What should an audit firm document about its use of AI?
An audit firm should document enough for an experienced reviewer to understand how AI affected the procedure, what evidence was used, how the output was evaluated and who remained responsible for the conclusion.
Depending on the use case, relevant documentation may include:
- the approved purpose and scope of the tool;
- the procedure the AI performed or supported;
- the data and evidence provided to it;
- significant configuration or methodology settings;
- how completeness and accuracy of inputs were considered;
- exceptions, contradictory evidence and limitations;
- the auditor's review, changes and approval;
- the version of the tool or workflow where that is relevant.
The engagement file does not need to become a technical model dossier. Central firm functions may retain validation, security and change-management evidence, while the engagement documents how the approved tool was used on that audit.
The FRC's guidance makes the direction clear: firms should be able to explain and evidence the use of AI, not treat it as an invisible productivity layer.
References: FRC AI in Audit · ISA 230 audit documentation