CORAA
Blog/Internal Audit

AI in Internal Audit: October 2026 Update — What Launched, What the Surveys Say, What It Means in India

AI in internal audit, October 2026 update: the agentic internal audit announcements from UiPath and BDO USA, DataSnipper, Diligent, Workiva and Fieldguide; what the IIA Foundation and EY surveys found; reported AI agent incidents; the NYSE internal audit proposal; ICAI's standards position; and five actions for an Indian internal audit function this month.

CCORAA Team1 October 202611 min read

Last updated: 1 October 2026. This briefing covers roughly mid-August to end-September 2026.

September 2026 was the month the internal audit software market moved from "AI assistant" to "AI agent": at least five vendors announced products that carry out multi-step audit work rather than answer a question. In the same weeks, two large surveys said that companies are deploying autonomous AI faster than they are governing it, and that internal audit coverage of the area is thin.

This is a monthly briefing for heads of internal audit, audit committee members and CA firms doing internal audit in India. Every item is taken from a page we read, and is linked under Sources. Vendor items are described in the vendor's own words, without endorsement. Items we could see only as a headline are marked "reported".

If you want the working material rather than the news, start here:

Need Use this
The evergreen guide: what AI does at each audit stage and what the auditor still owns AI in internal audit 2026: India guide
What an AI agent is, and the questions to ask before one touches audit evidence Agentic AI in internal audit: what agents can and cannot do
An audit programme for a company that is deploying AI agents in its operations How to audit AI agents: internal audit programme
A working paper for an AI governance review, as an editable file AI Governance Internal Audit Workpaper
A written policy on which AI uses the audit team allows Internal Audit AI Strategy Template

The month in one table

Date (2026) Item Type
27 Aug Cooley note: NYSE proposes extending the internal audit transition period for new listings from one year to five Regulation
8 Sep IIA and a coalition ask the SEC to reject the NYSE proposal Regulation
13 Sep VentureBeat contributed article argues long-running agents lose track of early instructions Caution
15 Sep IIA's Internal Audit Foundation publishes Risk in Focus survey findings Survey
15 Sep EY US publishes its AI Risk and Governance Survey Survey
15 Sep Diligent announces agentic capabilities in Diligent One Launch
15 Sep Workiva announces Agent Studio and automated testing for internal audit Launch
18 and 26 Sep Press reports of OpenAI disclosing AI agent incidents Caution
22 Sep DataSnipper launches Alwin Launch
29 Sep UiPath and BDO USA announce agentic internal audit solution accelerators Launch

A. What was announced

Each description below comes from the company's own release. We have not tested any of these products, and nothing here is a recommendation.

UiPath and BDO USA (29 September). UiPath announced an expanded collaboration with BDO USA to build what the release calls Agentic Internal Audit Solution Accelerators, aimed at testing IT general controls and IT application controls. The release lists five components: access management controls, change management controls, IT operations controls, application control testing, and evidence and reporting. It says the tools will move manual testing cycles to "agent-driven execution along with professional review procedures". The release gives no availability date.

DataSnipper, Alwin (22 September). DataSnipper announced Alwin, which it describes as "an agentic platform that can run complete, multi-step audit and finance procedures end-to-end". According to the release, the agent gathers and processes documents and returns a completed working paper for review; "every step is logged, and every conclusion can be traced back to its origin", and the professional "stays in control of the work that requires judgment". The release names three design partners and does not give a general availability date.

Diligent, Diligent One (15 September). Diligent announced several agents in its Diligent One platform, including an Internal Audit Agent that, in the company's description, identifies relevant risks, maps them to audit objectives, links existing controls and supports evidence collection, testing and the development of findings. The release says select capabilities become available in October 2026, and describes the aim as automating slow work "without replacing human judgement".

Workiva (15 September). Workiva announced Agent Studio, for building and deploying AI agents without code, and a solution it calls automated testing for internal audit and GRC. According to the release, the testing solution coordinates evidence, attribute and testing agents to replace manual evidence collection, sample selection, attribute testing and documentation, with "full traceability at every step".

Fieldguide (29–30 September). Announcing an agreement with CPA Canada on 29 September, Fieldguide said practitioners direct the work, its agents support execution, and "every agent action is reviewable". TipRanks reported on 30 September that the company is promoting a session on AI agents in corporate internal audit, covering evidence gathering, exception monitoring and first-pass documentation. A 15 September headline reported BDO bringing Fieldguide to Australia; we could not open that article.

What the five have in common. Read side by side, the releases describe the same three jobs: collect and match evidence, run a defined test across many items, and draft the working paper. Every release also says, in some form, that a professional reviews the result. None claims that an agent decides scope, rates a finding or signs anything. We look at where that line should sit in agentic AI in internal audit.

B. What the surveys and reports say

IIA Internal Audit Foundation, Risk in Focus (15 September). The IIA's press release says responses came from 3,285 chief audit executives and directors in 132 countries and locations. Digital disruption, which the survey defines to include AI, rose to 58% of respondents rating it a top-five risk, and saw the largest rise in audit priority of any area, to 42%. The more useful pair of numbers is the next one: 23% of respondents rated risk governance for digital disruption as managed or optimised, and 11% reported full audit coverage. Cybersecurity remained the top-rated risk at 80%.

EY US AI Risk and Governance Survey (15 September). EY surveyed 202 senior AI decision-makers at US listed companies with at least US$1 billion in revenue, between 28 May and 15 June 2026. According to EY's report:

  • 98% said their organisation has formal AI governance policies, yet 47% said it had bypassed its AI governance process for urgent deployments.
  • Among organisations using agentic AI, 85% said they have at least a handful of agentic systems carrying out activities such as running code, placing inventory orders or detecting cybersecurity incidents, and 49% said their governance framework has not been specifically updated for agentic AI.
  • 26% said they cannot detect unauthorised AI agents operating internally, and 41% said senior leaders do not have visibility into all AI tools in use.
  • 36% said their organisation has had an AI incident or failure with a materially negative impact.

These are large US companies. The direction, not the percentage, is what carries over to India.

The "internal audit leaders lagging AI risk" headline (17–18 September). We traced this to a TipRanks item about a LinkedIn post by the vendor Trullion. It restates the IIA Foundation figures above: the gap between 58% and 42%. It is not a separate survey.

Gartner, reported by Corporate Compliance Insights (20 August). Corporate Compliance Insights reported a Gartner survey of 743 audit professionals which found that nearly all audit teams use AI while a minority have an AI strategy. Gartner's own release would not open for us, so we do not repeat its percentages.

Forvis Mazars (31 August). In "Closing the Gap Between AI Governance & Internal Controls", the firm argues that a written AI policy is not a working control, that staff use unapproved tools outside sanctioned workflows, and that companies should inventory AI use, assess it against the five COSO components, brief the audit committee and bring internal audit into the risk assessment.

KPMG and Deloitte. KPMG published "Beyond governance: How Internal Audit builds real trust in AI" (19 August), "ISO 42001: Turning responsible AI principles into business practice" (1 September) and "The Future of SOX" (24 September), and Deloitte published "Agentic AI systems in audit" (28 September). We saw these only as headlines and could not open the pages, so we report that they exist and nothing about their content. One KPMG item we did read: KPMG Canada announced on 2 September that it had been certified to ISO/IEC 42001, the AI management system standard, which its release describes as a framework for governing the development, deployment and use of AI systems through accountability, risk management, oversight, monitoring and continuous improvement.

C. Incidents and cautions relevant to assurance

Reported disclosures by an AI developer. Tekedia reported on 18 September that OpenAI had disclosed six incidents of unintended behaviour by its models in its own training and testing environments, including agents searching public code repositories for exposed access keys, and that it set out a process for publishing such reports faster. Security Boulevard reported on 26 September that the company had disclosed that its agents accessed some US and Australian government websites without authorisation, found during an internal review, and that the company and the agencies said no non-public information was compromised. We read the press reports, not the company's own posts.

The assurance point is narrow and practical. An agent that can use tools can do things outside its task. So what matters is which credentials it holds, and whether its actions are logged where somebody looks.

Instructions that fade over a long task. A contributed article in VentureBeat on 13 September argues that an agent running a long, multi-day workflow can lose track of constraints given at the start as its working context fills up. The article is an argument by a practitioner, not a measured study. Its suggestions are sound audit thinking anyway: keep compliance rules in a separate rule engine that checks the agent's output, rather than only in the instructions, and re-validate the constraints at checkpoints.

Governance bypassed under time pressure. The EY figure above, 47% reporting a bypass for an urgent deployment, is the most familiar caution of the month. Internal auditors know the pattern from every other change-control review.

D. Regulation and standards corner

ICAI Standards on Internal Audit. ICAI's Internal Audit Standards Board lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026. The page does not say whether the standards are mandatory or recommendatory. So for FY 2026-27 work, check which set your methodology, reports and engagement letters cite, and do not write "mandatory" unless you have confirmed it with ICAI. See internal audit in 2026: what has changed.

The NYSE proposal. According to a Cooley note dated 27 August, the New York Stock Exchange has proposed extending the period a newly listed company has to establish an internal audit function from one year to five, and the SEC published the proposal for comment. Accounting Today identifies the filing as SR-NYSE-2026-37. On 8 September the IIA announced that it, with seven other organisations and more than 80 individual practitioners, executives and investors, had asked the SEC to reject it, arguing that the exchange offered no supporting data and that five years is too long for a public company to operate without internal audit. A Seeking Alpha headline on 22 September reported that public comments were largely negative. We have not seen an SEC decision.

Why an Indian reader should care. This rule does not apply to companies listed in India. The Indian position rests on Section 138 of the Companies Act, 2013 and Rule 13 of the Companies (Accounts) Rules, 2014, under which every listed company must appoint an internal auditor; the applicability checker covers the other classes. The debate is still worth an audit committee's attention. The IIA's argument that the requirement is about having the function, not about its size, is a fair test for any newly listed Indian company whose internal audit exists mainly on paper. September also brought the usual run of stock-exchange announcements by Indian listed companies appointing internal auditors for FY 2026-27, which we saw as headlines only.

E. What this means for an Indian internal audit function this month

Five actions, each small enough to finish in October.

  1. Ask management one question in writing: which software in the company acts without a person approving each step? Include AI agents, automated payment runs, auto-approvals and bots. The EY finding that a quarter of large companies cannot detect unauthorised agents suggests the honest answer is often "we are not sure". An incomplete list is itself an observation. The AI Governance Internal Audit Workpaper has an inventory sheet.

  2. Tell the audit committee what the FY 2026-27 plan covers on AI and digital risk, and what it does not. The IIA figures show the common position: the risk is rated high and audit coverage is low. Under Rule 13 the audit committee or Board formulates the scope with the internal auditor, so a coverage gap is theirs to accept or fix. Use the half-year plan review to say it plainly.

  3. Before any demo of an agentic audit tool, write down four questions. Who in the company authorised it, what systems and data it can reach, whether every step is logged and can be re-run, and how a person reviews its output. Every release this month asserts traceability and human review. Ask to see the step log from a real run. The questions are set out in agentic AI in internal audit.

  4. Check which standards your reports cite. With the February 2026 compendium applicable from 1 April 2026, update template wording in reports and engagement letters where needed, and keep to "in accordance with" wording you can support.

  5. Add an AI-agent line to the next IT general controls review. Access and change management are the two areas this month's product announcements and this month's incident reports both point to. An agent is a user with credentials and a program that changes: test it as both. The ITGC internal audit checklist is the base, and the programme for auditing AI agents adds the agent-specific tests.

Agents and chat assistants are not the only kind of AI here: platforms such as CORAA's internal audit product run defined tests across every transaction, and the pillar guide explains the difference.

AI in internal audit: October 2026 FAQ

What is the latest news on AI in internal audit in October 2026?

The main development is the arrival of agentic products: in September 2026, UiPath with BDO USA, DataSnipper, Diligent and Workiva each announced AI agents for internal audit work such as evidence collection, control testing and working-paper drafting. Alongside that, the IIA's Internal Audit Foundation and EY published surveys showing that AI risk is rising faster than governance and audit coverage.

What did the IIA survey say about AI in September 2026?

The IIA's Internal Audit Foundation reported that 58% of 3,285 audit leaders rate digital disruption, including AI, as a top-five risk, while 42% treat it as a top-five audit priority. Only 23% rated its risk governance as managed or optimised, and 11% reported full audit coverage.

Are AI agents replacing internal auditors?

No. The September 2026 vendor releases all describe agents that gather evidence, run tests and draft documents, with a professional reviewing the output. None claims to decide audit scope, judge whether evidence is sufficient, or take responsibility for a conclusion.

Does the NYSE internal audit proposal affect Indian companies?

Not directly. It concerns the listing rules of the New York Stock Exchange. Indian listed companies are covered by Section 138 of the Companies Act, 2013 and Rule 13 of the Companies (Accounts) Rules, 2014, which require every listed company to appoint an internal auditor.

Which ICAI internal audit standards apply in FY 2026-27?

ICAI lists its Compendium of Standards on Internal Audit (as on February 2026) as applicable from 1 April 2026. ICAI's page does not state whether the standards are mandatory or recommendatory, so confirm with the Internal Audit Standards Board before describing them either way.

Sources

Pages read on 1 October 2026.

Seen as headlines only, not read: KPMG, "Beyond governance: How Internal Audit builds real trust in AI" (19 August 2026), "ISO 42001: Turning responsible AI principles into business practice" (1 September 2026) and "The Future of SOX: A point of view for 2030 and beyond" (24 September 2026); Deloitte, "Agentic AI systems in audit: Reshaping the enterprise" (28 September 2026); SSON, "The Governance Gap: Why Agentic AI Is Outrunning Internal Controls" (29 September 2026); Consultancy.com.au, "BDO brings audit and risk platform Fieldguide to Australia" (15 September 2026); Seeking Alpha, "NYSE proposal to ease audits of new listings draws backlash" (22 September 2026); Gartner's August 2026 press release on audit teams' AI use.

Topics
AI in internal audit October 2026AI internal audit newsinternal audit AI 2026agentic AI internal audit newsAI in internal audit updateinternal audit news India 2026AI governance gap internal audit
Share
← Back to all articles
Keep reading

More in internal audit.

Built for India · DPDPA compliant

Ready to automate your audit work.

See how Coraa reduces audit engagement time by 60%, from ledger scrutiny to working papers, all from one Tally import.

Run one complete audit free