1. Home
  2. Job Skills with AI
  3. Auditors
Job Skills with AI · Finance & Accounting

AI for Auditors

AI drafts the planning memo, writes the journal-entry test script, pulls every exception and user control out of a 200-page SOC 1 report, and turns your rough finding into condition, criteria, cause, and effect. Evidence, skepticism, and the conclusion in the workpaper are still yours.

Reviewed September 2026. Free to use. No account needed.

Tasks covered6 workflows
Ready prompts5 to copy
Skills to build5 skills
Cautions5 role-specific
Plan6 steps, 30 days

Audit work splits into gathering evidence and writing about it. AI helps with the writing at every stage: planning memos, risk assessment brainstorming, walkthrough narratives, findings, management letter points, and the review notes you clear at midnight. It also helps you build the analytics you used to wait on a data specialist for, if you can describe the test.

It does not produce evidence. A model's summary of a contract is not the contract, its count of round-dollar entries is wrong unless it ran code, and its citation of AS 2401 or AU-C 240 may point to a paragraph that does not say what it claims. Under PCAOB AS 1215 and AICPA AU-C 230, the workpaper has to let an experienced auditor understand what you did and what you concluded, and the model said so does not qualify.

Client data stays inside firm-approved tools. Uploading a client's general ledger or contracts to a consumer AI service is a confidentiality breach under the AICPA Code and your engagement letter, and depending on the tool's terms it can raise independence and quality management questions. Never paste client financial data into a consumer AI tool unless your firm has approved it. Most of what follows works on de-identified extracts or your own drafts.

Quick wins this week

  • Paste your rough notes on a finding and ask for it in condition, criteria, cause, effect, and recommendation. Then make it more specific than the model did.
  • Describe a client's industry and entity type (no name) and ask for fraud brainstorming angles your team has not considered: where estimates hide, where management override would show up, which accounts a tired reviewer skips.
  • Upload a SOC 1 Type 2 report to NotebookLM and ask for every exception, every complementary user entity control, and the testing period, with page numbers. Then read the pages.
  • Ask for a Python or Excel approach to a journal-entry test you describe (weekend postings, round amounts, unusual users), then run it in a firm-approved environment on the real extract.

What AI can do for auditors, task by task

Planning memos and risk assessment

Give the entity type, industry, size, known changes (new system, new revenue stream, turnover in finance), and prior-year issues, all without the client name. Ask for a planning memo skeleton, the significant accounts and assertions likely at risk, and the questions to ask management. Check every risk against what you actually know; the model generalizes from the industry, which is where audit failures start.

Journal entry testing and data analytics

Describe the extract's fields and the criteria from your firm's methodology (period-end entries, round amounts, unusual users, entries to seldom-used accounts, blank descriptions) and ask for the script or the Excel steps. Run it in the firm's approved environment (a licensed code-execution tool, IDEA, HighBond, or MindBridge) on the actual data, and document the criteria, population, and results in the workpaper. The model's own count of anything is not evidence.

Ask: write a Python script that flags entries posted on weekends or after 8 pm, over the threshold I give you, by users outside this list.

Reading contracts, leases, and debt agreements

Upload the agreement to a firm-approved document tool and ask targeted questions: performance obligations, variable consideration, renewal options, covenants, related-party terms, with page references. Open every cited clause and read it. Then apply the standard yourself; the model's ASC 606 or ASC 842 analysis is a draft argument, not a conclusion.

SOC reports and third-party evidence

Upload the SOC 1 or SOC 2 report and ask for the scope, period, carved-out subservice organizations, exceptions, and the complementary user entity controls, each with page numbers. Map the user controls to the client's controls yourself. This is an extraction task the model does well, followed by a judgment task it does not.

Output: 4 exceptions in CC6.1 and CC7.2 (pages 61 and 64), 11 complementary user entity controls on pages 18 through 20, bridge letter needed for the last two months.

Findings, management letters, and internal audit reports

Paste your rough notes and ask for the finding in the five-C structure: condition, criteria, cause, consequence, corrective action, with a severity rating on your firm's scale. Ask for the sentence a CFO would push back on and a more precise version of it. Every fact in the finding must trace to a workpaper reference you can name.

Walkthrough narratives and control descriptions

Record the walkthrough with a firm-approved tool (with the client's consent) or paste your notes, and ask for a process narrative with control points, who performs each control, frequency, and the evidence produced. Verify every step with the process owner; the model will insert a plausible approval step that does not exist.

Prompts for auditors

Replace the bracketed placeholders, paste into any chat assistant, and iterate on the result.

Fraud brainstorming for a specific entity

You are an audit senior manager leading the fraud brainstorming session required under [AU-C 240 OR AS 2401]. Entity: [INDUSTRY, ENTITY TYPE, SIZE, OWNERSHIP, KEY SYSTEMS, RECENT CHANGES, NO CLIENT NAME].

Produce: 1) incentives and pressures specific to this profile, 2) opportunities, including where management override would most plausibly occur, 3) the accounts and estimates where a misstatement would be easiest to hide, 4) ten questions for management and those charged with governance, 5) three journal-entry test criteria tailored to this entity. Be specific to the profile; generic risks do not count.

Tip: Bring it to the meeting as a starting list; the value is in what the team adds and rejects.

Journal-entry test script

You are a data analytics specialist supporting an audit team. The GL extract has these fields: [LIST FIELDS, E.G. ENTRY ID, POSTING DATE, POSTING TIME, USER ID, ACCOUNT, DEBIT, CREDIT, DESCRIPTION, SOURCE].

Write a [PYTHON OR EXCEL POWER QUERY] procedure that flags entries meeting any of: posted on weekends or outside [BUSINESS HOURS], round amounts over [THRESHOLD], posted by users not in [APPROVED USER LIST], posted to accounts with fewer than [NUMBER] entries in the year, blank descriptions, and manual source with an amount just under [APPROVAL THRESHOLD]. Output a table with one flag column per criterion and a summary count by criterion. Comment every step so a reviewer can follow it.

Tip: Run it in the firm's approved environment on the real extract, and paste the commented script into the workpaper.

Extract the essentials from a SOC report

You are an IT audit senior. Answer only from the uploaded SOC [1 OR 2] Type [1 OR 2] report. Provide, with page numbers: 1) scope, system, and period covered, 2) subservice organizations and whether each is carved out or inclusive, 3) every exception noted by the service auditor with the control reference, 4) every complementary user entity control, verbatim, 5) whether the opinion is unqualified.

If the report does not state something, say NOT STATED. Do not use outside knowledge.

Tip: Use NotebookLM or a firm-approved document tool; then map the user controls to the client's controls yourself.

Draft a finding in five-C format

You are an internal audit manager. Turn these rough notes into a finding using Condition, Criteria, Cause, Consequence, Corrective Action, each as one short paragraph, followed by a one-line severity rating on this scale: [YOUR SCALE]. Cite the criteria source exactly as stated in my notes; do not invent policy or regulatory references. Then list any fact in the finding that I have not supported in my notes.

Notes:
[PASTE ROUGH NOTES WITHOUT CLIENT IDENTIFIERS]

Tip: The last list is your evidence gap; close it before the finding goes in the report.

Outline a planning memo

You are an audit manager. Draft a planning memo outline for a [FIRST-YEAR OR RECURRING] audit of a [ENTITY TYPE] in [INDUSTRY] with [REVENUE RANGE] revenue, [OWNERSHIP AND FINANCING], key systems [SYSTEMS], and these changes since last year: [LIST CHANGES].

Include: engagement objectives, materiality approach (no figures), significant accounts and relevant assertions with the reason each is significant, identified risks including fraud risks, planned reliance on controls, use of specialists, and open questions for management. Mark any standard you reference [VERIFY].

Tip: Every risk it lists is a hypothesis; the memo gets real when you replace its reasons with yours.

Want a prompt for something else? Use the Prompt Builder or browse finance and analysis prompts.

Skills to build

Prompting with the methodology, not the client

Why: Your firm's methodology is what makes an analytic or a memo defensible. The model does not know it unless you paste it, and it should never need the client's data to help.

How: Keep the relevant methodology excerpt and criteria in a saved prompt; give the model fields and rules, not the extract.

Treating output as a hypothesis

Why: Automation bias is the opposite of professional skepticism. A clean-looking risk list or contract summary invites you to stop looking.

How: Before accepting any output, write one sentence on what would make it wrong and one on how you checked. Put both in the workpaper.

Running analytics in an environment that counts

Why: A chat model estimates arithmetic; a script computes it. Sampling, stratification, and exception counts must come from executed code or an audit tool.

How: Learn one firm-approved code-execution path (Python through an approved tool, IDEA, HighBond, or Copilot in Excel) and document inputs, script, and outputs every time.

Verifying standards in the source

Why: Models produce plausible paragraph numbers for AS, AU-C, IIA, and ISA standards that do not say what the model claims.

How: Every citation gets opened in the PCAOB, AICPA, or IIA text before it appears in a memo. Use NotebookLM with the standard uploaded for questions.

Documenting AI use in the file

Why: Reviewers, inspectors, and your quality management system need to know which tools touched which workpapers and how the output was checked.

How: Follow your firm's documentation template for AI-assisted work; if none exists, note the tool, the input, the check performed, and who reviewed it.

Tools worth knowing

Cautions for auditors

Independence, confidentiality, and client data

Client information is confidential under the AICPA Code and your engagement letter, and consumer AI tiers may retain or train on inputs. Running attest client data through an unapproved tool creates a confidentiality breach and, depending on the vendor's terms, documentation and independence questions under SEC and PCAOB independence rules. Use only tools cleared by your firm's quality management system, and never paste client financial data into a consumer AI tool unless your firm has approved it.

AI output is not audit evidence

PCAOB AS 1105 and AICPA AU-C 500 define evidence by its source and reliability; a model's summary or count is neither. AS 1215 and AU-C 230 require documentation an experienced auditor can follow. Record the population, the criteria, the executed procedure, and your conclusion. A chat transcript is not a workpaper.

Hallucinated standards and invented controls

The model will cite AS 2401 paragraphs that do not exist, describe an ASC 606 step incorrectly, and insert an approval control into a walkthrough that the client does not perform. Read the standard, read the contract, and confirm every control with the person who performs it.

Quality management and inspection readiness

PCAOB QC 1000 and AICPA SQMS No. 1 took effect in December 2025, and both expect firms to govern the technology used on engagements. Inspectors are asking how AI-assisted work was supervised and reviewed. If your firm has not addressed AI in its system of quality management, raise it before you use a tool on an engagement.

Professional skepticism and automation bias

A confident, well-formatted risk assessment or contract summary is easier to accept than to challenge, and the standards require the opposite reflex. Treat every output as a staff draft from someone who has never met the client.

Your 30-day plan

  1. Week 1: Read your firm's AI and technology policy. Confirm which tools are approved for client data, which for non-client work, and how AI use must be documented. No client data goes into anything else.
  2. Week 1: Do three quick wins on your own drafts: a finding in five-C format, a review-note checklist, and fraud brainstorming for a de-identified entity.
  3. Week 2: Rebuild one journal-entry test from last year's file with a model-written script in the approved environment. Compare exception counts with last year's and document the differences.
  4. Week 2: Upload one SOC report through an approved tool and time the extraction against your manual read. Note anything the model missed or misstated.
  5. Week 3: Save your best prompts, with methodology excerpts and the [VERIFY] rule, as a firm-approved Project or custom GPT for the team.
  6. Week 4: Draft a one-page AI documentation template for engagement files if none exists, share it with your quality lead, and brief your team on the errors you caught.

Frequently asked questions

Will AI replace auditors?
It is replacing drafting, summarizing, and the wait for analytics. It is not replacing evidence, skepticism, judgment about estimates and going concern, or the signature on the opinion. Firms that use the tools well are shifting hours from writing to inquiry and evaluation.
Can auditors use ChatGPT on client data?
Not through a consumer account. Client information is confidential under the AICPA Code, and unapproved tools raise independence and quality management questions. Use the enterprise tools your firm has cleared, with terms that exclude training on your data, and de-identify where you can.
Does AI output count as audit evidence?
No. Evidence is defined by its source and reliability under AS 1105 and AU-C 500, and a model's summary or count is neither. Use AI to plan, to draft, and to write the script; the evidence is the executed procedure on the actual population, documented so a reviewer can re-perform it.
What do PCAOB inspectors think about AI?
PCAOB staff have published observations on how firms are using generative AI and have signaled attention to supervision and documentation of AI-assisted work. QC 1000 expects firms to govern the technology they use. Ask your quality lead what your firm has told inspectors.
How is AI different for internal audit?
Internal auditors work under the IIA's Global Internal Audit Standards, which took effect in January 2025, and inside the company's own data controls, so tool access is often broader. The evidence and documentation expectations are the same, and internal audit is increasingly asked to audit the company's own AI use as well.

Terms used on this page

Related roles