A refereed study in The CPA Journal, published August 26, interviewed eight auditors about adopting AI. Three were internal, five external. The internal auditors were the confident ones. They said AI would not drastically change the nature of their work, because their work already involves emerging technology.

That is the sentence I keep returning to. It sounds like maturity. I think it is closer to the opposite.

Take the study for what it is first. Eight interviews is a small, qualitative sample, and the four authors, all academics at the University of Massachusetts Lowell, are careful to call the work exploratory rather than confirmatory. It measures nothing. But it does something a large survey usually cannot. It puts internal and external auditors next to each other on the same question and lets you hear the difference in how they talk.

The difference is stark. The internal auditors had adopted AI more extensively. One described AI already embedded in the firm’s own internal controls, used to flag potential employee misconduct. The external auditors had done less, were more hesitant, and were also the ones who named the risks out loud.

The group doing less was the group asking more

The external auditors listed three unintended consequences of leaning on AI. It might replace entry-level auditors and hollow out the way the profession trains its next generation. The data it produces might not be reliable, and auditors might not know how to assess that reliability. And it might reduce the human contact through which an auditor actually comes to understand a business. One of them put the discipline plainly: technology is “an input into our processes and not the driver and certainly not the determinant of what we do.”

So the group doing less with AI was the group interrogating it more. That asymmetry is the interesting part, and I do not think it is about temperament.

External audit works under a referee. In the United States that is the PCAOB, and this is external, financial-statement audit, a different regime from ours. Inside the large firms there is a second gate above the individual engagement. One external auditor in the study described it exactly: you might convince your local audit partner to rely on your use of AI, but will you convince the firm? Before an external auditor can lean on an AI output, someone above them has to be satisfied that the reliance is defensible, because the answer has to survive an inspection.

Internal audit has no PCAOB. Our framework is the IIA’s Global Internal Audit Standards, effective since January 2025, and they ask for independence, objectivity, due professional care and skepticism. But no external inspector arrives to test whether we applied any of that to our own tools. In most functions there is no internal gate either. If the chief audit executive is comfortable, the tool goes into use.

Speed is not the same as readiness

Read that way, the head start reads differently. Internal audit is adopting AI faster partly because nothing external is making it stop and explain the reliance first. Freedom to adopt without a forcing function is the exact condition under which you adopt before you have articulated why the output can be trusted.

The study frames external auditors as behind, and in raw adoption they are. But the constraint slowing them down is doing a job. It makes them answer a control question before they depend on the control. Internal audit’s lead is, in part, the absence of that question.

This is where the internal auditors’ comfort worries me most. They said AI would not change their work much. I have argued the opposite, that AI splits the function into the assurance we must keep human and the advisory the business can now reach in minutes rather than weeks. A profession that believes a technology will not change it, while adopting that technology faster than its regulated cousin, is not reading its own situation clearly. That is a potential indicator of under-examined exposure, not a conclusion, and it is the first thing I would examine.

The reliability worry the external auditors raised is one this blog keeps circling back to. Connect a model to your own organization’s material and it starts producing answers that sound like they are about your business. Sounding right and being reliable are different properties, and only one of them is testable. The same incentive I wrote about when only 7 percent of finance leaders said their organization puts governance ahead of speed operates on us too. Fast, useful and unexamined is a comfortable place to sit.

Run the referee’s test on yourself

The study’s own closing line is the one to keep. Firms, the authors write, may need to prepare for how to audit the AI technology itself and ensure the validity of the AI outputs. Written about us, by people watching us adopt.

So the test I would run on my own function is the one the referee runs on external auditors, turned inward:

  • Pick one AI tool the function already uses and write down why its output can be relied on. Its sources, its known error modes, and who checks it before it reaches an engagement. If that page is hard to write, the reliance is already happening without it.
  • Name your own three unintended consequences the way the external auditors named theirs. If the function cannot produce them, the comfort is untested rather than earned.
  • Name the human answerable for the tool’s output. That accountability belongs in the part of the work that stays human, and it should exist before the tool does.

None of this slows adoption for its own sake. Internal audit’s willingness to use these tools is real, and it is an advantage worth keeping. But the advantage was never the speed. It was supposed to be the judgment we bring to what the tools produce. The auditors in that study who had a referee were the ones practising that judgment out loud. We do not have a referee, which means the skepticism has to come from us, before someone else decides it should have come sooner.