Gains:
- Being able to distinguish where artificial intelligence saves real time in the audit cycle (planning, evidence collection, analysis, documentation, reporting) and where decisions such as audit opinion and material misstatement judgment are left to the independent auditor, depending on the task risk level.
- Ability to apply a discipline that validates each AI output through the steps of linking it to the source, recalculating it, and testing it with auditor skepticism.
- Anonymizing audit data within the scope of confidentiality and independence principles and gaining the habit of choosing safe vehicles
An auditor's day is spent between "accumulating evidence" and "making a judgment" much more than most people realize. You scan thousands of journal entries, you document the balance of an account, you question the reasonableness of an estimate, you ask "Is it really so?" rather than accepting a statement from the customer at face value. you dig. Some of this work is repetitive and time-consuming: organizing data, searching for standard clauses, drafting working papers, listing reconciliation variances. Others are judgments that directly determine your audit opinion—that is, your publicly expressed opinion about whether the financial statements are “true and fair in all material respects”—which must have a very low margin of error.
Artificial intelligence (AI for short, or AI in short – computer systems that can produce text like humans, recognize patterns, find relationships in large data sets, and perform calculations) sits right in the middle of this picture. When used correctly, it reduces a three-hour analytical review summary to forty minutes; scans hundreds of thousands of records in seconds; It guides you to find a standard item. When used incorrectly, it can carry into your working paper—and ultimately into your audit opinion—a seemingly safe and fluent but completely made-up number, a non-existent standard clause, or an unsubstantiated result.
The first unit of this module is not a software introduction. Its purpose is to clarify where to put AI in the audit business and where not to put it at all. Because auditing is a compliance-critical profession that relies on public trust and whose results affect investors, creditors, tax administration and society. Let's lay out the basic principle from the beginning: Artificial intelligence is an assistant, not a controller. Responsibility and final approval of all decisions regarding audit opinion, material misstatement judgment and concluding opinion belong to the competent and independent auditor.
Control loop and place of AI
To understand an independent audit, it is useful to think of the work as a cycle. During the planning and risk assessment phase, you get to know the business and determine where there is a high probability of going wrong. During the evidence collection and testing phase, you link account balances, transaction classes, and disclosures to documents, confirmations, and analyses. In the evaluation phase, you weigh the findings in terms of significance and come to a conclusion. During the reporting phase, you put your opinion and findings in writing. Throughout the entire cycle, documentation (working papers) creates traceable evidence of your work.
AI can touch every stage of this cycle, but with a different authority at each stage. Generates risk idea and materiality scenario in planning; prepares the data in the test, scans it, and marks anomalies; writes draft comments in evaluation; It accelerates the findings and report language in reporting. However, he does not make a decision at any stage. The decision requires professional judgment and skepticism; These are not transferable.
Let's define a few basic terms from the beginning. Audit evidence is the information (document, confirmation, recalculation, analysis) on which the auditor bases his opinion. Materiality is the threshold for whether an error is large enough to influence the decision of users of financial statements. BDS are the Independent Auditing Standards in force in Türkiye; It complies with international auditing standards (ISA) and is published by the POA (Public Oversight, Accounting and Auditing Standards Authority). A working paper is a document in which the work done and the results obtained are recorded. We will explain these concepts one by one in the following units; For now, know this: In all of these concepts, AI gives you outline and analysis, but no judgment.
The following table summarizes the role and risk level of AI by mission:
Quest
Role of AI
Risk level
Who approves/decides
Data cleaning, formatting
worker, accelerator
low
Audit team member
Working paper/summary draft
sketch generator
Low-Medium
senior auditor
Standard/item finding
direction finder
medium
Auditor (confirmation by official text)
Analytical procedure interpretation
hypothesis generator
medium
Audit officer
Journal / anomaly scanning
statistical marker
Medium-High
Auditor (examines every exception)
Materiality/risk judgment
auxiliary input
high
Auditor's professional judgment
Audit opinion / conclusion
It's not even input, it's draft language
very high
Responsible auditor (signature)
Keep this one line in mind: as risk increases, the AI's role becomes smaller and the auditor's judgment grows.
Why "verification" is the heart of this business
Artificial intelligence language models seem confident in their answer, but they may not be sure. This is called hallucination in technical jargon: it is when the model fabricates information that does not actually exist—a number, a standard item, a date—into a sentence that flows as if it were true. For an auditor, this is a deadly trap. The model might produce a number for you like “last year gross margin was 34 percent”; However, he has never seen your data and this number is completely made up. Or it may say "TMS 36 article 22 changed in 2021"; However, there may be no such clause or change. Since he says both with the same fluency and the same confidence, the only thing that distinguishes right from wrong is your knowledge and your habit of verifying.
Verification discipline consists of three steps in auditing:
- Link to the source: For numbers, ratios, balances and standard items, rely on your own audit evidence (trial balance, subsidiary ledger, bank confirmation, contract) and official sources (BDS and TFRS texts published by the KGK, relevant communiqués), not on the memory of the AI. Use AI to comment on that data, not to remember it.
- Recalculate/compare: Independently check each numerical result, rate and trend the AI returns. Verify a percentage, a total, a balance difference yourself.
- Test auditor skepticism: Question with a skeptical eye whether the output conflicts with evidence, regulations, and common sense. “If this is true, what else must be true?” and “If this is false, what evidence would show it?” ask.
Caution: Putting a working paper produced by an AI into a file without verifying a finding or a number is like considering an unsigned working paper as evidence. Just because the output is fluent is not true; It's only true if you prove it to be true.
Independence and confidentiality: two inviolable principles of auditing
The legitimacy of auditing is based on two basic principles. First, independence: the auditor must be independent, both in fact and in appearance, from the entity he audits; He/she should stay away from relationships of interest that would distort his/her opinion. Secondly, confidentiality: information learned during the audit cannot be shared with unauthorized persons or used for personal benefit.
The use of AI directly concerns both of these principles. Pasting the audited company's current account with customer names, tax identification numbers, bank information, and amounts into a public AI tool means this data goes to an external server. This violates both the confidentiality principle in professional ethics and, if personal data is involved, the KVKK (Personal Data Protection Law). The rule is simple: anonymize data and don't share unnecessary. Instead of "ABC Tekstil A.Ş., TIN 1234567890, balance of 4,850,000 TL", write "a medium-sized manufacturing company, a receivable balance of size X". If possible, choose corporate tools that have a data processing agreement, do not use your data in model training, and keep an audit trail.
There is an additional subtlety to independence: blindly trusting an AI tool embedded in the audited company's own system, whose output you cannot independently control, can undermine your independence. AI is a tool; Who built it, where your data goes, and whether you can verify its output are all part of your independence.
three mini cases
Case 1 — Safe use. A senior auditor typically spent 3 hours hand-writing a 22-item analytical review summary. He gave the numbers he took from the trial balance anonymously (no company name, only account and amount) to YZ and asked for a draft comment. The AI produced a sketch in 12 minutes; The auditor compared each ratio to his worksheet, corrected two erroneous percentages, and evidenced two explanations for deviations. Duration: 45 minutes instead of 3 hours. AI gave the draft, responsibility and opinion remained with the auditor.
Case 2 — Unverified number trap. A trainee auditor asked AI, "What is the average inventory turnover rate in this industry?" AI gave a confident number of "about 6.4" even though he had no access to any industry data. The intern wrote this on the worksheet as the expectation value, making the client's rate of 4.1 seem "reasonable." When the auditor asked, it turned out that the source was an invention of the AI; The analytical procedure was redone. Mistake: Asking the AI for benchmark data it doesn't have.
Case 3 — Breach of confidentiality. A team member uploaded the full list of customers to whom he would send confirmation letters — title, address, amount, contact name — into a public AI tool and “drafted the confirmation letter,” he said. The data went outside the organization; A confidentiality review was opened in the audit company's quality unit. The correct way: was to strip out the actual data and just ask for a template with placeholders like "[CUSTOMER NAME]", "[AMOUNT]".
Weak prompt / Strong prompt
Weak prompt:
Interpret the financial statements of this company and tell me if there is any risk.
This claim is flawed: the AI is given no data, context, or role. Since AI does not have any data, it either makes general statements or produces "interpretations" with made-up numbers. Neither the period, nor the account, nor the audit purpose are clear.
Powerful prompt:
Your role: you are an analysis assistant assisting an independent auditor. The control jurisdiction belongs to me; you will produce drafts and accounts.Context: Below is an anonymised trial balance summary (no company name). My aim is to see the significant changes (horizontal analysis) between the current year and the previous year and to determine the deviations that need to be examined.Data:[account name; previous year amount; current year amount lines]Task:1) Calculate the amount and percentage change for each account; show the calculation step so I can verify it.2) Mark items that exceed 20% or change sign (such as profit->loss) as "to be examined".3) Suggest 2-3 possible explanation HYPOTHESIS for each marked item; Note that these must be verified with evidence.4) Do not make up any numbers that you are not sure of or cannot deduce from the data. Write "cannot extract from data". Give the output as a table.
This claim is powerful because it clearly establishes the role, the boundary (in the judicial auditor), the data, the steps, the verifiability, and the “ban on fabrication.”
Common mistakes
- Mistaking AI for a resource. Relying on the AI's memory for the number, ratio, standard item, and date. AI is a direction finder; source control evidence and official text.
- Writing prompts without context. Saying "interpret" without giving role, data and purpose; The result will be fake.
- Pasting confidential data as is. Sharing transcripts containing customer name, TIN, personal data without anonymization; privacy and KVKK violation.
- Putting the output into file without validating it. Thinking the fluent text is correct and transferring it to the worksheet.
- Delegating judgment. Jumping to a conclusion on the grounds that "the AI said so"; Audit opinion is not transferable.
Tip: Go into every AI session with an auditor's mind: "Where could this output be wrong?" This question is the antidote to automation bias and we will repeat it throughout the module.
In summary
Artificial intelligence is a powerful assistant in auditing: it prepares data, scans, drafts, calculates and reduces hours to minutes. But the audit opinion, judgment of material misstatement and conclusion belong to the independent and competent auditor. Unless the AI's output is verified, it is as valid as an unsigned working paper. Three inviolable principles: source and recalculate (authentication), test with auditor skepticism, anonymize data and choose secure means (confidentiality and independence). As the risk increases, the AI's role becomes smaller and your judgment grows.
Application task
Select three repetitive tasks from your own audit practice (or a hypothetical audit): for example, (1) extracting a horizontal analysis summary from the trial balance, (2) locating a standards clause, (3) drafting a working paper. Write a prompt for each using the "strong prompt" pattern above; Add the role, anonymized data, steps and “fabrication ban”. Then run the output through three verification steps (source, recalculate, test with skepticism) and note what errors you catch.
checklist
- [ ] I anonymized the data I gave to AI; I did not share customer name, TIN, personal data.
- [ ] I added role, context, purpose, and “no fabrication” to the prompt.
- [ ] I recalculated every number and ratio in the output with independent source.
- [ ] I have confirmed the standard/substance references from the official text.
- [ ] Convert the output to "where could it go wrong?" I tested it skeptically with the question:
- [ ] I made the final judgment and opinion myself; I did not cite AI as a reason.
- [ ] I evaluated the suitability of the tool I used in terms of data confidentiality and independence.