After 28 years leading internal audit functions across Big 4 firms and as CAE at Informatica, I have seen the profession transform many times. From paper-based working papers to Excel, from Excel to GRC platforms, from periodic audits to continuous monitoring. Each shift was met with resistance, then adoption, then wonder at how we ever worked without it.

We are at the beginning of the most significant shift yet. And unlike previous transitions, this one is happening faster than the profession is ready for.

Where the Profession Stands Today

The data is sobering. The IIA's 2024 Global Internal Audit Common Body of Knowledge (CBOK) shows that fewer than 30% of internal audit functions are using AI tools in any meaningful way. Most teams are still manually classifying evidence, drafting findings by hand, and spending the majority of their time on documentation rather than judgment.

Meanwhile, the regulatory environment is moving quickly. PCAOB staff guidance on AI acknowledges its growing role in audit but emphasises that auditor responsibility — and auditor accountability — cannot be delegated to a machine. The SEC has issued guidance requiring disclosure of AI use in financial reporting, which creates an entirely new demand: not just audit with AI, but audit of AI. The Big 4 are investing heavily in AI for financial statement audit. Internal audit, for the most part, has been left behind.

What AI Can and Cannot Do in Audit

I want to be honest here, because the hype often outpaces the reality. AI is genuinely transformative in some areas and genuinely limited in others. Knowing the difference is what separates good AI adoption from reckless dependency.

What AI does well

What AI cannot do — and should not

The PCAOB and SEC Direction

PCAOB AS 2201 does not prohibit AI in MRC testing — but it requires the auditor to evaluate the control, not merely the AI output. If you use AI to assess whether a management review control was performed effectively, you still need to document how you evaluated the AI's conclusion and why you agree or disagree with it. The AI is an input to your judgment, not a substitute for it.

PCAOB staff have been consistent: AI tools are aids to auditor judgment. They do not change the fundamental accountability of the auditor for their work. The direction of travel is toward more AI use, accompanied by stronger documentation standards for how AI was used and how conclusions were independently validated.

AssurAI's human-in-the-loop design is built specifically to meet this requirement. Every AI output is labelled as a draft. Every classification, conclusion, and recommendation requires auditor sign-off before it enters the engagement file. This is not a limitation — it is a deliberate design choice aligned to professional standards.

What External Auditors Are Thinking

The Big 4 firms are building their own AI tools for their own use. They are not sharing these tools with internal audit clients. What they are doing is asking increasingly pointed questions in management letters and audit committee communications: How are you using AI? How are you validating AI outputs? What controls do you have over AI-generated content?

These are questions CAEs need to be able to answer. External auditors who used to ask about your sampling methodology are now asking about your AI governance framework. The auditor of the future will need to understand AI not to build it, but to govern it — to assess how management is using AI in financial reporting processes and whether appropriate controls are in place.

This creates a new competency requirement for CAEs. Not software engineering. Not data science. But AI literacy — the ability to understand what AI can and cannot do, what controls are needed around it, and how to audit an AI-assisted process.

Will AI Make Internal Auditors Redundant?

I get this question regularly. Let me answer it directly.

No. But it will change what auditors spend their time on — and that change is already happening.

AI handles the routine. Classification, documentation, initial drafting, population testing. Auditors focus on judgment, relationships, and insight — the things that actually drive audit value and cannot be automated. The auditors who use AI effectively will cover more ground with smaller teams. A team of five that uses AI well can produce the output of a team of eight working traditionally.

The real risk is not AI replacing auditors. It is auditors who use AI replacing those who do not. The profession has always rewarded efficiency, and AI is the most significant efficiency multiplier since the spreadsheet.

IIA Standard 2030 on resource management requires CAEs to ensure the function has the competencies needed to fulfil its responsibilities. AI literacy is becoming one of those competencies. CAEs who ignore this are not just missing an opportunity — they may be failing a professional obligation.

Practical Advice for CAEs

If you are a CAE thinking about how to approach AI adoption, here are five recommendations based on what I have seen work — and what I have seen fail.

  1. Start with one use case. Evidence Intelligence or MRC testing are strong starting points — well-defined, bounded, and easy to validate. Do not try to transform everything at once. Run a pilot, validate the outputs, build confidence, then expand.
  2. Build AI literacy in your team. You do not need data scientists. You need auditors who understand enough about how LLMs work to use them well and to spot when they are wrong. Even a half-day introduction to AI concepts reduces fear and improves usage quality significantly.
  3. Document your AI usage. PCAOB and external auditors will ask. Create a simple policy that defines what AI is used for in your function, what review is required before AI outputs enter the engagement file, and who is accountable. This does not need to be complex — but it needs to exist.
  4. Maintain the human in the loop. Every AI output should require auditor review before it enters the engagement file. Build this into your process, not as an afterthought but as a default. Document the review. This protects you professionally and creates the audit trail external auditors expect.
  5. Engage your audit committee. Your audit committee is almost certainly asking about AI in other parts of the business. Proactively brief them on how you are using AI in internal audit and how you are managing the risks. This positions you as a thought leader, not a follower.

Conclusion

The question is no longer whether AI will transform internal audit. It is whether your function will lead that transformation or be left behind by it.

The profession has always rewarded those who embrace change thoughtfully — combining new tools with the irreplaceable judgment, integrity, and relationships that define great auditing. The CAEs who will thrive in the next decade are those who understand what AI can do, what it cannot, and how to build a function that leverages both.

That has not changed. Only the tools have.