CORAA
Blog/Internal Audit

ChatGPT for Internal Audit (2026): 12 Copy-Ready Prompts, Where It Helps and Where It Fails

ChatGPT for internal audit in 2026: twelve complete prompts grouped by audit stage (RCM from a process narrative, walkthrough questions, test steps, sampling rationale, five-part observations, management-response challenge, audit committee summary, ATR follow-up), what not to paste, how to check the output, and what to record in the working paper.

CCORAA Team1 October 202611 min read

ChatGPT is useful in internal audit for drafting and structuring: an RCM from a process narrative, walkthrough questions, an observation in five parts, a summary for the audit committee. It does not test a population, it can invent a section number or a threshold, and the internal auditor remains responsible for every fact and conclusion in the file.

This guide gives twelve prompts you can copy, grouped by audit stage, then what matters more than the prompts: what not to paste, how to check what comes back, and what to record. It is written for internal audit work in India, in-house or by a CA firm.

If you want the working files the prompts feed into, start here:

Stage Prompts Working file
Scope and RCM 1, 2 RCM Builder
Walkthrough and data request 3, 4 Walkthrough Memo Generator, Data Request List
Testing 5 to 7 Sampling Plan Generator, Fieldwork Testing Tracker
Observations 8, 9 Observation Report Generator
Reporting and follow-up 10 to 12 ATR Tracker

For where a chat assistant sits in the whole audit, read the pillar guide: AI in internal audit 2026.

Where ChatGPT helps in internal audit

Task What you still check
Drafting an RCM from a process narrative That each control exists and operates as described
Walkthrough question lists That the questions fit this system and process
Turning rough notes into a five-part observation Criteria, cause and every number
Challenging a management response Whether the gap it finds matters
Summarising for the audit committee That no qualifier or number changed
A spreadsheet formula or a test step The formula, on rows you have checked by hand

Everything in that table is drafting. Whether a control operated across the year is a question for evidence; that route is described in continuous internal audit and full-population testing.

Set it up once. Put your standing rules (observation format, rating scale, no invented citations) in custom instructions or a project. If several people do the same task, a shared custom GPT holding the instructions and blank templates keeps output consistent; load methodology, not company data. Check your plan's data-use and retention settings before any work material goes in.

Scope and RCM

1. Draft an RCM from a process narrative

You are assisting an internal auditor in India. Below is a process
narrative for [process, e.g. procure-to-pay], names removed.

Draft a risk and control matrix as a table: Sub-process | Risk | Control
described in the narrative | Control owner (role) | Preventive or
Detective | Manual, Automated or IT-dependent manual | Frequency | Test of
design | Test of operating effectiveness | Evidence to request.

Use only controls the narrative describes. Where a risk has no control in
the narrative, write "NO CONTROL DESCRIBED". Mark every assumption as
[ASSUMPTION]. Do not cite any section, rule or standard number I have not
given you.

Narrative:
[paste]

2. Find the gaps in an RCM you already have

Review our draft RCM for [process] as a critical reviewer. List in tables:
(a) risks common to this process in an Indian [industry] company that the
RCM does not cover; (b) controls described too vaguely to test, with a
suggested rewording; (c) controls where the test step does not test the
control. One-line reason for each. Mark every assumption as [ASSUMPTION].
Do not invent section, rule or standard numbers; if law seems relevant,
write "CHECK LAW" and describe the topic in words.

RCM:
[paste]

Walkthrough and data request

3. Walkthrough questions by control

For each control in the RCM extract below, write walkthrough questions for
the process owner: three on how the control is performed (who, when, on
what document or screen), two on what happens when it fails or is
bypassed, one on evidence retained, and the one document or screen I
should ask to see. The system is [Tally / SAP / other]. Plain language.
Mark every assumption as [ASSUMPTION]. Do not invent menu paths,
transaction codes, field names or section numbers.

RCM extract:
[paste]

4. Data request list from the scope

From the scope note below, draft an information request list. Columns:
Sr no | Item | Purpose (control or test it supports) | Period | Format |
Owner (role). Group by sub-process. Books are in [Tally / SAP]. For Tally,
describe items as a user sees them (Day Book, ledger vouchers, bill-wise
outstandings, stock summary). For SAP, describe the data in words and
write "TABLE TO BE CONFIRMED WITH IT" unless you are certain of the table.
Mark every assumption as [ASSUMPTION]. Do not cite section or standard
numbers.

Scope note:
[paste]

Testing

5. Write a test step

Write a test of operating effectiveness for this control: [control,
frequency, evidence it leaves]. Give: the population and its source, how
to confirm it is complete, numbered attributes to test, what counts as an
exception for each, and what to record per item. Do not suggest a sample
size; I will decide it. Mark every assumption as [ASSUMPTION]. Do not cite
section, rule or standard numbers.

6. Sampling rationale for the file

Draft a sampling rationale note using only the facts below. Sections:
population and source, completeness check, whether the full population or
a sample was tested and why, basis of selection, sample size and how it
was arrived at, treatment of exceptions. Use my figures exactly; do not
calculate or suggest a sample size or quote a sample-size table. Where a
fact is missing, write "AUDITOR TO COMPLETE". Mark every assumption as
[ASSUMPTION]. Do not cite standard or paragraph numbers.

Facts:
[paste]

7. A spreadsheet formula for a test

My Excel sheet has these columns: [e.g. A Vendor code, B Invoice number,
C Invoice date, D Amount]. Data starts in row 2. Write a formula for
column [X] that flags [the test, e.g. rows where the same vendor and
amount appear more than once and invoice numbers match after removing
spaces, slashes and leading zeros]. Explain it in two lines, list any case
it will miss, and give three test rows to check it. Mark every assumption
as [ASSUMPTION]. Calculation only: do not add any section or standard
number.

Observations

8. Rough notes to a five-part observation

Convert the notes below into an internal audit observation: Condition,
Criteria, Cause, Effect, Recommendation.
- Use only facts in my notes. Add no numbers, dates or names.
- Criteria: quote only the policy clause or requirement I supply. If none,
  write "CRITERIA TO BE CONFIRMED BY AUDITOR".
- Cause: if my notes do not establish it, write "CAUSE NOT YET
  ESTABLISHED" and list two questions that would.
- Do not rate it. Neutral tone, no blame on individuals, under 220 words.
- Mark every assumption as [ASSUMPTION]. Do not invent section, rule,
  standard or policy clause numbers.

Notes (names masked):
[paste]

9. Challenge a management response

Below are an observation, the recommendation and management's response.
Assess the response: Does it accept the facts? Does it address the cause
or only the instances found? Is there an owner (role) and a date? What
evidence would show closure? Then list my follow-up questions, most
important first. Do not judge who is right on the facts; flag only what is
unanswered or vague. Mark every assumption as [ASSUMPTION]. Do not invent
section, rule or standard numbers.

Text:
[paste]

Reporting and follow-up

10. Audit committee summary

Summarise the internal audit report below for the audit committee in one
page: what was covered and what was not; overall view in two sentences; a
table (observation in one line | rating as given | owner | agreed date);
repeat observations; items where management disagreed. Keep every number,
rating and qualifier exactly as in the report; do not round, re-rate or
generalise. List anything you were unsure how to summarise. Mark every
assumption as [ASSUMPTION]. Do not add any section, rule or standard
number that is not in the report.

Report (names masked):
[paste]

11. ATR follow-up note

From the action taken report extract below, draft a follow-up note to
[role]. For each overdue item: the agreed action, the agreed date, days
overdue as stated, the latest management comment, and the evidence I need
to validate closure. List separately items marked closed with no evidence
shown. Polite, direct, under 300 words plus the table. Do not recompute
dates or ageing. Mark every assumption as [ASSUMPTION]. Do not cite
section, rule or standard numbers.

ATR extract:
[paste]

12. Reviewer's check before the report goes out

Act as the reviewing manager. For each observation in the draft below,
answer in a table with "Yes", "No" or "Partly" and a one-line reason: Is
the condition specific (what, where, how many, period)? Is a criterion
stated and attributed to a source? Is the cause stated? Is the effect
quantified or explained? Does the recommendation address the cause? Are
owner and date present? Do not rewrite or supply missing facts. Mark every
assumption as [ASSUMPTION]. Flag any section, rule or standard number as
"VERIFY CITATION"; do not add or correct one yourself.

Draft:
[paste]

General prompts for audit work are in the tested prompt library for auditors and the prompt engineering guide; both are written for statutory audit.

What not to paste, and why

Do not paste Why
Payroll, PAN, Aadhaar, bank accounts, salaries Personal data, covered by the Digital Personal Data Protection Act, 2023; you have no authority to send it to a consumer tool
Customer and vendor masters with names, GSTINs, bank details Personal and commercially sensitive
Ledgers, Day Book exports, bank statements Confidential, and a chat is the wrong place to test them
Whistle-blower complaints, investigation notes, legal advice A leak does the most damage here
Unpublished results of a listed company Restricted under the company's own insider-trading code

Confidentiality is one of ICAI's basic principles of internal audit, and a CA firm also has its engagement terms to honour. Mask or describe instead: "Vendor A", "a branch in the west region", "an invoice of about ₹4 lakh". See can you upload client ledgers to AI tools? and DPDP for CA firms.

How to check its output

Invented citations. A section, a rule, an SIA number or a policy clause that does not exist, or exists and says something else. Standards on Internal Audit are a particular trap: ICAI has two numbering sets in circulation, so one number can mean two standards (see internal audit in 2026). Open the source for every citation. If you cannot find it, delete it.

Wrong thresholds. Limits, due dates and rates arrive stated with confidence and are sometimes wrong. An illustrative case: asked which private companies need an internal auditor, a chat assistant may add a paid-up capital test. Under Rule 13 that limb applies to unlisted public companies; a private company is tested on turnover and on borrowings from banks or public financial institutions. Check against the rule or the applicability checker.

Confident summaries of data it never saw. Paste part of a file, or upload a large one, and the answer may describe "the data" as a whole. Ask how many rows it read. Better, test in a spreadsheet or a testing tool where every result ties to a row.

Filled gaps. If your notes do not say who approved, the draft may say "the manager approved". Treat any detail you did not supply as wrong until shown otherwise. The patterns are catalogued in AI hallucinations in audit.

What to record in the working paper when AI assisted

ICAI's SIA 330 on internal audit documentation, in the October 2022 compendium, expects the file to show the purpose of each procedure, the source of evidence, the outcome, and who performed and reviewed the work. Apply the same idea to AI assistance. A filled example, with illustrative details:

Item Example entry
Working paper P2P-07, observation on duplicate vendor invoices
Tool and use ChatGPT (company-approved account), to structure the observation from auditor's notes
What was given to it Auditor's notes, names masked. No ledger data
What it produced First draft in five parts, saved as P2P-07a
What was verified Count and amount agreed to test sheet P2P-05; criterion agreed to the procurement policy clause; cause confirmed with the AP lead
What was changed Cause rewritten (draft said "lack of training"; actual cause is an exact-match duplicate check); rating added by auditor
Prepared by, reviewed by Initials and dates

ICAI's revised SIA set, in the February 2026 compendium that ICAI lists as applicable from 1 April 2026, includes a standard titled "Use of Tools". We have not verified its text; check the ICAI Internal Audit Standards Board compendium before you settle your documentation rule.

ChatGPT for internal audit FAQ

Can ChatGPT be used for internal audit in 2026?

Yes, for drafting and structuring work such as RCMs, walkthrough questions, observations and committee summaries. It should not be used to test transactions or to conclude whether a control worked, and its output must be verified before it enters the file.

Is it safe to upload company data to ChatGPT for an internal audit?

Not without authority. Check your plan's data-use and retention settings, get the company's approval for the class of data, and keep personal data of employees, customers and vendors out of consumer tools. Masked or described data is enough for most drafting.

Can ChatGPT analyse a ledger and find exceptions?

It can run calculations on a file you upload, but that is not a reliable audit test: the logic is not fixed in advance, completeness is not checked, and it may summarise rows it did not read. Use a tool where every exception traces to an entry, and use ChatGPT to write the test step or formula.

Do I have to disclose that ChatGPT was used in an internal audit?

Record it in the working paper: the tool, the use, what was given to it, what was verified and who reviewed. Whether to mention it in the report is for the audit committee, which settles the methodology of internal audit under Rule 13.

Sources

Topics
ChatGPT for internal auditChatGPT internal audit promptshow to use ChatGPT in internal auditChatGPT prompts for internal auditorsChatGPT RCM promptChatGPT audit observation promptChatGPT internal audit India 2026
Share
← Back to all articles
Keep reading

More in internal audit.

Built for India · DPDPA compliant

Ready to automate your audit work.

See how Coraa reduces audit engagement time by 60%, from ledger scrutiny to working papers, all from one Tally import.

Run one complete audit free