Auditing AI employees:

How auditors assess risks and control

How auditors assess risks and control
  • Blog
  • 24/09/26
Yan Borboën

Yan Borboën

Partner, Leader Digital Assurance & Trust, PwC Switzerland

Mark Meuldijk

Mark Meuldijk

Director, AI Assurance & Trust, PwC Switzerland

Artificial intelligence is transforming financial processes. This is changing the requirements for controls, traceability and financial audits.

Artificial intelligence is increasingly evolving from a productivity tool into an end-to-end solution for core business processes. The trend is towards so-called agentic AI: systems with greater autonomy that can independently plan, perform and optimise tasks.

AI agents, mostly based on generative AI, can be regarded as digital employees. They process instructions in natural language, interact with IT systems and deliver results. In financial processes, they can retrieve and analyse data, support decisions and prepare reports.

Accordingly, AI is becoming increasingly relevant to the preparation of financial statements, including in sales, procurement, inventory management, consolidation and general ledger accounting. For example, it can support inventory-taking activities that affect financial reporting, or analyse receivables, identify overdue balances and prepare commentary for further review. Activities that were previously performed manually are increasingly being supported by digital assistants.

Evidence rather than mere trust

This also brings AI increasingly into the focus of financial audits. The central question is whether its use could impair the reliability of financial reporting. Unlike traditional automation, generative AI is based on probabilities, is trained on large datasets that are often not fully validated, and operates through complex neural networks whose reasoning steps that lead to their conclusions may be difficult to trace. If AI agents process financial data, support financial decisions or prepare reports, companies must be able to demonstrate that this does not result in material misstatements. What matters is robust evidence, not mere trust in the technology.

The audit begins by determining whether AI is used in processes relevant to financial reporting. An AI application inventory or AI agent register can provide a basis for this assessment. Auditors then assess which tasks the agents perform or support, whether they affect the financial statements, and what impact potential errors could have on the balance sheet or income statement.

This is followed by the risk assessment: Which AI-related risks could impair the reliability of the results? What consequences could this have for financial reporting? And what measures has the company implemented to reduce these risks to an acceptable level?

Responsibility remains with people

Despite technological progress, one fundamental principle remains unchanged: responsibility lies with people. Employees must review, challenge and approve AI processing and results. This includes reconciling information with source systems, validating key processing steps and documenting the supporting evidence. The audit trail should meet the same requirements as work performed by a person. This “human in the loop” principle remains a key control measure.

Auditors also assess other aspects of the company’s AI control environment. These include:

  • Responsibilities: Responsibilities for operation, monitoring and escalation are clearly defined.
  • Data quality: Measures are in place to ensure that data sources are reliable and relevant.
  • Security: AI systems are protected against manipulation and misuse.
  • Traceability: The sources, processes and results of AI systems can be reviewed.
  • Risk monitoring: Hallucinations, model drift and security risks are continuously monitored, with clear measures taken when deficiencies are identified.
  • Access rights: AI systems may only be used or modified by authorised individuals.
  • External assurance: Independent assurance reports or certifications such as ISO/IEC 42001 provide additional assurance.

However, there is no universally applicable checklist. The requirements depend on the specific use case, the underlying processes, the financial-reporting risks and the company’s control environment. The auditor’s role is to obtain sufficient appropriate evidence and conduct the audit using a risk-based approach.

One thing is clear: as AI becomes increasingly integrated into core business processes, the requirements for governance, controls and traceability will continue to rise. For companies and auditors, the question is therefore becoming less whether AI needs to be audited more how its use can be designed to be reliable and transparent. 

This article was originally published on bilanz.ch in German

Contact our experts

Yan Borboën

Partner, Leader Digital Assurance & Trust, PwC Switzerland

+41 58 792 84 59

Email

Mark Meuldijk

Director, AI Assurance & Trust, PwC Switzerland

+41 58 792 44 00

Email