Evidence an auditor will accept for an automated entry
There is a persistent worry that auditors object to AI in accounting. In practice they mostly do not. Automated processing has existed for decades and audit approaches accommodate it.
What auditors object to is an entry that cannot be explained after the fact. That is a records problem, and it exists identically in manual bookkeeping done badly.
So the question is not "will the auditor accept AI" but "does the record support the entry". Here is what that record has to contain.
The six elements
For any automated entry, the record should show:
The source. The document the entry derives from, or a durable reference to it. Not a filename in someone's folder — the document itself, retrievable and demonstrably unaltered.
The treatment and its basis. What was posted, and why that treatment. "Coded to freight; supplier's previous 47 invoices with similar descriptions coded to freight" is a basis. "Coded to freight" alone is an assertion.
The rule or model version. Which logic produced it. This matters because processing behaviour changes over time, and an entry from March may have been produced by different logic than one from September. Without version recording, you cannot tell an auditor what the control environment was during any given part of the year.
The confidence. How certain the system was, and therefore whether it fell above or below the review threshold. This is what evidences why a particular entry was or was not reviewed.
Human involvement, or its absence. Who reviewed, when, what they saw, what they decided. And where nobody reviewed, the record should show that too — the absence should be explicit and explained by the threshold, not merely a gap.
Amendments. Any change, with its author, timestamp and reason, without the original being overwritten.
Missing one of these creates a class of question you cannot answer, and you discover which during the audit.
The three that are usually missing
In practice, most systems capture the source and the treatment. The gaps cluster in three places.
Rule version. Rarely recorded, and the most damaging omission when something has gone wrong for a period, because it prevents you establishing when the behaviour changed or identifying the affected population.
The configuration change log. Who changed a threshold, when, and why. Frequently not captured at all. "We tightened the tolerance at some point during the year" is not an answer to an auditor, and it converts a straightforward question into a scoping problem.
Evidence of monitoring. The auditor asks how you know the automation is working. A description of the system is a statement of intent. A file showing you sampled 40 transactions quarterly, found three errors, identified causes and corrected them is evidence — and it cannot be produced retrospectively. See sampling automated transactions.
What "unalterable" has to mean
An audit trail that the person operating the system can edit is not evidence of anything.
This is worth testing rather than assuming. Ask directly: who can amend or delete an entry in the audit log, and is that action itself logged somewhere they cannot reach? In a small business where one person administers everything, the honest answer is often that nobody is prevented — in which case the compensating measure is external: a periodic export or review by someone outside finance.
Better to know and compensate than to present a log that will not withstand a question about who can edit it.
The distinction that matters most
Recorded at the time, versus reconstructed now.
A system can produce a fluent explanation of why a transaction was treated as it was, generated on request. It will read exactly like a record of what actually happened, and it is not one — it is an inference about what probably happened, produced by the same system whose behaviour is in question.
Ask a vendor plainly: are explanations retrieved from decision records stored at the time, or generated on demand? The distinction is the whole difference between evidence and a plausible account. Vendors who have thought about audit answer immediately.
What auditors will ask
Expect these, and prepare answers before the fieldwork:
- What proportion of transactions were processed without human review?
- What determined which ones? What was the threshold, and did it change?
- Who is accountable for the automated process?
- How do you satisfy yourself it is working correctly?
- Show me the trail for this entry, from the figure back to the document.
- What changed during the year — rules, thresholds, system versions?
None are difficult if the record exists. All are difficult if it does not, and the difficulty is not about AI.
The reframe worth carrying
Automated books are frequently easier to audit than manual ones, because the evidence is attached to every transaction rather than sitting in folders, and because the population is complete rather than sampled by whoever filed things.
The businesses that find automation makes the audit harder are usually the ones that automated processing without recording the basis — which is a choice made during implementation, not a property of the technology.
Common questions
Do auditors accept AI-generated accounting entries?
Generally yes. Automated processing has been part of accounting for decades and audit approaches accommodate it. What auditors object to is an entry that cannot be explained or attributed afterwards, which is a records problem rather than an AI problem and occurs equally in poorly documented manual bookkeeping.
What evidence is needed for an automated entry?
The source document or a durable reference to it, the treatment applied and the basis for it, the rule or model version that produced it, the confidence level, whether a human reviewed and what they decided, and any subsequent amendment with author and reason. Rule version and configuration change logs are the elements most often missing, and they are the ones that matter most when something has been wrong for a period.
What is the difference between a recorded and a generated explanation?
A recorded explanation is retrieved from what the system stored at the moment of the decision; a generated one is produced on request and is an inference about what probably happened. They read identically, which is why it is worth asking a vendor directly which their product provides — only the first constitutes evidence.
Does an audit trail need to be unalterable?
It needs to be alterable only by people who cannot conceal the alteration, which means amendments should themselves be logged where the person making them cannot reach. In a small business where one person administers everything this often is not achievable technically, and the honest response is a compensating control such as periodic export or review by someone outside finance.
Related: preparing for an audit with automated books · explainability in accounting automation · the audit trail you will wish you had
Read next
See what you could build
Start a free trial and describe what your business needs in plain language — SmartB Studio builds the module for you.
Start free trial