractable, because evidence can be redefined in distribution rather than in instance. An audit result then becomes a distribution of possible answers rather than a single exact one, which complicates both its evaluation and the choice of measures to take in response. Quantum information systems break the record itself. A quantum state cannot be copied, a prohibition known as the no-cloning theorem, and it cannot be read without being altered, because measurement disturbs the state it examines. These are not limitations of current engineering that better hardware will remove. They are laws of physics, and they bind every machine that will ever be built. Quantum evidence therefore exists in a single copy that is spent in the act of examining it: no forensic image, no second look, no re-inspection by another reviewer.
What follows examines what these challenges mean for COBIT 2019, ITAF and Risk IT, and argues that the frameworks require extension rather than replacement. The aim here is deliberately limited: to name these gaps precisely and to summon the certified community that maintains the frameworks, not to propose the methods, because methods designed before the profession agrees on the problem tend to solve the wrong one.
1. Stochastic systems: when re-performance stops being evidence
Consider a routine engagement task. A control routes customer complaints: those alleging regulatory violations must escalate to compliance within 24 hours. When the routing logic is a rules engine, the auditor inspects the rules, re-performs a sample of decisions against the deployed configuration, and signs off. When the routing decision is made by a language model, the same test collapses. The auditor submits the same complaint to the same model version and gets a different classification. Not necessarily a wrong one. A different one. Five runs, three escalations.
Nothing in ITAF prepares the auditor for this, because its evidence-gathering techniques inherit the assumption of determinism. Re-performance, generally regarded as the strongest form of audit evidence, presumes that past behavior can be reproduced. Setting the sampling temperature to zero does not restore that: batching effects, floating-point non-associativity across hardware, silent model updates on hosted APIs and imperfectly reconstructed context all leave residual variance.
Three framework assumptions fail here.
The first is that configuration determines behavior. COBIT's build and run objectives, BAI06 and DSS05 among them, rest on the premise that an organization governs what its systems do by governing what they are: configurations are documented, changes to them are approved, and the approved state fixes the behavior. A system with a stochastic component breaks that equation. Everything the organization can document, approve and audit, the deployment settings, the integrations, the access rights, remains manageable in the usual way, yet no longer determines the decisions the system produces. The part that decides is not recorded in any configuration item the organization maintains. An organization can therefore pass every change-management test in the framework while its actual decision behavior drifts with every update its vendor ships.
The second is that control effectiveness is binary over a period: the control operated or it failed. Stochastic control operates probabilistically per invocation. The routing control above, effective in most invocations but not in all, is neither an operating control nor a failed one in the framework's vocabulary. It is a new kind of object with no native category. The nearest existing category, attribute sampling with its tolerable deviation rate, looks close but does not fit. Sampling tolerates deviations in the operation of a deterministically designed control, where every exception has an assignable cause to investigate and remediate; a stochastic control deviates by design, and its deviation rate is an intrinsic property with no cause to find. Sampling inference also presumes that the underlying behavior is stable across the audit period.
The third is that anomalies have discoverable causes. MEA-level monitoring presumes that a deviation traces to a change, a fault or an actor. Stochastic outputs deviate as a matter of course, and telling "within expected distribution" from "degrading" requires a statistical baseline no framework currently requires anyone to build.
All three failures share a root: the truthful output of a stochastic system is not an answer but a distribution over answers, and any single run is a sample from it. That is a hard shift for the consumers of the results, not only for their auditors. Decision makers are trained on point answers: approved or rejected, operated or failed, right or wrong. Handed a measured rate with a confidence interval instead, a risk committee faces questions it has no practiced way to answer. Acceptable against what baseline? What loss does the residual failure rate represent, and over what volume? Risk IT compounds the difficulty from both ends: its scenarios treat control failure as an event rather than a rate, so a small but persistent leak has no home in the scenario library, and its impact arithmetic of frequency and magnitude turns into compound probability once the control itself contributes a rate.
The organizational reflex is predictable and dangerous: collapsing the distribution back into a false point. The dashboard shows a green tick, the model's answer becomes the answer, and the uncertainty that honest measurement produced is stripped out exactly where risk decisions are made. The countermeasures are cultural as much as technical: risk appetite restated as explicit tolerance rates per control, reporting that carries uncertainty upward instead of laundering it out, and enough statistical literacy at the top to act on an interval.
None of this makes stochastic systems unauditable. It makes them unauditable by instance, and that changes what an audit can deliver. The honest result of auditing a stochastic system is not an opinion that the control operated but a distribution: an observed rate of correct operation, with uncertainty around it. That output is useful only if something upstream can receive it. A management framework built for binary findings has no defined way to accept a distributional one, and a risk evaluation built on point estimates has no defined way to evaluate a risk that arrives as a distribution. How such risks should be evaluated, by what methods, how they aggregate across controls, how they are compared against appetite, is an open methodological question, and the frameworks today neither ask it nor answer it.
Named precisely, the gap is this: the profession needs a management framework that takes distributional audit results as a first-class input, a risk evaluation discipline able to work on distributions rather than points, and framework guidance that addresses this class of risk explicitly. None of this is unknown territory in itself: quantitative risk practice already works with distributions, through simulation and loss exceedance curves. What is missing is their place inside the frameworks, which today neither require nor accommodate a distributional treatment of control effectiveness. The gap is closable, because nothing in it defies logic or measurement; it is work the frameworks have simply not yet been asked to do. The next problem is different in kind.
Quantum information: evidence that physics will not let you keep
The discussion of quantum technology in the governance literature is almost entirely a discussion of cryptography, and that emphasis, understandable as it is, points to the wrong problem. The cryptographic side is real but conventional: an algorithm weakens, so inventory it and migrate, as the profession has done before from DES through SHA-1. Quantum computers of sufficient scale will break RSA and elliptic-curve cryptography; NIST finalized its first post-quantum standards in 2024; and harvest-now-decrypt-later means data exfiltrated today becomes readable later, so for data whose confidentiality lifetime exceeds the arrival of such machines the loss has, in effect, already begun. The framework work this requires is ordinary: a control objective for cryptographic agility, an inventory of cryptographic dependencies with a demonstrated ability to migrate them, and a risk scenario template for retroactive loss. One harder item belongs to later framework iterations: all practical encryption and signature algorithms rest on unproven assumptions, post-quantum candidates included, and several respected candidates were broken during standardization itself, so a period with no algorithm considered reliable is a plannable contingency rather than an unthinkable one. All of it, though, is the governance of inventories, deadlines and contingencies. The unconventional problem is what happens when quantum information itself becomes the object of assurance.
Classical audit evidence has two properties so basic they are never stated: it can be copied, and it can be read without being changed. Forensic imaging depends on the first, preserve the original, work on the duplicate, prove the match. Independent review and chain of custody depend on both. Quantum information denies both properties as a matter of physical law. An unknown quantum state cannot be copied, a result known as the no-cloning theorem, and its information content cannot be extracted without disturbing it, since measurement yields a single outcome and destroys the state that produced it. These are theorems, not engineering constraints, and they are held for every future generation of hardware.
Translated into audit language: no forensic image of quantum evidence, by theorem; no second look, because the state the first observer examined no longer exists; no chain of custody, because custody cannot be verified at a checkpoint without consuming the thing in custody. The classical regime of evidence does not degrade in a quantum environment. It vanishes.
The immediate objection is that this is distant, since today's enterprise exposure is mostly cloud access to quantum processors with classical inputs, classical outputs and a transient quantum middle. Audit the classical boundary, the objection goes, and the problem disappears. But notice what that concedes: the computation itself becomes a black box that is opaque in principle. An opaque conventional system is opaque only in practice; with enough effort it can be logged and examined. A quantum computation in flight cannot be logged, snapshotted or replayed, and this is guaranteed by the same physics that makes the computer worth using. The auditor of a material quantum-dependent process, a portfolio optimization, say, is being asked to accept results from a process that no evidence-gathering technique in ITAF can reach.
Part of the answer may simply be acceptance. Some properties of quantum systems will never be audited in the classical sense, and the profession gains nothing by pretending otherwise: there will be no backups of quantum states and no evidence archives, and a framework that demands them demands the impossible. Where an assumption cannot be restored, auditors already know the response from other domains, compensating controls. Assurance shifts to what can be observed classically: the preparation of inputs, the configuration and calibration of the hardware, the statistical behavior of outputs over many runs, the integrity of the classical systems surrounding the quantum core. Research on the verification of quantum computation may add another layer, interactive protocols by which a classical party gains justified confidence in a computation it cannot follow. None of this yields evidence in the ITAF sense of an inspectable record. It yields a different kind of basis for confidence, and the familiar ladder of audit techniques, from inquiry through inspection to re-performance, which ITAF's evidence requirements presuppose, has no place for it, nor for an honest register of what will not be assured at all. Defining both, with competence requirements for the auditors who will rely on them, is work a framework body can begin ahead of mass adoption; the cost of waiting is that early quantum-dependent processes will be assured by analogy and improvisation. Here too, the methods belong to the working groups.
Conclusion: Extension, not replacement
It has become fashionable to declare established frameworks obsolete in the face of new technology. This article supports a narrower and more durable conclusion. The governance layer, the accountability structures, the direction-evaluate-monitor cycle, survives intact, because it never depended on any particular kind of machine, though the people within it must now learn to direct and monitor over rates and intervals rather than point assertions. What strains is the layer beneath: control objectives that equate configuration with behavior, an evidence hierarchy built on reproducibility and copyability, and risk evaluation built on point estimates. That is extension work, not demolition work.
The gaps in this article names, without pretending to close them, are three. For stochastic systems: a management framework that accepts distributional audit results as a first-class input, and a risk evaluation discipline able to work on distributions rather than points. For quantum information: an honest register of what will never be auditable in the classical sense, no copies, no backups, no second look, together with a defined place in the evidence hierarchy for compensating classical controls and for assurance built on interaction rather than inspection. For cryptography: migration on a deadline set by physics, and, filed for later framework iterations, a posture for the day no algorithm is trusted at all.
The stakes are not abstract. The frameworks’ authority, and the value of the certifications built on them, comes from one source: they describe how assurance actually works for the technology organizations actually run. Stochastic systems are in production now; quantum systems are arriving on a schedule set by physics and funding, not by revision cycles. Without extension, the frameworks will not fail loudly. They will keep operating, keep certifying, and quietly stop describing reality, first for what is already here, then for what is coming.
None of this will be written by anyone else. ISACA's frameworks are not handed down; they are drafted, reviewed and revised by certified practitioners, through working groups, exposure drafts and the accumulated weight of what members report from the field. If you hold a CISA, CISM, CRISC or CGEIT, these gaps are yours to close, and the first tasks are concrete. Write the finding honestly when a stochastic control resists instance testing, rather than forcing it into the old vocabulary. Report distributional results as distributions, so that precedents accumulate before the frameworks require them. Respond to exposure drafts by naming the broken assumption, not only amending the procedure. Bring the uncomfortable questions, how a risk that arrives as a distribution should be evaluated, what replaces inspection where physics forbids it, into guidance while guidance is still early enough to shape.
The alternative is already visible: a profession attesting, with procedures that still run perfectly, to things the procedures no longer prove.