AI use case

Generative AI copilot for internal audit

A copilot for internal auditors that drafts planning memos and document request lists from prior audits, summarises large evidence sets, builds risk and control matrices from policies and process documents, and drafts findings and reports, with every statement traceable to its evidence and a qualified auditor accountable for every conclusion.

By Len Debets · Last verified 27 September 2026 · 3 public deployments

55%
Reported handling time reduction
Banco Bradesco, vendor claim.
65%
Reported productivity gain
Banco Bradesco, vendor claim.
USD 236,250 to USD 1.4 million
Indicative value per year
A bank internal audit function with 60 auditors. Worked example, see how it is calculated.

What problem does it solve?

Internal audit functions are asked to cover a widening risk universe (cyber, third parties, AI, conduct, operational resilience), and every new area competes for the same auditor hours. A large share of each engagement is reading and writing: going through prior workpapers, policies and process documents to plan the scope, summarising hundreds of pages of evidence, documenting walkthroughs, and drafting findings and reports that go through several rounds of review.

Generative AI fits that reading and writing work, and audit leaders are adopting it quickly. The question for a third line function is how to use it without weakening what makes audit valuable: independence, evidence that stands up to challenge and a qualified auditor who owns every conclusion. A fluent sentence in a workpaper that no evidence supports is worse than no sentence.

How does it work?

  1. Plan from what is known. The copilot retrieves prior workpapers, previous findings and their status, the risk assessment and relevant policy changes, and drafts the planning memo, scope and document request list for the audit lead to edit.
  2. Build the control picture. From policies, procedures and process documents it drafts a risk and control matrix and walkthrough narratives, citing the document behind each control.
  3. Digest the evidence. It summarises evidence files, meeting notes and management responses, and answers the auditor's questions about them with page level citations.
  4. Point at anomalies. Analytics on full populations (payments, access logs, journal entries) surface outliers and exceptions for the auditor to test; the AI explains the pattern, it does not conclude on it.
  5. Draft findings and reports. It drafts findings in the house structure (condition, criteria, cause, effect, recommendation) from the auditor's notes and tested evidence, and checks draft reports for consistency and tone.
  6. Keep the trail. Every AI draft, the prompt context and the auditor's edits are stored with the workpaper, so reviewers can see what the AI wrote and what the auditor concluded.
Audience
Employee facing
Autonomy
Copilot
Adoption
Early adopters
Channels
Internal tools, Microsoft Teams

What is it worth?

Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.

Value benchmarks for Generative AI copilot for internal audit
KPIMedianReported rangeData pointsClaimed by
Handling time reductionToo few to pool
30% to 55%
22 vendor
Productivity gainToo few to pool
30% to 65%
22 vendor

Value drivers: Employee productivity, Speed and cycle time, Compliance quality, Risk and loss reduction.

Indicative value

A bank internal audit function with 60 auditors

USD 236,250 to USD 1.4 million

Auditor capacity released for testing and additional coverage per year

How this is calculated

Formula: auditors * hoursPerYear * draftingShare * timeSaved * hourlyCost. The low scenario uses every low input, the high scenario every high input.

InputLowHighBasis
Auditors using the copilot auditors, auditors6060The reference organization.
Productive hours per auditor per year hoursPerYear, hours per auditor per year1,5001,600Editorial assumption after leave, training and administration.
Share of auditor time spent on planning documents, evidence summaries, workpaper write ups and reports draftingShare, fraction of time0.250.4Editorial assumption. Replace with your own time recording.
Share of that drafting and summarising time saved timeSaved, fraction of time0.150.3Conservative against the evidence on this page (Microsoft reports 30% less time writing internal audit reports at BCI and 55% less time in reporting at Bradesco), because those are vendor reported best cases.
Fully loaded auditor hour hourlyCost, USD per hour70120Editorial assumption. Replace with your own rate.

What it leaves out: Capacity only, which most functions reinvest in coverage rather than headcount. It leaves out the value of broader risk coverage and full population testing, and the cost of reviewing AI drafts and maintaining the workpaper corpus.

Who already uses it?

3 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.

Banco Bradesco

Brazil · Banking · 2025

ProductionGrade C

Bradesco built AILA, an assistant on Azure OpenAI that supports its audit process across planning, reporting, drafting and proofreading, and root cause analysis. Microsoft reports efficiency and time savings for each of those steps in a customer story round up, without stating the measurement method or period.

  • Productivity gain: 65%
    "With AILA, they achieved 65% more efficiency in audit planning, 55% less time in reporting, 50% less time writing/proofreading, and improved the identification of the root cause of problems by reducing the time required for this step by 20%."
    Claimed by: vendor
  • Handling time reduction: 55%
    "With AILA, they achieved 65% more efficiency in audit planning, 55% less time in reporting, 50% less time writing/proofreading, and improved the identification of the root cause of problems by reducing the time required for this step by 20%."
    Claimed by: vendor

British Columbia Investment Management Corporation

Canada · Wealth and asset management · 2025

ProductionGrade C

BCI uses Microsoft 365 Copilot and the Azure ecosystem to automate manual tasks across its operations. Among the outcomes Microsoft reports is less time spent writing internal audit reports; the source does not say which tool produced that result. The organization wide productivity figures on the same page are not specific to audit and are not recorded here.

  • Handling time reduction: 30%
    "The organization saved more than 2,300 person-hours through automation, reduced the time spent on writing internal audit reports by 30%, and saved a month of processing time to analyze 8,000 survey comments."
    Claimed by: vendor

XP Inc.

Brazil · Capital markets · 2025

ProductionGrade C

XP Inc. uses Microsoft 365 Copilot to automate tasks across the company, and Microsoft reports a gain in audit team efficiency alongside total hours saved. The hours figure is company wide; how efficiency was measured is not published.

  • Productivity gain: 30%
    "XP Inc. uses leverages Microsoft 365 Copilot to automate tasks, significantly boosting productivity by saving more than 9,000 hours and increasing audit team efficiency by 30%."
    Claimed by: vendor

How do you implement it?

A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.

Data you need

  • Prior workpapers, findings and reports in the audit management system
  • The audit methodology, templates and finding structure
  • Policies, procedures and process documents for the audited areas
  • Population data (transactions, logs, journals) for analytics where testing needs it

Systems to integrate

  • Audit management system (workpapers, issues, action tracking)
  • Document management and policy repositories
  • Data platform for population analytics
  • Microsoft Teams or the audit team's collaboration tool

Complexity: Medium

Drafting and summarising on a secure platform is quick to start. The harder parts are giving the copilot permission aware access to workpapers and evidence without breaching confidentiality between engagements, and agreeing the methodology changes for documenting AI assistance.

  1. 1

    Update the methodology first

    Decide where AI may assist (planning, summarising, drafting) and where it may not (forming opinions, rating findings), and how AI assistance is recorded in workpapers. Brief the audit committee and the external auditor.

  2. 2

    Start with low risk drafting

    Planning memos, document request lists and summaries of prior audits give quick wins with little risk, because the auditor edits every output before it is used.

  3. 3

    Ground everything in the audit corpus

    Connect prior workpapers, the methodology and policies with retrieval and require a citation for every statement, so reviewers can check it quickly.

  4. 4

    Respect engagement boundaries

    Apply the audit management system's permissions, so the copilot only retrieves from engagements the auditor may see, especially for investigations and sensitive reviews.

  5. 5

    Add analytics and findings drafting

    Move to anomaly detection on full populations and drafting of findings once reviewers trust the citations, and measure review time and rework per report.

  6. 6

    Audit the copilot

    Treat the copilot as an AI system in the inventory, with testing of its outputs on past audits and periodic review by someone independent of the team that built it.

Guardrails

  • A qualified auditor reviews, edits and signs every workpaper, finding and report; the AI never forms an audit opinion or rates a finding
  • Every AI generated statement cites the evidence document and page it relies on
  • Retrieval respects engagement and document permissions, including restrictions on investigations
  • AI assistance is recorded in the workpaper, with the draft and the auditor's changes retained
  • Anomalies surfaced by analytics are leads for testing, never conclusions
  • Audit data stays within the approved tenancy and region and is not used to train external models

KPIs to instrument

  • Hours per engagement phase (planning, fieldwork documentation, reporting), before and after
  • Time from fieldwork end to final report
  • Share of AI drafted statements changed or removed by the auditor or reviewer
  • Review notes raised on AI assisted workpapers compared with others
  • Audit plan coverage (auditable entities covered per year)

Human in the loop

Auditors own every conclusion and the chief audit executive owns the methodology. Reviewers check AI assisted workpapers with the same rigour as any other, using the citations, and the audit committee is informed how AI is used in the function.

Common failure modes

Unsupported statements in workpapers
A fluent summary includes a claim that no evidence supports and survives review. Require citations and train reviewers to check them.
Confidentiality leaks across engagements
The copilot retrieves material from an investigation or another engagement the auditor may not see. Enforce document level permissions in retrieval.
Independence eroded by shared tooling
Audit relies on the same AI tools and prompts as the first line it audits. Keep audit's own configuration and test it independently.
Anchoring on the AI draft
Auditors accept the drafted risk and control matrix rather than challenging it. Have auditors edit, not approve, and track the change rate.

What are the risks and rules?

EU AI Act

Minimal risk

An internal drafting and analysis assistant for auditors that makes no decisions about natural persons. It would need reassessment if used to evaluate individual employees' behaviour or performance, which falls under Annex III point 4(b).

Guidance

  • 2024 Global Internal Audit Standards (The Institute of Internal Auditors, Global). A mandatory component of the IPPF, and The IIA expects every internal audit function to conform. Its principles (among them objectivity, due professional care and confidentiality) and the Domain V requirements for planning engagements and developing findings apply to AI assisted work as to any other.

Controls to put in place

  • Methodology section on AI use approved by the chief audit executive and shared with the audit committee
  • Workpaper field recording AI assistance, with the draft retained
  • Periodic independent testing of the copilot's outputs on past engagements
  • Access control aligned with engagement permissions in the audit management system
  • Inventory entry for the copilot with an accountable owner

Frequently asked questions

How much time can generative AI save in internal audit?
Reported figures are early and vendor published, without a stated method. Microsoft reports that BCI reduced time spent writing internal audit reports by 30%, that Bradesco achieved 55% less time in reporting with its AILA audit assistant, and that XP Inc. increased audit team efficiency by 30%. Measure hours per engagement phase on your own audits before and after.
Does using AI compromise auditor independence?
Not if the auditor owns every conclusion, the AI's contribution is recorded in the workpaper, and audit's tooling is configured and tested independently of the first line it audits. The Global Internal Audit Standards, including objectivity and due professional care, apply to AI assisted work as to any other.
What should the AI never do in an audit?
Form an audit opinion, rate a finding, or treat an anomaly as a conclusion. It drafts, summarises and points at exceptions; qualified auditors test, judge and sign.

How to cite this page

Blits.ai AI Use Case Library, "Generative AI copilot for internal audit", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/internal-audit-copilot. Licensed under CC BY 4.0. Method: how we verify use cases.

Changelog
  • 27 September 2026: First published

Related use cases

Cross industryBanking

AI for continuous controls testing and control self assessment

AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.

Deployments
3 public, best grade B
Autonomy
Supervised agent
Cross industryBanking

AI system and model inventory with shadow AI discovery

A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.

Deployments
4 public, best grade B
Autonomy
Copilot
Cross industryBanking

AI for policy drafting and policy gap analysis

An assistant that takes a new or changed obligation, finds every internal policy, standard and procedure it touches, flags clauses that now conflict or are silent, and drafts the updated wording in house style as a redline for the policy owner to approve.

Deployments
3 public, best grade B
Autonomy
Copilot
BankingInsurance

AI for supervisory exam and information request responses

An assistant for the bank's regulatory affairs team that reads a supervisory information request or exam question, retrieves the relevant evidence, policies and prior correspondence, drafts a response for legal and compliance to approve, and tracks every commitment and remediation action through to closure.

Deployments
3 public, best grade B
Autonomy
Copilot
Cross industryBanking

Governed text to SQL analytics assistant

An assistant that turns a business user's plain language question into a query against governed data, runs it under that user's own data permissions and returns the table or chart together with the SQL and the tables used, so routine ad hoc questions no longer queue for the data team.

Deployments
3 public, best grade B
Autonomy
Assist