Consider an illustrative scenario, not a real engagement. A mid-sized distributor connects an audit agent to its ERP, its document repository and its ticketing tool. Within a week the agent has pulled invoices, receipts and approvals for 240 purchase orders and produced a tidy memo saying the procure-to-pay control passed. The audit manager reads it, likes it, and asks the only question that matters: which records did the agent open? Nobody can answer.
The short answer to the sequencing problem is this. Agentic AI should first take bounded, repeatable, evidence-based work: a finite set of documents, stable rules, and output you can check against a known result. It must not decide audit scope, judge whether evidence is sufficient, conclude that a control works, rate a finding, or close an issue. Those decisions belong to accountable auditors, and an agent can only prepare the ground for them.
This article is for internal auditors, chief audit executives and the managers and audit committee members who oversee them. After reading it you will be able to sort audit tasks into automate now, automate with review gates, and keep human. You will also have a short list of access rules, evidence requirements and escalation triggers to put in place before any agent touches a workpaper. The question to ask is not whether AI can replace internal auditors. Ask which audit activities are bounded enough to automate safely, and which decisions need independent professional judgment and a named person who answers for them.





