Preparing for an audit of AI-enabled financial reporting processes: why AI assurance matters and what to do now
In many ways, developing and deploying AI resembles the implementation of other technology: define requirements, build or configure, test, approve and operate. Many of the “traditional” risks, like appropriate user access, change management, segregation of duties, security and data interfaces, still apply.
At the same time, AI (and especially generative AI) has characteristics that introduce incremental risks that, due to their nature, can be harder to evaluate. These include probabilistic outputs, limited explainability, sensitivity to prompts and contextual inputs, and performance that can shift over time as data, models and usage patterns evolve. Without sufficient governance and controls that operate both before and after tools and technologies are placed into production, these characteristics can create new pathways to material misstatement, regulatory noncompliance or operational disruption.
These considerations become especially critical within the finance function and financial reporting processes. As AI becomes embedded in core finance activities, ranging from journal entry preparation and reconciliations to forecasting, analytics and disclosure support, stakeholders will increasingly ask a fundamental question: Can we have confidence in what the system is doing, and can we demonstrate that confidence? Audit procedures over AI-enabled processes are ultimately focused on establishing trust that AI use is governed, controlled and evidenced in a way that supports management’s assertions related to reliable financial reporting.
Deciding up front in the design phase what “audit-ready” means for AI systems within financial reporting processes allows the organization to build for reproducibility, appropriate human-in-the-loop review and documentation standards that yield an auditable AI process. Being ready for an audit over the use of AI means focusing on several key areas with actions and considerations.
AI governance and risk management: make ownership, scope and risk explicit
Audit readiness starts with clarity: where AI is used, why it is used and how it influences decisions that matter for financial reporting. For many companies, AI is already present in the “edges” of the process, drafting narratives for close packages, prioritizing exceptions, suggesting classifications or supporting management review. Over time, these use cases can become embedded and relied upon, creating audit-relevant dependencies.
