How should audit firms manage hallucination risk?
Audit firms should manage hallucination risk by constraining the AI to relevant evidence, requiring source citations, making uncertainty visible and keeping an auditor responsible for the conclusion.
Hallucinations are plausible statements that are not supported by the available facts. In audit, the danger is not only a dramatic invented answer. It may be a subtle control description, missing qualification or confident conclusion that goes beyond the evidence.
Practical controls include:
- using engagement evidence rather than open-web generation for conclusions;
- requiring every material statement to link to a source;
- preventing the model from silently filling an evidence gap;
- testing the workflow against known cases and edge cases;
- routing low-confidence or contradictory results for review;
- monitoring overrides and recurring errors;
- controlling model and prompt changes.
No control removes the need for professional scepticism. The aim is to make unsupported output difficult to create and easy to detect. A product that produces fluent answers without an evidence chain is not suitable for important audit conclusions.
References: FRC generative and agentic AI guidance · IAASB technology overreliance guidance