Skip to content
Review Open access

A GOVERNANCE-ORIENTED PROMPT ENGINEERING FRAMEWORK FOR AI-ASSISTED INTERNAL AUDITING

Aug 2026 · Denetişim · 0 citations · 12 references

TL;DR

A governance-oriented framework that links 13 audit-specific prompt types to the main phases of the internal audit lifecycle: planning, fieldwork, reporting, and follow-up is developed and indicates that structured prompting can improve repeatability, transparency, and professional skepticism.

Abstract

The diffusion of generative Artificial Intelligence (AI) across organizational environments is reshaping both the objects of internal audit and the tools auditors use during assurance work. Although prior research has discussed AI adoption in auditing and the risks associated with large language models (LLMs), less attention has been paid to how auditors should structure, document, and govern their own interaction with these systems. This study adopts a conceptual synthesis design and integrates three literature domains: internal audit standards and governance guidance, LLM risk and security frameworks, and prompt engineering / human–AI interaction research. Based on this synthesis, the study develops a governance-oriented framework that links 13 audit-specific prompt types to the main phases of the internal audit lifecycle: planning, fieldwork, reporting, and follow-up. The proposed framework treats prompts and AI-assisted outputs not as informal productivity aids, but as reviewable working-paper artifacts subject to evidentiary discipline, human validation, and documentation controls. The analysis indicates that structured prompting can improve repeatability, transparency, and professional skepticism by making assumptions explicit, constraining unsupported inference, and strengthening the linkage between AI-generated text and auditor-supplied evidence. The article contributes to the literature by reframing prompt engineering as a governable audit competency and by providing a lifecycle-based prompt taxonomy for practical implementation. It also clarifies that LLM output should be used as intermediate analytical support rather than as audit evidence or authoritative judgment.

Read PDF

Similar papers

Review Open access Jul 2026

From the EU AI Act to Audit Practice: A Governance-to-Controls Framework for Quality Management and Evidence

Artificial intelligence (AI) tools—including audit data analytics, robotic process automation, machine-learning models, and generative AI—are changing how audit teams identify risks, select procedures, and evaluate evidence. At the same time, Regulation (EU) 2024/1689 (the EU AI Act) establishes a risk-based governance architecture built around risk management, data governance, technical documentation, logging, transparency, human oversight, robustness, cybersecurity, and post-market monitoring. The Act is not an auditing standard and does not directly regulate every tool used by audit firms. Nevertheless, its governance logic is relevant where audit firms develop, procure, or rely on AI-enabled systems that process sensitive client data, influence professional judgement, or become part of audit-relevant client systems. This conceptual study uses doctrinal requirements-to-controls mapping and design-oriented analysis to translate selected AI Act governance objectives into firm-level and engagement-level quality-management controls and into criteria for evaluating AI-enabled audit evidence. The paper specifies three modes of AI Act relevance: direct legal relevance where a regulated AI Act role is engaged; indirect relevance where AI compliance documentation becomes audit-relevant information; and benchmark relevance where the Act supplies governance objectives for quality management without creating an audit-law duty. The resulting artefacts are a traceable AI Act/IAASB standards crosswalk, an evidence-risk typology, a quality-management integration model, a documentation and review checklist, and a proportional maturity model. The framework clarifies when AI outputs remain triage or risk-assessment tools, when they provide directional or corroborative evidence, and the narrower conditions under which they may contribute to substantive evidence. It links reliance to data completeness, reconciliation, versioning, validation, false-positive and false-negative behaviour, explainability, logging, source-document corroboration, and reviewer challenge. The contribution is a scalable governance-to-controls framework that supports defensible reliance and inspection readiness without overstating the AI Act’s direct legal applicability. Empirical validation in audit firms remains a priority for future research. It further explains how quantitative risk features and anomaly-detection outputs feed into qualitative audit judgement: models can route attention to unusual transactions or documents, but evidential weight still depends on base-rate-aware error analysis, source-document corroboration, and reviewer challenge.

János Kálmán · 0 citations
Review Open access Jul 2026

The Auditor Prepared for the Era of Artificial Intelligence: Competencies, Roles, and Implications for Professional Bodies

Artificial intelligence (AI) is fundamentally reshaping the auditing profession, challenging traditional competency frameworks and redefining the scope of the auditor’s role. This study is based on the premise that, beyond traditional financial audit tasks, the contemporary auditor is increasingly expected to contribute to audit committee governance, sustainability (ESG) assurance, as well as the direct application of AI-based tools in audit engagements. Despite the growing academic and professional interest in AI adoption, a comprehensive and integrated framework capturing the full spectrum of AI- related competencies required across all auditor roles remains insufficiently developed in the literature. This paper addresses this gap through a Structured Literature Review (SLR) that examines 22 peer-reviewed articles indexed in Web of Science and published between 2019 and 2025, identifying and synthesizing evidence on how AI is reshaping auditor competencies across four interconnected roles: financial auditor, audit committee member, ESG assurance provider, and user of AI tools. Based on the synthesized evidence, the authors propose an integrated competency framework for the auditor prepared for the AI era, structured around six competency dimensions and four professional roles, with direct implications for professional bodies, Continuing Professional Development (CPD) programmes, and certification requirements.

Elena Claudia BADEA (FLOREA), A. Olteanu (Burca), M. Bunea et al. · 0 citations
Review Open access 2026

The Human-AI Interface: Socio-Technical Challenges in Implementing Generative AI for Project Documentation and Governance

An exploratory literature review of the socio-technical issues involved in the adoption of GenAI tools in project documentation and governance and suggests a socio-technical conceptual framework that integrates these aspects into a unified view to inform people's understanding of responsible Human-AI collaboration in project settings.

Bela Lestari Dwireja, F. Abdalla, Yuhang Liu et al. · 0 citations
Review Open access Sep 2026

Auditing as a Governance Mechanism for Artificial Intelligence: Institutional Design, Accountability, and Ethical Oversight

The rapid diffusion of artificial intelligence (AI) across organisational and societal settings has heightened concerns about accountability, transparency, and ethical oversight. Existing governance mechanisms, including regulation and principle-based ethics frameworks, often struggle to address the scale, opacity, and socio-technical complexity of AI systems. In response, auditing has increasingly been proposed as a means of implementing accountability by translating ethical and legal expectations into structured oversight practices. The study employs a structured literature review methodology, analysing 71 peer-reviewed articles published between 2020 and 2025, retrieved from Scopus, Web of Science, and ProQuest. Through thematic synthesis, the review shows that AI auditing has evolved beyond technical verification towards a socio-technical governance infrastructure grounded in transparency, independence, ethics integration, and professionalisation. However, its effectiveness is constrained by persistent challenges, including algorithmic opacity, regulatory lag, fragmented standards, capability gaps, and risks of symbolic compliance. The study positions auditing as both a central tool and a critical institutional challenge within AI governance, offering insights for scholars, regulators, and practitioners seeking durable accountability mechanisms for responsible AI.

Alexander Oluka · 0 citations
Review Jul 2026

AI adoption as technology transfer: an integrative review and conceptual framework for governance, validation and knowledge preservation

It is argued that AI adoption should be understood not merely as automation but as a technology-transfer problem, and the AITTF is introduced, a seven-stage governance model designed to help organisations transfer workflows, expertise and decision-making into AI-enabled systems while maintaining accountability, operational integrity and organisational memory.

Musarat Kabir-Chisty · 0 citations
Review Open access Jul 2026

The AI Implementation Gap: Policy–Audit Misalignment in the UAE and Egypt

The authors conclude that governance and transparency issues, regional disparities in implementation, and algorithmic complexity contribute to the difficulties in auditor practices in adopting AI tools.

John Joshua C. Rañeses, Dr. Ain Bemisal Alavi, Rafia et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.