Talking to your external auditor about AI accounting
Businesses automate their finance processes and then, months later, an auditor arrives and discovers that the way transactions are processed has fundamentally changed.
That is an expensive way to run it. Not because the auditor will object, but because they now have to understand a new control environment while under deadline pressure, and their response to uncertainty is more testing.
Tell them first. The conversation takes an hour and it changes the audit.
Why the timing matters
An auditor plans their approach around your controls. If controls are reliable, they test the controls and reduce substantive testing. If they cannot rely on the controls, they test transactions directly, in volume, which costs more of your time and theirs.
Presented with an unfamiliar automated process during fieldwork, with no time to evaluate it properly, the safe choice is to assume they cannot rely on it. That is a rational response to being surprised, and it is entirely avoidable.
Raised in advance, the same process can be evaluated calmly, and if it is sound, relied upon — which usually means less testing rather than more.
What to cover in the conversation
What changed, and when. Which processes are now automated, from what date. If the change happened mid-year, say so explicitly — it means the year has two control environments and they need to plan for both.
What posts without human review. The proportion, and what determines it. Be specific about thresholds.
What controls constrain it. The hard limits, the categories requiring human classification, the approval rules that cannot be overridden by the system.
How exceptions are handled. Who works the queue, what they attest to, what the record shows.
How you monitor it. Your sampling, its frequency, what you have found. This is the part auditors are most interested in and the part businesses most often have not done.
Who is accountable. A named person per process. See who is accountable for an automated entry.
What the trail records. Ideally demonstrate it: take an entry, show the document, the basis, the rule version, the review.
What they will probe
Expect scepticism in four specific places, and prepare rather than improvise.
Anything near period end. Cut-off is the most tested area in most audits, and automation is least reliable there because the decision depends on facts about events rather than patterns. If cut-off is automated, expect that to be the focus. If it is not, say so early — it is reassuring.
Changes during the year. A threshold adjusted in August means transactions before and after were processed under different logic. Have the configuration change log.
Whether review is real. They will look at whether exceptions were genuinely examined or cleared in bulk. Approval timestamps clustered in a two-minute window on the last day of the month tell a story.
Whether anyone verified the system independently. Your own sampling, or nothing.
The question that is hardest to answer well
"How do you know it is working?"
There are two possible answers. The first describes the system — what it does, how it decides, what the vendor says. That is a statement of intent and auditors recognise it as such.
The second is evidence: a file showing that each quarter you sampled a set of confidently-processed transactions, checked them against source documents, recorded what you found, and corrected the causes. Three errors found in a year and fixed is a better answer than none found, because it demonstrates the monitoring is real.
The second answer cannot be assembled retrospectively. Sampling done during the audit is not evidence of monitoring during the year — see sampling automated transactions.
Where the auditor may add value
Worth asking, rather than treating the relationship as one-directional:
- Which of our automated processes would you consider highest risk?
- What would you want to see us monitoring that we are not?
- Is our documentation sufficient for you to place reliance on the process?
Auditors see many finance functions and generally know where automated processing goes wrong. Asking those questions before implementation is cheaper than discovering the answers in a management letter.
If you are mid-implementation now
The practical sequence:
- Tell them before year end, not after
- Give them the process description you should already have written
- Show them the trail on a real transaction
- Show them your sampling file, or start one immediately if there isn't one
- Ask what else they need to rely on the process
An auditor who understands your automation before fieldwork is materially cheaper than one who meets it during.
Common questions
Should I tell my auditor before automating accounting processes?
Yes, ideally before the change rather than after. Auditors plan their testing around whether they can rely on your controls, and an unfamiliar automated process encountered during fieldwork under deadline pressure will reasonably be treated as unreliable — leading to more substantive testing. The same process raised in advance can be evaluated properly and, if sound, relied upon.
What will an auditor want to know about automated accounting?
What changed and from what date, what proportion of transactions post without human review and what determines that, which controls constrain the system, how exceptions are handled and by whom, how you monitor that it is working, who is accountable, and what the audit trail records. They will probe hardest around period cut-off, changes made during the year, and whether review was genuine rather than bulk approval.
How do I answer "how do you know it is working"?
With evidence rather than a description. A file showing quarterly sampling of confidently-processed transactions, checked against source documents, with findings recorded and causes corrected, is what demonstrates monitoring. Finding and fixing a few errors over a year is a stronger answer than finding none, because it shows the monitoring is real rather than nominal.
Does automation make an audit more expensive?
It usually makes it cheaper, because evidence is attached to every transaction rather than sitting in folders and the population is complete. It becomes more expensive when processing was automated without recording the basis for each treatment, or when the auditor encounters the change unexpectedly and has no time to evaluate it.
Related: evidence an auditor will accept · preparing for an audit with automated books · documenting an automated process for review
Read next
See what you could build
Start a free trial and describe what your business needs in plain language — SmartB Studio builds the module for you.
Start free trial