Executive summary
AI can help SOX and internal audit teams test larger populations and improve efficiency. It can also expose an inference gap between documented controls and the way the business operates. Organizations gain the greatest value from AI when they investigate unexpected results and their root causes and use those insights to strengthen controls and improve future testing.
Closing the inference gap
For decades, internal audit and SOX compliance teams have relied on meticulous verification to evaluate controls. But they also rely on implied logic and institutional knowledge that may never have been formally documented.
As organizations expand their use of AI and automation within governance functions, they are discovering that some long-standing processes depend on knowledge that exists outside of documented data and controls.
“That creates what I call ‘the inference gap,’” said Greg Haberer, Grant Thornton Risk Advisory Associate Partner. “Automated tools can only evaluate the information available in source and configured logic. If automation is brought into long-standing processes that once relied on any undocumented knowledge, it may generate results that conflict with established business practices.”
Auditors need to pay attention to those discrepancies. When AI flags an anomaly or fails a control test, it’s often the sign of a disconnect between documented controls and the way the business actually operates.
To unlock greater value from AI, auditors need to shift from validating exceptions to understanding why they occurred.
Moving from anomalies to root causes
Unexpected results can create tension between audit teams and other business units.
For example, a test may flag transactions that appear to be missing required approvals, even though the approvals were in the provided evidence. In reality, the test procedures were written imprecisely or may contain technical inaccuracies, requiring revision to remove ambiguity.
While automated testing can uncover data, process and control issues, that doesn’t mean data remediation should sit with the internal audit team. Responsibility for data remediation should remain with the appropriate business owner.
“The first line owns their data,” Haberer said. “But traditional auditing often masks these data deficiencies by smoothing over ‘exceptions’ that humans intuitively understand but AI systems don't reflect.”
When AI delivers an unexpected result, the modern auditor's role is to investigate the chain of events behind it using a forensic problem-solving approach.
Unexpected AI output ➔ Validate model parameters➔ Identify systemic input/process flaw ➔ Issue root-cause finding to business
Audit teams should ask:
- What human assumptions are not reflected in the data or testing logic?
- Are the source data complete and accurate?
- Is this anomaly a true control failure, or is it evidence that the organization’s Information Produced by the Entity lacks the precision required for automated governance?
- What evidence should be retained from this investigation to support regulatory review and external audit requirements?
When the internal audit team effectively identifies and communicates root causes of an unexpected result, the business group responsible for the data can address recurring problems and improve the reliability of future testing.
How we can help you
SERVICES
SERVICES
Building defensible, repeatable AI-enabled governance
When teams use AI-enabled testing to strengthen processes and controls, they can strengthen the internal audit function as a driver of organizational maturity. This leads to:
- Defensible repeatability: Processes become standardized when they reduce reliance on individual interpretation and institutional knowledge.
- Audit-ready efficiency: Once data inputs, controls and system configurations are aligned, AI can run continuous, full-population testing with a transparent audit trail that satisfies external auditors.
- Better risk identification: AI-enabled testing can help teams focus on unusual patterns, exceptions and areas that warrant further investigation.
Over time, these improvements can help organizations build a more repeatable and scalable approach to risk management and compliance.
Summary
SOX and internal audit teams are already using AI for productivity and cost savings. They're also finding that unexpected results often expose gaps between documented controls and how the business actually operates. But those findings can't explain themselves. Auditors still need to follow the evidence to understand what the results reveal about the underlying process.
“The most effective audit functions will be those that use AI as a tool for insight, rather than simply a tool for automation,” Haberer said. “By examining what unexpected results reveal about the real state of their data and operations, organizations can identify underlying conditions that create recurring control exceptions and increase confidence in their automated testing over time.”
Content disclaimer
This Grant Thornton Advisors LLC content provides information and comments on current issues and developments. It is not a comprehensive analysis of the subject matter covered. It is not, and should not be construed as, accounting, legal, tax, or professional advice provided by Grant Thornton Advisors LLC. All relevant facts and circumstances, including the pertinent authoritative literature, need to be considered to arrive at conclusions that comply with matters addressed in this content.
Grant Thornton Advisors LLC and its subsidiary entities are not licensed CPA firms.
For additional information on topics covered in this content, contact a Grant Thornton Advisors LLC professional.
Share with your network
Share