An AI agent is software that is given a goal, works out the steps needed to reach it, and carries those steps out by using other systems, such as opening files, running a query or sending an email. A chatbot answers the question you typed and stops; an agent keeps going until the job is done or it gets stuck.
This explainer is for a chartered accountant who keeps hearing the word and wants a clear meaning before the next vendor demo. It covers the definition, the two things an agent is often confused with, one worked illustration, and the questions to ask before an agent touches client data.
Where to go next, depending on what you need:
| Need | Read this |
|---|---|
| What agents can and should not do in an internal audit | Agentic AI in internal audit 2026 |
| What agents automate at each stage of a statutory audit | AI agents for audit: what they actually automate |
| A first beginner's introduction | Understanding AI agents for audit |
| A working paper for reviewing how a company governs its AI | AI Governance Internal Audit Workpaper |
The definition, one part at a time
Take the sentence apart.
"Given a goal." You do not tell an agent each step. You tell it the result you want: "Send balance confirmation requests to the top 50 debtors and tell me who has not replied."
"Works out the steps." The agent decides it must first get the debtor list, then find the email addresses, then prepare the letters, then send them, then watch for replies. If the email address for one debtor is missing, it decides what to do about that.
"Carries them out by using other systems." This is the part that separates an agent from everything that came before. It does not only write about the work. It opens the ledger export, creates the letters, sends the emails and updates the tracker, using whatever access it has been given.
Underneath, an agent is usually a language model (the same kind of technology as a chatbot) placed inside a loop: think about what to do next, do it, look at what happened, think again. The loop and the access are what make it an agent.
Agent, chatbot and rule-based check: three different things
Most confusion comes from mixing up these three.
| Chatbot | AI agent | Fixed rule-based check | |
|---|---|---|---|
| Plain description | Answers what you type | Pursues a goal across many steps | Applies one written rule to every record |
| Everyday comparison | A knowledgeable colleague you ask a question | An assistant you hand a task and the office keys | A stamp that marks every invoice over a limit |
| Who chooses the steps | You, one prompt at a time | The software | The person who wrote the rule |
| Does it act on other systems? | No, it produces text | Yes, within the access it has | It reads data and flags; it does not decide anything |
| Same data, same answer every time? | Not reliably | Not reliably, unless the steps are locked | Yes |
| Typical audit use | Drafting, summarising, explaining | Collecting, chasing, compiling, drafting | Testing every transaction against a condition |
| Where it goes wrong | States something untrue with confidence | Takes a wrong step that nobody sees | The rule was badly written or the data was incomplete |
Two points follow from the table.
First, a rule-based check is not a lesser kind of AI. "Flag every payment made to a vendor whose bank account changed in the previous seven days" is a fixed rule. It gives the same answer on every run, and a reviewer can re-perform it. For testing a population, that repeatability is exactly what an auditor needs.
Second, the three work best together. The agent fetches the data and runs the fixed rule; the rule decides what is an exception; a chat-style draft turns the exceptions into readable text; a person reviews. Trouble starts when the agent is allowed to decide what counts as an exception by its own judgement, differently each time.
A worked illustration: debtor confirmations
The numbers below are illustrative. They are not drawn from any real engagement.
An audit team wants external confirmation of trade receivable balances as at 31 March 2026. The engagement partner has approved the selection: the 50 largest balances, covering ₹18.4 crore of a ₹26.1 crore ledger.
Done by hand. An article assistant exports the debtor list, looks up contact details, mail-merges 50 letters, sends them, keeps a tracker in Excel, sends reminders after ten days, and chases the client for the ones that bounce. It takes parts of three weeks.
Done with a chatbot. The assistant asks the chatbot to draft the confirmation letter and the reminder. Useful, and it saves an hour. Everything else is still done by hand.
Done with an agent. The team gives the agent the approved list, read access to the debtor master, and permission to send email from a dedicated audit mailbox. The agent's log reads:
| Step | What the agent did | Outcome |
|---|---|---|
| 1 | Read the approved list of 50 debtors | 50 balances, ₹18.4 crore, agrees to the partner's selection |
| 2 | Looked up email addresses in the debtor master | 46 found, 4 missing |
| 3 | Stopped and asked the team about the 4 | Team supplied 3; 1 to go by post |
| 4 | Prepared and sent 49 confirmation emails | 49 sent, 2 bounced |
| 5 | After 10 days, sent reminders to non-responders | 31 replies in, 16 reminded |
| 6 | Compared each reply with the ledger balance | 27 agree, 4 differ |
| 7 | Drafted the confirmation control sheet | Draft for review |
What stayed with people. The partner chose the sample. The team resolved the four missing addresses. A senior opened all four differences and found three timing items and one disputed invoice of ₹7.2 lakh. The senior also checked a handful of the 27 "agreed" replies against the actual emails, to make sure the agent had read them correctly, and decided what alternative procedures to perform for the debtors who never replied.
Notice step 3. A well-built agent stops and asks when it meets something outside its instructions. A badly built one guesses an email address and sends a client's balance to the wrong person. That single difference is worth more than any feature list.
Tools, memory and autonomy: what the words mean in practice
Vendors use three words constantly. Here is what each means for you.
Tools
A tool is anything the agent can use to act outside the conversation: read a folder, query the accounting database, send an email, write to a spreadsheet, call another program. An agent with no tools is a chatbot.
For an auditor, the tool list is the access list. Ask for it in writing. "Read the ledger export" is one risk. "Post a journal entry" is a very different one.
Memory
Memory is what the agent keeps. There are two kinds.
- Working memory is what it holds during one task: the instructions, the files it has read, the steps so far. This is limited. On a long task, early instructions can be crowded out by later material, which is one reason important rules should be enforced by a separate check and not left only in the opening instructions.
- Stored memory is what it keeps between tasks: notes, past results, client preferences. This is convenient and it is also a confidentiality question. If the agent remembers Client A's data while working on Client B, you have a problem.
Ask where memory is stored, for how long, who can read it and how it is deleted.
Autonomy
Autonomy is how far the agent goes before a person looks. It is a setting, not a fixed property.
| Level | What it means | Suitable for |
|---|---|---|
| Suggest only | The agent proposes each step; a person approves every one | Anything new, anything that sends or changes data |
| Act, then report | The agent completes a bounded task and shows the full log | Collecting documents, matching, compiling schedules |
| Act within limits | The agent works unattended inside written limits and stops at the edge | Routine chasing and reminders, repeat extractions |
| Unrestricted | The agent decides its own limits | Not suitable for audit work |
A sound starting point is the lowest level that still saves time, raised only after the logs show the agent behaves.
Ten questions before you trust an agent with client data or audit evidence
Ask the vendor, or your own IT team, and ask for the answers in writing.
- What exactly can it access? List every system, folder and mailbox. Is access read-only?
- Does it have its own login? An agent using a staff member's password leaves no way to tell who did what.
- Where does the data go? Which servers, which country, and is any of it retained or used to improve the provider's models? Check the plan's data-use and retention settings yourself.
- Is there a step-by-step log? Not a summary. Each action, in order, with the time and the result.
- If I run it again on the same data, do I get the same result? If not, which parts vary and why?
- Where does it stop and ask? What happens when data is missing, a rule conflicts or a figure does not agree?
- What can it never do? Send outside the firm, delete, post entries, approve its own work. Are those limits enforced by the system or only requested in the instructions?
- What does it remember afterwards? And how is one client's information kept apart from another's?
- How is its work reviewed? Who opens the source records, and for how many items?
- Who is accountable? A named person in the firm who approved its use for this purpose.
On evidence, hold a simple line. What an agent produces is a draft working paper. It becomes audit evidence only when the source records are retained, the steps can be followed, and a qualified person has checked and signed it. The auditor's responsibility for the conclusion does not move.
On personal data, remember that ledgers, payroll files and confirmations contain names, bank details and contact details. Never give client or employee personal data to an AI tool without authority to do so. The Digital Personal Data Protection Act places duties on whoever decides how personal data is used, and using a vendor's agent does not pass those duties to the vendor. See DPDP for CA firms.
A short glossary
| Term | Plain meaning |
|---|---|
| AI agent | Software that is given a goal, plans the steps and carries them out using other systems |
| Agentic AI | A general label for systems built from one or more agents |
| Chatbot / chat assistant | A program that replies to each message you type and does nothing else |
| Language model | The underlying technology that reads and writes text; the "brain" inside both chatbots and agents |
| Prompt | The instruction you type |
| Tool | Something an agent can use to act: read a file, run a query, send an email |
| Working memory (context) | What the agent can hold in mind during one task; limited in size |
| Stored memory | Information the agent keeps between tasks |
| Autonomy | How many steps the agent takes before a person checks |
| Human in the loop | A person must approve before the agent proceeds |
| Orchestrator | A controlling program that hands parts of a job to several specialised agents |
| Rule-based check | A fixed, written test applied identically to every record |
| Deterministic | Gives the same output every time for the same input |
| Hallucination | A confident statement by an AI tool that is not true or not supported |
| Guardrail | A limit enforced by the system, such as "cannot send email outside the firm" |
| Audit trail / log | The step-by-step record of what the agent did |
For why "deterministic" matters so much to an audit file, see deterministic vs probabilistic AI in audit. CORAA's own approach, for what it is worth, is to let fixed rules decide what is an exception and keep the agent to fetching and drafting.
What is an AI agent: FAQ
What is an AI agent in simple words?
An AI agent is software that is given a goal, decides the steps and carries them out using other systems. You tell it the result you want, not each action.
What are AI agents used for in audit in 2026?
Mostly for mechanical, multi-step work: collecting documents, sending and chasing confirmations, matching records, running tests that were defined in advance, and drafting working papers for review. Judgement, sampling decisions and conclusions stay with the auditor.
What is the difference between an AI agent and a chatbot?
A chatbot produces a reply to each message and stops. An agent plans a sequence of steps and acts on other systems to complete a task, often without a prompt for each step.
Is an AI agent the same as automation or a macro?
No. A macro or a rule-based check follows fixed steps written by a person and gives the same result every time. An agent chooses its own steps, which makes it more flexible and less predictable.
Can an AI agent be trusted with client data?
Only after you know what it can access, where the data goes, what it retains, and who reviews its work, and only with authority to use it for that client. Start with read-only access and the lowest level of autonomy.
Will AI agents replace auditors?
No. An agent can take over collecting, matching and drafting. It cannot take responsibility for scope, for whether evidence is sufficient, or for the opinion or conclusion, and those remain with the professional who signs.
Related CORAA resources
- Agentic AI in internal audit 2026: what an agent can take over and what it should not
- AI agents for audit: what they actually automate
- Understanding AI agents for audit: a beginner's guide
- How to audit AI agents: an internal audit programme
- Deterministic vs probabilistic AI in audit
- AI Governance Internal Audit Workpaper