How should client audit data be protected when using AI?
Client audit data should be protected through the same disciplined controls expected for other confidential engagement systems, with additional attention to how AI providers process and retain information.
Firms should understand:
- where the data is hosted and processed;
- whether client evidence is used to train models;
- how access is restricted and logged;
- encryption in transit and at rest;
- retention and deletion arrangements;
- subprocessors and model providers;
- incident response and business continuity;
- independent security assurance.
The contract and technical design should match the answer given to clients. Audit teams also need practical controls: upload only relevant evidence, use approved tools, avoid personal accounts and keep access aligned to the engagement team.
Platformed capability: Platformed states that client audit evidence is not used to train AI models. It is backed by ISO 27001 certification and a SOC 2 Type II report, with local data-hosting options available. Firms should still complete their own security, legal and procurement assessment based on their clients and jurisdictions.
References: Platformed security information · Platformed Trust Center