An AI agent is software that is given a goal, works out the steps, and carries them out by using other systems: opening files, running queries, filling in a working paper. A chat assistant answers one prompt and stops. In internal audit, an agent can take over collecting and matching documents, running tests that were defined in advance, and drafting the working paper. It should not decide scope, judge whether evidence is sufficient, rate a finding or close an issue.
This guide is for heads of internal audit, internal auditors and CA firms in India who are being shown "agentic" audit tools and need to decide what to allow. It does not repeat the stage-by-stage view in the AI in internal audit 2026 guide.
Start here if you want the working file first:
| Need | Use this |
|---|---|
| A written rule on which AI uses the audit team allows, restricts or prohibits | Internal Audit AI Strategy Template |
| A working paper for reviewing how AI is governed, with inventory and test sheets | AI Governance Internal Audit Workpaper |
| The audit programme for agents the company itself is deploying | How to audit AI agents |
| This month's launches and surveys | AI in internal audit: October 2026 update |
What is an AI agent, in plain words
Think of three levels of help.
A chat assistant is like asking a well-read colleague a question across the desk. You ask, it answers, and the conversation ends. If the answer needs a file opened or a number looked up, you do that.
An agent is like handing the same colleague a task and a set of keys. "Check that every vendor payment above ₹5 lakh in the second quarter has an approved purchase order and a goods receipt, and write up what you find." The agent breaks the task into steps, logs into the systems it has been given access to, pulls the records, compares them, and comes back with a working paper. Nobody typed each step.
Three things make it an agent rather than a chat assistant:
- It plans. It turns a goal into a sequence of steps and adjusts when a step fails.
- It uses tools. It can read files, query a database, call another system or write to a document, with whatever access it has been given.
- It carries on without a prompt for each step. It may work for minutes or hours before a person sees anything.
The third point is where the audit risk sits. A chat assistant's mistake is on the screen in front of you. An agent's mistake can sit at step 7 of 40, and you see only the finished working paper.
| Chat assistant | AI agent | Defined tests over every transaction | |
|---|---|---|---|
| What you give it | A question or a file | A goal and access to systems | Written test logic and a full data set |
| What it does | Writes one response | Plans and carries out many steps | Applies the same logic to every record |
| Who decides the steps | You | The agent | Whoever wrote the test |
| Same input, same result? | Not reliably | Not reliably, unless the steps are fixed | Yes |
| Main risk | Wrong or invented content | A wrong step nobody saw; access wider than the task | A badly defined test or incomplete data |
An agent is strongest when it is used to run the third column, not to replace it: the agent fetches the data and calls a fixed, written test, and the test, not the agent, decides what counts as an exception. For why that matters for evidence, see deterministic vs probabilistic AI in audit.
For a first introduction to agents in statutory audit, see understanding AI agents for audit and AI agents for audit: what they actually automate. The rest of this piece is about internal audit.
What an agent can take over in an internal audit
Good candidates share three features: the task is mechanical, the rule is written down before the work starts, and a reviewer can check the result against source records.
| Work | What the agent does | What the auditor checks |
|---|---|---|
| Gathering documents | Pulls invoices, purchase orders, goods receipts, approvals and bank advice for each item selected | That the documents came from the system of record and belong to the item |
| Matching | Compares amount, date, vendor, quantity and approver across the documents | The mismatches, and a few of the matches |
| Running predefined tests across a population | Applies the written test to every record and lists the exceptions | That the population is complete and the test is the one that was approved |
| Chasing evidence | Sends requests, tracks what has arrived, flags what is overdue | Nothing is marked "received" that is not on file |
| Drafting the working paper | Records the objective, the procedure, the items tested, the results and the references | Every statement against the evidence, before signing as reviewer |
| First-pass follow-up | Compares management's closure evidence with the original recommendation and lists gaps | Whether the closure is real |
What an agent should not decide
These are judgments, and somebody has to answer for them.
- Scope. Under Rule 13 of the Companies (Accounts) Rules, 2014, the audit committee or the Board, in consultation with the internal auditor, formulates the scope, functioning, periodicity and methodology of the internal audit. An agent that "identifies risks and proposes audit areas" is producing a draft for that discussion.
- Whether evidence is sufficient. An agent can report that 212 of 240 items had all three documents. Whether that supports a conclusion about the control is the auditor's call.
- Whether an explanation is credible. "The goods receipt was posted late because the stores system was down" needs someone to ask, check and decide.
- Rating a finding. High, medium or low depends on the company's risk appetite and context. An agent's suggested rating is an input.
- Cause. Agents find what happened. Why it happened usually comes from people.
- Closing an issue. An agent should never mark an observation closed. See the closure evidence and retesting checklist.
- Anything that changes the company's records. An audit agent reads. If it can post, approve or amend, internal audit has become part of the process it is auditing.
One test, with and without an agent: an illustrative example
The figures are illustrative. The test: every vendor payment above ₹5 lakh in the July–September quarter must have an approved purchase order and a goods receipt dated before the payment.
Without an agent. The team draws a sample of 40 from 1,860 payments, requests documents, and spends most of a week matching them.
With an agent calling a fixed test. The auditor writes the test, approves it, and gives the agent read-only access to the payment register, the purchase order list and the goods receipt list. The agent's log shows:
| Step | What the agent did | Result |
|---|---|---|
| 1 | Extracted payments above ₹5 lakh for the quarter | 1,860 records, total ₹412.6 crore |
| 2 | Compared record count and total to the payment register control report | Agreed |
| 3 | Ran the approved test | 1,794 passed, 66 exceptions |
| 4 | Fetched documents for the 66 | 61 complete sets, 5 missing goods receipts |
| 5 | Drafted the working paper | Draft for review |
What the auditor then did. Re-performed step 2 independently. Opened all 66 exceptions: 48 were advance payments permitted by contract, 13 were goods receipts posted late, and 5 had no goods receipt at all, for ₹38.4 lakh. Asked the stores and accounts teams why. Opened 15 of the 1,794 passes to confirm the test was not passing bad items. Decided the rating.
The agent saved the matching time and widened coverage from 40 items to 1,860. The steps that made the result evidence were the fixed test, the reconciliation to the register, and the auditor's examination of the exceptions.
Four control questions before an agent goes near audit evidence
Ask these of any agentic tool, whether bought or built in-house. Ask for the answer on paper.
| Question | What a good answer includes | Warning sign |
|---|---|---|
| 1. Who authorised it? | A named approver in the company (and in the client, if you are a CA firm), the purposes approved, and the data classes approved | "IT set it up" or "the vendor enabled it" |
| 2. What can it access? | Its own named account, read-only, limited to the systems and periods in scope; no shared passwords; access removed when the engagement ends | It uses an employee's login, or has write access "for convenience" |
| 3. Are its steps logged and repeatable? | A step-by-step log kept with the working papers; the test logic fixed and versioned; a rerun on the same data gives the same exceptions | A summary instead of a log; results that change between runs |
| 4. How does a human review the output? | A reviewer who opens source records for all exceptions and a selection of passes, signs the working paper, and records what was changed | Review means reading the agent's summary |
Two further points for Indian teams.
Data. An agent that reads payroll, customer or vendor bank records is processing personal data. The Digital Personal Data Protection Act, 2023 leaves the duties with the party that decides how the data is used, even when a vendor's tool does the processing. Confirm where the data goes and what the tool retains. See DPDP for CA firms and the AI vendor due diligence checklist.
Documentation. ICAI's Standards on Internal Audit, in the set compiled in the October 2022 compendium, ask for sufficient and appropriate evidence (SIA 320), for documentation from which a peer could reach the same conclusion (SIA 330), and for review of working papers (SIA 350). An agent-drafted working paper meets none of these by itself. The step log, the source records and the reviewer's sign-off do. ICAI lists a newer compendium (as on February 2026) as applicable from 1 April 2026, so check the current text before citing a number.
How the September 2026 announcements fit this picture
Several vendors announced agentic internal audit products in September 2026. The descriptions below are from their own releases; we have not tested the products and do not rank them.
| Announced | Company | What the release says the agents do | What it says about review and trail |
|---|---|---|---|
| 29 Sep | UiPath with BDO USA | Solution accelerators for IT general and application control testing: access, change management, IT operations, test execution, evidence and reporting | "Agent-driven execution along with professional review procedures" |
| 22 Sep | DataSnipper (Alwin) | Runs "complete, multi-step audit and finance procedures end-to-end" and returns working papers for review | "Every step is logged, and every conclusion can be traced back to its origin" |
| 15 Sep | Diligent (Diligent One) | An Internal Audit Agent that identifies risks, maps them to audit objectives, links controls, and supports evidence collection, testing and findings | Automating work "without replacing human judgement" |
| 15 Sep | Workiva | Evidence, attribute and testing agents that replace manual evidence collection, sample selection, attribute testing and documentation | "Full traceability at every step" |
| 29 Sep | Fieldguide | Agents that support execution while practitioners direct the work | "Every agent action is reviewable" |
Set against the two lists above, most of what is described falls in the "can take over" column: evidence collection, matching, test execution, documentation. Two descriptions touch the judgment column: identifying risks and mapping them to audit objectives, and developing findings. Treat both as drafts for the auditor and the audit committee.
Every release claims a trail and human review. That makes questions 3 and 4 easy to put to a vendor: show the step log from a real run, and show what the reviewer sees. Details and links are in the October 2026 update.
Tools of the other kind, which run fixed tests across every transaction without an agent choosing the steps, include CORAA's internal audit product.
Agentic AI in internal audit FAQ
What is an AI agent?
An AI agent is software that takes a goal, plans the steps, and carries them out using other systems, without a person prompting each step. A chat assistant, by contrast, answers one prompt at a time and takes no action outside the conversation.
What is agentic AI in internal audit in 2026?
Agentic AI in internal audit means AI agents carrying out multi-step audit tasks, such as collecting evidence, matching documents, running defined tests across a population and drafting working papers. In 2026 several audit software vendors announced such products, each describing a professional reviewing the agent's output.
What is the difference between an AI agent and ChatGPT?
A chat assistant such as ChatGPT responds to a prompt with text; an agent acts on systems to complete a task. Chat products now include agent features, so the useful question is not the product name but whether the software is taking actions with access to your systems.
Can AI agents do an internal audit on their own?
No. An agent can execute procedures, but the scope is settled by the audit committee or Board with the internal auditor, and the internal auditor remains responsible for the evidence, the ratings and the conclusions.
Is the output of an AI agent audit evidence?
The agent's summary is not evidence. The source records it retrieved, the results of a fixed test that can be re-run, and the auditor's own examination of exceptions can be, when documented so that a reviewer could reach the same conclusion.
Related CORAA resources
- AI in internal audit 2026: India guide
- AI in internal audit: October 2026 update
- How to audit AI agents: an internal audit programme
- Deterministic vs probabilistic AI in audit
- AI Governance Internal Audit Workpaper
- AI agents for audit: what they actually automate
Sources
Pages read on 1 October 2026.
- UiPath, "UiPath and BDO Expand Partnership to Build Agentic Solution Accelerators for Continuous Monitoring and Testing", 29 September 2026 — https://www.uipath.com/newsroom/uipath-expands-partnership-with-bdo
- DataSnipper (PR Newswire), "DataSnipper Launches Alwin for End-to-End Agentic Automation", 22 September 2026 — https://www.prnewswire.com/news-releases/datasnipper-launches-alwin-for-end-to-end-agentic-automation-302886146.html
- Diligent, "Diligent Unveils New Agentic Capabilities in Diligent One to Power the Future of Governance, Risk and Compliance", 15 September 2026 — https://www.diligent.com/company/newsroom/diligent-unveils-new-agentic-capabilities-in-diligent-one
- Workiva (press release as carried by Yahoo Finance), "Workiva Advances Regulatory Work with AI Innovation", 15 September 2026 — https://finance.yahoo.com/technology/ai/articles/workiva-advances-regulatory-ai-innovation-150000292.html
- Fieldguide, "Fieldguide Reaches Agreement with CPA Canada to Embed Trusted Canadian Engagement Forms within Industry-Leading Agentic AI", 29 September 2026 — https://www.fieldguide.com/blog/cpa-canada-fieldguide-partnership
- ICAI Internal Audit Standards Board, "Compendium of Standards on Internal Audit" — https://internalaudit.icai.org/compendium-of-standard/
- Companies Act, 2013, Section 138, and Companies (Accounts) Rules, 2014, Rule 13 — https://www.mca.gov.in/content/mca/global/en/acts-rules/companies-act/companies-act-2013.html