Strip away the demos and every AI-in-audit question reduces to these. They are also, not coincidentally, the questions a peer reviewer or NFRA inspector will ask about machine-assisted work.
A finding that changes every time the tool runs cannot be defended in a peer review or an NFRA inspection — the reviewer will ask you to show how you got it. Whatever AI you use, the numbers, selections and exceptions must come from deterministic computation you can re-run; the model layer belongs on top, explaining, never underneath, computing. Ask any vendor: "if I run the same engagement twice, do I get the same answer, byte for byte?"
SA 200 places the opinion on the auditor, and no standard carves out an exception for machine assistance. In practice that means AI may draft, rank, summarise and suggest — and the auditor concludes. The cleanest discipline: AI never writes a figure into a working paper. Amounts come from the books through computation; the model writes only the words around them, and even those get reviewed.
Client books are stuffed with personal data — employee payroll, director PANs, customer ledgers — and the DPDP Act 2023 applies to it. Before any ledger leaves your office, know where the tool processes and stores data, whether it trains on your clients’ books, and whether hosting is in India. The Code of Ethics confidentiality duty (and your engagement letter) applies to a model API exactly as it applies to an article assistant.
Drafting emails faster is nice; the structural change is that software reads 100% of the population. Sampling exists because humans cannot read fifty thousand vouchers — machines can, and then surface the entries that deserve judgment: unusual journal combinations, round-sum month-end entries, related-party patterns, Benford deviations. SA 530 sampling still has its place, but risk assessment on the full population is a materially stronger base for it.
SA 230 asks for documentation that lets an experienced auditor understand what was done and why. When AI assists, record what ran, on what data, what it flagged, and what you did with each flag. If the vendor disappeared tomorrow, your working-paper file should still tell the whole story — exports, locked papers, and the trail of who reviewed what.
Internal audit is where AI becomes operational fastest because the work repeats by cycle. The useful pattern is not “ask a chatbot for an audit programme”; it is a controlled workflow where the RCM, exception logic, evidence and management action tracker all refer to the same population.
Challenge the annual plan against cyber, AI, third-party, P2P, R2R, compliance, monitoring, treasury, H2R and closure risks.
Open resource ->Audit critical vendors, AI providers and outsourced systems for data access, SLA breaches, sub-outsourcing, BCP and exit readiness.
Open resource ->Define approved IA use cases, data boundaries, governance gates, documentation rules, quality metrics and rollout plan before AI use spreads informally.
Open resource ->Audit the company’s own AI systems: inventory, ownership, data/privacy controls, model changes, validation, incidents, human review and monitoring.
Open resource ->Map AI phishing, fabricated invoices, deepfake approvals, synthetic identities and generated evidence risks to internal-audit controls and source verification.
Open resource ->Use AI to summarise prior findings, ERP change, process change and compliance history; keep the scorecard deterministic so the audit plan is explainable.
Open resource ->Start from a control repository, then let AI suggest missing risks, duplicate controls and weak test procedures before the auditor locks the programme.
Open resource ->Convert recurring exceptions into rule logic: duplicate vendors, stale BRS items, late compliance payments, SoD conflicts and month-end journal spikes.
Open resource ->Use AI to read access dumps, change tickets and backup logs, but test access, SoD and change approvals against source evidence.
Open resource ->AI can convert exception facts into condition-criteria-cause-effect-recommendation format; the auditor owns severity, root cause and recommendation.
Open resource ->Summarise management responses, ageing and repeat findings, then route overdue or unsupported closures back to fieldwork.
Open resource ->The most reliable implementation path is a controlled replay of a known file, not a firm-wide rollout. That protects audit quality and makes the productivity gain measurable.
For internal audit teams, AI should sit around a conventional file structure: scope, risk assessment, RCM, monitoring rule, exception evidence, observation and action taken report. That is the difference between useful automation and a collection of disconnected chatbot prompts.
Take these to any vendor demo — including ours. A “no” on any row is a finding waiting to happen.
| Ask | Why it decides |
|---|---|
| Same input, same output? | Re-runs must reproduce byte-identically — the peer-review and NFRA test. |
| Who writes the figures? | Amounts should be computed from the books, never generated by a model. |
| Can every number drill to a voucher? | Auditors trust vouchers, not indicators. A metric with no drill-down is an assertion, not evidence. |
| Where does the data live? | India hosting, no training on client data, DPDP-compatible processing. |
| Does the file export and lock? | Working papers must survive outside the tool — locked, dated, reviewable. |
| Does it suggest or decide? | Good tools surface and explain; the conclusion box belongs to the auditor. |
CORAA is built as our answer to this table — deterministic computation underneath, AI narration on top, every number drilling to its voucher. See the AI Modules or start free: your first audit is on us. See also audit software in India — what to actually evaluate for how this maps onto the wider tooling landscape.
Yes. The Standards on Auditing are technology-neutral — nothing in the current SAs, or revised standards as and when notified, prohibits machine assistance, and ICAI itself is building AI tooling for members. What the standards do fix is responsibility: the auditor signs, so the auditor must be able to reproduce, evaluate and document whatever the tool contributed (SA 200, SA 230).
The evidence points the other way: AI is absorbing the reading — scanning full ledger populations, drafting schedules, reconciling registers — while the concluding remains human because the law puts the signature, the skepticism and the liability on a member. The realistic risk is competitive, not existential: firms that audit with full-population tooling will out-deliver firms that sample by hand at the same fee.
CA GPT (ai.icai.org) is ICAI’s conversational AI platform for members and students — annual-report analysis, financial ratios, exam support and task-specific assistants. ICAI stated at AIS 2026 that it had built 150+ GPT-based tools, trained 50,000+ members in AI, signed an MoU with Sarvam AI and launched AICA Level 3. CA GPT is a research assistant, not an audit tool: it does not connect to client books or produce working papers.
Only if they are reproducible and reviewed. A reviewer will test three things: can the firm regenerate the paper and get the same result; do the figures trace to the books; and did a member actually review and conclude. Papers that pass those tests are fine regardless of what drafted them; papers that fail them are indefensible even if a human typed every word.
Judge any tool — including ours — against the evaluation checklist above: deterministic re-runs, computed (never generated) figures, voucher-level drill-down, India hosting, exportable locked files, and suggestions rather than verdicts. CORAA is our answer to that checklist for Indian statutory audit — Tally-native, full-population scrutiny, Schedule III / CARO / 3CD reporting — and your first audit on it is free, which is the honest way to evaluate.
Start narrow and data-first: pick one completed engagement whose books you know, run it through the tool, and compare its output against what the team concluded by hand. Automate the reading layers first — ledger scrutiny, reconciliations, ageing, lead schedules — and keep partner review gates exactly where they are. Document the tool’s role in the file under SA 230 from engagement one, train the team on evaluating flags rather than clearing them, and only then scale across the client list. Budget for the checklist above before price.
AI is most useful in internal audit when it turns recurring process data into reviewable exceptions: duplicate vendors, SoD conflicts, stale BRS items, unusual journals, delayed compliance payments, payroll changes and overdue action plans. It should accelerate risk assessment, RCM drafting, monitoring and observation writing; it should not replace auditor judgment on root cause, severity or closure.
The file should show the data used, rule or prompt applied, tool output, exception population, reviewer conclusion and management response. For AI-drafted observations, retain the source exception facts separately from the narrative draft so a reviewer can see which part was computed, which part was suggested, and which part the auditor concluded.
ICAI facts sourced from ai.icai.org and ICAI’s 26 June 2026 AI Innovation Summit release; standards status from NFRA/MCA reporting — verify current notification status before citing dates in a report.