CORAA
AI × Statutory Audit · 2026

AI in audit and internal audit — what actually matters.

ICAI has trained 50,000+ members in AI, built 150+ GPT-based tools, signed an MoU with Sarvam AI and launched AICA Level 3. The question for a practising firm is no longer whether to use AI — it is which uses create audit evidence, which only create drafts, and which controls keep the file defensible.

The five things that matter

Strip away the demos and every AI-in-audit question reduces to these. They are also, not coincidentally, the questions a peer reviewer or NFRA inspector will ask about machine-assisted work.

1 · If you cannot reproduce it, it is not audit evidence

A finding that changes every time the tool runs cannot be defended in a peer review or an NFRA inspection — the reviewer will ask you to show how you got it. Whatever AI you use, the numbers, selections and exceptions must come from deterministic computation you can re-run; the model layer belongs on top, explaining, never underneath, computing. Ask any vendor: "if I run the same engagement twice, do I get the same answer, byte for byte?"

2 · Responsibility does not transfer

SA 200 places the opinion on the auditor, and no standard carves out an exception for machine assistance. In practice that means AI may draft, rank, summarise and suggest — and the auditor concludes. The cleanest discipline: AI never writes a figure into a working paper. Amounts come from the books through computation; the model writes only the words around them, and even those get reviewed.

3 · Confidentiality now has a statute

Client books are stuffed with personal data — employee payroll, director PANs, customer ledgers — and the DPDP Act 2023 applies to it. Before any ledger leaves your office, know where the tool processes and stores data, whether it trains on your clients’ books, and whether hosting is in India. The Code of Ethics confidentiality duty (and your engagement letter) applies to a model API exactly as it applies to an article assistant.

4 · The real win is coverage, not speed

Drafting emails faster is nice; the structural change is that software reads 100% of the population. Sampling exists because humans cannot read fifty thousand vouchers — machines can, and then surface the entries that deserve judgment: unusual journal combinations, round-sum month-end entries, related-party patterns, Benford deviations. SA 530 sampling still has its place, but risk assessment on the full population is a materially stronger base for it.

5 · The file must stand without the tool

SA 230 asks for documentation that lets an experienced auditor understand what was done and why. When AI assists, record what ran, on what data, what it flagged, and what you did with each flag. If the vendor disappeared tomorrow, your working-paper file should still tell the whole story — exports, locked papers, and the trail of who reviewed what.

Where AI changes internal audit

Internal audit is where AI becomes operational fastest because the work repeats by cycle. The useful pattern is not “ask a chatbot for an audit programme”; it is a controlled workflow where the RCM, exception logic, evidence and management action tracker all refer to the same population.

Internal audit priority risk areas 2026

Challenge the annual plan against cyber, AI, third-party, P2P, R2R, compliance, monitoring, treasury, H2R and closure risks.

Open resource ->

Third-party AI and outsourcing risk

Audit critical vendors, AI providers and outsourced systems for data access, SLA breaches, sub-outsourcing, BCP and exit readiness.

Open resource ->

Internal audit AI strategy template

Define approved IA use cases, data boundaries, governance gates, documentation rules, quality metrics and rollout plan before AI use spreads informally.

Open resource ->

AI governance internal audit workpaper

Audit the company’s own AI systems: inventory, ownership, data/privacy controls, model changes, validation, incidents, human review and monitoring.

Open resource ->

AI-enabled fraud preparedness

Map AI phishing, fabricated invoices, deepfake approvals, synthetic identities and generated evidence risks to internal-audit controls and source verification.

Open resource ->

Audit-universe risk scoring

Use AI to summarise prior findings, ERP change, process change and compliance history; keep the scorecard deterministic so the audit plan is explainable.

Open resource ->

RCM drafting and tailoring

Start from a control repository, then let AI suggest missing risks, duplicate controls and weak test procedures before the auditor locks the programme.

Open resource ->

Continuous monitoring rules

Convert recurring exceptions into rule logic: duplicate vendors, stale BRS items, late compliance payments, SoD conflicts and month-end journal spikes.

Open resource ->

ITGC and ERP control review

Use AI to read access dumps, change tickets and backup logs, but test access, SoD and change approvals against source evidence.

Open resource ->

Observation drafting

AI can convert exception facts into condition-criteria-cause-effect-recommendation format; the auditor owns severity, root cause and recommendation.

Open resource ->

Follow-up and ATR monitoring

Summarise management responses, ageing and repeat findings, then route overdue or unsupported closures back to fieldwork.

Open resource ->

Implementation sequence for a CA firm

The most reliable implementation path is a controlled replay of a known file, not a firm-wide rollout. That protects audit quality and makes the productivity gain measurable.

  1. Pick one completed engagement where the partner knows the file well. Do not start with the largest client.
  2. Load only the data required for one cycle: P2P, R2R, O2C, payroll, treasury or ITGC.
  3. Run the same population through the old programme and the AI-assisted workflow, then compare exceptions, false positives and missed issues.
  4. Document exactly where AI was used: rule design, summarisation, observation drafting, reviewer notes or follow-up analysis.
  5. Lock the exportable working paper and confirm every exception drills back to source evidence.
  6. Train the team to clear exceptions with reasons, not just to accept the tool output.
Download evaluation checklistSee Internal Audit module

The AI internal audit stack

For internal audit teams, AI should sit around a conventional file structure: scope, risk assessment, RCM, monitoring rule, exception evidence, observation and action taken report. That is the difference between useful automation and a collection of disconnected chatbot prompts.

Scope with AI carefullyUse AI to draft the SOW and data request list, then lock management-approved scope and exclusions.Open ->Request the right dataCreate a PBC tracker with source system, owner, purpose, due date and status before testing starts.Open ->Rank the audit universeSummarise change, compliance sensitivity and prior issues, but keep the scoring factors visible.Open ->Build the RCMGenerate control rows for the selected cycle, then edit risk, evidence and sample approach before fieldwork.Open ->Run monitoring rulesTurn exceptions into repeatable logic for duplicate payments, stale BRS, leaver access and late filings.Open ->Export cycle workbooksUse P2P, O2C, R2R, H2R, treasury, inventory, fixed assets, compliance and ITGC Excel/PDF packs.Open ->Track action takenUse AI to summarise ageing and repeat issues, not to close observations without evidence.Open ->

Evaluating an AI audit tool: six questions

Take these to any vendor demo — including ours. A “no” on any row is a finding waiting to happen.

AskWhy it decides
Same input, same output?Re-runs must reproduce byte-identically — the peer-review and NFRA test.
Who writes the figures?Amounts should be computed from the books, never generated by a model.
Can every number drill to a voucher?Auditors trust vouchers, not indicators. A metric with no drill-down is an assertion, not evidence.
Where does the data live?India hosting, no training on client data, DPDP-compatible processing.
Does the file export and lock?Working papers must survive outside the tool — locked, dated, reviewable.
Does it suggest or decide?Good tools surface and explain; the conclusion box belongs to the auditor.

CORAA is built as our answer to this table — deterministic computation underneath, AI narration on top, every number drilling to its voucher. See the AI Modules or start free: your first audit is on us. See also audit software in India — what to actually evaluate for how this maps onto the wider tooling landscape.

Resources to use next

Internal Audit ResourcesThe full hub: Section 138, SIA, RCMs, checklists, calculators and templates.Open ->Internal Audit Priority Risk Areas 2026Planning hub for 2026 internal-audit priorities with direct links to workpapers and monitoring tools.Open ->Internal Audit AI Strategy TemplateAI adoption plan for IA teams with use-case register, governance gates, evidence rules and metrics.Open ->AI Governance WorkpaperEngagement-ready AI governance internal audit file with Excel/PDF export.Open ->Internal Audit ModuleCORAA product workflow for RCMs, continuous process monitors, observations and reporting.Open ->Enterprise IntelligenceMoney-flow graph, Business DNA, CFO vitals and internal-audit signals from the same voucher population.Open ->AI Tool Evaluation ChecklistVendor checklist for determinism, evidence, hosting, security and audit-file exports.Open ->Audit Software IndiaHow to evaluate audit software beyond demos, dashboards and generic AI claims.Open ->

AI in audit, frequently asked

Is AI allowed in a statutory audit in India?

Yes. The Standards on Auditing are technology-neutral — nothing in the current SAs, or revised standards as and when notified, prohibits machine assistance, and ICAI itself is building AI tooling for members. What the standards do fix is responsibility: the auditor signs, so the auditor must be able to reproduce, evaluate and document whatever the tool contributed (SA 200, SA 230).

Will AI replace chartered accountants?

The evidence points the other way: AI is absorbing the reading — scanning full ledger populations, drafting schedules, reconciling registers — while the concluding remains human because the law puts the signature, the skepticism and the liability on a member. The realistic risk is competitive, not existential: firms that audit with full-population tooling will out-deliver firms that sample by hand at the same fee.

What is CA GPT from ICAI?

CA GPT (ai.icai.org) is ICAI’s conversational AI platform for members and students — annual-report analysis, financial ratios, exam support and task-specific assistants. ICAI stated at AIS 2026 that it had built 150+ GPT-based tools, trained 50,000+ members in AI, signed an MoU with Sarvam AI and launched AICA Level 3. CA GPT is a research assistant, not an audit tool: it does not connect to client books or produce working papers.

Can AI-generated working papers survive a peer review?

Only if they are reproducible and reviewed. A reviewer will test three things: can the firm regenerate the paper and get the same result; do the figures trace to the books; and did a member actually review and conclude. Papers that pass those tests are fine regardless of what drafted them; papers that fail them are indefensible even if a human typed every word.

Which is the best AI audit software for CA firms?

Judge any tool — including ours — against the evaluation checklist above: deterministic re-runs, computed (never generated) figures, voucher-level drill-down, India hosting, exportable locked files, and suggestions rather than verdicts. CORAA is our answer to that checklist for Indian statutory audit — Tally-native, full-population scrutiny, Schedule III / CARO / 3CD reporting — and your first audit on it is free, which is the honest way to evaluate.

How do I implement AI audit automation in my CA firm?

Start narrow and data-first: pick one completed engagement whose books you know, run it through the tool, and compare its output against what the team concluded by hand. Automate the reading layers first — ledger scrutiny, reconciliations, ageing, lead schedules — and keep partner review gates exactly where they are. Document the tool’s role in the file under SA 230 from engagement one, train the team on evaluating flags rather than clearing them, and only then scale across the client list. Budget for the checklist above before price.

How is AI useful in internal audit?

AI is most useful in internal audit when it turns recurring process data into reviewable exceptions: duplicate vendors, SoD conflicts, stale BRS items, unusual journals, delayed compliance payments, payroll changes and overdue action plans. It should accelerate risk assessment, RCM drafting, monitoring and observation writing; it should not replace auditor judgment on root cause, severity or closure.

What should an internal auditor document when AI is used?

The file should show the data used, rule or prompt applied, tool output, exception population, reviewer conclusion and management response. For AI-drafted observations, retain the source exception facts separately from the narrative draft so a reviewer can see which part was computed, which part was suggested, and which part the auditor concluded.

ICAI facts sourced from ai.icai.org and ICAI’s 26 June 2026 AI Innovation Summit release; standards status from NFRA/MCA reporting — verify current notification status before citing dates in a report.