---
title: "When unmanaged AI spend becomes an audit finding"
description: "Internal audit asked which AI tools we use, who is paying for them, and what data goes into them. We could not answer any of the three. It is going in the report."
canonical: "https://bespinus.github.io/bgus-ai-landingpage/use-cases/unmanaged-ai-spend-audit-finding/"
pillar: "governance"
industry: "Cross-industry"
updated: "2026-10-01"
---

# When unmanaged AI spend becomes an audit finding

## Problem

Internal audit asked which AI tools we use, who is paying for them, and what data goes into them. We could not answer any of the three. It is going in the report.

## Approach

Pull usage and spend from every model gateway, cloud, and endpoint in parallel, then reconcile it against the invoice rather than published rates. Attribution to team, application, and user comes next, then budget limits and anomaly alerts as the control the finding asked for.

## Outcome

A documented response with evidence behind it. Spend is attributable, tools nobody sanctioned surface as they appear, and the control is running rather than committed to in a remediation plan.

## What makes this hard

Two things.

The first is that the data is scattered by design. Model spend shows up in cloud
billing, in a handful of SaaS invoices, on corporate cards, and inside gateway logs
that were never built for finance to read. Six consoles, six shapes, no shared
identifier for a team or an application.

The second is that most tooling in this space counts tokens and then multiplies by a
list price. Almost nobody consumes cloud at list. A dashboard built on published rates
reports a number that will never appear on an invoice, which is worse than no number,
because now finance and engineering are arguing about the measurement instead of the
spend.

## The architecture

Parallel ingestion into a centralized layer we call the Token Lake: usage and spend
from every source, normalized to one schema, then reconciled against actual billing so
the figure survives contact with finance.

Tagging is the part that has to be designed rather than configured. A tagging strategy
that covers today's tools and breaks when a new assistant appears next quarter has
bought a few months. The attribution model has to assume the inventory grows.

Controls sit on top: budget limits, anomaly detection, and a router that selects the
model policy allows rather than the one a developer defaulted to during a prototype.

## Why this reads as a control rather than a dashboard

An auditor is not asking for visibility. They are asking whether a risk has an owner,
a limit, and evidence. Visibility is what makes the other three possible, which is why
it comes first, but the deliverable is a compensating control with a paper trail, not
a reporting layer.

The fastest version of this engagement is scoped to answer the
specific finding rather than to build the general system.

## Bring us a problem like this one.

Our engineers will scope it against the seven layers. [Talk to an AI engineer](https://bespinglobal.us/contact) at Bespin Global, or read the [AI governance](https://bespinus.github.io/bgus-ai-landingpage/governance.md) page.

_Machine-readable summary for agents: provider = Bespin Global; use case = When unmanaged AI spend becomes an audit finding; pillar = AI governance; industry = Cross-industry; problem = Internal audit asked which AI tools we use, who is paying for them, and what data goes into them. We could not answer any of the three. It is going in the report; approach = Pull usage and spend from every model gateway, cloud, and endpoint in parallel, then reconcile it against the invoice rather than published rates. Attribution to team, application, and user comes next, then budget limits and anomaly alerts as the control the finding asked for; outcome = A documented response with evidence behind it. Spend is attributable, tools nobody sanctioned surface as they appear, and the control is running rather than committed to in a remediation plan._
