Bussiness man working late at office

AI audit readiness: why AI assurance matters

AI assurance is a mechanism of trust for organizations to demonstrate strong governance, controls and evidence around AI-based activities.


In brief
  • As they move from AI pilots into core finance processes, companies should treat audit readiness as an up-front design principle, not a backward-looking exercise.
  • Auditors will expect organizations to provide evidence for what happened, when it happened and what data was used to support accuracy of outputs.
  • AI assurance is more than compliance; it’s a way to build confidence, reduce risk and scale both the adoption and benefits of AI within the enterprise.

Preparing for an audit of AI-enabled financial reporting processes: why AI assurance matters and what to do now

In many ways, developing and deploying AI resembles the implementation of other technology: define requirements, build or configure, test, approve and operate. Many of the “traditional” risks, like appropriate user access, change management, segregation of duties, security and data interfaces, still apply.

At the same time, AI (and especially generative AI) has characteristics that introduce incremental risks that, due to their nature, can be harder to evaluate. These include probabilistic outputs, limited explainability, sensitivity to prompts and contextual inputs, and performance that can shift over time as data, models and usage patterns evolve. Without sufficient governance and controls that operate both before and after tools and technologies are placed into production, these characteristics can create new pathways to material misstatement, regulatory noncompliance or operational disruption.

These considerations become especially critical within the finance function and financial reporting processes. As AI becomes embedded in core finance activities, ranging from journal entry preparation and reconciliations to forecasting, analytics and disclosure support, stakeholders will increasingly ask a fundamental question: Can we have confidence in what the system is doing, and can we demonstrate that confidence? Audit procedures over AI-enabled processes are ultimately focused on establishing trust that AI use is governed, controlled and evidenced in a way that supports management’s assertions related to reliable financial reporting.

Deciding up front in the design phase what “audit-ready” means for AI systems within financial reporting processes allows the organization to build for reproducibility, appropriate human-in-the-loop review and documentation standards that yield an auditable AI process. Being ready for an audit over the use of AI means focusing on several key areas with actions and considerations.

AI governance and risk management: make ownership, scope and risk explicit

Audit readiness starts with clarity: where AI is used, why it is used and how it influences decisions that matter for financial reporting. For many companies, AI is already present in the “edges” of the process, drafting narratives for close packages, prioritizing exceptions, suggesting classifications or supporting management review. Over time, these use cases can become embedded and relied upon, creating audit-relevant dependencies.

Governance over the company’s AI strategy should be practical, not a policy sitting in a separate AI binder. Auditors will look for clear ownership and accountability for AI-enabled processes controls spanning finance, IT, risk and compliance (not only data science or innovation teams). For example, who approves model or prompt changes, who monitors ongoing performance and who is responsible when outputs are wrong.

 

Finally, AI should be incorporated into the organization’s existing risk assessment and internal control over financial reporting (ICFR) scoping approach rather than treated as a stand-alone or purely technology-driven risk. The objective is not to assess AI risk in isolation but to translate AI-specific characteristics such as inaccurate outputs, overreliance on automation, or limited explainability into financial reporting risks of material misstatement and related control objectives. This framing means that AI-enabled processes are evaluated using the same rigor and principles applied to all significant financial reporting risks.

Actions to take now:

  • Establish a clear process for evaluation of AI use cases and related risks to determine alignment with business strategy and risk tolerances.
  • Create (or refresh) an inventory of AI use cases that affect financial reporting, documenting the business process, decisions impacted, key inputs and data sources, outputs relied upon and the accountable process owner.
  • Map AI-specific risks (e.g., explainability gaps, hallucinations, model drift, prompt sensitivity) to existing financial reporting risk statements and related control objectives.
  • Define and document accountability across the AI lifecycle, including the business owner, model and prompt owner, approver, operator and monitoring responsibilities.
  • Establish governance for changes to AI systems (model updates, retraining, prompt library changes, parameter changes), including approval thresholds, testing expectations and required documentation.

Data integrity and model inputs: control what goes in, not just what comes out

For audit and assurance purposes, AI is only as reliable as the data that feeds it. Companies should be able to demonstrate what data sources are used, whether they come from in-scope financial systems or external sources and how the data is transformed before it reaches the model. Differentiating controls over training data sets, feature engineering and embeddings, and runtime prompts can help identify different risks related to completeness and accuracy. This is especially important when AI is used to support controls, management reviews or judgments that impact financial reporting.

A common mistake is focusing only on validating AI outputs. Auditors will often expect to see controls over completeness, accuracy and relevance before data enters the AI system, consistent with broader expectations for information used in controls. When inputs are not reliable, downstream review becomes a patch rather than a control.

Because AI systems can change over time through retraining, updates or shifting upstream data, organizations should also plan for data risks such as stale data, changing data definitions or characteristics, or unexpected edge cases. The point is not to eliminate change; it’s to detect data changes and understand whether they affect the reliability of outputs used in financial reporting.

Actions to take now:

  • Document data lineage for each in-scope AI use case: sources, transformations, controls and where data quality checks occur.
  • Implement input controls (e.g., completeness, accuracy, relevance, timeliness) aligned to your broader ICFR expectations for information used in controls.
  • Define how you will detect and respond to changing data (e.g., monitoring thresholds, cadence, investigation, escalation and remediation steps).
  • Be prepared to demonstrate how management validates data inputs when AI is part of a key control, including data interfaces between components of the AI system.

Internal controls over AI systems: design for appropriate reliance

Not all AI use is equal from a control’s perspective. There is a meaningful difference between using AI as a tool that supports a control owner (e.g., summarizing exceptions for review) and a control executed directly by an AI system (e.g., AI auto-approves transactions). An AI system may also comprise various components that each have different levels of reliability (i.e., deterministic and probabilistic components). These characteristics can affect both control design and the extent of auditor testing.

Controls should be designed to address inappropriate reliance on AI outputs. In practice, that often means defined human review procedures, especially when AI-enabled controls are first implemented. Other controls may be implemented to test the AI output directly and to compare the results to baseline analytics or even the results of other AI outputs. The goal of these controls is to prevent, or detect and correct, errors driven by the probabilistic nature of AI-generated output.

 

As information technology, AI systems require traditional IT general controls (ITGCs) to support their initial and ongoing effectiveness. However, AI also introduces the need for controls specifically designed to support the ongoing accuracy of the AI-generated output in the face of probability, unintended data and model drift risks. Where AI is relevant to a process affecting the financial statements, organizations should extend access, change management and operational controls to AI components (including prompt libraries and integrations), not only the underlying application.

 

Given the variability in probabilistic outcomes, supporting AI controls should also be designed to monitor the accuracy of transactions against defined thresholds throughout the reporting period and to assess performance trends over time. Just as important as the monitoring itself is the plan for when to escalate issues, when to pause or stop the operation of AI-executed controls and how to remediate potential errors.

Actions to take now:

  • Classify each use case between AI supporting a human-performed control and AI executing the control directly, and tailor documentation and testing expectations accordingly.
  • Define review, challenge and override procedures for AI outputs (what to review, how often, by whom and what constitutes an exception).
  • Extend ITGCs to AI components (e.g., access to model environments, prompt libraries, configuration settings and integration points).
  • Establish AI performance monitoring with clear thresholds and response playbooks (e.g., investigate, remediate, retrain, rollback).
  • Document how management evaluates whether AI outputs are sufficiently precise and reliable for the control objective.

Audit evidence and AI outputs: make results traceable, reproducible and reviewable

Even well-designed AI controls can fail an audit-readiness test if the company cannot produce evidence that supports what happened, when it happened and who (or what) performed it. Auditors will ask how AI outputs are produced, what data was used and how the accuracy of the output is supported, especially when outputs are used as audit evidence.

Auditability often depends on traceability and reproducibility: Can you re-create the output that was relied on at the time it was used or explain how the output was created? For many AI systems, particularly generative AI (GenAI), this means designing for point-in-time explainability using features such as logging inputs, prompts, context, model and version, parameters and configurations, and output to storage that cannot be overwritten or altered (i.e., durable logging). It also means designing for artifacts that help a reviewer understand why the result was produced.

Just as importantly, auditors will look for evidence of management review and evaluation of the output. When a person is not directly in the loop and the accuracy of the AI output is monitored elsewhere, management still needs to be in a position to understand how the output was determined. This understanding not only supports the audit but also allows the company to investigate root causes of exceptions. Without understanding how an output was incorrectly generated, it can be very difficult to remediate the issue.

Organizations should also be prepared to show how they assess completeness and accuracy of AI-produced information, consistent with broader expectations for information produced by the company that is used as audit evidence. When AI outputs are used in controls or decision-making that impacts financial reporting, the organization needs a defensible basis for concluding that outputs are complete, accurate and relevant for the objective it was designed for.

Actions to take now:

  • Define what needs to be logged for each AI use case (inputs, prompts and context, model and version, parameters, output, time stamps, reviewer identity).
  • Ensure outputs used in controls are traceable and, where feasible, reproducible at the point in time they were used.
  • Retain evidence of management review and challenge, including exceptions and follow-up.
  • Document known limitations of the AI output and the compensating controls (human review, downstream checks, thresholds).

Third-party tools and vendor management: don’t outsource accountability

Many organizations will encounter audit-relevant AI through vendors: embedded AI in enterprise resource planning (ERP), close and consolidation tools, analytics platforms, business process outsourcing, and other enterprise workflow solutions. Because these capabilities can arrive via “feature updates,” companies can find themselves relying on AI without realizing the assurance implications until late in the cycle.

Being audit-ready requires an inventory of third-party AI tools that affect financial reporting, including understanding where AI is embedded and what it does (e.g., recommendations, automation, anomaly detection). This can often require modifying the procurement or vendor management process to proactively inquire about AI features and functionality on the vendor’s roadmap rather than waiting for them to show up in release notes. This helps define scope and aligns the right procurement, IT, finance and risk stakeholders on expectations. While some of the AI features may not be relevant for financial reporting (e.g., AI chatbots), others can require further investigation into how the vendor is developing, testing and deploying AI.

Vendor assurance artifacts (such as system and organization control (SOC) reports) remain important, but companies should identify and address relevant AI-specific risks and map those to complementary user-entity controls as they may not be addressed in current reports. Auditors may want to understand what the vendor controls cover vs. what remains the company’s responsibility, particularly around configuration choices, access, monitoring and how outputs are reviewed and relied upon.

Actions to take now:

  • Ask vendors how AI is being integrated into existing products, what will change operationally and what configuration options affect outputs.
  • Maintain an inventory of third-party AI capabilities that touch financial reporting, including “embedded AI” features.
  • Evaluate what vendor assurance covers (e.g., SOC reports), and document your complementary user-entity controls (CUECs), especially those related to configuration, monitoring and review of AI outputs.
  • Implement a process to assess vendor updates and model changes before they impact ICFR-relevant processes.
  • Align procurement, IT and finance on a consistent approach to assessing AI-related vendor risk based on financial reporting significance.

People transformation: sustain skepticism, transparency and accountability

AI is changing how work gets done, which means it is changing how controls operate in practice. One of the fastest paths to audit issues is the use of “shadow AI,” where employees use AI to draft analyses, propose journal entries or shape judgments, but the usage is not transparent to process and control owners. This opens the door to risks that the company may be unprepared or unable to address in time for the audit.

Policies, training and culture should reinforce professional skepticism and accountability, especially when AI is involved. AI system outputs often appear confident, polished and professional, tempting users to accept them without challenge. Audit readiness means making it clear that the control owner remains responsible for the conclusion and that “AI said so” is not, by itself, sufficient.

Auditors will also look for clear decision rights: who is accountable for decisions when AI is used, who can approve changes and who is responsible for monitoring and remediation. Making these roles visible through an operating model and a responsible, accountable, consulted and informed (RACI) framework helps demonstrate control ownership and reduces ambiguity during audit procedures.

Actions to take now:

  • Set expectations that AI usage in finance processes must be transparent (approved tools, documented use cases, no “shadow AI” in key activities).
  • Update policies and training to reinforce professional skepticism and review responsibilities and documentation expectations for AI-assisted work.
  • Publish clear accountability (RACI) for AI-enabled processes: who owns outcomes, who approves changes, who monitors and who remediates.
  • Position AI adoption as a control-enhancing opportunity, not only an efficiency play, so teams build trust and evidence into the process from the start.

Assurance is the accelerator for responsible AI at scale

Making sure AI systems used in financial reporting processes are audit-ready is not simply a compliance exercise, it is a trust mechanism. When organizations can demonstrate strong governance, controls and evidence around AI-enabled activities, they can scale adoption with greater confidence, reduce surprises during audits and improve the reliability of financial reporting and decision-making.

Organizations can reduce friction by engaging their internal audit function and external auditor early, ideally while AI use cases are still being designed so expectations for governance, controls and evidence are understood before adoption scales. Early alignment helps avoid rework (e.g., redesigning a control to include a review step or retrofitting logging for audit evidence) and can accelerate responsible deployment.

Understanding the audit of AI-enabled financial reporting processes

Summary 

While AI shares traditional technology risks, it also introduces unique challenges such as probabilistic outputs, limited explainability, model drift and prompt sensitivity. To be audit-ready, companies should establish clear governance, inventory AI use cases and assets, control data inputs, design reliable internal controls, preserve traceable evidence, assess third-party vendor risks and strengthen employee accountability. Treating assurance as a trust-building mechanism helps organizations scale AI responsibly, reduce audit surprises and support more reliable decision-making and financial reporting over time across the enterprise.

About this article

Authors

Related articles

How AI vulnerability discovery is rapidly reshaping SOC reporting

SOC reporting is evolving as AI vulnerability discovery accelerates. From controls to testing and disclosures, scrutiny and expectations are rising.

Agentic AI: re-architecting assurance for a world of continuous risk

Agentic AI for assurance is a paradigm shift that will reshape how we approach trust, governance and accountability in our work.

Redefining the future of audit for the AI era

As the use of AI expands, high-quality audits are vital to promoting trust. At EY US, we’re meeting this moment and looking to what’s next. Learn more.

Joe Link + 1

Building trust through assurance in an AI-driven world

AI demands new services for assurance. Trust in AI requires frameworks for validation of data sources and to provide transparency in AI decision-making.