ICAI Journal Focus • Technology • Next-Generation Assurance & Advisory

Impact of Technological Disruption in Auditing

A Comprehensive Exposition on the Transformation of the Assurance Mandate: The Tripartite Model (Assure, Advise, Anticipate), IFAC and ICAI DCMM 2.0 Benchmarks, Practical Deployment of Digital Assets (RPA, AI, GRC, Cyber Audits), Agile Sprint Auditing, and Transitioning to Foresight-Driven Value Creation

Authors: CA. Yukti Arora & CA. Mukesh Gupta (Members of the Institute • yuktiarora@hotmail.com • eboard@icai.in)
Citation: The Chartered Accountant, Vol. 69, No. 4, October 2020, pp. 82–85 (Journal pp. 441–444)
Classification: Information Technology, Digital Audit, Internal Audit Framework, GRC & Cyber Assurance

⚠ The Next-Generation Auditing Paradigm • Core Editorial Insight

“The technological disruptions are bringing multiple changes in the ways we live, interact and work. The evolution in technology has created strong dependence of human beings on gadgets and technologically enabled systems, processes and machines. In the current scenario, auditors are facing challenges in providing assurance and advisory services in different domains that are using emerging technologies like analytics, artificial intelligence, robotic process automation and Internet of things. At the same time they are also faced with challenges in using these technologies to perform their own tasks in much more efficient and effective manner to meet the expectations of various stakeholders. The environment requires auditors to leverage digital assets as well as develop new skills to be change catalyst, be more innovative in their approach and possess a mix of business and technology skills. Adoption of disruptive technology will enable auditor to introduce new and enhanced auditing, advisory and risk management services to their customer. It will also enable them to be ready for next generation auditing model wherein there is, technology adoption for refining auditing procedures as well as for understand complex client landscape and meet ever increasing expectations from varied stakeholder.”

1. Introduction: The Tsunami of Data and Complex Risk Landscapes

We are witnessing technology everywhere and are in an environment where there is a tsunami of data, some structured and mostly unstructured. Auditors are experiencing an uphill task of increased demand to understand the risks and customise auditing procedures accordingly.

Auditors are required to embrace the change arising from disruptions caused by the use of Artificial Intelligence (AI), Cognitive Computing, Robotics and Internet of Things (IoT) in their clients’ businesses. The auditors are being called upon to provide assurance, advisory services and predict risk arising from these technological disruptions. Hence, it becomes imperative for auditors that they themselves demonstrate how they adopt emerging technologies like AI, Cognitive and Robotics to counter audit challenges posed to them by large datasets or data lakes to review.

Auditors are required to be adept in the use of these disruptive technologies in order to deal with the complexities which arise due to:

  • The need for enhanced corporate governance and ethics;
  • The “Blackbox model” of AI algorithms and autonomous neural networks;
  • Rules and exception response mechanisms of robotics;
  • Regularly changing global compliance requirements; and
  • Escalating cyber threats inherent in enterprise digital transformation.

Businesses have fast-forwarded the adoption of these technologies due to their obvious benefits and the recent pandemic experienced across the Globe, leading to processes becoming leaner, efficient, rule-based, repeatable and machine-dependent.

2. The Tripartite Auditor Mandate: Assure, Advise, and Anticipate

The role of the auditor is witnessing a transformational change due to the rapid evolution and adoption of modern technologies. The auditor’s role can be broadly categorised into three strategic pillars: Assure, Advise, and Anticipate.

Pillar 1: Assure

The assurance role is governed by various Acts and Rules. In addition to statutory requirements, as defined in the SIA framework governing internal audit issued by ICAI:

“Internal audit provides independent assurance on the effectiveness of internal controls and risk management processes to enhance governance and achieve organisational objectives.”

Internal Audit is responsible for providing independent and objective assurance on the adequacy and effectiveness of governance and risk management. The biggest consideration is identifying high-risk areas and channelising audit efforts accordingly. Auditor understanding of technology architecture, governance over technological changes, and comfort on design-level controls are critical for discharging duties to the Audit Committee.

Pillar 2: Advise

The Internal Auditor is uniquely placed to provide valuable real-time advice to business owners as they adopt, upgrade, and modify technologies. In-depth domain knowledge enables advice on IT strategy, governance, application configurations, and cyber controls.

Auditors are increasingly called to advise on emerging technology governance, ethics, algorithm and model assumptions, data quality, and cybersecurity standards. Crucial Boundary: In their advisory capacity, auditors must never assume management ownership of controls; designing strategy, processes, and systems remains the sole responsibility of enterprise management.

Pillar 3: Anticipate

The auditor’s ability to visualise what could go wrong and demonstrate farsightedness provides an indispensable tool to management, establishing a sophisticated technology-led organization with best-in-class control environments.

With vast data pools available, auditors must anticipate emerging exposures around transparency, accuracy, privacy, social expectations, and legal shifts. Auditor knowledge must be deployed for “risk learning” – sensitizing process owners on ethical boundaries and regulatory constraints while leveraging analytics, AI, and robotics to deliver proactive risk responses.

Institutional Perspectives on Technology-Led Audit: IFAC & ICAI DCMM 2.0

Analytics and AI have elevated stakeholder benchmarks; regulators and investors now expect near-100% assurance. In its resource publication, Data Analytics: An Information Resource for IFAC Members, the International Federation of Accountants (IFAC) observed:

“Together with automation, analytics enables better risk understanding across thousands of data points in P&L reporting. Data analytics can improve the co-operation with external auditors to detect patterns and trends, and identify process improvements that can increase efficiency and enhance audit quality. The automation of large parts of audit plans using analytics can also make the internal audit function more efficient and effective.”

Similarly, the Digital Competency Maturity Model 2.0 (DCMM 2.0) issued by the ICAI underscores the urgent necessity for CA firms to adopt digital assets to achieve operational upgradation.

3. Digital Assets: Practical Deployment of RPA, AI, GRC & Cyber Audit Tools

While auditors have utilized basic analytics and dashboards for over a decade, today’s digital age demands smarter deployment of integrated digital assets:

A. Robotic Process Automation (RPA) in Master Data & Expense Testing

BOT algorithms can be programmed to automatically log in and download all changes to system master data during a period, cross-reconciling them against ticketing systems that capture approvals and scanned records. A 100% direct exception report is instantly generated identifying unauthorized changes, post-facto approvals, or unreconciled variances.

Similar algorithms verify business expense approvals across hard-copy vouchers or emails by combining RPA with Optical Character Recognition (OCR) and AI. Furthermore, RPA validates default system configuration controls, automatically populates audit documentation workpapers, and tests Segregation of Duties (SoD) and environmental controls.

B. Customised Analytics Dashboards

Exception reports configured with predefined business rules enable auditors to isolate anomalies and focus substantive testing on true high-risk outliers. Client-specific analytics dashboards provide holistic operational views, enabling comprehensive analytical reviews across massive datasets.

C. Governance, Risk, and Compliance (GRC) Tools

GRC platforms perform dynamic risk scoring for processes managed through enterprise applications. Equipped with pre-built control libraries, GRC software enables an integrated control framework – rationalizing diverse statutory and regulatory mandates (such as SOX, PCI DSS, GDPR) into a unified, streamlined compliance matrix.

D. Mandatory System & Cyber Risk Auditing

Auditors must mandatorily conduct system and cybersecurity audits using established risk methodologies. Reviewing incident response readiness, containment protocols, and disaster recovery mechanisms is fundamental to guaranteeing the confidentiality, integrity, availability, and authenticity (CIAA) of financial reporting.

4. Emerging Skills, Agile Sprints & Foresight-Based Reporting

Next-generation auditing will be technology-led, with routine transactional testing conducted autonomously by machines. The emerging role of the auditor centers on:

  • Value-Chain Synthesis: Connecting disparate datasets, understanding inter-tool dependencies, and identifying missing links within automated workflows (e.g. evaluating automated airport or hotel check-in kiosks to establish precisely when exceptions must escalate to human intervention).
  • Strategic Human Judgment: Channeling professional intellect toward high-end strategic decision-making and governance risks.
  • Agile Auditing Sprints: Because digital issues require rapid rectification, audit engagements are transitioning into agile sprints concluded in real-time or within 2 to 3 weeks maximum.
  • From Observation to Foresight Reporting: Moving away from historical, retrospective observation reporting toward insight- and foresight-based reporting that prevents operational breakdowns and strengthens advisory relationships with the C-suite.

“Today, besides finance, cyber and digital technical skills, an auditor requires adaptability, collaboration, social skills, and the capacity for working with tools and techniques effortlessly.”

5. Conclusion: Building the Enterprise Digital DNA

Digital transformation is profoundly more than superficial technology adoption. Auditors in the digital era must actively partner with organizations to build a cohesive digital DNA – harmonizing business strategy, organizational structures, operational processes, people, and technological capabilities.

By viewing operations through a comprehensive risk lens, auditors harness risk to power performance. In the next-generation assurance model, technology adoption to refine audit testing and decode complex client architectures is no longer optional – it is mandatory.

“In next generation auditing model, technology adoption for refining auditing procedures as well as for understanding complex client landscape and meet ever increasing expectations from the auditor shall be mandatory.”