Audit work splits into gathering evidence and writing about it. AI helps with the writing at every stage: planning memos, risk assessment brainstorming, walkthrough narratives, findings, management letter points, and the review notes you clear at midnight. It also helps you build the analytics you used to wait on a data specialist for, if you can describe the test.
It does not produce evidence. A model's summary of a contract is not the contract, its count of round-dollar entries is wrong unless it ran code, and its citation of AS 2401 or AU-C 240 may point to a paragraph that does not say what it claims. Under PCAOB AS 1215 and AICPA AU-C 230, the workpaper has to let an experienced auditor understand what you did and what you concluded, and the model said so does not qualify.
Client data stays inside firm-approved tools. Uploading a client's general ledger or contracts to a consumer AI service is a confidentiality breach under the AICPA Code and your engagement letter, and depending on the tool's terms it can raise independence and quality management questions. Never paste client financial data into a consumer AI tool unless your firm has approved it. Most of what follows works on de-identified extracts or your own drafts.
Quick wins this week
- Paste your rough notes on a finding and ask for it in condition, criteria, cause, effect, and recommendation. Then make it more specific than the model did.
- Describe a client's industry and entity type (no name) and ask for fraud brainstorming angles your team has not considered: where estimates hide, where management override would show up, which accounts a tired reviewer skips.
- Upload a SOC 1 Type 2 report to NotebookLM and ask for every exception, every complementary user entity control, and the testing period, with page numbers. Then read the pages.
- Ask for a Python or Excel approach to a journal-entry test you describe (weekend postings, round amounts, unusual users), then run it in a firm-approved environment on the real extract.
What AI can do for auditors, task by task
Planning memos and risk assessment
Give the entity type, industry, size, known changes (new system, new revenue stream, turnover in finance), and prior-year issues, all without the client name. Ask for a planning memo skeleton, the significant accounts and assertions likely at risk, and the questions to ask management. Check every risk against what you actually know; the model generalizes from the industry, which is where audit failures start.
Journal entry testing and data analytics
Describe the extract's fields and the criteria from your firm's methodology (period-end entries, round amounts, unusual users, entries to seldom-used accounts, blank descriptions) and ask for the script or the Excel steps. Run it in the firm's approved environment (a licensed code-execution tool, IDEA, HighBond, or MindBridge) on the actual data, and document the criteria, population, and results in the workpaper. The model's own count of anything is not evidence.
Reading contracts, leases, and debt agreements
Upload the agreement to a firm-approved document tool and ask targeted questions: performance obligations, variable consideration, renewal options, covenants, related-party terms, with page references. Open every cited clause and read it. Then apply the standard yourself; the model's ASC 606 or ASC 842 analysis is a draft argument, not a conclusion.
SOC reports and third-party evidence
Upload the SOC 1 or SOC 2 report and ask for the scope, period, carved-out subservice organizations, exceptions, and the complementary user entity controls, each with page numbers. Map the user controls to the client's controls yourself. This is an extraction task the model does well, followed by a judgment task it does not.
Findings, management letters, and internal audit reports
Paste your rough notes and ask for the finding in the five-C structure: condition, criteria, cause, consequence, corrective action, with a severity rating on your firm's scale. Ask for the sentence a CFO would push back on and a more precise version of it. Every fact in the finding must trace to a workpaper reference you can name.
Walkthrough narratives and control descriptions
Record the walkthrough with a firm-approved tool (with the client's consent) or paste your notes, and ask for a process narrative with control points, who performs each control, frequency, and the evidence produced. Verify every step with the process owner; the model will insert a plausible approval step that does not exist.
Prompts for auditors
Replace the bracketed placeholders, paste into any chat assistant, and iterate on the result.
Fraud brainstorming for a specific entity
You are an audit senior manager leading the fraud brainstorming session required under [AU-C 240 OR AS 2401]. Entity: [INDUSTRY, ENTITY TYPE, SIZE, OWNERSHIP, KEY SYSTEMS, RECENT CHANGES, NO CLIENT NAME]. Produce: 1) incentives and pressures specific to this profile, 2) opportunities, including where management override would most plausibly occur, 3) the accounts and estimates where a misstatement would be easiest to hide, 4) ten questions for management and those charged with governance, 5) three journal-entry test criteria tailored to this entity. Be specific to the profile; generic risks do not count.
Tip: Bring it to the meeting as a starting list; the value is in what the team adds and rejects.
Journal-entry test script
You are a data analytics specialist supporting an audit team. The GL extract has these fields: [LIST FIELDS, E.G. ENTRY ID, POSTING DATE, POSTING TIME, USER ID, ACCOUNT, DEBIT, CREDIT, DESCRIPTION, SOURCE]. Write a [PYTHON OR EXCEL POWER QUERY] procedure that flags entries meeting any of: posted on weekends or outside [BUSINESS HOURS], round amounts over [THRESHOLD], posted by users not in [APPROVED USER LIST], posted to accounts with fewer than [NUMBER] entries in the year, blank descriptions, and manual source with an amount just under [APPROVAL THRESHOLD]. Output a table with one flag column per criterion and a summary count by criterion. Comment every step so a reviewer can follow it.
Tip: Run it in the firm's approved environment on the real extract, and paste the commented script into the workpaper.
Extract the essentials from a SOC report
You are an IT audit senior. Answer only from the uploaded SOC [1 OR 2] Type [1 OR 2] report. Provide, with page numbers: 1) scope, system, and period covered, 2) subservice organizations and whether each is carved out or inclusive, 3) every exception noted by the service auditor with the control reference, 4) every complementary user entity control, verbatim, 5) whether the opinion is unqualified. If the report does not state something, say NOT STATED. Do not use outside knowledge.
Tip: Use NotebookLM or a firm-approved document tool; then map the user controls to the client's controls yourself.
Draft a finding in five-C format
You are an internal audit manager. Turn these rough notes into a finding using Condition, Criteria, Cause, Consequence, Corrective Action, each as one short paragraph, followed by a one-line severity rating on this scale: [YOUR SCALE]. Cite the criteria source exactly as stated in my notes; do not invent policy or regulatory references. Then list any fact in the finding that I have not supported in my notes. Notes: [PASTE ROUGH NOTES WITHOUT CLIENT IDENTIFIERS]
Tip: The last list is your evidence gap; close it before the finding goes in the report.
Outline a planning memo
You are an audit manager. Draft a planning memo outline for a [FIRST-YEAR OR RECURRING] audit of a [ENTITY TYPE] in [INDUSTRY] with [REVENUE RANGE] revenue, [OWNERSHIP AND FINANCING], key systems [SYSTEMS], and these changes since last year: [LIST CHANGES]. Include: engagement objectives, materiality approach (no figures), significant accounts and relevant assertions with the reason each is significant, identified risks including fraud risks, planned reliance on controls, use of specialists, and open questions for management. Mark any standard you reference [VERIFY].
Tip: Every risk it lists is a hypothesis; the memo gets real when you replace its reasons with yours.
Want a prompt for something else? Use the Prompt Builder or browse finance and analysis prompts.
Skills to build
Prompting with the methodology, not the client
Why: Your firm's methodology is what makes an analytic or a memo defensible. The model does not know it unless you paste it, and it should never need the client's data to help.
How: Keep the relevant methodology excerpt and criteria in a saved prompt; give the model fields and rules, not the extract.
Treating output as a hypothesis
Why: Automation bias is the opposite of professional skepticism. A clean-looking risk list or contract summary invites you to stop looking.
How: Before accepting any output, write one sentence on what would make it wrong and one on how you checked. Put both in the workpaper.
Running analytics in an environment that counts
Why: A chat model estimates arithmetic; a script computes it. Sampling, stratification, and exception counts must come from executed code or an audit tool.
How: Learn one firm-approved code-execution path (Python through an approved tool, IDEA, HighBond, or Copilot in Excel) and document inputs, script, and outputs every time.
Verifying standards in the source
Why: Models produce plausible paragraph numbers for AS, AU-C, IIA, and ISA standards that do not say what the model claims.
How: Every citation gets opened in the PCAOB, AICPA, or IIA text before it appears in a memo. Use NotebookLM with the standard uploaded for questions.
Documenting AI use in the file
Why: Reviewers, inspectors, and your quality management system need to know which tools touched which workpapers and how the output was checked.
How: Follow your firm's documentation template for AI-assisted work; if none exists, note the tool, the input, the check performed, and who reviewed it.
Tools worth knowing
Claude
A careful writing and analysis assistant that shines on long documents.
ChatGPT
The general-purpose AI assistant most of your coworkers already use.
NotebookLM
A research notebook that only answers from the sources you give it, with citations.
Microsoft Copilot
AI inside Word, Excel, Outlook, and Teams, with your company's data protections.
Julius AI
Chat with your spreadsheets and data files and get charts, stats, and answers back
Zoom AI Companion
The meeting notetaker and assistant already built into your paid Zoom account
Cautions for auditors
Client information is confidential under the AICPA Code and your engagement letter, and consumer AI tiers may retain or train on inputs. Running attest client data through an unapproved tool creates a confidentiality breach and, depending on the vendor's terms, documentation and independence questions under SEC and PCAOB independence rules. Use only tools cleared by your firm's quality management system, and never paste client financial data into a consumer AI tool unless your firm has approved it.
PCAOB AS 1105 and AICPA AU-C 500 define evidence by its source and reliability; a model's summary or count is neither. AS 1215 and AU-C 230 require documentation an experienced auditor can follow. Record the population, the criteria, the executed procedure, and your conclusion. A chat transcript is not a workpaper.
The model will cite AS 2401 paragraphs that do not exist, describe an ASC 606 step incorrectly, and insert an approval control into a walkthrough that the client does not perform. Read the standard, read the contract, and confirm every control with the person who performs it.
PCAOB QC 1000 and AICPA SQMS No. 1 took effect in December 2025, and both expect firms to govern the technology used on engagements. Inspectors are asking how AI-assisted work was supervised and reviewed. If your firm has not addressed AI in its system of quality management, raise it before you use a tool on an engagement.
A confident, well-formatted risk assessment or contract summary is easier to accept than to challenge, and the standards require the opposite reflex. Treat every output as a staff draft from someone who has never met the client.
Your 30-day plan
- Week 1: Read your firm's AI and technology policy. Confirm which tools are approved for client data, which for non-client work, and how AI use must be documented. No client data goes into anything else.
- Week 1: Do three quick wins on your own drafts: a finding in five-C format, a review-note checklist, and fraud brainstorming for a de-identified entity.
- Week 2: Rebuild one journal-entry test from last year's file with a model-written script in the approved environment. Compare exception counts with last year's and document the differences.
- Week 2: Upload one SOC report through an approved tool and time the extraction against your manual read. Note anything the model missed or misstated.
- Week 3: Save your best prompts, with methodology excerpts and the [VERIFY] rule, as a firm-approved Project or custom GPT for the team.
- Week 4: Draft a one-page AI documentation template for engagement files if none exists, share it with your quality lead, and brief your team on the errors you caught.
Frequently asked questions
Will AI replace auditors?
Can auditors use ChatGPT on client data?
Does AI output count as audit evidence?
What do PCAOB inspectors think about AI?
How is AI different for internal audit?
Terms used on this page
Related roles
- AI for AccountantsAI drafts the flux commentary, writes the XLOOKUP, explains the K-1 to your client in plain English, and reads the 40-page lease for you. You still own the numbers, the judgment, and the signature.
- AI for Compliance OfficersAI rewrites the policy nobody reads into one people will, finds the rule change you missed, drafts the training deck, and structures the investigation chronology. It also puts a new line on your risk register: the company's own use of AI, which regulators now expect you to govern.
- AI for Financial AnalystsAI writes the first pass of your variance commentary, audits your model for hard-codes and sign errors, and turns a 10-K into a table with page references. You decide what the numbers mean and what to tell the CFO.
- AI for Data AnalystsAI writes the SQL, the pandas, the DAX, and the sentences around the chart. It cannot know your data, so your job shifts to the right question, the checked join, and keeping regulated data out of the wrong tool.