
This comprehensive guide integrates the Financial Reporting Council's insights on implementing and documenting AI tools in audit procedures, fostering innovation while upholding professional standards. It also introduces Guidenet.ai's powerful Risk and Control Matrix (RACM).
In June 2025, the UK’s Financial Reporting Council (FRC) released its first formal guidance on the use of Artificial Intelligence in audit. While aimed at auditors, the implications go much further. For any organisation deploying AI in finance or risk functions, this guidance should be leveraged, it offers a blueprint for designing systems that stand up to scrutiny.
Official FRC Guidance (reference): FRC official guidance
As AI tools increasingly automate journal testing, anomaly detection, and forecasting, auditors are being asked to evaluate their validity. The FRC’s message is clear: AI can enhance audit quality when it is explainable, controlled, and appropriately documented.
This creates a powerful incentive for businesses:
Build AI with these expectations in mind, and you are far more likely to gain auditor acceptance, reduce last-minute delays, and strengthen trust in your financial reporting.
This guide is written for finance, risk, compliance and digital leaders.
It unpacks the FRC guidance and translates it into a set of practical design and documentation principles that organisations can adopt proactively. You’ll find:
This is your chance to build audit-ready AI, before it becomes a compliance bottleneck.
It's important to note that auditors will take at least the same expectations outlined in this document when they encounter use of AI systems by management in financial reporting. This ensures consistent standards are applied whether AI is used by auditors or by the entities they audit.
XYZ LLP has been the auditor of ABC PLC, a listed retail business, for several years. The firm has recently completed in-house development of a technology-enabled tool to enhance fraud procedures, leveraging AI to identify potentially anomalous items unusual relative to the population.
While traditional fraud procedures often consist of filtering journals by rules-based criteria, this tool allows identification of more subtle patterns that may indicate risk, enhancing the quality of the procedure. The tool has progressed through limited deployment and is now mandated on qualifying engagements.
The firm considered two main options: an unsupervised machine learning model that applies statistical techniques to identify unusual items, and a deep learning model (neural network) trained on large quantities of data to recognize patterns.
The firm determined users should understand why transactions were flagged as unusual, allowing audit teams to design responsive procedures. This required either selecting an inherently explainable model or augmenting a complex model with explainable AI techniques.
The firm used a combination of real and synthetic data for testing and calibration, ensuring appropriate authorization was obtained and data processing met legal and regulatory requirements.
The development of the methodology supporting the tool occurred concurrently with the tool itself, with representatives from the firm's central methodology team included on the project leadership. This promoted collaboration between methodology and technology experts, ensuring the final tool embedded well into the firm's methodology.
The firm decided to combine the AI tool with traditional rules-based techniques rather than replacing them entirely. This addresses the limitation that the AI tool only identifies items unusual relative to the population, potentially missing consistently posted unusual transactions.
Significant professional judgment was required to calibrate how much weight each routine should contribute to identifying riskier transactions and setting thresholds. This process required both theory and experimentation with data to ensure a robust approach.
The team begins by determining if criteria for mandatory tool use are met: sufficient data quality (complete and accurate general ledger data with required fields) and whether additional evidence is needed to address fraud risk.
The team documents that criteria are met and runs the tool, which identifies journals deemed high risk. The tool is integrated into audit software with controls ensuring only the latest approved version is used.
The team follows up on flagged items, considering why transactions were identified as potentially anomalous to determine appropriate evidence-gathering procedures.
The methodology requires teams to be alert for information indicating the tool's assessment may be systemically flawed in the engagement context.
The FRC has provided comprehensive guidance on what should be documented centrally by firms regarding AI tools, whether developed in-house or obtained from third parties.
Explanation of what the tool does conceptually, its objective, and the nature of the underlying technology in broad terms.
The criteria that should be met for tool use to be appropriate, including data characteristics, transaction categories, and business model considerations.
The rationale for development, standards compliance, data sources and permissions, model selection and architecture, training approach, and version history.
For third-party tools, firms may need to rely on independent assurance that the tool operates as intended when full development information isn't available.
The governance architecture around development and operation, and key steps in any certification process including operational testing.
Available materials on appropriate use, operation, and output interpretation, including strategies to mitigate automation bias.
How the tool was designed to be appropriately explainable, recognizing that appropriate levels of explainability vary based on intended use.
Documentation of how the tool aligns with the 5 government AI principles: safety/security/robustness, transparency/explainability, fairness, accountability/governance, and contestability/redress.
The FRC guidance outlines key material that should be documented on the audit file for AI-powered ATTs. As a guiding principle, the more widely used a tool is across engagements, the more documentation can shift toward central repositories.
Brief explanation of what the tool does conceptually, its objective, version number, and any team-specific configuration or modifications.
The team's assessment against centrally determined criteria, particularly how they ensured input data completeness and accuracy.
Evidence of approval from relevant central functions (unless centrally documented for universally approved tools).
How the team used the outputs to conclude on relevant judgments or inform further procedures.
For AI tools that aren't used to perform audit procedures directly, there may be no requirement to document their use on the audit file if not needed for an experienced auditor to understand the basis for the auditor's report or significant matters. However, teams may choose to document when it would help reviewers better understand the work performed.
While formal documentation requirements may be limited, teams should consider whether documenting the use of these tools would:
The FRC's expectations are informed by the regulatory environment with respect to AI, including the government's 5 AI principles. These principles provide a framework for responsible AI development and use:
Ensuring AI systems operate reliably, securely, and as intended even in unexpected situations or when facing attempts to compromise them.
Making AI systems understandable to users and those affected by them, with appropriate levels of disclosure about how decisions are made.
Developing and using AI systems that are inclusive and accessible, avoiding unfair bias or discrimination against individuals or groups.
Establishing clear responsibility and oversight for AI systems throughout their lifecycle, from development to deployment and use.
Providing mechanisms for people to challenge AI-based decisions that affect them and seek correction or redress when needed.
Auditors will take at least the same expectations outlined in this document when they encounter use of AI systems by management in financial reporting. This ensures consistent standards whether AI is used by auditors or by the entities they audit.
Auditors need to understand how management's AI tools function, their purpose, and how they impact financial reporting.
Assessment of management's governance and controls over AI systems, including development, testing, and ongoing monitoring.
Procedures to test the reliability and appropriateness of outputs from management's AI systems that affect financial statements.
When auditing entities using AI in their financial reporting processes, auditors should apply professional skepticism and consider whether additional specialized skills or knowledge are needed on the engagement team.
The FRC encourages innovation while ensuring adherence to professional standards. This balance is critical for maintaining audit quality while embracing technological advancement.
The FRC recognizes that AI has the potential to significantly enhance audit quality when deployed responsibly. The guidance aims to support firms in implementing innovative approaches while providing clarity on expectations.
The material is not prescriptive and does not represent a static set of expectations, acknowledging the rapidly evolving nature of AI technology.
While encouraging innovation, the FRC emphasizes that the fundamental requirements of auditing standards remain unchanged. AI tools must support auditors in meeting these standards, not replace professional judgment.
Documentation requirements aim to be proportionate, recognizing that over-documentation can divert resources from areas where they can better enhance audit quality.
To support consistent, high-quality application of the FRC guidance, this comprehensive Risk and Control Matrix (RACM) translates expectations and audit standard obligations into a practical control framework.
The RACM is structured to facilitate seamless integration of AI-related controls across audit engagements, encompassing 15 key controls strategically grouped across five critical domains of AI governance and assurance.
Ensuring clear roles, responsibilities, and ethical considerations for AI deployment.
Controls over the completeness, accuracy, and relevance of data used by AI systems.
Processes for designing, building, testing, and validating AI models for intended use.
Controls for secure deployment, continuous monitoring, and performance evaluation of AI in operation.
Requirements for comprehensive documentation and transparent reporting on AI system design, use, and outcomes.
The Risk and Control Matrix (RACM) serves as a vital resource for a diverse group of stakeholders, ensuring clarity and consistency in the application of AI within audit practices. Its comprehensive framework is tailored to meet the needs of:
Providing practical guidance for the responsible use of AI-enabled tools in daily audit procedures.
Facilitating consistent and effective oversight of AI integration and related controls.
Supporting the development and update of audit frameworks to incorporate AI effectively.
Enabling robust monitoring and assurance design concerning AI risks in audit.
Offering clear insights into AI governance and accountability within the audit profession.
Continuing our deep dive into the Risk and Control Matrix, this section outlines critical controls for integrating AI responsibly into audit processes. These controls ensure robust governance, explainability, and human oversight, maintaining audit quality and integrity.
We've covered the critical aspects of designing and implementing a robust AI Control Framework. This comprehensive guide provides a foundation for mitigating risks, ensuring compliance, and fostering responsible AI innovation within your organization.
To deepen your understanding and access the full suite of resources, including detailed framework documentation and practical tools, visit our dedicated platform.
The content presented in this publication is provided for informational and professional development purposes only. It is intended to reflect the authors’ professional judgment and insights at the time of publication and does not constitute legal, regulatory, audit, compliance, or other professional advice.
This material may reference or draw conceptual alignment from publicly available frameworks and guidance, including but not limited to the NIST AI Risk Management Framework, ISO/IEC 42001, the EU Artificial Intelligence Act, the UK Corporate Governance Code, and other relevant standards. Such references are provided solely for contextual purposes. GuideNet.ai makes no representation or claim of compliance with, endorsement by, or affiliation to any such frameworks, regulatory bodies, or standards-setting organisations.
Users of this publication are solely responsible for evaluating its applicability in the context of their specific organisational, regulatory, legal, and operational environments. Any actions or decisions taken based on this material are undertaken at the user’s own risk. The authors and GuideNet.ai expressly disclaim any liability for loss or damage arising from reliance on or implementation of the content herein.
All rights, including copyright and intellectual property rights, in and to this publication are reserved. No part of this material may be copied, reproduced, distributed, adapted, or disclosed to third parties in any form or by any means without the prior written consent of GuideNet.ai.
FRC Guidance: Enhancing Audit Quality with AI & Guidenet.ai's essential control considerations