Case Study 2: Professional Accountant in Practice – AI in Audit Evidence CollectionCase Study 2: Professional Accountant in Practice – AI in Audit Evidence CollectionCase Study 2: Professional Accountant in Practice – AI in Audit Evidence CollectionCase Study 2: Professional Accountant in Practice – AI in Audit Evidence Collection
  • Home
  • About
    • Education and Training
    • Board of Directors
  • Values
    • Tackling Economic Crime
    • Contribution of the Profession
    • Regulation
    • Ethics Group
    • SORP LLPs
  • Ethics & Insights
    • CCAB Ethical Leadership Podcast
    • Ethics Resources
    • Ethical Dilemmas Case Studies
    • AI Hub
  • Podcasts
  • News
  • Contact
✕

Case Study 2: Professional Accountant in Practice – AI in Audit Evidence Collection

7 May, 2026

SCENARIO

You are a partner in a mid-sized accounting firm that has recently invested in an AI-powered audit platform. The system promises to transform your audit methodology by automatically extracting information from client financial systems, analysing entire transaction populations instead of samples, identifying anomalous patterns, and generating risk assessments

Your firm has implemented the system on an audit engagement for Advanced Widgits Retail Ltd, a client in the retail sector with multiple locations and a complex inventory management system. The AI system has flagged a pattern of transactions at certain store locations as “high risk,” suggesting potential revenue recognition issues.

However, when the engagement manager attempted to explain these findings to the client’s CFO, they were unable to clearly articulate why these specific transactions were flagged beyond stating “the AI system identified them as anomalous.”

Additionally, you’ve noticed the following issues:

  • For certain parts of the client’s custom ERP system, the AI extraction tools captured incomplete data, creating potential gaps in audit coverage.
  • Junior auditors on the team have begun to focus exclusively on AI-flagged issues without applying broader professional judgement to identify risks.
  • The documentation of procedures performed has become less detailed as team members rely on the AI system’s automated workpapers.
  • When challenged by the client on the findings, your team struggled to explain the underlying logic of the AI’s risk assessment methodology.
  • The client’s data is being processed through the AI system’s cloud servers, raising questions about data security and confidentiality that weren’t fully addressed in the engagement letter.

The client has expressed frustration with what they perceive as an over-reliance on “black box” technology and has questioned whether your firm is exercising appropriate professional judgement in conducting the audit.

Ethical Considerations

Integrity

  • Are you being straightforward and honest with the client regarding the capabilities, limitations, and the lack of explainability of the AI audit system?
  • Would continuing to rely on AI findings that the team cannot sufficiently explain or validate compromise the integrity of the audit process and the audit opinion?

Objectivity

  • Is there a risk that the audit team’s professional scepticism and judgement are being compromised by an over-reliance on the AI system’s outputs, potentially overlooking other risks or biases inherent in the AI model? Is there a risk of “confirmation bias”, using the AI system to confirm their initial assumptions?
  • Could the AI system itself have biases (e.g., in how it defines “anomalous”) that affect its risk assessments, requiring objective evaluation by the audit team?

Professional Competence and Due Care

  • Do you and your audit team possess sufficient understanding of the AI system’s workings, including its data extraction methods and analytical logic, to use it competently and exercise due care in evaluating its outputs?
  • Is relying on potentially incomplete data extracted by the AI, or on unexplained AI findings, consistent with the requirement to act diligently and gather sufficient appropriate audit evidence? Is the level of documentation adequate?

Confidentiality

  • Were adequate safeguards and client permissions secured regarding the processing and storage of sensitive client financial data on the third-party AI system’s cloud servers?
  • Has the firm taken appropriate steps to protect client confidentiality throughout the AI-assisted audit process, consistent with professional obligations and data protection laws?

Professional Behaviour

  • Does the current use of the AI system, particularly the lack of explainability and potential data gaps, comply with relevant auditing standards, regulations, and ethical requirements?
  • Could the inability to explain AI findings to the client or potential reliance on flawed AI analysis damage the reputation of your firm and the accountancy profession?

Possible Course of Action

  • Enhance understanding of the AI system: Invest in training for the audit team to better understand how the AI system works, including its capabilities and limitations, so they can properly interpret and explain its outputs.
  • Implement explainability tools: Work with the AI vendor to enhance the system’s ability to explain risk assessments in plain language, providing clear rationales for flagged items.
  • Develop a blended approach: Establish protocols requiring both AI-directed and traditional risk-based testing to ensure comprehensive audit coverage.
  • Verify data completeness: Implement rigorous procedures to verify the completeness of data extracted from client systems before relying on AI analysis.
  • Enhance documentation standards: Develop specific documentation requirements that maintain detailed understanding of client businesses despite automation.
  • Establish client communication protocols: Train engagement teams on how to explain AI-assisted audit approaches to clients while maintaining confidence in their professional judgements.
  • Implement human oversight mechanisms: Ensure that experienced auditors review and approve all AI-generated risk assessments before they are acted upon.
  • Review data handling procedures: Assess and strengthen data security protocols for client information processed through third-party systems, including data minimisation, retention periods, and secure deletion.
  • Update engagement letters: Revise standard engagement terms to explicitly address AI usage, data processing, and the respective responsibilities of the firm and the client.

Recommendation

Action plan:

  • Meet with the client to address their concerns, explaining how the AI system is used as a tool to enhance, not replace, professional judgement. Acknowledge the limitations in explaining certain findings and propose a supplementary approach combining traditional audit techniques with AI-enhanced procedures.
  • Address the data security and confidentiality concerns by providing detailed information about the safeguards in place and offer to sign additional confidentiality agreements specific to AI data processing if necessary. Consider whether the client should be given the option to opt out of having their data processed through external cloud servers.
  • For the specific transactions flagged as high risk, conduct additional manual testing to validate the AI’s findings and provide the client with a clear, jargon-free explanation of why these items merited additional scrutiny.
  • Going forward, establish an AI governance framework within your firm that includes regular assessment of the AI system’s performance, clear guidelines for human oversight, comprehensive data protection protocols, and ongoing training for all audit staff on the appropriate use of AI tools.
Share
Subscribe to our Newsletter
Privacy Notice
Links
How to choose an Accountant or Tax Advisor
Contact Us
© 2020 CCAB. All Rights Reserved | Privacy Policy
Registered in England and Wales No. 1864508
Registered Address: CCAB Limited, Chartered Accountants' Hall, Moorgate Place, London EC2R 6EA