What makes an AI-generated audit output defensible?
An AI-generated audit output is defensible when a reviewer can understand what the system did, which evidence it used, how the conclusion was reached, what judgement the auditor applied and how exceptions were resolved.
Defensibility comes from the evidence chain, not the confidence of the wording. The output should link claims to source material, separate evidence from inference, preserve contradictory information and show the review history. The procedure should also align to the firm's approved methodology and be appropriate for the engagement.
The system itself needs governance: defined use cases, testing, access controls, change management and monitoring. But a well-governed tool can still produce weak work if the engagement input is poor or the auditor reviews it superficially.
A useful test is whether an experienced auditor who was not involved in preparing the work could understand the nature, timing and extent of the procedure, the evidence obtained and the significant conclusions. AI should make that easier, not ask the reviewer to trust an invisible model process.
Platformed capability: Platformed keeps each material conclusion connected to the evidence, rationale, exceptions and review history. That makes the work inspectable; it does not make an unsupported conclusion defensible.
References: ISA 230 audit documentation · FRC AI in Audit