Artificial intelligence is increasingly being incorporated into audit, financial reporting and other professional workflows. While AI can improve efficiency, support data analysis and reduce time spent on repetitive tasks, its use does not alter the fundamental responsibilities of accountants and auditors.

For firms adopting AI, the key challenge is no longer simply whether the technology can perform a task. The more important questions are whether its use is properly governed, its output can be explained and verified, and an appropriate evidence trail exists to support professional conclusions.

Five Lessons to Put into Practice

1. AI can support professional work — but accountability remains human

AI may assist with document preparation, research, data analysis, working papers and review activities, but responsibility for the final output remains with the professional using the technology.

An accountant or auditor should therefore be able to:

  • understand the work performed with AI assistance;
  • review the resulting output critically;
  • explain the basis for conclusions reached;
  • correct inaccurate or inappropriate AI-generated information; and
  • accept responsibility for documents, decisions and professional judgements issued under their name.

AI should therefore be treated as a tool rather than as an independent decision-maker.

This principle is particularly important because responsibility for the audit file, audit evidence and ultimately the audit opinion continues to rest with the engagement team. An AI-generated explanation cannot substitute for the auditor’s own understanding and professional judgement.

2. Effective AI governance requires ongoing monitoring, not merely initial approval

Approving an AI platform or use case is only the beginning of the governance process.  AI systems may change over time, interact with other applications, process increasing volumes of information or be deployed in ways that were not anticipated when initially approved.

Firms therefore need controls that address not only implementation but also continuing performance and oversight. Relevant considerations may include:

  • whether the AI remains appropriate for its intended purpose;
  • whether approved controls remain operational;
  • whether access continues to be appropriately restricted;
  • whether incidents or unusual outputs are identified promptly;
  • whether the cost of ongoing monitoring has been adequately considered; and
  • whether the level of human oversight remains appropriate as usage expands.

A control that exists in design but is not actively operating provides limited protection. Firms should therefore incorporate AI monitoring into normal governance and risk-management processes.

3. The audit objective remains unchanged — but the auditor’s questions are evolving

The use of AI does not remove the requirement to obtain sufficient appropriate audit evidence or change the fundamental objective of supporting an appropriate audit conclusion.

What may change is the nature of the enquiries and procedures required when AI contributes to information used in financial reporting or audit work. Auditors may increasingly need to understand:

  • how the information was generated;
  • which systems and data sources were involved;
  • whether management understands the AI-assisted process;
  • whether the information can be independently corroborated;
  • what controls were applied over the AI process; and
  • whether the resulting information is sufficiently reliable for the audit purpose.

Accordingly, AI does not reduce the need for professional scepticism. In many cases, it may require auditors to ask additional questions about the origin, processing and reliability of information.

The underlying principle remains familiar: technology may change how evidence is produced and analysed, but the auditor must still determine whether that evidence adequately addresses the identified risks and relevant assertions.

4. Traceability and documentation are becoming increasingly important

As AI becomes more integrated into financial reporting and audit processes, firms will need stronger records showing how an output was produced.  This may include maintaining appropriate information about:

  • the original source data;
  • transformations or processing applied to the data;
  • the AI tool or system used;
  • relevant prompts or instructions;
  • review and validation performed by staff;
  • significant adjustments made to the AI-generated output; and
  • the evidence supporting the final conclusion.

This concept is closely related to data lineage — the ability to trace information from its original source through the various processing stages to the final reported or audited output.

Inadequate traceability may make it difficult to assess the reliability of information or demonstrate how an audit conclusion was reached.  Firms may also consider using AI itself to help create concise records of lengthy interactions, such as summarising the sequence of prompts, analysis and revisions undertaken. Such records would still require appropriate review before being retained as audit or engagement documentation.

5. Existing IT control principles provide a useful foundation for AI governance

Firms do not necessarily need to build an entirely new control framework simply because AI is involved.  Many established technology and information-security controls can be adapted to AI environments, including controls over:

  • user access and authorisation;
  • data security and confidentiality;
  • change management;
  • system monitoring;
  • incident identification and escalation;
  • third-party service providers;
  • data retention;
  • business continuity; and
  • management oversight.

The practical difference is that firms need to consider how these familiar controls apply to AI-specific risks.  For example, an organisation may need to understand not only who can access an AI platform, but also:

  • what information users are permitted to enter;
  • whether confidential or client information may leave the organisation;
  • where data is processed or stored;
  • whether third-party providers themselves use additional AI services; and
  • how inappropriate or unexpected AI behaviour would be detected.

Extending established IT general control concepts to AI can therefore provide a more practical starting point than attempting to design an entirely separate governance structure.

Impact on audit firms

The growing use of AI is likely to affect several areas of professional practice.

Audit methodology
Audit procedures may increasingly include enquiries and testing directed at AI-enabled processes, particularly where AI affects financial information, controls or management estimates.

Audit documentation
Engagement teams may need stronger documentation explaining the source of AI-assisted work, the review performed and how the resulting evidence supports the audit conclusion.

Quality management
Firms may need policies specifying approved AI tools, permitted uses, review requirements and circumstances in which AI should not be used.

Confidentiality and privacy
The use of public or inadequately controlled AI platforms may create risks where client or commercially sensitive information is entered into the system.

Staff competence
Professionals need sufficient knowledge to understand both the capabilities and limitations of the AI tools they use. Reliance on AI without understanding the underlying work may create a quality risk rather than an efficiency benefit.

Management responsibilities
Where clients use AI in accounting or financial reporting processes, management remains responsible for the resulting information and should be able to explain how it was generated and controlled.

Practical issues

Organisations introducing AI should consider several implementation challenges:

  • Approved tools: Determine which AI platforms may be used and for what purposes.
  • Data restrictions: Clearly define what client, personal or confidential information may be entered into AI systems.
  • Ownership: Require a named individual to remain responsible for AI-assisted work.
  • Review controls: Establish the level of review required before AI-generated content is relied upon.
  • Evidence trails: Retain sufficient records to explain how important outputs were produced.
  • Third-party risk: Understand where data is stored, processed and potentially shared by technology providers.
  • Monitoring: Confirm that approved controls continue to operate after implementation.
  • Cost management: Consider the continuing cost of AI usage and monitoring, rather than assessing implementation cost alone.
  • Training: Ensure staff understand both how to use AI effectively and when its output should be challenged.
  • Shadow AI: Identify unapproved AI usage and address it through education, governance and appropriate controls rather than relying solely on prohibition.

Action points

Audit firms may wish to assess their current AI arrangements against five basic questions:

  1. Who is accountable for AI-assisted work?
  2. How is AI usage monitored after implementation?
  3. Can the firm explain and verify information produced with AI assistance?
  4. Is there an adequate audit trail from source data to final output?
  5. Have existing IT, privacy and security controls been appropriately extended to AI?

AI has the potential to make audit and accounting work faster and more analytical, but efficiency does not replace professional responsibility. The firms that obtain the greatest benefit are likely to be those that combine technological capability with clear accountability, robust evidence and disciplined governance.