CORAA
Resources · Internal Audit · AI Fraud

AI-enabled fraud internal audit checklist.

AI-enabled fraud is not a separate fraud category for internal audit. It is a force multiplier: phishing becomes personalised, invoices and contracts can be fabricated, voice approvals can be spoofed, applicant records can be synthetic, and malicious code can move faster. This checklist turns those risks into internal-audit preparedness tests, control questions and source-evidence checks.

Build AI governance workpaperOpen monitoring rules
Why now

The readiness signal is already visible gap

The strongest 2026 signal is not that AI proves more fraud. It is that internal audit teams expect the risk to grow faster than their tools, skills and evidence routines. Use the numbers below as global and North America-heavy risk signals, then tailor the audit programme to the entity's India obligations, systems, contracts and DPDP exposure.

Fewer than 40%
preparedness confidence

IIA/AuditBoard reported that fewer than four in ten surveyed senior internal audit leaders believe their functions are adequately prepared to detect or respond to AI-enabled fraud.

88%
AI phishing concern

AI-powered phishing was the most cited concern in the same survey, followed by fabricated invoices or financial documents and automated social engineering.

83%
expect IA AI usage to rise

Internal audit teams expect to use more AI themselves, which makes governance, source verification and reviewer discipline part of the fraud-readiness file.

2,402
occupational fraud cases

ACFE Occupational Fraud 2026 analysed 2,402 real cases across 143 countries and territories, giving the baseline fraud-risk context behind AI-enabled variants.

Threat map

Map the threat to the control and the source evidence

A red flag is only a starting point. The useful internal-audit question is which control was intended to address the scenario, what source evidence supports the reviewer conclusion, and which owner must respond if the evidence is missing or inconsistent.

AI-enabled threatControl weakness to testSource evidence to inspect
AI-powered phishingPayment, bank-master or credential-reset workflows that rely on email authenticity without callback or ticket evidence.Payment request, approval trail, callback log, bank change ticket, email header or security alert, and final bank file.
Fabricated invoices or financial documentsAP accepts invoice PDFs, vendor declarations or support documents without source-system, GSTIN, PO/GRN or vendor-master verification.Vendor master, PO, GRN, e-invoice/GST trail where applicable, invoice metadata, payment voucher and approver evidence.
Automated social engineeringEmployees can bypass approvals when a message appears urgent, senior or commercially sensitive.Delegation matrix, exception approval, helpdesk/security ticket, training record and incident escalation trail.
Deepfake audio or video impersonationTreasury, payroll or vendor payment release accepts voice/video confirmation as sufficient evidence for exceptional approval.Secondary written approval, maker-checker release, call-back evidence, bank portal log and board/committee ratification where relevant.
Malicious code inserted with AI assistanceApplication or report changes move to production without code review, change ticket, access segregation or deployment approval.Change request, code review, deployment log, privileged access log, rollback evidence and post-implementation review.
Forged contracts or legal documentsProcurement, revenue or treasury teams rely on unsigned drafts, unauthenticated PDFs or unsupported amended terms.Executed contract, version history, board/contract approval, counterparty confirmation, obligation register and revenue/payment linkage.
Fabricated applicants or employee profilesHiring and payroll onboarding accept generated resumes, identities or references without independent verification.Background verification, PAN/bank/PF/ESI checks, joining approval, employee master change log and first salary release.
Synthetic identity fraudCustomer, vendor or employee onboarding lacks duplicate, related-party, bank-account and document-authenticity checks.KYC/registration documents, bank validation, duplicate master checks, related-party screening and transaction history.
Cycle test plan

Where internal audit should test first fieldwork

P2P
  • Select vendor creations and bank-detail changes near high-value or urgent payments.
  • Match invoice support to PO, GRN, e-invoice/GST records where applicable and source metadata.
  • Check whether any exception payment relied only on email, voice or PDF evidence.
O2C
  • Review customer onboarding, credit-limit overrides and last-minute billing changes for source approval.
  • Trace unusual credit notes, revised contracts and dispatch/service evidence back to originating systems.
  • Check whether fabricated customer support or related-party indicators were investigated.
R2R
  • Test manual journals posted near close with weak narration, unusual attachments or same-user approval.
  • Verify provision, accrual and contract support at source, not only from generated summaries.
  • Check whether management estimates relied on unsupported AI-generated analysis.
H2R
  • Test new hires, rehires and salary changes for background verification and master-change approval.
  • Match payroll bank accounts, PAN, PF/ESI and attendance records for duplicate or synthetic indicators.
  • Check leaver access and post-exit payments where social engineering could bypass normal controls.
Treasury
  • Test urgent fund transfers, bank mandate changes and covenant submissions for non-email approval.
  • Verify bank portal maker-checker logs and callback evidence for exceptional releases.
  • Check whether deepfake or executive-impersonation risk is covered in payment-release procedures.
ITGC
  • Test privileged access, change management and deployment logs for AI-assisted code or script changes.
  • Review access to AI tools, document-generation systems and finance report extract utilities.
  • Confirm incident, phishing and security-alert evidence is retained for internal-audit review.
Evidence skepticism

Verify generated evidence at the source source

AI-generated emails, PDFs, contracts, voice notes, screenshots and summaries can look complete while being unsupported. Internal audit should separate three things in the workpaper: the red flag, the source evidence inspected, and the reviewer conclusion. If the conclusion depends only on generated content, the evidence file is weak.

Minimum reviewer question

Can an independent reviewer trace this exception to an original system record, third-party confirmation, approved ticket, immutable log, bank portal record or signed source document without relying on the generated artefact itself?

Monitoring rules

AI-fraud-specific rule examples exceptions

These examples do not prove fraud. They create recurring exception queues for reviewer conclusion and follow-up. Use the full monitoring library for broader P2P, O2C, R2R, H2R, treasury, compliance and ITGC rules.

CycleRule exampleData source
P2PNew vendor + first payment within 7 days + high-value or round invoice amountVendor master, AP ledger, payment run, invoice metadata
P2PVendor bank account changed within 10 days before payment releaseVendor master audit log, bank file, approval ticket
TreasuryUrgent manual transfer with email approval and no callback evidenceBank portal log, treasury register, email/ticket trail
H2RNew employee with duplicate bank account, missing statutory ID or no attendance recordHRMS, payroll, bank file, PF/ESI/PT records
R2RManual journal with attached support created outside the source processGL, journal attachment, source system, approver log
ITGCPrivileged deployment or script change without ticket/code reviewChange system, repository log, deployment log, privileged activity
Download monitoring rules
Execution files

Use the existing workpapers downloads

AI Governance Workpaper

Build the AI inventory, owner RACI and governance test file before assessing AI-enabled fraud exposure.

Monitoring Rules Library

Download the wider cycle-wise exception-rule library for P2P, O2C, R2R, payroll, treasury, compliance and ITGC.

RCM Builder

Turn fraud-readiness risks into controls, tests, evidence and reviewer columns.

Fieldwork Tracker

Track test status, evidence blockers, exceptions and reviewer conclusions.

Evidence Escalation Tracker

Escalate missing source evidence before a red flag is treated as an audit observation.

Observation Report Generator

Convert validated exceptions into a report pack only after evidence and root cause are reviewed.

Authority notes

What the sources do and do not prove limits

IIA/AuditBoard AI-enabled fraud survey, 2026
IIA Internal Audit and AI-Enabled Fraud report page
IIA Internal Auditor: AI Truth Decay, June 2026
ACFE Occupational Fraud 2026: Report to the Nations
ACFE/SAS 2026 Anti-Fraud Technology Benchmarking findings

These sources support risk awareness, threat taxonomy and preparedness design. They do not endorse CORAA, create an India-specific legal standard, prove fraud in any entity or replace professional judgement.

FAQ

Practical answers for internal audit teams questions

What is AI-enabled fraud in internal audit?

AI-enabled fraud means a fraud risk where artificial intelligence is used to scale, disguise or accelerate deception: phishing, fake invoices, forged contracts, deepfake approvals, synthetic identities, fabricated applicants, malicious code or generated support documents. Internal audit should treat these as red flags that need source verification, not as automatic fraud conclusions.

Does this checklist replace forensic audit?

No. This is a preparedness and control-testing checklist for internal audit before or around an incident. It does not determine who committed fraud, quantify legal loss, preserve evidence for court or replace a forensic investigation.

Can an AI-generated document be used as audit evidence?

A generated document by itself should not be treated as sufficient evidence. The auditor should verify the source record, system log, approval trail, counterparty confirmation or original transaction population behind it, then document the reviewer conclusion.

Is the IIA/AuditBoard AI-enabled fraud survey India-specific?

No. The survey was based on senior internal audit leaders in North America. It is useful as a current risk signal, but Indian internal audit teams should tailor procedures to their own systems, contracts, DPDP obligations, sector rules and fraud-risk assessment.

Next step

Turn the risk map into an audit file. workpaper.

Start with the AI governance workpaper, then route selected risks into the RCM, monitoring rules, fieldwork tracker and observation report only after source evidence is reviewed.

Build AI governance workpaperOpen internal audit hub