When I review how a firm is using AI on audits, I ask one question before looking at any tool: could an experienced auditor who has never seen this engagement pick up the file and understand what was done, what was found and why the team concluded what it did? That is not my invention. It is, in substance, the requirement in SA 230, Audit Documentation, as issued by ICAI. It is also the cleanest test I know for deciding which parts of working-paper preparation AI should touch.

AI is very good at producing text that looks like a working paper. That is the danger. A fluent narrative that nobody performed, or a tie-out nobody checked, makes a file look complete while hollowing out the evidence underneath it.

What SA 230 actually asks of the file

Paragraph 8 of SA 230 requires documentation sufficient to enable an experienced auditor, having no previous connection with the audit, to understand the nature, timing and extent of procedures performed, the results and evidence obtained, and significant matters, conclusions and professional judgements. Paragraph 9 requires recording who performed the work and when, and who reviewed it, when and to what extent. The application material notes that assembly of the final audit file is ordinarily completed not more than 60 days after the date of the auditor’s report.

None of that is suspended because a model drafted part of the paper. If anything, AI raises the bar on the “who performed” and “who reviewed” lines, because the honest answer now has three parties: the person, the tool, and the reviewer.

What I would automate

The work worth automating is mechanical, checkable and repetitive:

  • PBC tracking and indexing. Matching client uploads to the request list, naming files consistently, flagging what is missing.
  • Lead schedules and tie-outs. Mapping the trial balance to lead schedules and flagging differences — work that is easy to re-perform and verify.
  • Extraction for vouching support. Pulling dates, amounts and parties from invoices, confirmations and agreements into a schedule, with the source document linked on every row.
  • Reading aids. Summarising board minutes or long contracts to direct attention — not to replace reading the relevant sections.
  • Drafting narratives of completed work. Turning a senior’s notes on procedures already performed into a clean working-paper narrative, which the senior then checks line by line.

What must stay human

Risk assessment and materiality. The judgement on whether evidence is sufficient and appropriate. The rationale for sampling approaches, even if a tool generates the selection. Evaluation of misstatements. Going-concern and key judgement areas. Communication with management and those charged with governance. Review and sign-off. These are the places where the file has to show professional judgement, and SA 230 expects significant judgements to be documented as judgements made by the engagement team.

Illustrative split for a statutory audit working file. Adapt to your firm’s methodology and quality policies.
Working-paper taskAutomate?Human responsibilityEvidence to keep on file
PBC tracking and indexingYesSenior confirms completeness of the request listTracker with dates and source links
TB to lead schedule tie-outYesPreparer investigates every difference flaggedTie-out with differences and resolutions
Field extraction from invoices and confirmationsYes, with source linksPreparer checks a sample back to documentsExtraction schedule, tool used, sample check noted
Sample selectionTool may generateTeam sets population, method and rationaleParameters, output and rationale
Minutes and contract summariesAs a reading aidTeam reads relevant sections in fullNote of what was read and matters identified
Risk assessment, materiality, conclusionsNoEngagement team and partnerDocumented judgements and review evidence

Documenting AI use without drowning in it

Firms tend to swing between two extremes: no record of AI use at all, or a policy so heavy that people quietly stop disclosing it. I prefer a short, standard block on any working paper where a tool contributed: the tool and version, what it was given, what it produced, who reviewed it, when, and what they changed. That is enough for a reviewer to reconstruct the work, and it fits naturally alongside the preparer and reviewer sign-offs SA 230 already expects.

Keep prompts that are reused across engagements in a controlled library, with an owner and change notes. When a prompt changes, the output changes; a reviewer should be able to see which version produced which paper. The NIST AI Risk Management Framework is a sensible reference for this kind of proportionate logging.

Confidentiality and client data

Audit files contain some of the most sensitive information a client has: unpublished results, payroll, related-party dealings, legal matters. Consumer chatbot accounts are not an approved environment for that material. Use tools your firm has assessed for data processing, storage location, retention and access control. Where working papers include personal data — payroll and KYC are obvious examples — the Digital Personal Data Protection Act, 2023 expects the business to protect it with reasonable security safeguards, including when a processor handles it on its behalf. Your professional confidentiality obligations under ICAI’s framework apply regardless of which tool you choose.

For audits within the remit of the National Financial Reporting Authority, expect files to be read closely by people who were not on the engagement. That is precisely the reader SA 230 has in mind.

A sensible first quarter

Pick two or three engagements with cooperative clients and stable systems. Automate PBC tracking and lead-schedule tie-outs first. Add extraction for vouching support with a documented sample check. Introduce the standard AI-use block on every paper a tool touched. At the end of the quarter, ask a manager from a different team to read one file cold. If they can follow it, extend. If they cannot, the problem is the file, not the reviewer.

For the full CA implementation map, see the AI for chartered accountants in India hub. Related pieces: using AI for GST reconciliation without risking client data, AI tools for chartered accountants and when to say no to an AI pilot. To see where AI fits across your practice, start with the free AI Opportunity Scorecard, look at the scoped AI Opportunity Audit, or book a discovery call.

Monday-morning checklist

  • Pick two or three engagements and name the manager accountable for the AI trial.
  • Automate PBC tracking and lead-schedule tie-outs before anything judgement-heavy.
  • Add source links to every extracted row and document a sample check.
  • Adopt a standard AI-use block: tool, input, output, reviewer, date, changes.
  • Keep client files out of consumer chatbot accounts; confirm vendor data terms.
  • At quarter end, have someone outside the team read one file cold.

Frequently asked questions

Does using AI on an audit change what SA 230 requires?

No. SA 230 still requires documentation sufficient for an experienced auditor with no previous connection to the audit to understand the procedures performed, the evidence obtained and the significant judgements made. AI-assisted work has to meet the same test, which usually means recording how the tool was used and who reviewed its output.

Which audit tasks are safest to automate first?

Administrative and mechanical work: PBC tracking, indexing and cross-referencing, tying lead schedules to the trial balance, extracting fields from confirmations and invoices, and drafting narratives of work already performed. These are easy to check and do not replace judgement.

Can AI select audit samples?

Tools can generate selections, but the sampling approach, the population, and the rationale remain the engagement team’s responsibility and should be documented as such. Keep the parameters and the output on file so the selection can be re-performed.

How should I document AI use on the working paper?

Note the tool and version, the input it was given, the output, who reviewed it and when, and what the reviewer changed. Keep it short, but make it possible for a reviewer to reconstruct what happened.

Sources

Disclaimer: this article is general educational commentary from implementation work. It is not tax, legal, audit or data-protection advice, and it does not create an adviser–client relationship. GST procedures, portal functionality, Standards on Auditing and data-protection rules change; check the primary sources and take professional advice on your specific facts before acting.