6 min readSanitized AI Team

AI in Auditing: Where It Helps and Where It Creates Risk

AI GovernanceData SecurityComplianceData PrivacyRisk

Artificial intelligence is becoming part of audit work, but not always in the dramatic way headlines suggest. In many firms, AI first appears in research, document handling, data analysis, drafting, or administrative support. Over time, the same technology may become more involved in planning, risk assessment, and audit procedures.

The useful question for audit teams is not whether AI belongs in auditing. It is where AI genuinely improves the work and where it creates risks that require stronger controls.

Where AI can help audit teams

1. Working through large volumes of information

Audits involve financial records, contracts, journal entries, supporting documents, policies, and other information that can be difficult to review manually at scale.

Automated tools can help auditors organize large datasets, identify patterns, extract information, and flag unusual items for further investigation. The International Auditing and Assurance Standards Board, or IAASB, recognizes artificial intelligence, data analytics, and other automated tools and techniques as technologies that may be used in audit work.

This can help the auditor focus attention. It does not mean every item flagged by the system is an error, or that items not flagged are automatically safe.

2. Supporting planning and risk identification

AI can also assist with early-stage audit work. A tool might help summarize prior-year documentation, compare financial information, organize risk factors, or identify transactions that warrant a closer look.

The Public Company Accounting Oversight Board, or PCAOB, reported in 2024 that the audit firms it contacted were using generative AI primarily for administrative and research activities, while many were also exploring its potential in planning and performing audits.

Used appropriately, AI can help an engagement team surface questions faster. The auditor still needs to decide which risks matter and what procedures are appropriate.

3. Reducing repetitive work

Not every valuable AI use needs to make an audit judgment.

Teams may use approved tools to summarize non-sensitive material, draft internal explanations, classify documents, prepare first-pass notes, or search firm guidance. Removing some repetitive work can give professionals more time for areas requiring judgment, client discussion, and investigation.

This is often a sensible place to begin because a human can review the result before it affects the audit.

Where AI creates risk

1. Overreliance on technology

One of the clearest risks is assuming a technology-generated result is correct because the system appears sophisticated.

The IAASB has specifically published guidance on the risk of overreliance on technology. Auditors still need professional judgment and professional skepticism when evaluating information produced by automated tools.

This becomes especially important with generative AI, which can produce confident language even when the underlying answer is incomplete or incorrect.

The International Ethics Standards Board for Accountants, or IESBA, has also highlighted automation bias, the tendency to favour technology-generated output even when other information calls it into question. Its technology guidance emphasizes understanding limitations, assumptions, data quality, and the appropriate level of reliance on technology outputs.

2. Weak or unreliable audit evidence

AI output is not automatically audit evidence.

If a tool identifies an exception, creates an analysis, or summarizes information, the auditor still needs to evaluate whether the underlying information is relevant and reliable and whether the procedure achieves its audit objective.

For U.S. public company audits, PCAOB amendments addressing technology-assisted analysis are effective for fiscal years beginning on or after December 15, 2025. The amendments are intended to reduce the risk that auditors use technology-assisted procedures without obtaining sufficient appropriate audit evidence.

A precise-looking AI result can still be built on weak source data or an inappropriate procedure.

3. Client confidentiality and data security

Audit teams regularly handle confidential financial, operational, employee, and customer information. Uploading that information into an AI tool can create privacy and security concerns if the product, account, or workflow has not been approved.

The PCAOB's outreach on generative AI noted that firms recognized the need for strong supervision to address risks including data privacy and security.

Before using AI with engagement information, teams should understand what data the tool receives, whether it is retained, who can access it, whether it is used for model improvement, and which third parties may process it.

A convenient AI feature should not bypass the firm's normal confidentiality and vendor-review requirements.

4. Opaque systems and difficult explanations

Some AI tools can produce outputs without making it easy for an auditor to understand how the result was reached.

That creates a problem when the engagement team needs to challenge the output, document its use, or explain why a conclusion was reasonable.

IAASB's current technology work specifically considers complex and opaque technologies such as AI-enabled tools within audit quality management. Its work is examining how emerging technology interacts with quality management standards and engagement responsibilities.

Audit firms should therefore think beyond whether a tool works during a demonstration. They need to understand how its use fits the firm's quality management system.

A practical way to introduce AI into an audit

Start with a defined use case rather than giving a team general permission to use AI.

For each proposed use, identify the task, the information the tool receives, the expected output, who reviews it, what could go wrong, and what evidence must be retained. Decide whether the output is administrative support or whether it affects an audit procedure or conclusion.

Higher-risk uses should receive more testing, documentation, supervision, and technical review.

Audit teams should also know when not to use AI. If the tool cannot protect the data involved, its output cannot be adequately verified, or the team does not understand its limitations well enough to rely on it, a manual or more established procedure may be more appropriate.

AI can make audit work faster and more analytical, but efficiency is not the same as audit quality. The strongest use cases are those where technology helps auditors process information or focus attention while professional skepticism, evidence evaluation, confidentiality, and final judgment remain with the engagement team.

The confidentiality risk in audit work has a timing problem at its core. Once an auditor pastes a client's journal entries, contract terms, or employee records into an AI tool and submits the prompt, that information has already left the firm's control, and no vendor policy or after-the-fact review can pull it back. This is the principle Sanitized AI is built on: the control has to act before the prompt is submitted, catching and redacting confidential engagement information so a convenient AI feature never quietly bypasses the firm's confidentiality and vendor-review requirements.

This quarter, take one approved AI use case that touches engagement information and map exactly what data the tool receives before the prompt is sent, then decide what should never reach it in the first place. If you would like to see how that pre-submission control works against real audit workflows, request a demo.

See how Sanitized AI stops sensitive data from leaving the prompt box. Writing your own rules instead? Start from our free AI acceptable use policy generator.