

Top 10 lessons on AI, trust and the future of audit
AI is moving quickly into audit and assurance. But the bigger question is no longer simply what the technology can do. It is how auditors preserve trust, accountability and evidence quality while using it.
That challenge was at the heart of a recent Caseware webinar featuring Portia Cerny, Strategic Risk and AI Transformation Leader and Chair of the Institute of Internal Auditors’ Artificial Intelligence Working Group, and Chin Ding Khoo of LNP Audit and Assurance.
Here are 10 of the most practical lessons from the discussion.
1. AI can assist the auditor, but it cannot own the work
Chin captured one of the webinar’s strongest principles in five words:
“AI cannot be the author.”
At LNP Audit and Assurance, staff can use AI to help draft, review, analyse and organise information, but the person using it remains responsible for the final work.
Portia reinforced the same point from a governance perspective: if you own a process or decision, introducing AI does not transfer that accountability to the technology.
For audit firms developing AI policies, that is a useful starting point: AI can contribute to the work, but ownership stays human.
2. Ongoing monitoring may be one of AI’s biggest control challenges
In Portia’s experience, one of the most easily overlooked weaknesses appears after an AI system goes live: ongoing monitoring and oversight.
Drawing on her earlier work with machine-learning models, she said monitoring had long been a weak point. With AI operating at greater speed and scale, the challenge becomes more significant.
For auditors, approval is therefore only part of the equation. They also need to ask:
How does the organisation know the AI is still behaving as intended?
Portia’s advice was to consider monitoring during design rather than adding it later.
3. Human oversight needs to be meaningful
Portia also challenged the assumption that a person can manually review every AI action as adoption scales.
She expects organisations to explore more AI-to-AI monitoring, where one model checks another’s output and people concentrate on areas requiring greater judgement.
That does not remove human accountability. Instead, it puts the emphasis on meaningful human oversight at the right points.
For assurance teams, deciding where those points sit could become an increasingly important control question.
4. Auditors can build AI governance on controls they already know
AI creates new risks, but many familiar control concepts still apply.
Portia suggested thinking in terms of “AI general controls” by adapting established IT general control principles to AI systems and agents.
Areas such as access controls, incidents, governance and oversight remain relevant.
The implication for audit teams is encouraging: they do not need to start from zero. Existing control frameworks provide a foundation, provided they evolve with the technology.
5. The audit objective is not changing — but the questions are
For Chin, the external audit fundamentals remain intact. Auditors still need sufficient, appropriate and reliable evidence.
What changes is the questioning required when AI contributes to management information or reporting.
Where did the information come from?
How was it produced?
Does management understand the process?
Has it been appropriately reviewed?
Can it be relied upon?
Chin’s message was that the audit objective remains the same, even if the route to establishing reliability changes.
AI may therefore make professional scepticism more important, not less.
6. Audit trails and data lineage will matter more
As AI becomes part of finance and assurance processes, auditors need to understand how an output was created.
Looking ahead, Chin suggested auditors could find themselves asking for something resembling an AI activity history to understand what research was conducted and where information originated.
Portia connected this to data lineage: tracing information from its source through to the final output.
She also offered a practical tip: use AI to help document its own use. A model can summarise a lengthy interaction and produce a cleaner record of the prompts and steps followed.
For auditors, that could make AI part of the evidence trail rather than simply another source to assess.
7. Shadow AI is the new shadow IT
Portia’s framing of shadow AI was refreshingly simple: organisations have seen this problem before.
AI can enter through employees using consumer tools or through third-party applications that introduce AI functionality without the organisation fully understanding how it is being used.
Her advice was to apply familiar shadow IT disciplines: identify what tools are being used, understand what data they access and assess which uses are material.
She also cautioned against responding too aggressively. Some employees may use unapproved AI inadvertently while policies are still evolving. A punitive response risks discouraging future disclosure.
The goal should be visibility and control — not driving AI use underground.
Watch the webinar recording for the full discussion on identifying and managing shadow AI. →
8. One of the simplest privacy controls is sharing less data
When discussing third-party AI risk, Portia returned to a basic principle: only share what is necessary.
Does the provider need every field? Can identifying information be removed? Can data be masked? Could the same task be completed with less sensitive information?
Later, she made the principle even clearer: if there is no good reason for a provider to receive a piece of information, it should remain inside the organisation.
For auditors assessing third-party AI risk, that creates a simple but powerful question:
Why does this provider need this data?
9. Board conversations may move from adoption to value
Portia expects board-level conversations to change as organisations become more mature in their AI use.
Early questions focus on visibility: Where is AI being used? Which tools are deployed? Is AI entering through third parties?
Over time, she expects the focus to shift towards cost, value and risk:
What is AI costing?
Are we getting value from it?
How is it changing our risk profile?
If that progression plays out, AI governance will increasingly become a business performance issue as well as a technology and risk issue.
10. Full-population testing changes the problem, not the need for judgement
Technology is making it possible for auditors to analyse much larger populations than traditional sampling approaches.
But more testing can create a different challenge.
As moderator Sarah observed, finding a few exceptions in a sample is very different from finding thousands across an entire population.
The question shifts from whether exceptions can be found to which exceptions matter and what the auditor should do with them.
Chin maintained that the underlying audit objective remains the same. Portia similarly argued that “sufficient” remains important because complete traceability may be possible but not always proportionate.
An auditing standards representative attending the webinar also commented that, in his view, sufficient appropriate audit evidence itself is unlikely to change, although the procedures used to obtain it will.
More data does not remove professional judgement. It gives auditors more information on which to exercise it.
The takeaway
AI is changing the mechanics of audit faster than it is changing the fundamentals.
Accountability still matters. Evidence still matters. Scepticism still matters. Controls still matter.
What is changing is the speed and scale at which those principles need to operate.
For auditors, that means the AI conversation is moving beyond productivity. As AI becomes more deeply embedded in audit and financial reporting, the questions around trust, evidence and accountability become more important, not less.

