ChatGPT is useful in internal audit for drafting and structuring: an RCM from a process narrative, walkthrough questions, an observation in five parts, a summary for the audit committee. It does not test a population, it can invent a section number or a threshold, and the internal auditor remains responsible for every fact and conclusion in the file.
This guide gives twelve prompts you can copy, grouped by audit stage, then what matters more than the prompts: what not to paste, how to check what comes back, and what to record. It is written for internal audit work in India, in-house or by a CA firm.
If you want the working files the prompts feed into, start here:
| Stage | Prompts | Working file |
|---|---|---|
| Scope and RCM | 1, 2 | RCM Builder |
| Walkthrough and data request | 3, 4 | Walkthrough Memo Generator, Data Request List |
| Testing | 5 to 7 | Sampling Plan Generator, Fieldwork Testing Tracker |
| Observations | 8, 9 | Observation Report Generator |
| Reporting and follow-up | 10 to 12 | ATR Tracker |
For where a chat assistant sits in the whole audit, read the pillar guide: AI in internal audit 2026.
Where ChatGPT helps in internal audit
| Task | What you still check |
|---|---|
| Drafting an RCM from a process narrative | That each control exists and operates as described |
| Walkthrough question lists | That the questions fit this system and process |
| Turning rough notes into a five-part observation | Criteria, cause and every number |
| Challenging a management response | Whether the gap it finds matters |
| Summarising for the audit committee | That no qualifier or number changed |
| A spreadsheet formula or a test step | The formula, on rows you have checked by hand |
Everything in that table is drafting. Whether a control operated across the year is a question for evidence; that route is described in continuous internal audit and full-population testing.
Set it up once. Put your standing rules (observation format, rating scale, no invented citations) in custom instructions or a project. If several people do the same task, a shared custom GPT holding the instructions and blank templates keeps output consistent; load methodology, not company data. Check your plan's data-use and retention settings before any work material goes in.
Scope and RCM
1. Draft an RCM from a process narrative
You are assisting an internal auditor in India. Below is a process
narrative for [process, e.g. procure-to-pay], names removed.
Draft a risk and control matrix as a table: Sub-process | Risk | Control
described in the narrative | Control owner (role) | Preventive or
Detective | Manual, Automated or IT-dependent manual | Frequency | Test of
design | Test of operating effectiveness | Evidence to request.
Use only controls the narrative describes. Where a risk has no control in
the narrative, write "NO CONTROL DESCRIBED". Mark every assumption as
[ASSUMPTION]. Do not cite any section, rule or standard number I have not
given you.
Narrative:
[paste]
2. Find the gaps in an RCM you already have
Review our draft RCM for [process] as a critical reviewer. List in tables:
(a) risks common to this process in an Indian [industry] company that the
RCM does not cover; (b) controls described too vaguely to test, with a
suggested rewording; (c) controls where the test step does not test the
control. One-line reason for each. Mark every assumption as [ASSUMPTION].
Do not invent section, rule or standard numbers; if law seems relevant,
write "CHECK LAW" and describe the topic in words.
RCM:
[paste]
Walkthrough and data request
3. Walkthrough questions by control
For each control in the RCM extract below, write walkthrough questions for
the process owner: three on how the control is performed (who, when, on
what document or screen), two on what happens when it fails or is
bypassed, one on evidence retained, and the one document or screen I
should ask to see. The system is [Tally / SAP / other]. Plain language.
Mark every assumption as [ASSUMPTION]. Do not invent menu paths,
transaction codes, field names or section numbers.
RCM extract:
[paste]
4. Data request list from the scope
From the scope note below, draft an information request list. Columns:
Sr no | Item | Purpose (control or test it supports) | Period | Format |
Owner (role). Group by sub-process. Books are in [Tally / SAP]. For Tally,
describe items as a user sees them (Day Book, ledger vouchers, bill-wise
outstandings, stock summary). For SAP, describe the data in words and
write "TABLE TO BE CONFIRMED WITH IT" unless you are certain of the table.
Mark every assumption as [ASSUMPTION]. Do not cite section or standard
numbers.
Scope note:
[paste]
Testing
5. Write a test step
Write a test of operating effectiveness for this control: [control,
frequency, evidence it leaves]. Give: the population and its source, how
to confirm it is complete, numbered attributes to test, what counts as an
exception for each, and what to record per item. Do not suggest a sample
size; I will decide it. Mark every assumption as [ASSUMPTION]. Do not cite
section, rule or standard numbers.
6. Sampling rationale for the file
Draft a sampling rationale note using only the facts below. Sections:
population and source, completeness check, whether the full population or
a sample was tested and why, basis of selection, sample size and how it
was arrived at, treatment of exceptions. Use my figures exactly; do not
calculate or suggest a sample size or quote a sample-size table. Where a
fact is missing, write "AUDITOR TO COMPLETE". Mark every assumption as
[ASSUMPTION]. Do not cite standard or paragraph numbers.
Facts:
[paste]
7. A spreadsheet formula for a test
My Excel sheet has these columns: [e.g. A Vendor code, B Invoice number,
C Invoice date, D Amount]. Data starts in row 2. Write a formula for
column [X] that flags [the test, e.g. rows where the same vendor and
amount appear more than once and invoice numbers match after removing
spaces, slashes and leading zeros]. Explain it in two lines, list any case
it will miss, and give three test rows to check it. Mark every assumption
as [ASSUMPTION]. Calculation only: do not add any section or standard
number.
Observations
8. Rough notes to a five-part observation
Convert the notes below into an internal audit observation: Condition,
Criteria, Cause, Effect, Recommendation.
- Use only facts in my notes. Add no numbers, dates or names.
- Criteria: quote only the policy clause or requirement I supply. If none,
write "CRITERIA TO BE CONFIRMED BY AUDITOR".
- Cause: if my notes do not establish it, write "CAUSE NOT YET
ESTABLISHED" and list two questions that would.
- Do not rate it. Neutral tone, no blame on individuals, under 220 words.
- Mark every assumption as [ASSUMPTION]. Do not invent section, rule,
standard or policy clause numbers.
Notes (names masked):
[paste]
9. Challenge a management response
Below are an observation, the recommendation and management's response.
Assess the response: Does it accept the facts? Does it address the cause
or only the instances found? Is there an owner (role) and a date? What
evidence would show closure? Then list my follow-up questions, most
important first. Do not judge who is right on the facts; flag only what is
unanswered or vague. Mark every assumption as [ASSUMPTION]. Do not invent
section, rule or standard numbers.
Text:
[paste]
Reporting and follow-up
10. Audit committee summary
Summarise the internal audit report below for the audit committee in one
page: what was covered and what was not; overall view in two sentences; a
table (observation in one line | rating as given | owner | agreed date);
repeat observations; items where management disagreed. Keep every number,
rating and qualifier exactly as in the report; do not round, re-rate or
generalise. List anything you were unsure how to summarise. Mark every
assumption as [ASSUMPTION]. Do not add any section, rule or standard
number that is not in the report.
Report (names masked):
[paste]
11. ATR follow-up note
From the action taken report extract below, draft a follow-up note to
[role]. For each overdue item: the agreed action, the agreed date, days
overdue as stated, the latest management comment, and the evidence I need
to validate closure. List separately items marked closed with no evidence
shown. Polite, direct, under 300 words plus the table. Do not recompute
dates or ageing. Mark every assumption as [ASSUMPTION]. Do not cite
section, rule or standard numbers.
ATR extract:
[paste]
12. Reviewer's check before the report goes out
Act as the reviewing manager. For each observation in the draft below,
answer in a table with "Yes", "No" or "Partly" and a one-line reason: Is
the condition specific (what, where, how many, period)? Is a criterion
stated and attributed to a source? Is the cause stated? Is the effect
quantified or explained? Does the recommendation address the cause? Are
owner and date present? Do not rewrite or supply missing facts. Mark every
assumption as [ASSUMPTION]. Flag any section, rule or standard number as
"VERIFY CITATION"; do not add or correct one yourself.
Draft:
[paste]
General prompts for audit work are in the tested prompt library for auditors and the prompt engineering guide; both are written for statutory audit.
What not to paste, and why
| Do not paste | Why |
|---|---|
| Payroll, PAN, Aadhaar, bank accounts, salaries | Personal data, covered by the Digital Personal Data Protection Act, 2023; you have no authority to send it to a consumer tool |
| Customer and vendor masters with names, GSTINs, bank details | Personal and commercially sensitive |
| Ledgers, Day Book exports, bank statements | Confidential, and a chat is the wrong place to test them |
| Whistle-blower complaints, investigation notes, legal advice | A leak does the most damage here |
| Unpublished results of a listed company | Restricted under the company's own insider-trading code |
Confidentiality is one of ICAI's basic principles of internal audit, and a CA firm also has its engagement terms to honour. Mask or describe instead: "Vendor A", "a branch in the west region", "an invoice of about ₹4 lakh". See can you upload client ledgers to AI tools? and DPDP for CA firms.
How to check its output
Invented citations. A section, a rule, an SIA number or a policy clause that does not exist, or exists and says something else. Standards on Internal Audit are a particular trap: ICAI has two numbering sets in circulation, so one number can mean two standards (see internal audit in 2026). Open the source for every citation. If you cannot find it, delete it.
Wrong thresholds. Limits, due dates and rates arrive stated with confidence and are sometimes wrong. An illustrative case: asked which private companies need an internal auditor, a chat assistant may add a paid-up capital test. Under Rule 13 that limb applies to unlisted public companies; a private company is tested on turnover and on borrowings from banks or public financial institutions. Check against the rule or the applicability checker.
Confident summaries of data it never saw. Paste part of a file, or upload a large one, and the answer may describe "the data" as a whole. Ask how many rows it read. Better, test in a spreadsheet or a testing tool where every result ties to a row.
Filled gaps. If your notes do not say who approved, the draft may say "the manager approved". Treat any detail you did not supply as wrong until shown otherwise. The patterns are catalogued in AI hallucinations in audit.
What to record in the working paper when AI assisted
ICAI's SIA 330 on internal audit documentation, in the October 2022 compendium, expects the file to show the purpose of each procedure, the source of evidence, the outcome, and who performed and reviewed the work. Apply the same idea to AI assistance. A filled example, with illustrative details:
| Item | Example entry |
|---|---|
| Working paper | P2P-07, observation on duplicate vendor invoices |
| Tool and use | ChatGPT (company-approved account), to structure the observation from auditor's notes |
| What was given to it | Auditor's notes, names masked. No ledger data |
| What it produced | First draft in five parts, saved as P2P-07a |
| What was verified | Count and amount agreed to test sheet P2P-05; criterion agreed to the procurement policy clause; cause confirmed with the AP lead |
| What was changed | Cause rewritten (draft said "lack of training"; actual cause is an exact-match duplicate check); rating added by auditor |
| Prepared by, reviewed by | Initials and dates |
ICAI's revised SIA set, in the February 2026 compendium that ICAI lists as applicable from 1 April 2026, includes a standard titled "Use of Tools". We have not verified its text; check the ICAI Internal Audit Standards Board compendium before you settle your documentation rule.
ChatGPT for internal audit FAQ
Can ChatGPT be used for internal audit in 2026?
Yes, for drafting and structuring work such as RCMs, walkthrough questions, observations and committee summaries. It should not be used to test transactions or to conclude whether a control worked, and its output must be verified before it enters the file.
Is it safe to upload company data to ChatGPT for an internal audit?
Not without authority. Check your plan's data-use and retention settings, get the company's approval for the class of data, and keep personal data of employees, customers and vendors out of consumer tools. Masked or described data is enough for most drafting.
Can ChatGPT analyse a ledger and find exceptions?
It can run calculations on a file you upload, but that is not a reliable audit test: the logic is not fixed in advance, completeness is not checked, and it may summarise rows it did not read. Use a tool where every exception traces to an entry, and use ChatGPT to write the test step or formula.
Do I have to disclose that ChatGPT was used in an internal audit?
Record it in the working paper: the tool, the use, what was given to it, what was verified and who reviewed. Whether to mention it in the report is for the audit committee, which settles the methodology of internal audit under Rule 13.
Related CORAA resources
- AI in internal audit 2026: the stage-by-stage guide
- Claude for internal audit: Projects, prompts and workflow
- Internal audit report format: observations, ATR and audit committee reporting
- Can ChatGPT do my audit?
- Internal Audit AI Strategy Template
Sources
- Companies (Accounts) Rules, 2014 — Rule 13, on the classes of companies required to appoint an internal auditor and on scope, functioning, periodicity and methodology
- ICAI Internal Audit Standards Board — Compendium of Standards on Internal Audit