Case Study 2: Professional Accountant in Practice – AI in Audit Evidence Collection
Your firm has implemented the system on an audit engagement for Advanced Widgits Retail Ltd, a client in the retail sector with multiple locations and a complex inventory management system. The AI system has flagged a pattern of transactions at certain store locations as “high risk,” suggesting potential revenue recognition issues.
However, when the engagement manager attempted to explain these findings to the client’s CFO, they were unable to clearly articulate why these specific transactions were flagged beyond stating “the AI system identified them as anomalous.”
Additionally, you’ve noticed the following issues:
- For certain parts of the client’s custom ERP system, the AI extraction tools captured incomplete data, creating potential gaps in audit coverage.
- Junior auditors on the team have begun to focus exclusively on AI-flagged issues without applying broader professional judgement to identify risks.
- The documentation of procedures performed has become less detailed as team members rely on the AI system’s automated workpapers.
- When challenged by the client on the findings, your team struggled to explain the underlying logic of the AI’s risk assessment methodology.
- The client’s data is being processed through the AI system’s cloud servers, raising questions about data security and confidentiality that weren’t fully addressed in the engagement letter.
The client has expressed frustration with what they perceive as an over-reliance on “black box” technology and has questioned whether your firm is exercising appropriate professional judgement in conducting the audit.
Ethical Considerations
Possible Course of Action
- Enhance understanding of the AI system: Invest in training for the audit team to better understand how the AI system works, including its capabilities and limitations, so they can properly interpret and explain its outputs.
- Implement explainability tools: Work with the AI vendor to enhance the system’s ability to explain risk assessments in plain language, providing clear rationales for flagged items.
- Develop a blended approach: Establish protocols requiring both AI-directed and traditional risk-based testing to ensure comprehensive audit coverage.
- Verify data completeness: Implement rigorous procedures to verify the completeness of data extracted from client systems before relying on AI analysis.
- Enhance documentation standards: Develop specific documentation requirements that maintain detailed understanding of client businesses despite automation.
- Establish client communication protocols: Train engagement teams on how to explain AI-assisted audit approaches to clients while maintaining confidence in their professional judgements.
- Implement human oversight mechanisms: Ensure that experienced auditors review and approve all AI-generated risk assessments before they are acted upon.
- Review data handling procedures: Assess and strengthen data security protocols for client information processed through third-party systems, including data minimisation, retention periods, and secure deletion.
- Update engagement letters: Revise standard engagement terms to explicitly address AI usage, data processing, and the respective responsibilities of the firm and the client.
- Meet with the client to address their concerns, explaining how the AI system is used as a tool to enhance, not replace, professional judgement. Acknowledge the limitations in explaining certain findings and propose a supplementary approach combining traditional audit techniques with AI-enhanced procedures.
- Address the data security and confidentiality concerns by providing detailed information about the safeguards in place and offer to sign additional confidentiality agreements specific to AI data processing if necessary. Consider whether the client should be given the option to opt out of having their data processed through external cloud servers.
- For the specific transactions flagged as high risk, conduct additional manual testing to validate the AI’s findings and provide the client with a clear, jargon-free explanation of why these items merited additional scrutiny.
- Going forward, establish an AI governance framework within your firm that includes regular assessment of the AI system’s performance, clear guidelines for human oversight, comprehensive data protection protocols, and ongoing training for all audit staff on the appropriate use of AI tools.