Where AI Actually Sits in the Audit
The Engagement, Walked
Set the brochure aside and walk the engagement. In risk assessment and planning, tools digest prior-year files, board minutes and industry material to suggest where risk might sit. In journal-entry testing, they score every posting against patterns worth a look — weekend entries, round amounts, unusual account pairings, back-dated postings. In document and contract review, they extract terms, dates and obligations from populations too large to read. Around confirmations, they chase, match replies and flag exceptions. In analytics, they extend the disaggregation and expectation work auditors already do to a finer grain. And in drafting, they produce first versions of memos, summaries and client requests. Every one of these sits inside an existing procedure; none of them is a new procedure. That placement matters, because a tool assisting a procedure inherits the procedure's evidence rules, and the auditor performing it still owns the conclusion.
- Planning and risk assessment: prior files, minutes and industry material digested into suggestions, not risk assessments
- Journal-entry testing: every posting scored against patterns worth attention rather than a sample scored deeply
- Documents, contracts and confirmations: extraction, matching and exception-flagging across whole populations
- Drafting and summarisation: first versions of memos and requests, which are the beginning of work, not the end
The Brochure and the Floor
Between what a tool genuinely does and what its marketing implies sits most of the disappointment in this field. The brochure says the tool finds fraud; on the floor it ranks journal entries by unusualness, and unusual is mostly legitimate — month-end corrections, one-off transactions, a new revenue stream the model has not seen before. The brochure says it reviews contracts; on the floor it extracts clauses with good but imperfect recall, and the misses are silent. The brochure says it automates confirmations; on the floor it automates the chasing and the matching, while the judgement about an exception remains exactly where it was. None of this makes the tools useless — the compression of reading time is real and large. It makes them assistants with a specific shape, and buying decisions and reliance decisions both go wrong when the shape is taken from the brochure.
- Ranked unusualness is not detected fraud: most flags are legitimate, and the ranking is the actual product
- Extraction has good but imperfect recall, and what it misses it misses silently
- Automated confirmation handling automates chasing and matching; the exception judgement does not move
- The reading-time compression is real and large — the error is taking the tool's shape from the brochure
The Pattern Under the Map
Walk back over the map and one pattern covers all of it: AI compresses reading and flagging, and stops there. It does not perform procedures — a procedure includes deciding what the results mean, and the tools do not decide. It does not evaluate evidence — relevance and reliability are judgements about the source and the assertion, and a similarity score is neither. And it does not conclude — a conclusion is a position a person takes and defends, first to a reviewer, eventually perhaps to an inspector. The practical consequence is a simple sorting rule for any claimed capability: locate it on the line that runs from reading, through flagging, to deciding. Left of the line, expect genuine and growing competence. Right of it, expect a demonstration that worked on well-behaved documents. This one rule filters most vendor conversations, and most internal enthusiasm, faster than any evaluation framework.
- The reliable pattern: compression of reading and flagging, across every stage of the engagement
- Performing a procedure includes deciding what the results mean, which is precisely what tools do not do
- Relevance and reliability are judgements about source and assertion; a similarity score is neither
- Sort any claimed capability along reading, flagging, deciding — and be sceptical to the right of that line
Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.