Inisghts

The unexpected obstacle to AI-enabled SOX and internal audit

Executive summary

AI can help SOX and internal audit teams test larger populations and improve efficiency. It can also expose an inference gap between documented controls and the way the business operates. Organizations gain the greatest value from AI when they investigate unexpected results and their root causes and use those insights to strengthen controls and improve future testing.

Index

For decades, SOX internal audit and compliance teams have relied on rigorous verification processes to evaluate controls. However, they also rely on implicit logic and institutional knowledge that has often never been formally documented.

As organizations broaden the use of AI and automation in governance functions, they are finding that many old processes rely on insights that exist outside of formally recorded data and controls.

"This creates what I call the 'inference gap. Automated tools can only evaluate the information available in the source data and configured logic. If automation is applied to historical processes that relied on undocumented knowledge, it can generate results that conflict with established business practices," said Greg Haberer, Associate Partner of Risk Advisory at Grant Thornton.

Auditors need to pay attention to these divergences. When AI flags an anomaly or fails a control test, it often indicates a misalignment between the documented controls and the way the organization actually functions.

To extract more value from AI, auditors need to move from just validating exceptions to understanding why they occurred.

From anomaly to root cause

Unexpected results can generate friction between audit teams and other business areas.

For example, a test may identify transactions that appear to be without the required approvals, even if those approvals are present in the evidence presented. In practice, testing procedures may have been written inaccurately or contain technical inconsistencies that need to be corrected to eliminate ambiguity.

While automated testing can reveal problems in data, processes, and controls, that doesn't mean that data remediation is the responsibility of internal audit. This responsibility must remain with the business area that owns the data.

"The first line is responsible for its own data," Haberer says. "But traditional auditing often masks data deficiencies by ignoring 'exceptions' that humans intuitively understand but that AI systems can't interpret."

When AI produces an unexpected result, the role of the modern auditor is to investigate the sequence of events that led to that result, using a root-cause-driven investigative approach.

Audit teams must question

  • What human assumptions are not reflected in the data or testing logic?
    Is the source data complete and accurate?
  • Does this anomaly represent a real failure of control or does it show that the Information
  • Produced by the Entity (IPE) does not have the necessary accuracy for automated governance?
  • What evidence should be preserved to support regulatory reviews and external audit requirements?

Unexpected AI result → Validate model parameters → Identify systemic input or process failure → Report the root cause to the business area.

When internal audit properly identifies and communicates the root causes of an unexpected outcome, the data department can correct recurring issues and increase the reliability of future testing.

Building AI-based governance that is defensible and repeatable

When teams use AI-enabled testing to strengthen processes and controls, they also strengthen internal audit as a driver of organizational maturity.

This generates benefits such as:

  • Defensible repeatability
    Processes become more standardized when they reduce reliance on individual interpretations and undocumented institutional knowledge.
  • Audit-ready efficiency
    Once data, controls, and system configurations are aligned, AI can run continuous tests across the entire population while maintaining a transparent audit trail that meets the requirements of external auditors.
  • Better risk identification
    AI-enabled testing helps teams direct efforts to unusual patterns, exceptions, and areas that deserve further investigation.

Over time, these advancements allow organizations to develop a more scalable and consistent approach to risk management and compliance.

Summary

SOX and internal audit teams are already using AI to increase productivity and reduce costs. At the same time, they are finding that unexpected results often reveal gaps between documented controls and the way the business actually operates. But these results do not explain themselves. Auditors still need to follow the evidence to understand what it reveals about the underlying processes.

"The most effective audit functions will be those that use AI as a tool for generating insights, and not just as an automation tool. By analyzing what unexpected results reveal about the true state of their data and operations, organizations are able to identify conditions that generate recurring control exceptions while increasing confidence in automated testing over time." concludes Haberer.