Everyone Is Talking About AI in Audit. I Think We're Asking the Wrong Question.

I've noticed a shift in the conversations I have with founders, CISOs, and GRC leaders evaluating audit firms over the past year. Not long ago, those discussions centered on topics like experience, methodology, industry expertise, and timelines. Today, one of the first questions is almost always about AI.

That isn't surprising, given that every board is asking about AI, every technology company is talking about AI, and every audit firm is trying to explain how AI will make audits faster, more efficient, or less burdensome for customers. While these are important conversations, I think they're causing many organizations to start in the wrong place.

The real question isn't whether an audit firm uses AI. The real question is if that technology is improving an audit process that’s already grounded in sound methodology, experienced professionals, and a deep understanding of risk. AI can accelerate a well-designed process, but it can't compensate for a poor one. It can't fix weak scoping, inconsistent methodology, or replace the professional judgment required to understand whether an organization's controls are actually reducing risk.

That distinction is important because an audit has never been about collecting evidence. It's about providing independent assurance that an organization's control environment is designed and operating effectively. The technology may change, but the responsibility doesn't.

Read more: AI Risk Management Is Becoming Operational, Not Theoretical

I was reminded of this recently when I met the founder of an early-stage company that came to Thoropass for its SOC 2 audit after preparing with another provider. It had been assigned more than 200 controls despite having a relatively simple operating environment. For a company at that stage, we’d have recommended a very different approach of 45 to 50 appropriately scoped controls. That isn't about lowering the standard; it's about designing a program that accurately reflects the company's risk profile.

Why were so many controls assigned? The issue wasn't a lack of automation, but that the audit started with the wrong scope. When companies are asked to manage controls that don't align to their actual risks, they create unnecessary work before the audit even begins.

Scoping is one of the least visible parts of an audit, yet it has an enormous impact on both the quality of the engagement and the customer experience. Organizations can be over-scoped, under-scoped, or focused on the wrong systems altogether. Each creates its own set of risks. The right scope requires experienced auditors who understand the framework, the technology environment, and, most importantly, the business itself.

Once those fundamentals are in place, AI becomes incredibly valuable. It can organize evidence, identify inconsistencies, surface missing documentation, and eliminate much of the administrative work that has historically slowed audits down. It allows auditors to spend less time managing artifacts and more time evaluating risk, testing controls, and exercising professional judgment. That is exactly where technology should create value, by empowering auditors to focus on the work that matters most.

Read more: The Future of Audit is AI-Powered – But Must be Human-Led

As someone who spent more than two decades leading IT Risk and Control functions before founding Thoropass, I've always believed that the best audits do more than satisfy customer requirements. They improve the organization's overall security posture.

Too often, companies think of an audit as a report they need to obtain so they can close enterprise customers or satisfy contractual obligations. The report is important, but it shouldn't be the only value they receive. This is why the best audit firms help organizations improve their security programs, and that starts with asking better questions during scoping. It continues by identifying opportunities to strengthen controls before they become findings, challenging assumptions where appropriate, and helping management teams understand how their risk profile will evolve as the business grows. Over time, the relationship becomes more than an annual compliance exercise. It becomes an opportunity to continuously strengthen governance, improve operational discipline, and build greater confidence in the organization's ability to manage risk.

This is one of the reasons respected audit firms earn long-term relationships with their clients. Organizations stay with them not simply because they issue reports, but because they bring perspective. Experienced auditors have seen hundreds of security programs across different industries and stages of growth. They recognize patterns, understand emerging risks, and provide context that helps leadership teams make better decisions. That, in my view, is where our profession is headed. 

Of course AI will continue to transform how audits are performed, and it will remove manual work, improve consistency, and create a significantly better customer experience. Before long, every audit firm will be using some form of AI throughout the audit lifecycle.

What will continue to differentiate firms is not the technology itself, but the quality of the professionals behind it. Customers should absolutely ask about AI, but they should spend just as much time asking about methodology, scoping, quality controls, peer review, and the experience of the people responsible for the audit opinion.

Ultimately, organizations aren't looking for software. They want confidence that their audit will withstand scrutiny, confidence that they're focusing on the risks that matter most, and confidence that they're building a stronger security program as their business grows.

Technology can help deliver that experience, but it can't create it on its own. That still comes from experienced auditors applying sound judgment, independent thinking, and a genuine commitment to helping organizations manage risk more effectively. As our profession evolves, I hope that's what we continue to value most.

In this post:

Stay Connected

Subscribe to receive new blog articles and updates from Thoropass in your inbox.


Eva Pittas

See all Posts

Related Posts

Stay connected

Subscribe to receive new blog articles and updates from Thoropass in your inbox.


Want to join our team?

Help Thoropass ensure that compliance never gets in the way of innovation.

View Open Roles

Have any feedback?

Drop us a line and we’ll be in touch.

Contact us