The future of
internal audit
Roughly 80% of our work is knowledge work.
Roughly 20% is intelligence work.
We have always been paid for 100%.
Knowledge is still useful. It is no longer scarce, and it has stopped being ours alone.
Audit work has historically combined two sources of value. One is the ability to retrieve knowledge and apply a repeatable methodology. The other is the ability to decide what matters when evidence is incomplete, incentives conflict and the organisation does not behave as its process description suggests. AI forces us to price those two contributions separately.
Which part of my value was the knowledge, and which part was the judgment?
Two kinds of work, bundled into one profession
- Read and retrieve
- Apply frameworks
- Compare criteria
- Run structured tests
- Synthesise evidence
- Document conclusions
- Judge ambiguity
- Read people and politics
- Sense emerging risk
- Challenge senior stakeholders
- Connect unwritten context
- Own the judgment
We have already built the first version
Our audit orchestrator can execute the main steps of an audit methodology. That proves the work can be decomposed and performed. It does not yet prove equivalence to known-good human judgments.
Ingest the record
Assess risk
Design and run tests
Draft the outputs
The uncomfortable discovery was that the human had become the bottleneck.Surviving the Oh-Fuck Moment · 30 January 2026
What the experiment established: substantial parts of audit expertise can be expressed as codified pattern recognition: condition against criteria, framework application, repeated testing and disciplined documentation. That exposes traditional sample-based and manually documented work. The remaining question is not whether the steps can run, but how accurately they run and where judgment must intervene.
The fee falls before the job disappears
Nobody needs to believe AI can replace an auditor. They only need to believe it materially reduces the effort. That belief is enough to reprice the work.
Judgment and relationships
Ambiguity, challenge, accountability and board trust remain scarce.
Reliable execution
The experienced professional whose core value is dependable delivery faces the strongest pressure.
Challenge the machine
Entry-level work shifts from producing evidence to testing and contesting it.
A CFO or Audit Committee will eventually ask why the function needs the same headcount, timelines and career pyramid. We should have an answer before they ask.
The threat is repricing, not only replacement. Historical fees, staffing and engagement lengths become difficult to defend once execution effort visibly falls. The middle faces the strongest pressure because reliable execution was its core differentiator.
Three shifts in where value sits
The answer is not to defend the old allocation of work. Move human capacity towards future failure, system design and accountable judgment while machines absorb repeatable execution.
Build the knowledge layer first
Corpus
Connect reports, workpapers, actions, policies, controls, incidents, risks and systems. Read-only.
Provenance & decay
Add effective dates, supersession, source authority and staleness labels.
Structured memory
Store risk, control, test, outcome, evidence, severity and action as linked objects.
Live signals
Connect incidents, changes, access and transactions. Memory becomes monitoring.
Advisory surface
Expose governed, cited and logged risk knowledge to the business.
Why first? This investment remains useful even if every capability forecast in this deck turns out to be wrong. Build for poisoning, anchoring, confidentiality and legal hold from day one.
Adoption logic: phases 0–1 make current work faster; phase 2 creates the evaluation history needed to widen review; phase 3 supports continuous risk sensing; phase 4 turns accumulated audit knowledge into a governed service.
If the machine does the 80%, where does the 20% come from?
Judgment used to emerge from repetition: vouching, reconciling and the fourth week of fieldwork taught us what “wrong” looks like. Remove the repetition and we must develop judgment deliberately.
The auditor records a conclusion before seeing the system output.
Reveal the machine's answer and reconcile the differences.
Store the disagreement as training data for both human and system.
Blind pre-commitment does three jobs: it trains judgment without the old apprenticeship, produces the evaluation data needed to widen review, and protects against anchoring on organisational precedent.
This does not fully solve the developmental problem. It changes apprenticeship from producing routine work to contesting machine output, explaining disagreements and rotating deliberately through ambiguous decisions. Judgment can no longer be assumed to appear automatically after enough years of execution.
We carry the whole organisation in our heads
The model carries a context window. We carry what was never written down.
Reality
How the process works, not how it is described.
Behaviour
Who escalates, absorbs or quietly works around.
Politics
What an observation costs the person who owns it.
History
What was tried, why it failed and what was promised.
Meaning
Why the same issue is trivial here and serious there.
Context the system may gain through better access, memory and retrieval.
Confidences, investigations and personnel matters that should not enter a broad memory layer.
Our role is translation: place the finding in the organisation, then explain the same truth to the business, ExCo, Audit Committee and supervisor.
Why this changes severity: the same technical condition may be a footnote in one organisation and a board-level matter in another. Auditors combine evidence with culture, history, incentives and implementation reality. That whole-organisation interpretation is likely to be among the last capabilities AI can reproduce reliably.
Do not build your career on a temporary gap
Slide 12 is where this profession wants to stop. It is comforting, and it is currently true. Some context will remain human-held because governance requires it.
Much of the rest is a gap, not a moat. Better memory, deeper access and stronger retrieval will narrow it.
Many AI failures are failures in how we instruct, scope and contextualise it.
Those are skills we can improve. We should not design a five-year operating model around a limitation that may not survive eighteen months.
Plan for the gap closing. Be pleasantly surprised if it doesn't.
The practical distinction: protect context that should remain restricted; engineer access, memory and instruction for everything else. Do not describe a remediable information gap as permanent human uniqueness.
Our auditees are getting the same tools
The gap closes because systems improve. It also closes because the people who bought our analysis no longer need us to produce it.
They will get most of the insight we would have given them, without waiting eight weeks and without us.When Your Auditee Doesn't Need You Anymore · 12 February 2026
The analysis monopoly fades
Management can connect agents to its own policies, transactions, incidents and controls. “Good enough to act on” is the threshold that matters.
The independence mandate remains
Management's assurance-by-agent becomes a new audit object. Somebody still needs to challenge whether it is trustworthy.
Internal Audit therefore cannot rely on being the only group able to identify a control weakness. Its proposition shifts from producing scarce insight to providing independent challenge, explaining why automated analysis is trustworthy and identifying the assumptions management's own agents may share with their owners.
Old control questions, a new actor
We must transform our own work with AI and assure the organisation's use of AI. Most governance questions are familiar; the subject is not.
Who can act, within what authority, with what evidence and which fallback?
An adaptive agent whose intent can change while its entitlement stays valid.
Name the exceptions: prompt injection, bias, evaluation design and probabilistic model behaviour require genuinely new tests. “Old problems, new actor” is a governance frame, not a complete AI audit methodology.
The practical advantage for auditors is that we do not need to wait for an entirely new profession. Inventory, identity, authorisation, segregation, audit trail, accountability, supplier resilience and change control already give us a strong starting point. The methodology must extend those questions to intent, autonomy and probabilistic behaviour.
Six tests we can run now
Reconcile the inventory
Compare the agent register with identities, API keys and vendor usage or spend.
The differences are the finding.
Stay within permission, leave the purpose
Attempt an allowed but out-of-purpose action in a controlled environment.
Least privilege does not constrain intent.
Reconstruct one transaction
Who instructed, what was accessed, what changed and whose authority was used?
If evidence cannot tell the story, the log is not an audit trail.
Exercise the stop
Test who can stop it, at 03:00 Sunday, and what happens to half-completed work.
Test the mechanism, not the policy.
Switch the model
Run the alternative and assess output quality, not merely whether it starts.
An alternative provider is not a tested contingency.
Version the methodology
Request the history of the production prompt, context configuration and model.
The methodology now lives in the instruction.
The technology is not the finding. The governance exception is the finding.
How to use this slide: each test begins with a familiar control objective, then asks how an adaptive actor changes the evidence. Failed reconstruction, unlisted agents, untested substitution or unversioned instructions are concrete findings, not general concerns about AI.
Start changing the work before the work changes us
This is a shared change programme, not an instruction for individuals to become AI specialists in their spare time. The function must supply governed tools, reusable knowledge and deliberate opportunities to practise judgment. Individuals must bring experimentation, scepticism and a willingness to redesign their own work.
Use a real task
Hand a genuine problem to a model. Discover which parts were pattern matching.
Master instruction
Scoping, context selection and evaluation are core professional skills.
Develop judgment deliberately
Use blind pre-commitment and rotate people through difficult calls.
Leave reusable memory
Every engagement should make the next one permanently smarter.
Build the foundation
Begin with the corpus, provenance and structured-memory phases.
Do not wait for permission to learn
No standard or professional body will hand us the answer in time.
I am not selling you optimism
Part of the current job becomes obsolete
If most execution becomes machine work, staffing, career pyramids, methodologies and timelines should not remain unchanged.
The scarce work gets our full attention
Judgment, challenge, risk anticipation, culture and behaviour become the profession rather than what fieldwork leaves time for.
Any version of this vision that tells you only one of those things is selling you something.
The point is not to promise that every auditor simply moves into more interesting work. Some capacity will disappear and some roles will be repriced. The opportunity exists only if we deliberately redirect freed capacity towards resilience, organisational intelligence, challenge and accountable judgment before others redesign the function for us.