Artificial Intelligence as a New Layer of Audit Evidence and Audit Risk
Artificial intelligence is moving into ordinary business processes, including customer support, credit operations, document handling, fraud screening, software delivery, and internal reporting. For internal audit, the important question is not only whether an organisation uses an AI model. It is also how model-supported decisions are embedded in a process, what evidence remains available, and who is accountable when the output is incomplete, biased, or simply unsuitable for the decision being made.
In the near future, audit teams may encounter a broader range of AI arrangements rather than one standard technology. Some institutions will use external services, while others will deploy controlled models within private environments. Some applications will produce recommendations that a person reviews; others may quietly influence prioritisation, routing, or the wording of communications. This variety makes simple checklist approaches less useful. Auditors may need to understand the purpose of a model, the data and assumptions around it, the points at which people can intervene, and the records retained for later review.
The effect on audit work could be two-sided. AI-supported tools may help auditors organise documents, compare policies, identify unusual transactions, or draft initial lines of enquiry. At the same time, those tools introduce questions about confidentiality, reproducibility, hallucination, access rights, vendor dependency, and the possibility that an apparently efficient process is difficult to explain. A sensible audit response is likely to remain measured: use technology where it improves the search for evidence, but preserve independent validation and do not treat a generated explanation as evidence in itself.
One emerging concern is the distance between a model’s technical design and the business decision it influences. A model may perform acceptably in a controlled test while producing less reliable results after data definitions, customer behaviour, or operating conditions change. Internal auditors may therefore spend more time examining how performance is monitored in practice, who reviews exceptions, and how changes are approved. The focus would not have to be a technical re-performance of every algorithm; it could be an assessment of whether the governance around the model is proportionate to its use.
Evidence preservation may become a central part of the audit conversation. A model output without the relevant input, version, prompt, configuration, reviewer action, and time stamp can be difficult to interpret later. This does not mean that every interaction must be retained indefinitely. It does suggest that important decisions may require a traceable record of what the system was asked to do, what it produced, how a person assessed it, and what ultimately happened. Internal audit may help management distinguish useful accountability records from unmanageable collections of technical logs.
Third-party AI services add another layer of uncertainty. Procurement documents and supplier assurances may describe security and availability controls, but they may not answer every question about model changes, data reuse, geographic processing, or the treatment of customer information. Audit teams could increasingly examine how management evaluates changes in a provider’s service and whether contractual rights provide enough visibility for the organisation’s own obligations. The realistic outcome may be better escalation and decision records rather than complete transparency into a provider’s model.
This may gradually expand the skills expected of internal auditors. Technical specialists will remain important, but non-specialists may also need a working vocabulary for data lineage, model limitations, human oversight, and change management. Audit documentation may include more explicit statements about the boundaries of an AI-assisted procedure. Training may focus on asking precise questions, challenging unsupported confidence, and translating technical observations into risks that business owners and boards can understand.
The future opportunity is therefore less about turning every auditor into a data scientist and more about enabling audit teams to ask disciplined questions of systems that increasingly shape operational decisions. AI may assist with the volume and organisation of evidence, but the responsibility for defining the audit objective, evaluating relevance, and communicating uncertainty remains human. Progress is likely to be uneven, with useful applications developing alongside cautious policies, limited data, and continuing debate about what constitutes sufficient explanation.