Strengthening Reporting Practices for AI-Assisted Audit Work
AI and Audit Reporting Resources Available for Download:
Protiviti experts explore the state of data quality and readiness to support AI efforts, uncovering both encouraging advancements and persistent challenges.
Audit Administration Project Questionnaire: Audit Planning, Fieldwork, Reporting and Wrap Up
Verify that key administrative requirements are addressed across planning, fieldwork, reporting and wrap-up while adapting each item to the project’s specific needs and timeline.
Internal Audit Risk Assessment Audit Committee Report
Learn internal audit strategies to strengthen your risk assessment and ensure robust governance practices.
AI, the Newest Member of the Audit Team
Artificial intelligence is changing how Internal Audit teams gather evidence, test controls and draft findings, and it is changing what audit committees expect to see in the final report.
More teams are feeding AI-generated summaries, anomaly detection and predictive risk scoring into their work.
This raises a new question: how do you report on AI-assisted work with the same rigor as a traditional review, without either overstating what the technology did or burying its role in vague language?
Answering well takes more than good intentions. It takes clear AI and audit reporting practices that spell out what gets disclosed, how AI's role in an engagement gets documented, and where human judgment still governs the conclusion.
Audit committees are asking pointed questions about data quality, model reliability and oversight. A report that cannot answer those questions convincingly loses credibility fast, regardless of how sound the underlying testing is. A committee that later learns AI played a bigger role than disclosed will start questioning every report that follows.
The good news is that Internal Audit does not need to build these practices from a blank page. Established governance, planning and reporting tools can be adapted to address AI-specific risk, giving audit teams a head start on producing reports that hold up to scrutiny from committees, regulators and management alike.
Best Practices
Two habits separate audit functions that report on AI confidently from those that scramble to explain it after the fact:
Getting governance in place before AI touches an engagement
Being honest about how much trust the underlying data deserves
Both call for consistent AI and audit reporting standards, applied the same way from one engagement to the next. This results in reports reflecting the same level of scrutiny regardless of which team produced them.
Setting Governance Expectations Before AI Enters the Picture
Reporting problems with AI usually trace back to a governance gap at the start of the process (nobody defined how AI would be monitored and disclosed). The audit team defaults to improvising language for a report that was never designed to explain algorithmic input, and the result often reads as either overly cautious or unconvincingly vague.
Knowing How Much to Trust the Data Behind the Report
An AI system is only as credible as the data feeding it, and that has direct implications for reporting. If a finding rests on data nobody has stress-tested, the report is making a promise the underlying evidence cannot keep, no matter how polished the language around it sounds.
Protiviti’s second AI Pulse Survey of over 800 professionals puts numbers behind this concern. It found that organizations reporting high confidence in their data capabilities are more likely to say their AI investments have exceeded expectations, while organizations with weaker data confidence tend to report outcomes that merely meet or fall short.
Among mature organizations, 74% conduct regular data audits, more than double the rate of less mature peers. The habit of auditing inputs and outputs can increase the confidence leadership places in AI-driven results.
The survey also found that confidence varies by role: IT professionals and C-suite executives tend to report the highest confidence in data quality. Teams closer to raw, unprocessed data report more skepticism. This is a gap worth keeping in mind when an audit report draws conclusions from data multiple teams have touched.
For audit teams, the practical takeaway is to build a data confidence check into the workpapers before AI-assisted conclusions ever reach a report, rather than assuming a polished output is automatically a reliable one.
Toolbox
Beyond governance and data confidence, reporting on AI-related work benefits from structure that already exists in most audit functions. Two resources built for traditional reporting adapt well to AI oversight, giving teams reliable AI and audit reporting templates and AI and audit reporting tools they do not have to invent from scratch.
Building AI Disclosure Into the Reporting Phase
Many audit teams already follow a checklist for the administrative steps of an engagement, and that checklist is a natural place to add AI-specific questions.
The Audit Administration Project Questionnaire: Audit Planning, Fieldwork, Reporting and Wrap Up walks through each phase of an engagement, from scoping and fieldwork through the reporting steps of drafting, reviewing and finalizing the report to the auditee.
The tool turns AI transparency into a routine part of AI and audit reporting procedures rather than an afterthought handled inconsistently from one engagement to the next.
Modeling Committee-Ready Risk Reporting
Audit committees have specific expectations for how risk gets summarized, and AI-related risk is no exception. The Internal Audit Risk Assessment Audit Committee Report offers samples showing historical ways of communicating:
Risk assessment approach
Top risks
Audit universe coverage
Proposed audit plans
The samples illustrate how to present the distribution of audit effort and the reasoning behind prioritizing certain risk areas over others. Applying that same structure to AI oversight gives committees a familiar format for a newer category of risk. The audit plan can show how AI-related risks were identified, prioritized and addressed, using AI and audit reporting templates that reviewers already trust rather than a one-off approach built for a single engagement.
Wrap Up
AI is not going away from internal audit work, and neither is the scrutiny that comes with using it. Getting ahead of that scrutiny means:
Treating AI oversight as a governance question from the start
Being honest about the data confidence behind AI-assisted findings
Building AI disclosure into the reporting steps and committee updates that already exist, rather than treating them as a separate, one-time exercise
None of this requires reinventing the audit function. It requires applying established tools, from governance questionnaires to reporting checklists to committee report templates, with an eye toward the specific questions AI introduces.
Staying current on AI and audit reporting regulations will matter more as adoption grows. Audit teams that build the habit of transparent, well-governed reporting now will have credible answers when the questions get harder. Teams that wait will be left scrambling to explain gaps after a committee has already noticed them.