How to Capture AI’s Efficiency Gains Without Sacrificing Professional Skepticism
prepared by Hafsa Research and Analysis
The Core Tension: Efficiency vs. Accountability
Artificial Intelligence is no longer a future prospect for auditing—it is present reality. EY has embedded agentic AI across 160,000 audit engagements in over 150 countries, processing 1.4 trillion lines of journal entry data annually . KPMG’s Clara platform, built on Microsoft Azure, automates data ingestion and anomaly detection across 80+ countries . PwC’s Halo for Journals analyzes full general-ledger populations, uncovering material misstatements months before manual review would detect them .
The efficiency gains are undeniable. But as the Deloitte Australia incident of 2025 demonstrated, these gains come with equally serious risks. A AU$440,000 report for the Australian government contained fabricated citations and a misquoted federal court judge—errors traced to AI hallucination that slipped through human review .
The path forward lies not in rejecting AI, but in building governance frameworks that capture its power while preserving the professional skepticism that auditing demands.
Solution 1: Establish “Glass Box” Governance Before Scaling AI
The most critical lesson from recent failures is that AI systems must be explainable, auditable, and subject to human override. MindBridge AI’s CEO Eli Fathi captured the principle: AI in finance must be a “glass box,” not a black box.
The regulatory landscape is catching up. In December 2025, the IAASB approved work on non-authoritative guidance for AI in audit, following global roundtables with 240+ stakeholders . The PCAOB’s Technology Innovation Alliance has floated a documentation framework. Until binding standards arrive, firms operate on internal judgment—making proactive governance essential.
Action step: Inventory every AI tool used in audit or financial reporting. For each, document: What data trains it? How are outputs validated? Who is accountable when it errs? If you cannot answer these questions, you are not ready to scale.
Solution 2: Treat Documentation as Non-Negotiable
The Deloitte failure was not solely an AI problem—it was a documentation and review problem. The first version of the 237-page report contained up to 20 errors, including references to non-existent academic papers and a fabricated judicial quotation . These errors persisted because the review process failed to validate AI-generated content.
Current audit standards require procedures to be documented, but do not yet specify whether documentation must include the AI tool’s training data, validation methodology, or known failure modes . This gap means documentation quality varies wildly between engagements.
Action step: Extend your documentation standards to cover AI-assisted work. For every AI-generated output that influences an audit conclusion, record: the prompt or query used, the model and version, the human reviewer’s assessment, and the basis for accepting or rejecting the output.
Solution 3: Preserve Professional Skepticism Through Structured Challenge
EY’s transparency report explicitly addresses the risk of “excessive confidence in technology,” emphasizing that AI tools “do not replace the important role of experience and professional judgment” . The firm requires procedures to encourage responsible use and mitigate over-reliance.
The Wirecard scandal offers a cautionary parallel. EY failed to detect €1.9 billion in missing cash despite having advanced data tools—because the fraud involved falsified documents that technology alone could not expose . Technology cannot replace real-world verification.
Action step: Implement mandatory challenge sessions where auditors must articulate why they accepted or rejected AI-flagged items. If the answer is “the system said so,” that is insufficient. The reasoning must be documented.
Solution 4: Address the “Shadow AI” Problem
A less visible but pervasive risk is the use of unapproved AI tools in the financial close. Staff quietly using consumer chatbots to draft disclosures or analyze data creates outputs with no validation trail—exactly what audit-evidence standards prohibit .
RSM’s analysis identifies this as one of five specific places where AI is quietly creating audit risk right now, alongside generative-AI hallucination in disclosures and thin documentation standards .
Action step: Conduct an anonymous survey of finance and audit staff. Ask: What AI tools are you using? Are they approved? If unapproved tools are in use, address the underlying need—provide approved alternatives with proper governance, rather than simply prohibiting use.
Solution 5: Prepare for the “AI Assurance” Opportunity
As 97% of companies embark on their own AI transformations, they will need accountants to “audit the algorithm” . EY is positioning itself as “client zero” and launching AI assurance services spanning diagnostics, governance, and risk management.
This is both a defensive necessity and a growth opportunity. Firms that build expertise in AI governance will capture high-value advisory work. Firms that lag risk losing ground to competitors who can demonstrate competence in managing “black box” systems.
Action step: Assess your firm’s or finance team’s AI governance capabilities. Can you evaluate whether a client’s or your own AI system is properly validated? If not, build that capability now—before clients or regulators demand it.
Executive Checklist: AI Audit Readiness
Governance:
- □ Inventory all AI tools used in audit or financial reporting
- □ Document validation methodology and human review processes for each
Documentation:
- □ Extend documentation standards to cover AI-assisted work
- □ Require reasoning logs for AI-influenced conclusions
Skepticism:
- □ Implement structured challenge sessions for AI-flagged items
- □ Train staff on recognizing AI hallucination and over-reliance
Risk Management:
- □ Survey staff for unapproved “shadow AI” use
- □ Provide approved alternatives with proper governance
Closing Thought
The Deloitte incident is not an argument against AI in auditing. It is an argument against unchecked AI. The firms that succeed will be those that pair AI’s efficiency with rigorous human judgment, transparent documentation, and a governance framework that treats explainability as non-negotiable.
As the IAASB’s global roundtables revealed, the profession is still building the quality management frameworks that AI-enabled audit requires . Early movers who build these frameworks now will define the standard—and capture the value.
The question is not whether AI belongs in auditing. It is whether your organization is prepared to manage it responsibly.
prepared by Hafsa Research and Analysis Company


