“We are going to do the profession differently, because we will increasingly rely on AI. But I think the profession will actually become much more important than it already is, and ultimately simply grow,” says Dwayne Valkenburg about the future of auditing.
As chairman of ISACA Netherlands and co-founder of AuditAgent, Dwayne builds the AI tools he works with every day. This gives him an unusually sharp perspective on what AI actually costs, who remains in control and where the auditing profession is heading. His perspective is particularly relevant to the broader discussion about innovation in security, where the question of how to implement AI often matters more than whether to implement it.
Listen to the podcast
Listen to the full conversation on Spotify or YouTube.
(the podcast is in Dutch).
This episode of Security Innovation Stories is part of a special series around Cybersec Netherlands on 9 and 10 September at Jaarbeurs Utrecht. ISACA Netherlands and Cybersec Netherlands work together based on a shared focus on knowledge sharing within the security and audit community. Dwayne Valkenburg, chairman of ISACA Netherlands, will also speak at Cybersec Netherlands this year about his experience building his own AI stack for IT auditing.
New technology destroys jobs, but also creates them
Dwayne mainly sees opportunities in the way AI is changing the auditor’s daily work. Validating evidence against controls, often hundreds of checks per quarter, is what he calls “the least enjoyable part of IT auditing.” According to him, these types of tasks are particularly well suited for automation, allowing auditors to spend more time on the cases that genuinely require attention.
He also understands why this transition does not happen automatically. Auditors often enter the profession directly from university, where, according to him, they mainly learn “to talk about risks, not about innovations.” This helps explain a reflex he recognises in himself and his peers: “As an auditor, you tend to look at innovation primarily from a risk perspective, and not enough from the opportunities it offers.”
For Dwayne, this is not a shortcoming. It is simply how the profession has historically developed, and exactly the kind of issue he wants to address within ISACA.
To explain why this does not make him pessimistic, he refers to economist Joseph Schumpeter and his theory of creative destruction: every technological breakthrough makes certain jobs obsolete, while creating new ones at the same time.
“We saw that with the internet, with the car, with the airplane,” says Dwayne, and he expects AI to follow the same pattern. His conclusion is optimistic: “I think our work as auditors will become much more important.”
The bill nobody sees coming in time
According to Dwayne, organisations working with AI models almost always underestimate the true costs. When a client needs to validate hundreds of controls at once, he warns: “With AWS Bedrock, you can easily spend 8,000 or 9,000 euros with a single push of the button.”
He compares this to the early days of Uber, when a ride cost just a few euros before prices gradually increased. According to Dwayne, something similar is happening with AI agents: “You think you’re paying 200 euros or 100 euros for a Cloud Max, but in reality you may be burning through 8,000 dollars in token costs every month.”
The Borg of the tech world
Token costs are not the only risk Dwayne warns about. Anyone building AI functionality on top of services from major technology companies is also tying themselves to rules they do not control.
Dwayne calls this a risky business and explains it using an analogy from Star Trek: the Borg, an alien civilisation that does not simply defeat other societies but assimilates them, adopting their technology and turning them into part of its own collective.
“Resistance is futile” is their well-known phrase, and Dwayne recognises the same pattern in the way large technology companies deal with smaller innovations. Once an integration or feature proves successful, it can simply be adopted and incorporated as a standard feature of the larger platform.
He illustrates this with an integration his team built between Figma and one of its own products. The moment Claude introduced its own design functionality, that integration suddenly became redundant.
“Big tech is simply the Borg. They assimilate you, and resistance is futile.”
Local models as a counterweight to the Borg
To avoid that risk, Dwayne chooses to run AI models locally on his own server rather than building entirely on the infrastructure of a major provider.
This offers two advantages: independence from rules that can be changed from above and no token costs, because everything runs on the organisation’s own hardware. Just as importantly, confidential customer data does not end up with an external provider.
His advice to CISOs and auditors who want to get started themselves is simple: just start experimenting instead of waiting for an external party to explain how it works.
He compares it to Excel in the 1990s, when its possibilities only really became clear to the people who started working with it themselves.
“You simply have to try it yourself and not rely on external parties telling you how to do it. When you experiment yourself, your team also learns how to use it, and you begin to see opportunities within your own processes to use it more effectively.”
Knowing what your AI model does is what matters to Dwayne
For Dwayne, cyber resilience starts with ownership: knowing what an AI model does, where data goes and what a tool actually costs, rather than blindly trusting the promises of large vendors.
He combines that caution with a pragmatic optimism about the profession itself. According to him, the role of the auditor will not disappear. Instead, it will become more important as organisations increasingly build their operations around AI.
Resistance is futile, so you might as well understand how it works yourself.