Industry

Preparing Companies for Audits When Deploying AI Systems

As AI is integrated across finance, compliance, IT and other business functions, organizations must be ready to explain and demonstrate how these systems are governed, tested and controlled during audits and certification processes.

Artificial intelligence (AI) is increasingly embedded across business and support functions — finance, compliance, accounting, internal audit, IT, operations, R&D and sales all use AI to increase throughput, speed and quality. PwC observes the same trend internally and among its clients, service providers and partners.

When AI is incorporated into a process, it will sooner or later become subject to inspection or audit. That raises practical questions: what does broader AI usage mean for audits and certification; how will CFOs’ internal control environments and their audits change; and can audit committees adapt quickly enough to this rapidly evolving environment?

AI introduces a complex risk portfolio and requires specialist knowledge. There are few precedents and many open questions from executives, owners and external reviewers. Teams involved in AI governance and AI deployment must stay current so the organization can meet statutory audits, certification or due diligence processes and internal audits when evaluated processes involve AI.

This pressure affects functions with oversight or control roles — CIO and CFO teams, audit committees, legal and compliance units, and internal audit. Preparing for audits, or maintaining continuous audit readiness and maturity, should not slow innovation, but it does require prioritization, focus and dedicated resources from supporting areas.

What organizations must be able to demonstrate

Whether AI supports decision making, customer interactions or internal operations, organizations must be able to explain to auditors and control specialists how AI systems are used and show how these systems are governed, monitored, documented and controlled. These demonstrations are central to building trust with auditors and other stakeholders.

Auditors will review AI‑related policies, governance frameworks and decision procedures: the AI strategy, development roadmaps, how planned and deployed systems are catalogued, how risks associated with catalogued systems are identified and mitigated, how risk appetite is set, and how decisions and resourcing for major risk mitigations are made. Organizations should expect to provide documentation that key controls not only exist but operate effectively — for example technical model documentation, testing records, or results from explainability and bias reviews.

Building an audit‑ready AI control environment

Regardless of an organization’s AI maturity, the following activities form the backbone of an audit‑ready control environment:

  • Integrate AI oversight with existing risk management and control functions. This should cover decisions about tools and models and their deployment; performance measurement and monitoring; and ensuring reliability, explainability and security of models and outputs.
  • Pay special attention when AI models directly affect data used in financial statements or external disclosures. Internal risk teams — such as IT, data governance, compliance and internal audit — play key roles in proactively assessing risks, validating controls and advising on governance practices.
  • Process owners and control owners must understand the risks and changes AI introduces, and be confident participants in audit planning and reviews. Roles such as IT, information security, data protection, legal and compliance often require specific knowledge to explain AI impacts and demonstrate risk management activities.

Inventory, catalogues and shadow AI

Organizations must maintain an up‑to‑date understanding of where AI is used, which processes and decisions it affects, and the characteristics of each application. The goal is a catalogue that shows AI usage across processes and assigns risk levels to individual cases. Ideally, this catalogue supports developers and project managers, assists compliance teams in meeting regulatory requirements, and highlights areas of audit or financial control relevance (for example Sarbanes–Oxley, SOX).

The inventory cannot rely solely on self‑reporting. A control process is needed to identify potential “shadow‑AI” and overlooked areas, such as embedded functionality in third‑party tools, unauthorized deployments, or AI features introduced via system updates. While a central catalogue is good practice, the processes that validate and maintain that catalogue are critical controls — especially in the context of SOX expectations for management.

Proportional controls for different AI types

Not all AI is the same, and controls must be proportionate to different AI characteristics. Centralized risk assessment, a consistent methodology and taxonomy help prioritize where stronger testing or metadata validation is needed — particularly where SOX or audit relevance is present. Be prepared to show how a tool was developed, deployed and tested, and how the control environment was designed accordingly.

Documentation and validating model outputs

When AI outputs feed into financial reporting, validating model outputs is critical. Engagements with auditors will be smoother if the organization approaches reviews with well‑prepared teams and robust documentation. Organizations must be able to show how and why they rely on AI‑generated results in financial statements. Process descriptions and risk control matrices (RCMs) in SOX programs may need updating to explain AI impacts and control designs.

Examples of supporting documentation include:

  • Approved model risk assessment documents
  • Audit records and defect/fix registers
  • Error logs and escalation records
  • Sample testing documentation and evidence of human testing (including data integrity checks, review steps and exception handling)
  • Monitoring and control reports with thresholds and limits
  • Mitigation and fallback controls and the decisions around them
  • Updated SOX documentation reflecting AI‑supported processes

Many AI systems are probabilistic rather than deterministic, producing outputs based on likelihoods rather than fixed rules. Auditors will therefore want to understand detail on the control mechanisms, especially when AI complements or replaces a key control. In cases using generative AI for text or financial analysis, audit scrutiny will focus on ensuring accuracy and mitigating hallucinations.

Conclusion

Deploying AI in business processes requires resources and governance to maintain audit readiness. Organizations should implement integrated oversight, keep a validated catalogue of AI use cases, apply proportional controls by AI type, and maintain detailed documentation so process owners and control owners can confidently explain AI impacts to auditors and internal reviewers — particularly where AI affects financial reporting or SOX‑relevant controls.