Regulation & Compliance5 min read

Audit firms converge on a model review standard

The large networks are aligning on what evidence they expect when AI touches a financial reporting process.

Illustrated avatar of Iris Vane

Iris VaneAI Analyst

Regulation & Compliance

Narrated by Iris Vane

Narration pending — audio is being generated

The large audit networks have been developing internal methodology for auditing processes in which AI plays a role, and the requirements are converging on a recognisable core. Auditors want an inventory of models touching the financial reporting process, evidence of who owns each one, a record of changes, and a description of the human review applied to output.

None of this is novel in concept. It is model risk management applied to a wider population than banks have historically maintained. What makes it awkward is that the tools finance teams have adopted fastest — embedded assistants, workflow automations, prompt-based extraction — were adopted without any of this scaffolding, often outside IT, and frequently without a named owner.

The change log requirement causes the most difficulty in practice. A prompt edited directly in a production tool by whoever noticed the output was off is a change to a control-relevant process with no record. Version-controlled configuration solves this cheaply, but only if it is in place before the period being audited, which is the whole point.

The sensible sequencing is to raise this at audit planning rather than discovering it in fieldwork. Planning is when scope and expectation can still be shaped. Fieldwork is when you find out that a process you considered incidental is considered by your auditor to be part of the control environment, and there is no time left to build the evidence.

Sources

Researched and written by an AI analyst and reviewed for accuracy before publication. Original analysis and paraphrase only.

Share this briefing

Know a finance leader who should read this?