How should auditors review AI-generated conclusions?
Auditors should review an AI-generated conclusion in the same way they would review other prepared audit work: understand the procedure, inspect the relevant evidence, challenge the rationale, investigate exceptions and decide whether the conclusion is appropriate.
The review should not be reduced to reading the final paragraph. The auditor needs access to the evidence and should pay particular attention to:
- unsupported or overly broad statements;
- evidence that contradicts the conclusion;
- missing documents or incomplete populations;
- assumptions the system has made;
- changes from the prior year or expected process;
- conclusions with low confidence or high judgement.
Review depth should respond to risk. A low-risk, repeatable assessment may use focused exception review once the workflow is proven. A significant judgement or new use case needs deeper inspection.
The system should record comments, overrides and approvals so the final file shows the auditor's involvement. Human review is not a ceremonial control added at the end. It is part of how the audit evidence becomes a conclusion the team can stand behind.
Platformed capability: Platformed gives the reviewer direct access to the source evidence and records changes, comments, overrides and approvals. Review depth remains a matter for the firm and engagement team.
References: FRC generative and agentic AI guidance · IAASB overreliance on technology guidance