Perspective

AI in internal audit: what actually changes

Where AI genuinely shifts the internal audit workflow, and where the auditor’s judgment stays firmly in charge.

Most conversations about AI in internal audit swing between two extremes, and both are wrong: that it changes nothing, or that it replaces the auditor. The more useful question is narrower. Which parts of an engagement eat time because they’re repetitive and evidence-heavy, and can those parts be done faster without loosening the standard of proof?

The work that AI is suited to

Internal audit runs on documents: policies, procedures, regulations, contracts, tickets, prior working papers. A large share of fieldwork is reading that corpus to find the passage that matters and set it against what actually happened. That is where AI earns its place, in the retrieving and the organising rather than the deciding:

  • Finding the passage. You ask the document universe a question and get an answer with a citation to the exact clause, instead of running keyword searches across folders.
  • Testing controls at scale. A defined test runs across the full population rather than a hand-picked sample, and the exceptions go to a person to examine.
  • Drafting the routine parts. Findings become a first-draft report, or a committee outline, which the auditor then edits and owns.
  • Keeping follow-up alive. Tracking which findings are closed and which are ageing, with the outstanding evidence listed against them.

The work that stays with people

Judgment does not transfer. Scoping an engagement against risk, deciding whether an exception is material, weighing management’s explanation, putting your name to a conclusion: these belong to the auditor and should stay there. The model we work to is human in command. Every AI output lands with a person who can accept, edit or reject it, and the record shows who decided what.

That principle isn’t a nicety. Internal audit has value only because someone independent is accountable for the opinion, and a tool that quietly makes the call breaks the thing that makes audit worth doing.

Why evidence and traceability come first

The failure mode for AI in an assurance setting is the confident answer with nothing behind it. An auditor can’t rely on a claim they can’t verify, and a committee can’t act on one. So the design constraint is simple: every answer shows its sources. Reviewers check the evidence themselves rather than taking the model’s word, and the trail from a user’s action to the system’s response is there when someone asks how a conclusion was reached.

If you cannot trace it, you cannot rely on it. And if you cannot rely on it, it has no place in the working papers.

What this looks like in practice

Across an engagement the pattern repeats: AI does the legwork, the auditor owns the judgment. Evidence gets gathered and cited, tests run across the population, exceptions come up for review, and the reporting arrives as a draft for a person to finish. TheLitmus suite is built around that division of labour, and around the discipline that every output carries its sources.

For teams weighing a tool, the deployment question matters as much as the workflow: where the documents live, and who can see them. We cover that in air-gapped AI and data sovereignty for UAE audit teams, and the practical selection criteria in how to evaluate internal audit software.

See Litmus on your kind of audit work.

A working session with the suite. Bring your security team — IT questions are welcome from the first meeting.

Book a demo