No items found.
Blog

Top 10 lessons on AI, trust and the future of audit

AI is moving quickly into audit and assurance. But the bigger question is no longer simply what the technology can do. It is how auditors preserve trust, accountability and evidence quality while using it.

That challenge was at the heart of a recent Caseware webinar featuring Portia Cerny, Strategic Risk and AI Transformation Leader and Chair of the Institute of Internal Auditors’ Artificial Intelligence Working Group, and Chin Ding Khoo of LNP Audit and Assurance.

Here are 10 of the most practical lessons from the discussion.

1. AI can assist the auditor, but it cannot own the work

Chin captured one of the webinar’s strongest principles in five words:

“AI cannot be the author.”

At LNP Audit and Assurance, staff can use AI to help draft, review, analyse and organise information, but the person using it remains responsible for the final work.

Portia reinforced the same point from a governance perspective: if you own a process or decision, introducing AI does not transfer that accountability to the technology.

For audit firms developing AI policies, that is a useful starting point: AI can contribute to the work, but ownership stays human.

Watch the webinar recording to hear Chin and Portia discuss AI ownership, review and professional accountability. →

2. Ongoing monitoring may be one of AI’s biggest control challenges

In Portia’s experience, one of the most easily overlooked weaknesses appears after an AI system goes live: ongoing monitoring and oversight.

Drawing on her earlier work with machine-learning models, she said monitoring had long been a weak point. With AI operating at greater speed and scale, the challenge becomes more significant.

For auditors, approval is therefore only part of the equation. They also need to ask:

How does the organisation know the AI is still behaving as intended?

Portia’s advice was to consider monitoring during design rather than adding it later.

3. Human oversight needs to be meaningful

Portia also challenged the assumption that a person can manually review every AI action as adoption scales.

She expects organisations to explore more AI-to-AI monitoring, where one model checks another’s output and people concentrate on areas requiring greater judgement.

That does not remove human accountability. Instead, it puts the emphasis on meaningful human oversight at the right points.

For assurance teams, deciding where those points sit could become an increasingly important control question.

Watch the webinar recording for Portia’s perspective on how human and automated oversight could work together. →

4. Auditors can build AI governance on controls they already know

AI creates new risks, but many familiar control concepts still apply.

Portia suggested thinking in terms of “AI general controls” by adapting established IT general control principles to AI systems and agents.

Areas such as access controls, incidents, governance and oversight remain relevant.

The implication for audit teams is encouraging: they do not need to start from zero. Existing control frameworks provide a foundation, provided they evolve with the technology.

5. The audit objective is not changing — but the questions are

For Chin, the external audit fundamentals remain intact. Auditors still need sufficient, appropriate and reliable evidence.

What changes is the questioning required when AI contributes to management information or reporting.

Where did the information come from?

How was it produced?

Does management understand the process?

Has it been appropriately reviewed?

Can it be relied upon?

Chin’s message was that the audit objective remains the same, even if the route to establishing reliability changes.

AI may therefore make professional scepticism more important, not less.

Watch the webinar recording to hear Chin explain what AI means for the audit evidence conversation. →

6. Audit trails and data lineage will matter more

As AI becomes part of finance and assurance processes, auditors need to understand how an output was created.

Looking ahead, Chin suggested auditors could find themselves asking for something resembling an AI activity history to understand what research was conducted and where information originated.

Portia connected this to data lineage: tracing information from its source through to the final output.

She also offered a practical tip: use AI to help document its own use. A model can summarise a lengthy interaction and produce a cleaner record of the prompts and steps followed.

For auditors, that could make AI part of the evidence trail rather than simply another source to assess.

7. Shadow AI is the new shadow IT

Portia’s framing of shadow AI was refreshingly simple: organisations have seen this problem before.

AI can enter through employees using consumer tools or through third-party applications that introduce AI functionality without the organisation fully understanding how it is being used.

Her advice was to apply familiar shadow IT disciplines: identify what tools are being used, understand what data they access and assess which uses are material.

She also cautioned against responding too aggressively. Some employees may use unapproved AI inadvertently while policies are still evolving. A punitive response risks discouraging future disclosure.

The goal should be visibility and control — not driving AI use underground.

Watch the webinar recording for the full discussion on identifying and managing shadow AI. →

8. One of the simplest privacy controls is sharing less data

When discussing third-party AI risk, Portia returned to a basic principle: only share what is necessary.

Does the provider need every field? Can identifying information be removed? Can data be masked? Could the same task be completed with less sensitive information?

Later, she made the principle even clearer: if there is no good reason for a provider to receive a piece of information, it should remain inside the organisation.

For auditors assessing third-party AI risk, that creates a simple but powerful question:

Why does this provider need this data?

9. Board conversations may move from adoption to value

Portia expects board-level conversations to change as organisations become more mature in their AI use.

Early questions focus on visibility: Where is AI being used? Which tools are deployed? Is AI entering through third parties?

Over time, she expects the focus to shift towards cost, value and risk:

What is AI costing?

Are we getting value from it?

How is it changing our risk profile?

If that progression plays out, AI governance will increasingly become a business performance issue as well as a technology and risk issue.

Watch the webinar recording to hear Portia discuss the questions boards are asking now — and those she expects next. →

10. Full-population testing changes the problem, not the need for judgement

Technology is making it possible for auditors to analyse much larger populations than traditional sampling approaches.

But more testing can create a different challenge.

As moderator Sarah observed, finding a few exceptions in a sample is very different from finding thousands across an entire population.

The question shifts from whether exceptions can be found to which exceptions matter and what the auditor should do with them.

Chin maintained that the underlying audit objective remains the same. Portia similarly argued that “sufficient” remains important because complete traceability may be possible but not always proportionate.

An auditing standards representative attending the webinar also commented that, in his view, sufficient appropriate audit evidence itself is unlikely to change, although the procedures used to obtain it will.

More data does not remove professional judgement. It gives auditors more information on which to exercise it.

The takeaway

AI is changing the mechanics of audit faster than it is changing the fundamentals.

Accountability still matters. Evidence still matters. Scepticism still matters. Controls still matter.

What is changing is the speed and scale at which those principles need to operate.

For auditors, that means the AI conversation is moving beyond productivity. As AI becomes more deeply embedded in audit and financial reporting, the questions around trust, evidence and accountability become more important, not less.

Watch the full webinar recording for insights on AI governance, audit evidence, data security and the future of audit testing. →

No items found.

Latest news and insights.

Explore expert perspectives to help your firm stay ahead.

This is some text inside of a div block.

Lead your firm to accuracy, efficiency, and growth with Caseware.

The authority in AI-powered audit.

Contact Us
Caseware Launches Verity AI Agents for Assurance
Discover how Verity brings workflow native AI agents directly into assurance engagements to enhance efficiency, transparency, and professional judgment.
Read the IDC study

By registering, you agree to our Privacy Policy.

/* [F-037] PROMO WIDGET CLOSE BUTTON — WCAG 2.1.1*/