IN BRIEF

Audit planning is one of the most complex but critical stages of the audit process. This leads auditors to look for technologies that can help make the process more efficient. Recently, artificial intelligence (AI) has been touted as a possible tool to help auditors find patterns and potential red flags in large sets of data. This article describes how an AI framework can be used by auditors to assess risk and plan the audit more effectively, while pointing out its limitations and the necessity for human judgment.

***

Audit planning is a critical stage in the audit process, where auditors identify areas of potential risk and design procedures to obtain sufficient and appropriate evidence. One of the most significant challenges during planning is assessing the risk of material misstatements (RMM) due to error or fraud. With the rapid growth of data and increasing complexity of business transactions, traditional risk assessment approaches may not be sufficient. Artificial Intelligence (AI) offers auditors advanced tools to enhance their ability to detect anomalies, patterns, and red flags that signal elevated risks of misstatement.

Studies have shown that a large percentage of audit opinions (both as to financial statements and as to reporting entities’ internal controls over financial reporting) are rendered without being adequately supported by sufficient appropriate audit evidence, as required under the professional standards (E. R. Onwubuariri, B. O. Adelakun, O. P. Olaiya, and J. E. K. Ziorklui, “AI-Driven Risk Assessment: Revolutionizing Audit Planning And Execution,” Finance & Accounting Research Journal, vol. 6, no. 6, 2024, pp.1069–109; M. S. Beasley, J. V. Carcello, and D. R. Hermanson, “Top 10 Audit Deficiencies,” Journal of Accountancy, Mar. 31, 2001, https://tinyurl.com/4tkfdh54). The failure to identify, obtain, and properly interpret audit evidence often springs from audit planning process failures (“PCAOB Sanctions Three Auditors for Failures Relating to Audit Evidence, Skepticism, and Other Violations,” PCAOB Press Release, 2024, https://tinyurl.com/yr59dcmd).

Just as obtaining or discovering the right answer to a question or solution to a problem is heavily dependent upon framing the proper inquiry, so too is conducting an audit that will include obtaining and evaluating appropriate evidence driven in large part by designing and executing an effective planning effort. One required (and highly useful) aspect of audit planning is the so-called “brainstorming” session during which most (or, better yet, all) of the engagement team hypothesizes “what can go wrong”-type issues. The advent of AI has transformed risk assessment, the basis for effective audit planning and execution, by equipping auditors with advanced tools to rapidly and accurately analyze large volumes of data.

Audit risk for an account or an assertion is at an appropriately low level when the auditors have obtained sufficient, appropriate audit evidence. One of the primary benefits of using AI in risk assessment is its ability to rapidly process and analyze large volumes of data, uncovering patterns and anomalies that may indicate potential risks. Thus, AI helps auditors achieve an appropriate understanding of the entity, its environment, and the applicable financial reporting framework, providing them with a foundation for maintaining the requisite professional skepticism throughout the audit.

AI encompasses a wide range of computational techniques and applications that enable machines to mimic human-like cognitive abilities. Machine Learning (ML) is a subset of AI that uses algorithms to learn from and make predictions or decisions based on data. A subset of ML is Generative AI (GenAI), which focuses on generating new content such as text, images, or computer code. Within GenAI, Large Language Models (LLMs) such as GPT, BERT, and BART are specifically trained on massive text datasets to understand natural language and perform generation tasks [Center for Audit Quality (CAQ), “Auditing in the Age of Generative AI,” 2024, https://tinyurl.com/4k638m24). Although GenAI is very popular, the future is shifting toward Agentic AI, which is proactive and goal-driven. It can sense/observe an environment, reason, choose actions, monitor results, and make adjustments (Forrester Report, “Agentic AI Is Rising and Will Reforge Businesses that Embrace It,” 2025, https://tinyurl.com/2p9t3d3h).

While AI and ML are not new, the accessibility and ease of use provided by GenAI chatbots and similar LLMs have led to increased use by individuals and businesses (CAQ 2024). The Big Four and other major firms are investing substantially in AI. Their initiatives range from multi-billion-dollar commitments and partnerships with tech giants to develop internal platforms and generative AI tools, to expansion into AI assurance services (e.g., Deloitte’s Omnia, KPMG’s Clara, PwC’s Halo, EY’s Canvas, Caseware AiDA, MindBridge AI). These efforts are reshaping audit, consulting, tax, risk assessment, and management functions. Several case studies have been developed by Big Four firms on responsible AI governance and risk assessment (Deloitte, “Do Bots Understand Risk?” 2025, https://tinyurl.com/2p58sthx; EY, “How Mott MacDonald Accelerated Responsible AI,” 2025, https://tinyurl.com/3zkz7b6m; KPMG, “Building Trusted AI in Financial Services,” 2025, https://tinyurl.com/2cfa8ds5; PwC, “Case studies—AI,” 2025, https://tinyurl.com/38py5ar8).

In 2024, the Public Company Accounting Oversight Board (PCAOB) issued AS 1000, General Responsibilities of the Auditor in Conducting an Audit, and related amendments to other PCAOB standards, citing “advancements in technology affecting the availability of electronic audit tools and use of audit software.” Relatedly, the International Audit and Assurance Standards Board (IAASB) has been examining disruptive technologies for their effects on audit and assurance services to be able to respond appropriately to enhanced risks created by the use of technology (PCAOB 2024a). AICPA’s AU-C 315, as amended by SAS 145, PCAOB’s AS 2110, and IAASB’s ISA 315 (Revised 2019) provide guidance on identifying and assessing the risks of material misstatements.

In accordance with AU-C 220, Quality Management, with respect to AI tools (e.g., data analytics, machine learning models) the auditor must ensure: the competence and reliability of the AI system; appropriate supervision of outputs, not blind reliance; and proper review and challenge of AI-generated conclusions. When creating an audit trail under AU-C 230, Audit Documentation, auditors should document what AI tools were used (model, parameters, data inputs), why the tool is appropriate for the audit objective, and how outputs were evaluated and corroborated. Thus, AI does not reduce documentation burden—it often expands it due to explainability needs.

Under AU-C 500, Audit Evidence, which focuses on obtaining sufficient appropriate audit evidence to support the audit opinion, AI outputs (e.g., anomaly detection, predictive analytics) are considered audit evidence, but their reliability must be critically assessed. It includes evaluating data quality used by the AI, model design, and potential bias, as well as consistency with other evidence. Because AI-generated evidence is often indirect or analytical, it typically requires corroboration with traditional procedures and evaluation of source credibility, similar to third-party or internally generated evidence. AI evidence may be high-volume but not inherently high-quality—AU-C 500 emphasizes quality over quantity.

Thus, AI-generated evidence is acceptable—but only when auditors understand it, document it, and critically evaluate it within the GAAS/PCAOB frameworks. This article delves into the effective integration of AI into the audit planning process, enabling auditors to anticipate risks more effectively and thus optimize their audit procedures. As AI becomes more accessible, and thus more widely employed, auditors need to understand both the opportunities and risks associated with its use.

A Framework for Integrating AI into Audit Risk Assessment

Audit risk assessment is a vital phase of the audit process, as it guides auditors in identifying areas of potential misstatement and in determining the nature, timing, and extent of appropriate audit procedures. With the growing complexity of business environments and their massive volumes of structured and unstructured data, AI represents a potential tool to enhance the accuracy, efficiency, and depth of audit risk assessment.

The following framework integrates all kinds of AI [ML, natural language processing (NLP), GenAI, LLM, and Data Analytics] to create a comprehensive approach to audit planning. While the article focuses on risk assessment—per the AICPA’s AU-C 315, as amended by SAS 145, PCAOB’s AS 2110, and IAASB’s ISA 315 (Revised 2019) standards—audit planning involves more than just risk assessment. Professional standards outline specific steps that auditors must follow, including understanding the entity, identifying areas of risk, designing audit procedures, evaluating internal controls, and documenting the audit plan. Under the PCAOB’s standards, in an integrated audit, the auditor’s risk assessment procedures should apply to both the audit of internal controls over financial reporting and the financial statement audit.

AS 2101, Audit Planning, states that an auditor should develop and document an audit plan that includes a description of: 1) the planned nature, timing, and extent of the risk assessment procedures; 2) the planned nature, timing, and extent of tests of controls and substantive procedures; and 3) other planned audit procedures required to comply with PCAOB standards. This framework should reflect these steps, and one must be careful not to simplify it as merely an application of AI in the risk assessment process.

Exhibit 1 illustrates a framework for integrating AI into audit risk assessment. It highlights four interrelated stages: data acquisition, risk identification, analytical modeling, and auditor judgment integration.

EXHIBIT 1

A Framework for Integrating AI into Audit Risk Assessment

The first stage, data acquisition, emphasizes the use of AI-enabled tools to collect and organize both structured data (such as financial transactions, ledgers, and regulatory filings) as well as unstructured data (such as emails, contracts, and industry news). NLP and ML algorithms allow auditors to process these diverse sources at scale, uncovering early signals of risk that might not be made evident through the application of traditional sampling techniques.

The second stage, risk identification, involves applying AI to detect anomalies, patterns, and red flags when identifying relevant assertions about a class of transactions, account balance, or disclosure. ML models can highlight unusual fluctuations in revenue recognition, sudden changes in expense patterns, or inconsistencies in related-party transactions. In industries with complex operational and financial structures, AI can provide predictive indicators of error or even fraud by comparing current data with historical data or industry benchmarks.

The third stage, analytical modeling, integrates advanced algorithms into risk scoring spectrums. Generative AI and predictive analytics can simulate scenarios to assist an auditor in assessing the likelihood and magnitude of risks of material misstatement under different conditions. This stage supports auditors in quantifying significant risk exposures; prioritizing high-risk transactions, accounts, and related disclosures; and efficiently allocating audit resources. Importantly, AI tools are able to improve throughout the engagement as new audit evidence is gathered, creating a dynamic, adaptive risk assessment process.

The final stage, auditor judgment integration, ensures that AI functions as an aid rather than a replacement for professional skepticism. Human auditors must interpret AI outputs and validate them against professional standards, as well as apply contextual knowledge of the client and industry. This stage preserves accountability and ethical responsibility, while enabling auditors to focus on higher-order analysis and decision-making.

An auditor’s assessment of the risks of material misstatement, including fraud risks, should continue throughout the audit. When auditors obtain evidence during the audit that contradicts the initial expectations of risk, they should revise the risk assessment and modify planned procedures or perform additional procedures. AI offers several advantages over traditional risk assessment methods. AI algorithms can “learn” from new data, allowing auditors to adapt to changing risk environments and identify emerging risks in real-time (Onwubuariri et al. 2024).

To ensure this framework is accessible, the technical AI terminology used in this article can be interpreted in practical audit terms. In essence, the AI tools automate tasks that auditors traditionally perform manually—such as reviewing contracts, comparing transactions to historical patterns, identifying unusual journal entries, and detecting abnormal revenue recorded near period end. By translating the analytics into familiar audit indicators, the framework helps auditors focus their professional skepticism on areas most likely to contain material misstatements. The Sidebar includes definitions for the AI terms used in this article.

Data Sources and Tools in AI Applications

An AI-powered audit risk assessment workflow begins with the integration of multiple structured and unstructured data sources. Structured data includes general ledger accounts activity, trial balances, revenue and expense schedules, and accounts receivable and accounts payable subsidiary ledgers. Unstructured data includes contracts, internal control policies, audit committee reports, board meeting minutes, management’s public pronouncements, and regulatory filings. All incoming data is preprocessed in order to cleanse, normalize, and format them for model consumption. Exhibit 2 presents data sources and tools in AI applications.

EXHIBIT 2

Representative AI Platforms, Data Sources, and Audit Technologies Used in AI-Enabled Audit Risk Assessment

 1. Pre-trained Models; Pre-trained models such as BERT, BART, or GPT for NLP tasks such as document analysis, contract review, and extracting critical data from unstructured sources. BERT: Hugging Face Transformers: https://huggingface.co/models BART: Hugging Face BART https://huggingface.co/facebook/bart-large OpenAI GPT Models: https://openai.com/api GPT-3 via Hugging Face Models: https://huggingface.co/models 2. AI Data Analytics Tools and Platforms; Several powerful tools and platforms are available to analyze and visualize structured financial data integrated with GenAI models. Pandas: https://pandas.pydata.org/docs NumPy: https://numpy.org/doc Jupyter Notebooks: https://jupyter.org Tableau: https://www.tableau.com Power BI: https://www.microsoft.com/en-us/power-platform/products/power-bi 3. Machine Learning Platforms; ML models are used to analyze risks and detect anomalies. Google Cloud AI and ML Tools: https://cloud.google.com/products/ai TensorFlow: https://www.tensorflow.org AWS SageMaker: https://aws.amazon.com/sagemaker Microsoft Azure ML: https://azure.microsoft.com/en-us/products/machine-learning 4. Financial Data for Risk Assessment; Sources are available for gathering structured and unstructured financial data for risk assessment. SEC EDGAR Database: https://www.sec.gov/edgar.shtml Yahoo Finance API: https://finance.yahoo.com Morningstar API: https://developer.morningstar.com/direct-web-services Alpha Vantage API: https://www.alphavantage.co 5. Internal Control Risk and Management Data; Repositories exist for control frameworks and best practices to evaluate internal control risk and compliance issues. COSO Framework: https://www.coso.org ISACA (COBIT 2019 Framework): https://www.isaca.org 6. Fraud Detection and Forensic Accounting Tools; Sources are available to analyze fraud risks and irregular financial activities. Galvanize Analytics: https://www.diligent.com CaseWare IDEA: https://www.caseware.com

Natural language processing uses pretrained models such as BERT, BART, and GPT, fine-tuned on audit-specific data from SEC filings, PCAOB findings, financial disclosures, internal audit records, and forensic accounting cases. BERT supports clause-level contract classification and red-flag detection, while BART summarizes lengthy audit reports and identifies judgmental areas in disclosures. GPT models assist with audit planning, anomaly explanation, and plain-language interpretation of AI outputs. Classification models must meet minimum accuracy thresholds and be validated through human review before they are used.

Numerical analysis relies on Pandas, NumPy, and SciPy to calculate transaction patterns, ratio changes, and peer deviations. Machine learning models hosted in TensorFlow, PyCaret, and AWS SageMaker classify inherent and control risks, while GenAI converts results into documentation-ready audit language. Additional tools can detect control failures, segregation of duties issues, and weak control mappings. Dashboards in Tableau and Power BI display risk across assertions and accounts, while explainability tools such as SHAP and LIME help auditors understand and justify findings that are derived from AI.

Risk Identification

Risk identification and assessment procedures are designed to obtain an understanding of the client and its environment, including its internal controls, to assess the RMM. All AI-generated insights are compiled into a risk assessment dashboard, where inherent risk (IR), control risk (CR), and the resulting RMM are visualized across different areas. Audit action plans are then recommended, aligned with risk levels—low RMM areas may rely on automated controls, while high RMM areas may require detailed substantive testing. This workflow facilitates not only audit compliance but also enhanced precision, consistency, and efficiency.

The spectrum of inherent risk refers to the range of possible levels of inherent risk for a given assertion, account balance, class of transactions, or disclosure—depending upon both the likelihood as well as the magnitude of potential misstatement. The spectrum of inherent risk is a concept introduced in AU-C section 315, as amended by SAS 145, to help auditors understand that inherent risk is not limited to high, moderate, or low assessments, but rather exists on a continuous scale. Risks with both high likelihood and high magnitude fall toward the upper end of the spectrum.

Auditors use professional judgment to determine where on this spectrum an inherent risk falls, which, in turn, affects the nature, timing, and extent of planned audit procedures. The spectrum of inherent risk depicts how risks move along a continuum from low to high depending upon the assessed likelihood and magnitude of potential misstatement. For example, in estimating warranty obligations, if the likelihood of misstatement is moderate (being dependent upon management’s estimation process), and magnitude is high (large dollar amount), this risk may fall toward the higher end of the spectrum.

Inherent risk assessment. Inherent risk (IR) refers to the susceptibility of an assertion to a misstatement, assuming there are no related internal controls. The model assesses various IR factors as well as the spectrum of risk associated with operations. Such factors may be quantitative or qualitative and include complexity, subjectivity, change, uncertainty, and susceptibility to misstatements due to management bias or other fraud risk factors (see SAS 145, AS 2110, ISA 315). The following are examples of IR factors:

  • Complex transactions: When a company engages in complex transactions such as mergers, acquisitions, or the use of intricate financial instruments or bundled contracts, LLMs and AI tools analyze legal contracts and financial filings to identify these transactions. Anomaly detection models help identify atypical transactions, with the risk level set to high if the complexity increases the chances of misstatements due to transaction intricacies.
  • Revenue fluctuations: The GenAI tool analyzes historical revenue data and identifies fluctuations or dependencies. ML models forecast future revenue trends and associated risks, while GenAI reviews earnings calls and reports to identify volatility concerns. The analysis provides insights into whether the fluctuations signal a high risk of misstatements in the financials. For example, if a company’s revenue is tied to a few high-value contracts with recent declines in key revenue streams, the inherent risk level would be moderate or high.
  • Inventory valuation: AI tools and data analytics enhance an auditor’s ability to identify patterns of overvaluation [cost vs. net realizable value (NRV)], management bias (i.e., expected sales being overstated), and inventory anomalies that could materially misstate financial statements. For example, for a fashion retailer, inventory represents a high percentage of total assets but quickly becomes obsolete and/or discounted; AI might identify that product prices dropped 20% after year-end, increasing the risk that closing inventory is valued above NRV.
  • Impairment testing: In this judgment-heavy area, AI can detect overly optimistic projections of future cash flows, incorrect cost of capital assumptions, misallocation of assets to avoid recognizing impairment, or the disregard of triggering events. For example, an auditor using ML might find that management applied a 10% discount rate while industry peers use 14-16%. AI flags this as an anomaly, thus identifying a higher risk.
  • Fraud detection: AI can detect potential fraud in manually inserted journal entries generated by personnel working at corporate headquarters (top level adjustments), especially those that are recorded near period-end, which is often when management override of controls occurs. The AI tool can also scan legal databases and news articles to identify historical fraud cases, which are linked to the likelihood of material misstatements. The risk level is often assessed as high when a company faces ongoing litigation or regulatory fraud investigations.
  • Industry and regulatory risks: Industry reports and regulatory filings can be scanned to understand the company’s operating environment and regulatory pressures. ML risk-scoring models assign scores based on current trends in the regulatory landscape. For example, in the fintech sector, where new privacy laws are being introduced, the risk of noncompliance increases, leading to a high inherent risk assessment.
  • Management and employee turnover: Significant management turnover, especially in key financial roles, can signal an increased risk of reporting errors and potentially fraud. Analysis is performed on public data such as LinkedIn and news articles, using NLP tools to track turnover patterns. A moderate inherent risk assessment is associated with turnover in financial management roles, as it can lead to inconsistencies in financial reporting and internal control lapses.
  • Market risks: Sentiment analysis and predictive models assess external market risks. GenAI reviews market reports and news to gauge external market factors like supply chain disruptions or economic pressures, raising the risk level if these factors significantly impact the business’s financial health, often resulting in assessment of high inherent risk.
  • Related party transactions: AI models can review public filings to detect related party transactions, including those not disclosed by management, to assess their transparency and management’s forthrightness. While these transactions are typically disclosed, complex or poorly documented transactions raise high inherent risk due to potential undisclosed conflicts of interest and other related misstatements in financial reporting.
  • Warranty obligation estimates: AI, including ML, NLP, and predictive analytics, can help auditors evaluate the reasonableness of warranty obligation estimates by combining historical data, predictive analytics, text analysis, and benchmarking. Use of these tools does not replace the exercise of sound professional judgment, but they potentially provide stronger risk indicators and help auditors focus their procedures where misstatements are more likely to occur.

Control risk assessment. Control risk (CR) is the risk that a material misstatement will not be prevented, detected, or corrected on a timely basis by the effective operation of an entity’s internal controls. It arises when an entity’s internal controls are ineffective, bypassed, or overridden—allowing material misstatements to occur and go undetected. Traditionally, auditors obtain an understanding of internal control and assess control risk through the performance of walkthroughs, sampling, and other modes of testing. With AI, this process can become more data-driven, allowing auditors to identify weaknesses early and to focus testing on high-risk areas. The following are examples of AI-assisted control risk assessment:

  • Internal control policies: LLMs can be used to analyze internal control documentation and check for alignment with best practices. If a company has comprehensive and well-documented control policies and the auditor performs sufficient tests of operating effectiveness, control risk can be assessed as low. Weak, missing, or outdated policies increase the risk of misstatement.
  • Frequency of control evaluations: For companies with an internal audit function, AI can process internal audit records to assess the frequency and thoroughness of management’s internal control evaluations. If there are infrequent updates or reviews of controls, the control risk level can be assessed as high.
  • Segregation of duties: An auditor can use graph-based ML models to analyze the organizational chart and detect potential violations, such as when personnel both authorize payments and perform reconciliations. Poor segregation of duties increases the risk of fraud and errors, leading to high control risk assessments.
  • Control breakdown history: Historical data, including past incidents of fraud or control failures, can be analyzed using AI tools. Patterns of recurrent control breakdowns, especially in high-risk areas such as inventory valuation, imply the assessment of control risk should be high.
  • Internal audit function effectiveness: AI reviews internal audit reports, identifying deficiencies in the control framework. If the internal audit function is ineffective, especially in critical areas, the risk can be assessed as moderate.
  • Control design and operating deficiencies: AI tools can be used to review the design of internal controls and monitor their operating effectiveness. If controls are outdated or are frequently bypassed, such as in reconciliation processes, the control risk can be assessed as high.
  • Fraudulent manual overrides: AI can help detect manual overrides in financial statements, such as changes to system-generated invoices or adjustments to revenue recognition modules. Management overrides are a key control risk area under AU-C 315, AS 2110, and ISA 315.
  • Oversight by management and audit committee: GenAI can analyze meeting minutes and internal reports to evaluate the level of oversight provided by management or the audit committee. If oversight is limited or inconsistent, the control risk should be assessed as high.

Assessing RMM

Assessing where on the spectrum of inherent risk a particular risk falls is one of the most judgment-heavy aspects of auditing. Auditors must weigh both likelihood and magnitude of potential misstatements, often with incomplete or uncertain information. The risk assessment process helps auditors identify and evaluate the RMM at both: 1) the overall financial statement level, and 2) the relevant assertion level (for significant classes of transactions, account balances, and disclosures). Identified RMM at the overall financial statement level may also affect the auditor’s assessment of significant risks at the relevant assertion level.

The model assists in identifying relevant assertions, which are those audit assertions that have one or more RMMs associated with them, based on an analysis of the likelihood and magnitude of a potential misstatement (assertion-level risk mapping). Significant classes of transactions, account balances, and disclosures are those that have one or more relevant assertions associated with them.

An RMM exists when: 1) there is a reasonable possibility or an actual probability of a misstatement occurring (usually evidenced by a 10–100% estimated likelihood of occurrence), and 2) if it were to occur, there is a reasonable possibility of the misstatement being material to the financial statements. RMM is calculated by combining the results of both the inherent and control risks. Under AU-C 240 (SAS 145), AS 2110, and ISA 240, fraud risks are always assessed as significant risks. Furthermore, when control risk is assessed as high, RMM is always assessed at the same level as inherent risk.

Exhibit 3 sets forth examples of professional judgment in assessing RMM for selected assertions and areas. Consistent with AU-C 315, the AI agent supports the auditor’s responsibility to identify and assess RMM by integrating inherent risk factors, control considerations, and observed data anomalies into a structured RMM rating at the assertion level. In line with AU-C 240, the model also highlights fraud-sensitive areas—such as complex revenue arrangements or indicators of management bias—so that auditors can designate significant risks, exercise heightened professional skepticism, and design targeted procedures while retaining ultimate responsibility for the audit judgment.

EXHIBIT 3

Risk of Material Misstatements by AI Agent for Selected Assertions /Audit Areas*

 Assertion/Area; Relevant ASC Topics (US GAAP); Inherent Risk Factors; L (0–5); M (0–5); RMM**; Key AI Metrics Detected; Status vs Rules Revenue—bundled contracts (high-growth tech); ASC 606 (identifying performance obligations (POBs); transaction price; allocation; timing); Complexity, Subjectivity, Bias/Fraud; 4.6; 4.3; 0.85 (Very High); Complexity 0.72 (Viol.); Subjectivity 0.61 (Viol.); Drift PSI 0.28 (Viol.); Benford |Z|=2.1 (Viol.); Cut-off +48% (Viol.); Multiple breaches → Significant risk AR Allowance—stable utility (CECL); ASC 326 (pooled lifetime loss, Q-factors, back-testing); Subjectivity, Uncertainty; 1.8; 3.2; 0.53 (Moderate); Brier 0.09 (OK); PSI 0.05 (OK); DQS 0.97 (OK); All Acceptable Inventory—fashion retailer (LCNRV); ASC 330 (cost vs NRV; obsolescence; markdowns); Change, Uncertainty; 3.6; 3.9; 0.73 (High); PSI 0.31 (Viol.); Anomaly +1.8σ (OK); DQS 0.93 (Amber); Drift breach + DQS amber → elevate Goodwill impairment—conglomerate; ASC 350-20 (qualitative/quantitative; reporting units; FV); Subjectivity, Uncertainty; 4.4; 4.8; 0.90 (Very High); Uncertainty 28% (Viol.); Calibration Brier 0.19 (Viol.); Significant risk Tax contingencies—international; ASC 740 (recognition & measurement of UTPs; disclosures); Complexity, Uncertainty; 3.1; 4.2; 0.70 (High); Jurisdiction dispersion high (context); Groundedness 96% (OK); Acceptable (High due to M) Revenue (midmarket SaaS) clean period; ASC 606; Complexity, Bias/Fraud; 2.4; 2.9; 0.53 (Moderate); Complexity 0.45 (OK); Cutoff +12% (OK); Benford |Z|=1.2 (OK); Drift 0.08 (OK); All Acceptable Assertion/Area; Relevant ASC Topics (US GAAP); Inherent Risk Factors; L (0–5); M (0–5); RMM**; Key AI Metrics Detected; Status vs Rules Manual JEs—corporate HQ; Crosscutting (presentation/classification; error correction ASC 250); Bias/Fraud; 3.9; 3.7; 0.74 (High); Outlier JEs 3.4% (Viol.); Override indicators (Viol.); Fraud signals breached * These examples are illustrative and are intended to demonstrate how AI-generated indicators may support—but not replace—the auditor’s professional judgment when assessing RMM. This analysis integrates US GAAP Accounting Standards Codification (ASC) guidance with an AI-driven detection framework to evaluate financial reporting risk across key different areas, including credit losses (ASC 326), inventory valuation (ASC 330), goodwill impairment (ASC 350), tax contingencies (ASC 740), and revenue recognition (ASC 606). ** RMM represents the combined effect of inherent risk and control risk—the risk that a material misstatement exists before audit procedures are performed. The AI agent supports RMM evaluation by identifying pattern anomalies, subjectivity indicators, drift, and other risk signals that align with AU-C 315 and AU-C 240 requirements. Legend: Inherent Risk Factors The inherent risk drivers (not controls) presented here are: Complexity, Subjectivity (estimates/Judgment), Change (business/IT/policy), Uncertainty (outcome dispersion), Bias/Fraud susceptibility. L: Likelihood—How probable a misstatement is, after considering inherent factors but before control testing. Heuristics: 0=remote, 1=unlikely, 2=possible, 3=reasonably possible, 4=likely, 5=very likely. Raise L when you breach rules like high anomaly/override, heavy subjectivity, fast change, or data quality issues. M: Magnitude—If a misstatement occurs, how big could it be (relative to materiality, users’ needs, and qualitative significance)? Heuristics: 0=trivial, 1=de minimis, 2=small, 3=moderate, 4=large, 5=very large/systemic. Raise M for high-balance accounts, pervasive disclosures, or items that affect covenant/debt metrics even at small amounts. RMM Computed risk score using the spectrum formula: RMM = 1 – (1 – L/5) (1 – M/5) Bands: Low ≤0.30; Moderate 0.31–0.60; High 0.61–0.80; Very High >0.80 (treat as significant risk). Key AI Metrics Detected—The concrete signals the AI agent computed that justify L/M (with pass/fail vs thresholds). Note: these should be kept short and refer to the rule set. Examples: Complexity 0.72 (Violation >0.60); Subjectivity 0.61 (Violation >0.55); PSI 0.28 (Violation >0.25); Benford |Z|=2.1 (Violation >1.96); Cut-off +48% (Violation >40%). Brier 0.09 (OK ≤0.12); DQS 0.97 (OK ≥0.95). Status versus Rules One-line conclusion from the metrics: OK, Amber, or Violation (and, if applicable,—> Significant risk). Examples: Multiple breaches —> Significant risk. / All Acceptable (remain moderate)/ Drift breach + DQS amber—elevate to high.

Thus, Exhibit 3 summarizes selected assertions or audit areas, the inherent risk drivers involved, the resulting RMM category based on the thresholds above, and descriptions of what the AI identified. Auditors must interpret these results within the context of the audit and modify procedures accordingly. These examples are illustrative. AI tools should be calibrated to the specific audit environment, and auditors must update risk assessments when new information becomes available.

Many audit methodologies employ a risk rating matrix with five categories for both likelihood and impact. Each category is assigned a numeric value from 1 (rare or insignificant) to 5 (almost certain or severe). Combining these scores produces a risk rating between 1 and 25. For example, widely used risk management guidance classifies scores of 1-4 as low risk, 5-9 as moderate, 10-16 as high, 17-20 as very high and 21-25 as extreme. In practice, organizations adapt these ranges to fit their needs.

In the examples in Exhibit 3, which illustrates how AI-derived indicators are mapped to likelihood and magnitude, the combined risk scores are scaled to a 0-1 range by dividing them by 25 (since 25 is the maximum possible score). Accordingly, risks with scores up to approximately 0.30 (equivalent to scores up to 7 or 8 out of 25) are considered low; scores between 0.31 and 0.60 (moderate); scores from 0.61 to 0.80 (high); and scores above 0.80 (very high). These thresholds align with the categories described above and provide a quantitative basis for classifying risks. By referencing established risk management guidance, the thresholds gain credibility and consistency.

Once the AI tool is used to identify and assess the risks, auditors can design and tailor audit procedures to respond appropriately—focusing on gathering higher-quality evidence and performing more extensive testing on high-risk areas. High RMM areas demand extensive substantive testing, while lower RMM areas may be tested less extensively using substantive analytical procedures. In accordance with the key principles in AU-C 315, AS 2301, and ISA 330, the higher the assessed risk of material misstatement, the more persuasive and extensive the audit evidence must be; the lower the assessed risk of material misstatement, the more limited or analytical the auditor’s procedures can be. Thus, risk assessment guides the determination of appropriate audit procedures (the nature, timing, and extent of “further audit procedures”) that best address each risk.

By leveraging AI, the audit process becomes more data-driven and customized, improving the efficiency and effectiveness of risk assessment, fraud detection, and overall audit strategy.

Getting Started with AI

Readiness assessment. First, an audit firm should evaluate its data availability, IT infrastructure, staff competencies, governance policies, and ethical safeguards related to data privacy and algorithm transparency. This assessment helps determine whether existing processes and controls can support the responsible use of AI tools.

Pilot engagements. Next, a firm should determine where AI can deliver clear value with manageable risk—such as large-volume transaction testing, journal entry analysis, or anomaly detection in revenue or expense accounts. Selecting engagements with well-structured data and experienced engagement teams increases the likelihood of successful implementation.

Success metrics. Finally, the firms should evaluate the pilot program, including improvements in audit efficiency, enhanced risk identification, audit evidence quality, and compliance with professional standards. Establishing these metrics allows firms to assess whether AI tools meaningfully support auditor judgment and whether broader deployment is justified, while maintaining appropriate oversight and professional skepticism.

Ethical and Professional Considerations

According to a KPMG survey (“AI in Financial Reporting and Audit: Navigating the New Era,” 2024, https://kpmg.com/xx/en/our-insights/ai-and-technology/ai-in-financial-reporting-and-audit.html), although GenAI is a relative newcomer, companies are hurrying to implement it in their financial reporting processes. The survey reveals that nearly 72% of companies surveyed are piloting or using AI in financial reporting and this number may increase. In addition, 64% of companies surveyed expect auditors to have a role in evaluating their use of AI in financial reporting, providing assurance and attestation over their AI controls.

AI holds significant potential to improve the efficiency and accuracy of financial statement audits, especially in the audit planning stage. To implement AI responsibly, however, auditors must understand AI’s limitations and focus on complementing, not replacing, auditors’ expertise (J. Lanz, “Artificial Intelligence: Evolving Risk Guidance and Considerations,” The CPA Journal, September/October 2023; J. Mökander, J. Schuett, H. R. Kirk, and L. Floridi, “Auditing Large Language Models: A Three-Layered Approach,” Feb. 16, 2023, https://ssrn.com/abstract=4361607; CAQ 2024; K. Kasztelnik, and E. Jermakowicz, “Financial Statement Fraud Detection in the Digital Age,” The CPA Journal, vol. 94, no. 3/4, 2025, pp.32–39). Thus, an AI-enabled audit introduces several important ethical considerations that auditors must actively manage, including:

  • Client consent is critical: Auditors should clearly communicate how AI tools will be used, what data will be analyzed, and obtain informed consent—especially when tools rely on sensitive or nontraditional data sources.
  • Data privacy and confidentiality remain paramount: Auditors must ensure compliance with professional standards and regulations when handling client data, including secure storage, restricted access, and safeguards against unauthorized use or breaches.
  • Explainability and transparency of AI outputs pose a challenge: Many AI models operate as “black boxes,” yet auditing standards require auditors to understand and justify their risk assessments. Auditors must therefore ensure that AI-generated insights can be reasonably interpreted, validated, and documented, avoiding overreliance on opaque outputs.
  • Model bias: AI models rely heavily on the quality of the training data. If the data is biased, out of date, or otherwise incomplete, the AI’s analysis may be flawed, leading to inaccurate conclusions. Failure to comprehend and control the models used would constitute an unacceptable deficiency in the audit process.
  • Governance: AI solutions may not be identified and managed appropriately and consistently across the company. Adopting a catalog-and-score approach—like Deloitte’s 60+ model review—however, clarifies ownership, risks, and controls for every AI component used in audit planning (Deloitte 2025).
  • The use of AI in audits is still evolving: Regulatory standards might not fully address the implications of AI-driven audits. Noncompliance with evolving regulations or improper use of AI tools can lead to legal and financial penalties.
  • Continuing education is essential: Certain knowledge and skills are required to develop, deploy, and monitor AI technologies, as well as adequate employee training on how to use AI-enabled tools effectively.
  • An excessive dependence on AI tools could lead auditors to overlook critical issues: AI can’t replace human judgment and professional skepticism. AI may struggle with nuanced scenarios that require contextual understanding or ethical considerations.
  • Auditors retain full professional responsibility for their judgments, even when using AI: If AI tools fail, produce biased results, or generate misleading conclusions, auditors are ethically and professionally obligated to exercise skepticism, perform additional procedures, and not defer judgment to technology. In essence, AI should augment—not replace—auditor judgment, with accountability remaining firmly with the auditor.

The integration of AI into audit risk assessment requires a systematic framework that balances technology with human expertise. By leveraging AI in data acquisition, risk identification, analytical modeling, and auditor judgment, auditors can enhance the reliability and timeliness of risk assessment and collect sufficient appropriate evidence supporting auditors’ professional skepticism throughout the audit.

Moreover, by continuously flagging outliers and correlations that might not be immediately apparent to humans, AI can reinforce professional skepticism, encouraging auditors to critically evaluate audit evidence rather than inappropriately relying too heavily on management representations. Auditors must still exercise judgment to interpret AI-generated insights, however, and ensure conclusions are grounded in professional expertise and proper application of relevant auditing standards.

Definitions of Terms Used

 AI Term; Definition Agentic AI; AI systems designed to accomplish specific goals with limited supervision, operating autonomously and adapting to tasks. AI Agent; A system that autonomously completes tasks and makes decisions using available tools. AWS SageMaker; A managed cloud service for building, training, and deploying machine-learning models. Apache Airflow; An open-source platform for scheduling and monitoring workflows. Artificial Intelligence (AI); Any technology that enables machines to mimic human intelligence. BART; A sequence-to-sequence model combining BERT and GPT techniques. BERT; A model that reads text bidirectionally to understand context. Chatbot; A program that simulates human conversation. Data Analytics; The process of analyzing data to find patterns and insights. DBSCAN; ML algorithm that identifies distinct groups (clusters) within data based on density of data points. Domain-Adaptive Pre-Training (DAPT); A technique in NLP where a pre-trained language model is further trained on domain-specific data. Generative AI; AI that creates new content such as text, images, or code. GPT; A generative pre-trained transformer–based model that generates human-like text. Isolation Forest; An algorithm that detects anomalies by isolating data points. Large Language Model (LLM); A model trained on large text datasets to understand language and interpret. LIME; A method to explain predictions of machine learning models. Machine Learning (ML); Algorithms that learn patterns from data. MLOps; Practices for managing machine learning lifecycle. Natural Language Processing (NLP); AI that processes and understands human language. Predictive Analytics; Using data to forecast future outcomes. PyCaret; A low-code Python library for machine learning workflows. SHAP; A method to explain model predictions using feature contributions. Task-Adaptive PreTraining (TAPT); Training a model on task-specific data. TensorFlow; An open-source machine learning library.

Future Directions for AI-Enabled Auditing

AI in auditing is expected to evolve from primarily decision support tools toward increasingly autonomous agents capable of executing defined audit tasks with minimal human intervention. While current AI applications largely assist auditors by identifying anomalies, prioritizing risks, or analyzing large datasets, future systems may independently perform continuous risk assessments, initiate audit procedures, and adapt testing strategies in real time. This evolution raises important questions regarding governance, accountability, and the auditor’s obligation to maintain professional judgment, as autonomy increases without eliminating the need for human oversight.

The growing sophistication of AI also enables the broader adoption of continuous auditing, shifting assurance from periodic, retrospective evaluations to near real-time monitoring of transactions and controls. AI-driven continuous auditing systems can ingest high-volume data streams, flag exceptions as they occur, and dynamically update risk assessments throughout the audit period. This model enhances the timeliness and relevance of audit assurance, but it requires robust data integrity, well-designed exception thresholds, and clear protocols for auditor intervention when anomalies are detected.

Emerging technologies such as blockchain may heighten the impact of AI on audit practice. Blockchain’s promise of immutable transaction records can serve as a reliable data foundation for AI analytics, reducing data reliability concerns and enabling automated verification of transaction completeness and occurrence. When combined, blockchain and AI have the potential to reshape audits from sample-based testing toward population-level assurance, while redefining audit evidence, control evaluation, and the auditor’s role in system design and oversight. Ultimately, the future of auditing will not be defined by artificial intelligence replacing auditors, but by auditors who effectively integrate AI with professional skepticism, ethical judgment, and deep knowledge of auditing standards.

Karina Kasztelnik PhD, MBA, CPA, AI Research Fellow, Distinguished AI Scientist, is a professor of accounting at the University of Maryland Global Campus.
Eva K. Jermakowicz PhD, CPA, is a professor of accounting at Tennessee State University. The authors would like to express their sincere gratitude to Barry Jay Epstein, PhD, CPA (inactive), and Ralph Nach, CPA, for their insightful comments and valuable recommendations, which helped improve the quality of this article.