AI in internal audit does two useful things in 2026. A general chat assistant drafts, summarises and structures the paperwork of an audit, and a testing system runs defined checks over every transaction and shows the entries behind each result. Neither one takes over the internal auditor's responsibility for the evidence and the conclusion.
This guide walks through an internal audit from the annual plan to follow-up and says, for each stage, what AI does well, what it does badly and what the auditor must still do. It is written for heads of internal audit, internal auditors inside companies, and CA firms that carry out internal audit engagements in India.
If you want the working files and the tool-specific guides first, start here:
| Need | Use this |
|---|---|
| Copy-ready prompts for a chat assistant, grouped by audit stage | ChatGPT for internal audit: prompts, uses and limits |
| A project set up for one engagement, with the scope, RCM and policies loaded | Claude for internal audit: Projects, prompts and workflow |
| What has changed for the function this year, beyond AI | Internal audit in 2026: what has changed |
| A written policy on which AI uses are allowed, restricted or prohibited | Internal Audit AI Strategy Template |
| The RCM, sampling plan and observation report as Excel files | RCM Builder, Sampling Plan Generator, Observation Report Generator |
The two kinds of AI, and why the difference matters for evidence
Most confusion about AI in internal audit comes from using one word for two different things.
A general chat assistant. ChatGPT, Claude, Microsoft Copilot in Excel and Gemini in Google Workspace belong here. You give it text or a file and an instruction, and it writes a response. It is good at language: turning a process narrative into a draft risk and control matrix, turning rough notes into a structured observation, summarising a forty-page policy. Ask the same question twice and the wording, and sometimes the substance, will differ. It can state a section number or a threshold that does not exist, in the same confident tone as one that does.
A system that runs defined tests over every transaction. Here the test is written down before it runs: for example, "same vendor, same amount, invoice numbers that match once prefixes and spaces are removed, within 90 days". The system applies that test to the full population from the ERP or Tally export, and lists every entry that met it. Run it again on the same data and you get the same list. A reviewer can open any result and see the vouchers behind it.
| Chat assistant | Defined tests over every transaction | |
|---|---|---|
| What it produces | A draft, a summary, a list of questions | A list of exceptions, each traceable to entries |
| Same input, same output? | Not reliably | Yes |
| Can a reviewer re-perform it? | Only by redoing the work | Yes, by rerunning the test |
| Typical place in the audit | Planning, drafting, reporting | Testing and monitoring |
| What the auditor adds | Checks every fact, owns the wording | Checks data completeness, investigates each exception, finds the cause |
| Is the output audit evidence? | No. It is a drafting aid | The exception list, tied to source entries, can be |
The practical rule follows from the last row. What a chat assistant writes is never evidence that something happened in the company. Evidence comes from the company's records and from procedures the auditor performed. A defined test over the full population is a procedure, provided the auditor can show what the test was, what data it ran on and what was done about each result.
A chat assistant with a data-analysis feature can run a calculation over a file you upload. That still falls short of a controlled test: the logic is composed on the spot, nobody has checked that the file is complete, and you are rarely permitted to upload the ledger at all. For the background, see deterministic vs probabilistic AI in audit and sampling vs 100% testing.
AI in internal audit, stage by stage
1. Annual plan and risk assessment
What works. Summarising last year's reports and open action items into themes. Turning a list of entities, locations and processes into a first-draft audit universe. Suggesting risks for an industry so that the team's own list is not missing an obvious one.
What does not. Ranking the risks. A chat assistant has no knowledge of this company's incidents, people, systems or pressure points, and it will produce a tidy ranking anyway.
What the auditor must still do. Carry out the risk assessment independently, record the basis for each score, and take the plan to the audit committee or Board for approval. Use the Annual Plan Generator and Risk Scorer to keep the scoring on file.
2. Scoping and the risk and control matrix
What works. Drafting an RCM from a process narrative or a policy: risks, the controls the document describes, control type, frequency and a proposed test step. Spotting where the narrative describes an activity but no control.
What does not. A generic RCM presented as this company's RCM. Controls the assistant assumed because "companies usually have them" are the most dangerous lines in the file.
What the auditor must still do. Confirm every control with the process owner and through a walkthrough. Mark missing controls as design gaps to be validated, and get the scope agreed in writing. The RCM Builder and Scope of Work Generator hold the result.
3. Walkthroughs
What works. Preparing question lists by control. Converting your own typed notes into a process narrative and a list of open points. Drafting the walkthrough memo.
What does not. Treating the narrative as fact. The assistant smooths gaps: if your notes do not say who approves, it may write that "the manager approves".
What the auditor must still do. Trace one transaction end to end, look at the screens and documents, and get the process owner to confirm the narrative. The Walkthrough Memo Generator gives the format.
4. Data requests
What works. Drafting the request list from the approved scope, in the vocabulary of the system in use: Day Book, ledger vouchers and bill-wise outstandings for Tally; the relevant tables and fields for SAP.
What does not. Field and table names from memory. Assistants mix up ECC and S/4HANA structures and invent field names that look right.
What the auditor must still do. Check each request against the system, and reconcile what was received to the books (record counts and control totals) before any test. See the Data Request List, the SAP data request tables and the guide to SAP tables by audit cycle.
5. Testing
What works. For testing, the second kind of AI matters more than the first. Defined tests over the full population find duplicates, breaks in sequence, approvals above limit, payments after a bank-detail change and entries posted on holidays, with the entries listed. A chat assistant helps around the edges: writing the test step, writing a spreadsheet formula, grouping similar narrations.
What does not. Asking a chat assistant "are there any exceptions in this data?" It may answer about rows it never read, and it cannot tell you which rows it skipped.
What the auditor must still do. Define the test and the population, confirm completeness, examine each exception against documents, and separate real exceptions from explainable ones. Many controls leave no data trail (a reconciliation reviewed, an override by a senior person), and those still need inspection and inquiry. Where testing is by sample, keep the sampling rationale on file with the Sampling Plan Generator; for a ready population test, see the Duplicate Payment Test Kit.
6. Drafting observations
What works. Turning verified facts into the five-part form: condition, criteria, cause, effect, recommendation. Tightening language, removing blame, making the recommendation specific enough to act on.
What does not. Cause and criteria. An assistant will supply a plausible cause ("lack of training") and a plausible criterion (a policy clause or a section number) that nobody verified.
What the auditor must still do. Supply the criterion from the actual policy, contract or law, establish the cause by asking and checking, decide the rating, and share the draft with the auditee before the report is final. The Observation Report Generator and the guide to the internal audit report format cover the structure.
7. Reporting to the audit committee
What works. Condensing a long report into a two-page summary. Rewriting technical findings in plain words. Checking that every observation in the summary has a rating, an owner and a date.
What does not. Letting the summary change the meaning. Summaries drop qualifiers ("in two of the fifteen locations tested") and soften or sharpen findings.
What the auditor must still do. Read the summary against the full report line by line, and state plainly what was covered and what was not. The audit committee reporting pack sets out what the committee should receive.
8. Follow-up
What works. Summarising the action taken report by age, owner and theme. Drafting reminders. Comparing a management response with the original recommendation to see whether it actually answers it.
What does not. Closing an item because the response reads well.
What the auditor must still do. Validate closure independently, with the depth of checking matched to the risk of the item, and escalate delays. Keep it in the ATR Tracker and use the closure evidence and retesting checklist.
One finding, two kinds of AI: an illustrative example
The figures here are illustrative. An internal auditor reviewing procure-to-pay has 18,400 vendor invoices for the year.
- With a chat assistant only. The auditor asks for a duplicate-payment test step and gets a sensible one: match on vendor, amount and invoice number, then widen to near-matches. The assistant has tested nothing. If the auditor pastes in 200 rows and asks for duplicates, the answer covers 200 rows at best, and has to be re-performed before it can be relied on.
- With a defined test on the full population. The test runs across all 18,400 invoices and lists 31 pairs. The auditor examines the 31: 24 are genuine repeat bills for monthly services, 7 are the same invoice entered twice, and 4 of those 7 were paid twice, for ₹6.80 lakh in total.
- What only the auditor did. Confirmed that the 18,400 invoices tie to the purchase register. Pulled the documents for the 31 pairs. Found the cause: the system's duplicate check compares invoice numbers exactly, so "INV/2231" and "2231" pass as different. Drafted the observation, and at that point a chat assistant is useful again, for wording.
The mechanics of the test are in duplicate payments: how they happen and the tests that catch them.
What the law and the standards leave unchanged
The scope belongs to the Board or audit committee. Section 138 of the Companies Act, 2013 requires prescribed classes of companies to appoint an internal auditor to audit the functions and activities of the company. Under Rule 13 of the Companies (Accounts) Rules, 2014, the audit committee or the Board, in consultation with the internal auditor, formulates the scope, functioning, periodicity and methodology of the internal audit. A tool does not widen or narrow that scope. If AI lets you cover every transaction in an area where the approved plan assumed a sample, that is a change in methodology worth reporting to the people who approved the plan. The applicability checker covers which companies fall under Section 138.
The internal auditor is responsible for evidence and conclusions. ICAI's Standards on Internal Audit, in the set compiled in the October 2022 compendium, ask for evidence that is sufficient and appropriate (SIA 320, Internal Audit Evidence) and for documentation that records the purpose of each procedure, the source of evidence, the outcome, and who performed and who reviewed it (SIA 330, Internal Audit Documentation). The test in SIA 330 is that a peer could reach the same conclusion from the file. A paragraph produced by a chat assistant does not meet that test on its own; the source documents and the auditor's own check do.
Review still applies. SIA 350 (Review and Supervision of Audit Assignments) expects working papers to be reviewed at least one level up. AI-assisted drafts are working papers like any other.
The draft goes to the auditee first. SIA 370 (Reporting Results) expects a written draft to be shared with the auditee before a final report is issued. It does not prescribe a report format. The five-part observation and High/Medium/Low ratings are convention.
A note on which standards. ICAI's Internal Audit Standards Board issued a revised, renumbered set during 2025-26, and its list includes a standard titled "Use of Tools". ICAI lists that set, in its February 2026 compendium, as applicable from 1 April 2026, so it is the current one. We have not verified its text, and ICAI's compendium page does not say whether the standards are mandatory or recommendatory. Before you cite a number or write "mandatory" in a report or engagement letter, check the ICAI Internal Audit Standards Board compendium. The fuller picture is in internal audit in 2026: what has changed.
Data and confidentiality
Confidentiality is one of ICAI's basic principles of internal audit: information is handled on a need-to-know basis and is not disclosed to third parties without approval, or a legal or professional duty to do so. A consumer AI tool is a third party.
Three rules cover most situations.
- Do not paste company, customer, vendor or employee data into a consumer AI tool without authority. Authority means the company's written approval (and, for a CA firm, the engagement terms) for that tool and that class of data.
- Check your plan's data-use and retention settings before any work data goes in. Do not assume what a plan does; read the settings and keep a note of what you found.
- Strip or mask personal data. The Digital Personal Data Protection Act, 2023 places duties on whoever decides how personal data is used, and those duties stay with that party when a tool vendor processes the data. Payroll files, customer lists and vendor bank details are personal data. See DPDP for CA firms and the decision guide on uploading client ledgers to AI tools.
Most of the useful drafting work needs no real data at all. An RCM can be drafted from a process description with names removed. An observation can be worded from facts with the vendor called "Vendor A".
A 90-day starting plan
Days 1 to 30: get control of what is already happening.
- List the AI tools the team already uses, for what, and with what data.
- Write a one-page rule: allowed uses, prohibited uses, data that never goes in, and who reviews AI-assisted work. The AI strategy template is a starting point; the reasoning is in the internal audit AI strategy guide.
- Tell the audit committee what the rule is.
Days 31 to 60: use a chat assistant on one live engagement, for drafting only.
- Draft the RCM, the walkthrough questions and the observations with it, using masked inputs.
- Record in the working paper where AI assisted and what was verified.
- Keep a short log of errors caught: wrong thresholds, invented references, controls that did not exist.
Days 61 to 90: run defined tests on the full population in one process.
- Pick a process with clean data, usually vendor payments or journal entries.
- Write three to five tests down before running them. The monitoring rules library has candidates.
- Reconcile the data, run the tests, examine every exception, and report coverage honestly: what was tested in full, what was sampled, what was not tested.
- Decide with the audit committee whether the method goes into next year's plan. Platforms such as CORAA's internal audit product run this kind of testing; so, with more effort, does a carefully built spreadsheet.
AI in internal audit FAQ
How is AI used in internal audit in 2026?
AI is used in two ways in 2026: chat assistants draft and summarise audit documents such as RCMs, walkthrough memos, observations and committee summaries, and testing systems run defined checks across every transaction and list the exceptions. The internal auditor still decides scope with the committee, verifies facts, investigates exceptions and forms the conclusions.
Can AI replace internal auditors?
No. AI cannot hold a walkthrough, judge whether an explanation is credible, establish why a control failed or take responsibility for a conclusion. It removes drafting time and makes full-population testing practical, which leaves the auditor more time for design, cause and the areas with no data trail.
Is ChatGPT output acceptable as internal audit evidence?
No. Output from a chat assistant is a draft, not evidence. Evidence comes from the company's records and the procedures the auditor performed, documented so that a reviewer could reach the same conclusion.
Does the audit committee need to approve the use of AI in internal audit?
There is no approval requirement specific to AI that we can point to in the Companies Act. But Rule 13 gives the audit committee or Board the job of settling the methodology of internal audit, so a material change in method, such as moving from sampling to full-population testing or allowing company data into an AI tool, should be put to them.
Is it safe to upload company data to an AI tool for internal audit?
Only with authority and after checking the tool's data-use and retention settings. Personal data of employees, customers and vendors should not go into a consumer AI tool. Most drafting uses work with masked or described data instead.
Related CORAA resources
- ChatGPT for internal audit: prompts, uses and limits
- Claude for internal audit: Projects, prompts and workflow
- Internal audit in 2026: what has changed
- Internal audit AI strategy: from experiments to governed workflows
- AI hallucinations in audit: how to detect and mitigate them
- AI Governance Internal Audit Workpaper
Sources
- Companies Act, 2013 — Section 138, Ministry of Corporate Affairs
- Companies (Accounts) Rules, 2014 — Rule 13, on the classes of companies required to appoint an internal auditor and on scope, functioning, periodicity and methodology
- ICAI Internal Audit Standards Board — Compendium of Standards on Internal Audit