Jon Morris explains how client use of AI does not change the auditor's role but can shift their focus and how they apply the existing framework.
When a company uses a model to help form an estimate, draft a disclosure or process a transaction, the output arrives on the auditor’s desk as management’s information. When artificial intelligence (AI) has been used, this is no different in principle from a spreadsheet, a valuation or a system report. It gets assessed for audit risk and tested the same way any other estimate, judgement or system output does. In this article, AI refers broadly to technologies that use data and algorithms to generate predictions, recommendations, content or other outputs, including machine learning and generative AI.
The use of AI in a client's finance function can feel like a category of its own, something that needs a new rulebook before you can respond to it. However, the auditor's job – to understand the entity (including use of information technology), identify the risks of material misstatement and respond with sufficient appropriate evidence – has not changed, although AI can shift where they need to focus their attention. This is what auditors will need to get their heads around as the implementation of AI is expected to ramp up significantly in the near to medium term.
What auditors are seeing in practice
Despite steadily rising adoption of AI (based on a sample of FTSE 100 auditor’s reports, as at June 2026), Grant Thornton has not found an auditor so far that has reported a client's use of AI as a key audit matter (KAM). This also aligns to our own experience, where we have yet to report a client’s use of AI as a KAM. That is a useful signal as KAMs are, by definition, the matters of most significance in the audit. Their absence here tells us that auditors are looking at current AI use and concluding that AI is either not being used, or its use is not a matter considered to be of most significance in the audit of the financial statements.
Board-level awareness of AI adoption is also increasing. Grant Thornton's Audit Committee Brief, drawing on six years of its Corporate Governance Review, finds that FTSE 350 companies consistently cite AI as one of the five emerging risks, while 56% recognise the opportunities it presents. Yet the capability to govern AI lags behind: only 7% of FTSE 350 boards report dedicated AI, data or cyber expertise. AI is firmly on the boardroom radar, but the governance around it is still maturing. A board naming a technology as an emerging risk is not the same as that technology being embedded in the numbers, and it is the numbers the auditor opines on.
The FRC's July 2026 research on the use of AI in corporate reporting reaches a similar conclusion from the preparer's side. It found that corporate reporting remains human-led: generative AI is emerging as genuinely useful in narrative reporting, but its use in the financial statements remains limited, and most deployment sits in lower-risk, task-specific activities rather than areas needing significant professional judgement. Preparers pointed to trust, data quality and governance as the reasons for caution, and noted that investors still place a premium on authenticity and accountability in the high-judgement parts of a report.
However, as management teams grow more confident and AI evolves, AI is likely to move from drafting and data-wrangling into the areas auditors care most about: the complex, judgemental estimates. Expected credit loss (ECL) models is an area management may explore. These models are already dense with assumptions, and an AI component could shape a genuinely material number. When it happens, it should be read as the normal evolution of risk assessment, rather than a looming threat. Auditors have absorbed new estimation techniques, new systems and new modelling approaches before and tested them within the existing auditing framework.
What to focus on
The practical starting point is narrower than "Does my client use AI?" Almost every client now uses AI somewhere. What matters is where AI has been used to produce information that feeds the financial statements.
Most operational AI use will not meet that test. For example, a store manager using a tool to optimise shift patterns, a business using a customer-service chatbot, or a marketing team generating campaign copy – these may be commercially significant, but they do not directly touch the balances the auditor is opining on. They sit outside the financial statement risk assessment in the same way most of a client's day-to-day operations do. However, auditors will need to remain alert for indirect impacts such as material savings built into going concern forecasts or impairment cashflows based on AI-driven changes to operations. Therefore, cataloguing every instance of AI across the business would be effort spent in the wrong place. This is not a new exercise for auditors, who have a wealth of experience determining which IT applications they need to assess for audit risk.
Contrast that with AI embedded in an ECL model, a stock provision, a valuation input or a revenue-recognition judgement. Here the output flows directly into a balance the auditor must test, and that is where attention belongs. This is the same materiality and risk lens auditors already apply to everything else. An AI tool that helps set a provision matters for exactly the same reason that a manual model setting that provision would: it drives a number in the accounts.
Almost every client now uses AI somewhere. What matters is where AI has been used to produce information that feeds the financial statements.
Once a relevant use is identified, the risk is assessed and a response designed. The auditors’ response draws on options auditors already have:
- Controls: How does management govern the model? Who owns it, how was it validated, what checks sit over its inputs and outputs and how is it monitored over time? These are the questions an auditor already asks of any significant IT-dependent process when identifying and assessing risk under ISA (UK) 315.
- Substantive testing: Whatever the tool, the output is testable. Understand the model, reperform the calculation, challenge the assumptions, test the underlying data and assess the estimate for reasonableness and management bias under ISA (UK) 540. An estimate does not become un-auditable because a model helped produce it. Auditors do not necessarily need to understand every line of code or follow every step in a model’s reasoning process, but they do need to critically evaluate the output, including the underlying data, assumptions and judgements, and consider whether the use of the model is appropriate for the audit evidence required.
- Experts: Where a model is genuinely complex, an auditor's expert can be engaged under ISA (UK) 620, just as they already are for pension valuations, complex financial instruments or specialist provisions.
None of these were invented for AI. They are the standard responses to any complex estimate or system-generated output. The novelty is in the back end, rather than the method. With additional focus in some new areas, an auditor who can test a manually built ECL model already has the framework to test one with an AI component.
With additional focus in some new areas, an auditor who can test a manually built ECL model already has the framework to test one with an AI component.
What changes
What changes is the specific set of questions asked about how the model was built, trained, governed, validated and monitored and whether the client can evidence answers to them.
This is also where the "black box" worry usually surfaces: the fear that a model is too opaque to audit. In practice, the auditor doesn’t always need to understand every internal weight and parameter. The auditor needs to have enough of an understanding of the model's purpose, inputs, key assumptions and outputs to design a meaningful response and to test whether the result is reasonable, consistent with other audit evidence and free from material error. Where a client cannot explain how a model reaches its conclusions well enough for the auditor to do that, the difficulty is real, but it is a limitation in the client's control environment and documentation, and it is scoped and reported as such.
There is a scepticism point here too, especially as many AI models are probabilistic and traditional software is deterministic. AI outputs can also carry a false air of precision and objectivity: a number produced by a model can feel more authoritative than the judgement that underpins it.
Professional scepticism means treating a model's output as an assertion to be corroborated, as opposed to a fact to be accepted. It also means staying alert to how a tool has been configured, prompted or selectively relied upon, as well as how its behaviour (and the behaviour of the humans interacting with it) may have evolved over time since it was first validated and deployed. A model tuned, deliberately or not, to produce a convenient answer is a familiar risk wearing new clothes. This is territory auditors know well, simply pointed at a new AI component.
Where this leaves the auditor
Concrete examples in the market are still limited but that will change quickly and probably first in the areas that matter most. The right posture is neither alarm nor complacency. There is no need for a "this could catch you out" mindset. Equally, today's lower risk profile is a snapshot, not a settled position, and standard-setters are already watching it closely. The FRC's audit technology and AI sandbox is one sign that the regulatory picture will keep developing alongside practice.
The practical approach is simply to ask where AI has been used. Filter for the uses that genuinely affect the financial statements. Assess those uses for risk, and respond with the controls, substantive testing and expert input you already rely on. Leave the rest outside the scope where they belong.
Client use of AI does not change the auditor's role. The objective is the same, the standards are the same and the framework is the same. What it changes is where auditors point their existing scepticism and how the existing framework is applied. Auditing a client that uses AI is the discipline auditors already have with some additional focus, applied to one more source of the information they have always been there to challenge.
Jon Morris, Director, Audit Professional Standards, Grant Thornton UK LLP
Join your peers...
ICAEW's Annual Conference 2026 is themed "Turning business complexity and change into value" and offers practical support to help you respond to economic, political and technological disruption.