1 More Paper.
Full Reading01:38:53

Exploring Large Language Models in external audits: Implications and ethical considerations

1 More Paper · Full Reading

Full Reading podcast cover
Listen to the Full Reading

About this paper

A full audio edition of this paper.

Authors: L.E. Fotoh, T. Mugwira

Publication date: 2025

Read the paper: https://doi.org/10.1016/j.accinf.2025.100748

Source license: Creative Commons Attribution 4.0 International — https://creativecommons.org/licenses/by/4.0/

The authors and publisher do not sponsor or endorse this recording.

Brief episode

Transcript

You’re listening to “Exploring Large Language Models in external audits: Implications and ethical considerations,” by L.E. Fotoh and T. Mugwira. Published in 2025.

Abstract.

This study explores the impact of Large Language Models (LLMs) on external audits and their associated ethical implications. A small-scale survey was conducted with auditors from non-Big Four firms to assess their general perceptions of LLMs, followed by a qualitative evaluation of external LLMs in audit-specific tasks. In the latter, ChatGPT’s responses to audit-related scenarios were assessed by experienced audit partners, who rated and commented on the outputs without knowing their source. The findings indicate that while LLMs efficiently perform routine and mundane tasks such as generating human-like responses and preparing basic audit working pa- pers and reports, external LLMs struggle to produce comprehensive, audit-specific reports.

Non- Big Four auditors recognise LLMs’ time-saving potential and relevance in audit planning; how- ever, concerns persist regarding the comprehensiveness and contextual relevance of external LLM-generated risk assessments and interpretations of auditing standards. Moreover, limitations inherent in external LLMs, such as outdated information and hallucinations, necessitate auditor oversight. Ethical concerns identified include threats to auditor objectivity, confidentiality, pri- vacy, accountability, and intellectual property rights. The study reinforces that while LLMs can enhance audit efficiency, they should complement rather than replace auditors. Their successful integration in external audits requires prompt engineering, regulatory guidance, and auditor oversight.

These findings contribute to the growing research on LLMs in auditing and provide insights for audit firms considering their adoption.

1. Introduction.

Auditors and accountants are among the professionals most exposed to the rapidly developing capabilities of artificial intelligence (AI) systems such as Large Language Models (LLMs). Given the novelty and limited research on the potential of LLMs in external auditing, this study explores non-Big Four auditors’ perceptions of LLMs and assesses the extent to which external LLMs can facilitate specific audit tasks. LLMs have shown their potential to recreate knowledge and perform simple tasks, making them available to a diverse community of users through interfaces that require minimal coding. Audit firms have invested billions of dollars in developing their internal LLMs.

However, due to the high costs associated with developing internal LLMs,1 small to medium audit firms are likely to face challenges in building their own, forcing them to rely on external LLMs if they intend to leverage this technology. For this reason, the second part of this paper, which qualitatively assesses seven scenarios, focuses on external publicly available LLMs, specifically the Chat Generative Pre-trained Transformer (ChatGPT). ChatGPT’s ability to generate coherent and contextually relevant prompts on a variety of topics, and its ability to write and document code, has attracted worldwide attention. However, the technology is also prone to limitations and weaknesses and poses new risks in terms of security, bias and accuracy.

LLMs are considered a notable advancement in AI and ML due to their potential to generate human-like responses. Some LLMs have a distinctive conversational voice, extensive knowledge, and versatile skills that enable them to provide information on various topics; engage in both general and technical conversations; compose emails with specified content and tone; edit text structure and wording; and generate computer code in multiple programming languages. Consequently, these technologies have the potential to disrupt the auditing profession in unprecedented ways.

Although LLMs have significant disruptive potential, current understanding of their application in the external auditing context remains limited. Existing discussions on the impact and implications of these technologies predominantly centre on their disruptive potential, their effects on accounting education, forensic accounting practice, their practical application in, and the leveraging of their use for, internal auditing, and the collaborative potential between auditors and such foundational models. However, due to the novelty of these technologies, knowledge about their transformative and disruptive potential in external auditing remains scarce. Furthermore, ongoing concerns regarding the evolution of AI and how auditors adapt to and interact with these technologies continue to have significant implications for future audits.

In addition, following the rapid growth and remarkable success of AI technologies, contemporary studies have underscored various ethical issues that must be addressed to fully realise their benefits. This study aligns with Munoko et al. (2020) by emphasising the importance of ethical considerations in the evolving role of LLMs in auditing. Munoko et al. (2020) further highlight the need for regulatory guidance and oversight, along with revised standards that keep pace with technological advancements. This includes monitoring the use of AI in auditing and keeping stakeholders informed about its implications.

Current auditing standards recognise the growing importance of technology by requiring engagement partners to consider technical competence, particularly the information and technology skills of the engagement team, when assessing their overall competence and capabilities (see International Federation of Accountants (IFAC), 2020, para. A12, IFAC, 2020).

Moreover, given that accounting and auditing tasks are highly exposed to AI systems, which have the potential to automate at least 50 percent of certain activities, this study explores the impacts of LLMs on external auditing, focusing on auditors’ general perceptions of LLMs and the extent to which external LLMs2 can perform specific audit tasks. Emerging literature underscores the potential of LLMs to produce prompt, human-like responses while refining outputs by eliminating irrelevant information. Additionally, these models are recognised for their ability to automate simple, repetitive, and error-prone tasks. Some studies highlight their usefulness in audit planning by enhancing risk assessment and enabling the identification of red flags, suspicious transactions, and areas where auditors may lack expertise.

Others emphasise their role in facilitating the preparation of audit working papers and reports. LLMs can also assess internal controls, detect weaknesses, and recommend areas for improvement. Consequently, they can contribute to time savings when performing manual and routine tasks.

In summary, the extant literature highlights the potential of LLMs to enhance audit efficiency, effectiveness, and the quality of audit procedures. However, the quality of prompts is crucial in ensuring high-quality outputs and maximising their benefits. While LLMs can enhance audit procedures, they should be seen as co-pilots—serving as audit assistants to support, rather than replace, auditors. Their role is to facilitate collaboration, with auditors retaining full responsibility for directing the audit. Nevertheless, most emerging studies adopt a conceptual and normative perspective, mainly within the internal audit context, highlighting the need to explore the potential of LLMs in external auditing.

Moreover, Big Four audit firms have been vocal about their initiatives and capabilities concerning LLMs, leaving a knowledge gap regarding the perspectives of non-Big Four firms, which conduct a significant proportion of audits for private companies and whose potential remains insufficiently examined. Additionally, non-Big Four audit firms differ in terms of resources, client bases, and operational structures compared to Big Four firms. Therefore, their insights can meaningfully complement the emerging literature, which has predominantly focused on Big Four audit firms.

Therefore, this study aims to explore the potential of LLMs in external auditing by assessing non-Big Four auditors’ general perceptions of LLMs in auditing and qualitatively examining the extent to which external LLMs can perform specific audit tasks. To achieve this objective, we employed a mixed-method approach. First, we conducted a small-scale online survey with non-Big Four auditors in Scandinavia, which included questions on the potential of LLMs in auditing. We received 51 usable responses, of which 34 came from highly experienced managers, partners, and directors. Second, we developed prompts for seven audit scenarios to be consumption. However, unless specified, the term LLMs in the paper will be used to refer to external LLMs such as ChatGPT.

performed by ChatGPT, four of which were subsequently evaluated by nine experienced Big Four audit partners, who provided critical qualitative reviews.

Our findings suggest that non-Big Four auditors perceive LLMs as valuable for performing routine tasks; generating audit working papers and reports; enhancing audit planning; saving time; improving internal control assessments; increasing audit efficiency and effectiveness; and potentially improving audit quality. However, concerns persist regarding potential legal liabilities, ethical implications, and the limitations of external LLMs in producing comprehensive, contextual, and audit-specific reports. The qualitative evaluation further underscores technical challenges, including outdated information, hallucinations, and insufficient depth in interpreting auditing standards. These findings are relevant for auditors and firms that have invested significantly in the adoption of such technologies.

As such, they offer practical insights for audit firms seeking to utilise this cutting-edge technology to reshape the audit landscape. Moreover, this study is relevant to regulators who recognise the growing adoption of technologies in audits, seek input on the implications of this trend, and emphasise the need for additional standards to regulate their use (Public Company Accounting Oversight Board (PCAOB), 2017, 2021; IAASB, 2018).

The remainder of this article is organised as follows: Section 2 presents the literature review; Section 3 outlines the research method; Section 4 presents the results; and Section 5 discusses the findings. Section 6 examines the ethical implications of using LLMs in external auditing, while Section 7 concludes the paper and suggests directions for future research.

2. Literature review.

2.1. Artificial intelligence in auditing.

Artificial intelligence (AI) is defined as a machine or system capable of thinking, learning, and imitating various aspects of human intelligence. It includes technologies that translate language, identify images and sounds, analyse and review documents, and apply knowledge and problem-solving skills to perform tasks. AI often comprises a range of technologies, including machine learning, data mining, speech recognition, image recognition, and sentiment analysis.

The current audit environment is under increasing pressure, particularly concerning reducing audit fees, which may have implications for audit quality. From a technological perspective, Austin et al. (2021) document tensions between auditors’ and clients’ expectations regarding the impact of technology on audit fees. While clients believe that audit fees will decrease due to efficiency gains from the use of technology, auditors resist by demanding higher fees owing to the additional investment costs associated with these innovations. Fedyk et al. (2022) report a comparable finding: following the introduction of advanced technologies, clients sought reduced audit fees, while auditors cited initial expenses as the reason to increase audit fees. Consequently, the adoption of advanced technologies may have adverse implications for audit fees, and potentially, for audit quality.

However, the current audit literature emphasises the potential of AI to alleviate these pressing challenges. For example, Fedyk et al. (2022) found that audit quality could be significantly increased by investing in AI, which was accompanied by a significant decrease in restatements, particularly material errors and those related to accruals and revenue recognition. The results also indicate that audit firms investing in AI tend to charge lower audit fees while reducing the number of audit staff, resulting in higher productivity, as calculated by total audit fees per employee. In summary, Fedyk et al. (2022) highlight the positive effects of AI on audit quality, efficiency (reduced audit fees), and staff costs, while also noting the negative consequence of staff reductions several years after AI implementation.

In addition, AI utilisation in auditing promises efficiency through time savings, improvement in effectiveness through heightened accuracy, and enhancement of client-auditor relationships through deeper insight into clients’ business processes, resulting in improved client services.

AI is valuable for recognising patterns in documents. Its natural language processing (NLP) capabilities enable auditors to analyse contracts and extract relevant information from contracts, invoices, and leases. Zhaokai and Moffitt (2019) propose a framework for contract analysis that combines NLP and text mining methods to accelerate the investigation and review of large volumes of low-risk contracts. The framework extracts audit-relevant content, generates evidence, and detects anomalies.

Many audit processes are well suited to the integration of AI and data analytics, particularly to support the analysis and extraction of large volumes of structured and unstructured data. For example, AI applications in auditing are often touted as aiding the detection of anomalies by monitoring all transactions and identifying high-risk transactions for further review and analysis. AI can also quickly examine and process large datasets or documents to recognise patterns, irregularities, and keywords. In addition, it can accelerate the creation of comprehensive audit plans, enhance audit efficiency through improved anomaly and fraud detection and risk assessments, and free auditors to focus on more advanced, high-risk audit tasks. The Big Four audit firms use AI for audit planning, risk assessment, transaction analysis, analytical procedures, and the preparation of working papers.

Raschke et al. (2018) argue that AI can enhance audit enquiries by enabling bots to interact with client personnel regarding unusual or unexpected transactions. If the client’s response raises further concerns, a human auditor can investigate the matter in greater depth. Consequently, AI enables real-time, continuous data monitoring and notifies auditors of questionable transactions.

2.2. Current discussions on LLMs and the situational context of emerging technologies in auditing.

Primary external audit regulatory bodies (e.g., IFAC and PCAOB) have made almost no mention of the potential use of the technology in auditing. Only a few professional associations have commented on the use of LLMs. For example, the Institute of Chartered

Accountants in England and Wales has acknowledged that the technology holds promise for responding to queries, generating audit file notes, and providing expert advice3. Similarly, Chartered Accountants Ireland (2023) notes the potential of the technology to save time and resources by automating repetitive tasks and boosting marketing efforts. This viewpoint is echoed by Kristen Beadle, CPA Australia’s Public Practice Manager, who noted:

Some members are already using the technology for marketing materials, saving them time to focus on client-facing work..

However, there are some challenges, such as the imperfection of current responses, the risk of misinformation, concerns about the reliability and transparency of the sources from which the data are drawn, reservations about responses on topics that require judgement, and the problem of hallucinations. With regard to the reluctance to include ChatGPT in audits, Tiffany Tan, CPA Australia’s Audit and Assurance Policy Lead, emphasises that auditors view ChatGPT as a speech-enabled model that produces convincingly articulated responses that are not necessarily accurate. Furthermore, this technology relies on outdated data.4 For instance, Tiffany notes:

Anecdotally, we understand audit firms won’t be using the free version of the ChatGPT in obtaining audit evidence as the AI tool is only drawing data up to 2021, therefore, not up to date..

The current slow discussion concerning the use of LLMs in auditing is a trend that has been observed in auditing, as current empirical findings underscore that insufficient regulatory guidance on the adoption of emerging technologies constrains the adoption of these technologies because of enhanced regulatory and public scrutiny. Numerous factors restrict the adoption of AI in the audit industry. Following high-profile accounting scandals and audit failures in recent decades, external auditors have faced increased litigation risks, higher insurance costs, intensified media attention, and more frequent regulatory reviews. Consequently, auditors increasingly strive to conduct regulatory-compliant audits.

Although contemporary studies underscore that updating auditing standards to reflect the realities of emerging technologies can enhance audit quality and the robustness of the audit process, current standards remain insufficiently adapted. Auditing regulations have not kept pace with progress in emerging technologies and are often more reactive than proactive. This regulatory lag contributes to auditors’ hesitation in adopting new technologies, as they remain uncertain about how regulators will respond. Auditors have expressed concerns about the risk of penalisation and increased legal liability in the event of audit failures or regulatory reviews and inspections—particularly when audit evidence is obtained using emerging technologies not yet fully addressed in existing standards.

This has led to uncertainty in the application of current auditing standards to new ways of collecting and analysing audit information.

While existing standards do not preclude the use of emerging technologies in auditing, the paucity of more elaborate discussions on suitable analytical techniques within the existing auditing standards restricts the audit profession from adopting new methods to perform audits. External auditors are unwilling to interpret current standards related to emerging technologies in auditing creatively; instead, they prefer standard setters to provide explicit guidance. Despite regulatory concerns, auditors face an additional dilemma: client management expects them to adopt these technologies to improve audit quality while reducing audit fees due to the efficiency gains associated with their use. There is near unanimity in the current literature that audit firms tend to be reactive, rather than proactive, in their use of these technologies compared to their clients.

This highlights the need for standard setters and regulators to proactively address the impact of new technologies on traditional audit evidence, as the traditional view of audit evidence may no longer be sufficient —a process that is both lengthy and complex.

Although auditing standards require auditors to be familiar with existing technology-based auditing techniques, more detailed guidance is needed on the specific techniques that auditors should learn and adopt. Even the PCAOB staff acknowledged in its May 2020 Spotlight that guidance or changes to the auditing standards on audit evidence (AS 1105) are needed due to the increasing use of technology-based tools in audits and the use of other information external to the company. Due to insufficient regulatory guidance, audit firms have taken a cautious and conservative approach to new technologies in auditing, including generative AI and LLMs.

3. Research method.

Given the exploratory nature of this study, we employed a mixed-method approach, as recommended by Hurmerinta-Peltom ̈aki and Nummela (2006), to obtain a broad and inclusive understanding of external LLMs in auditing. Firstly, we conducted a small-scale online survey with non-Big Four auditors in Scandinavia. The survey contained demographic questions and addressed the potential of LLMs in auditing. The survey included questions rated on a seven-point Likert scale (ranging from 7-Strongly 3 All citations linked to Schaller (2023) were made by Imran Vanker, the director of standards at the Independent Regulatory Board for Auditors (IRBA). 4 GPT-3.5 is confined to data available until September 2021, whereas GPT-4 encompasses data up to, but not beyond, April 2023 (refer to the linked source, the linked source). agree to 1-Strongly disagree), open-ended, and dichotomous (Yes/No) questions.

It was administered via SUNET5and received ethical approval from the institutional review board of one of the authors’ universities. The survey was conducted between September and November 2024.

To address potential non-response bias, we compared early and late responses across age (t = -0.980, p = 0.342), gender (t = 0.657, p = 0.521), audit experience (t = -0.935, p = 0.364), and audit position (t = -0.816, p = 0.426). No significant differences were observed for these variables, indicating no serious issues with non-response bias (see Fink, 2003). Additionally, we implemented proactive measures to mitigate concerns related to common method bias (CMB), which is common in survey research. These included the careful design and refinement of the survey instrument to enhance clarity.

We also adopted transparent procedures, safeguarded respondent anonymity to reduce socially desirable responses, diversified response formats (e.g., open-ended questions, seven-point scales, dichotomous questions), and provided a memo outlining the survey’s objectives and relevance to external auditing.

We analysed the quantitative data using SPSS to obtain descriptive statistics such as the one-sample independent t-test to obtain mean scores and standard deviations to examine non-big auditors’ perceptions of LLMs in auditing. In total, 51 usable responses were received.6 The number of responses was deemed sufficient due to the high experience of participants, with 51 % having more than 11 years of audit experience and 66.7 % holding positions as audit managers, partners, or directors, of whom 41.2 % were audit partners and directors. Additionally, 58.8 % of respondents identified as male, 37.3 % as female, and 3.9 % preferred not to disclose their gender, while 39.2 % were older than 40 years. Table 1 presents the descriptive statistics of the study.

Second, we developed prompts for seven audit scenarios to be performed by ChatGPT,7 four of which (Scenarios 1 to 4) were then evaluated by experienced Big Four audit partners. The remaining three scenarios (5 to 7) were not evaluated, as ChatGPT was unable to provide complete answers to Scenarios 5 and 6, and gave a completely incorrect response in Scenario 7. Table 2 presents information about the prompts. To improve the validity and reliability of ChatGPT’s responses, we meticulously crafted the prompts and employed prompt engineering techniques to mitigate potential bias within the AI tool. The incorporation of prompts from ChatGPT is consistent with existing research in the audit context. The effectiveness and reliability of prompts depend on prompt engineering and the skilful design of prompts to ensure that the results generated are accurate and aligned with the intended purpose.

This process involves the methodical refinement and optimisation of prompts to improve interactions according to precise goals and preconditions. The prompts for this study were formulated jointly by both authors and guided by the aims of the study. In line with the recommendations of Cheung (2023) and Street et al. (2023), we ensured that the questions were specific, rather than overly broad, complex, or ambiguous. The resulting output from ChatGPT was transcribed into a Word format and used to develop an instrument for survey participants.8

This study adopted an expert judgement approach, selecting audit partners from Big Four audit firms in Norway as participants. Given their extensive professional experience, in-depth knowledge of auditing standards, and contextualised understanding of audit scenarios, audit partners were well-positioned to enhance the credibility and relevance of our findings. We received twelve responses, of which three were eliminated due to incompleteness, resulting in nine valid responses. To mitigate potential bias, participants were not informed that the reports had been generated by ChatGPT. Instead, they were simply asked to rate the completeness and accuracy of the reports. Participants independently evaluated the reports based on two criteria: Accuracy and Completeness. Each response was rated on a 7-point Likert scale (1-Strongly inaccurate/incomplete to 7-Strongly accurate/complete).

Table 3 presents the demographic information of participants and their responses. In addition, participants provided qualitative comments highlighting the strengths and weaknesses of the reports. These qualitative insights were systematically analysed using qualitative content analysis to identify major themes. Data from the Likert-scale ratings were summarised to provide an overview of participants’ assessments, while qualitative feedback was analysed to offer deeper insights into the rationale behind the ratings. Consequently, the results were examined to uncover key themes related to perceived deficiencies and strengths. Relevant quotes from the participants are incorporated into the discussion section.

5 SUNET is a secure platform employed by universities for data collection, ensuring compliance with ethical standards.

Table 1

Participants’ demographic information.

Table 2

Prompts used for ChatGPT.

4. Results.

4.1. Non-Big Four Users’ Perceptions of Large Language Models in external auditing.

Considering the current dominance of Big Four firms in exploring the potential of Large Language Models (LLMs) in auditing, we asked our non-Big Four auditors to rate 12 statements on the potential applications of LLMs in auditing. Table 4 summarises their perceptions using a seven-point Likert scale (1 = Strongly disagree, 7 = Strongly agree). The results indicate that all mean ratings for the statements are significantly different from the midpoint at p < 0.05.

Non-Big Four auditors generally agreed that LLMs can generate human-like responses crucial to audit firms (4.75) and handle simple, repetitive, and mundane tasks (5.27), including those prone to error (4.86). Furthermore, they provided the highest ratings for the statement that LLMs can save time (5.86). They also believed that LLMs facilitate the preparation of audit working papers (4.94) and reports (4.76) and enhance audit planning by identifying areas where auditors may be deficient in knowledge (4.78). Additionally, they agreed that LLMs improve internal control assessments (4.41) and can perform certain tasks typically carried out by auditors (4.41). Importantly, non-Big Four auditors believed that LLMs enhance both the efficiency and effectiveness of the audit process (5.24) and audit quality (4.71).

However, participants noted that employing LLMs imposes additional legal liabilities on audit firms in cases

Table 4

Perceptions of Non-Big Four Auditors on the Potential of Large Language Models in External Auditing.

of audit failures caused by their use (4.55).

4.2. Use cases of ChatGPT in audit settings with experienced audit partners: Accuracy and Completeness assessment.

Scenario 1: Performing mundane tasks such as generating reports.

In evaluating the ability of external LLMs such as ChatGPT to generate human-like working papers, two audit partners rated the report as moderately complete and moderately correct. However, they highlighted key omissions, including the absence of information on the total inventory count, the scope of inventory examined, whether customer representatives participated, the amounts linked to immaterial errors, and an assessment of the nature and extent of those errors. One participant, for instance, noted:

No references to the total inventory amount or the scope of amounts tested during the control. No references to customer representatives who participated. No mention of the amount related to the immaterial error. No assessment of why the error occurred or whether it is, for example, a systematic error. (Audit Partner 1, 17 years of audit experience)

Six participants found the report to be strongly incomplete, incomplete, or moderately incomplete, while five audit partners rated it as strongly incorrect, incorrect, or moderately incorrect. The main reasons cited included the lack of a clear description of the test counting process and how it was documented. Additionally, the report did not specify what the inventory consisted of—whether it included work-in-progress, finished goods, or raw materials—nor did it indicate which items were examined, whether certain items were more prone to error or fraud, or whether the facility was closed during the inventory count. The following quotes illustrate these concerns:

It is not described how the test of counting was conducted or how the testing itself was documented. (Audit Partner 2, 24 years of experience)

No identification of items tested, no discussion on items more prone to error/fraud than others in the warehouse (Audit Partner 5, 24 years of experience)

What does the inventory consist of (WIP, finished goods, raw materials? etc) was the facility closed during the count? (Audit Partner 6, 21 years of experience)

Some participants highlighted missing discussions on inventory security and warehouse control, the sampling technique used, and why the test count was considered representative of the total inventory. They also noted the absence of details on how the test results were extrapolated to the full population and whether this extrapolation was significant. Furthermore, they pointed out the lack of information on sample size, the impact of errors on the sample, and how the size of the error compared to the sampling threshold. These omissions could undermine the reliability of the inventory count process. Additionally, concerns were raised about the absence of information on materiality, the size of the account, and whether the approach adopted was substantive or control-based.

No discussions on inventory security and control of warehouse. Physical inspection of inventory should also cover that. No discussion on sampling technique − how/why is test count representative for the state of the full inventory. Noted that no material error in test count was identified; but how are the test results extrapolated to the full population − no mention of whether extrapolation is significant. (Audit Partner 5, 24 years of experience)

Some review points. − There is no information on materiality, size of account, is it a substantive approach or controls approach, what is the sample size, how did the error impact our samples, how big was the error compared to sampling threshold? (Audit Partner 6, 21 years of experience)

John has not assessed the effect of the error on the entire population and thus the inventory may be significantly flawed. No documentation nor consideration about sample size. (Audit Partner 7, 25 years of experience)

Other participants highlighted that the report does not specify the analytical procedure adopted or how reasonable tests were performed. They also noted that it fails to clarify whether the analytical procedures were substantive or part of risk assessment analytics, and it does not indicate the type of analysis conducted—such as trend analysis, KPI analytics, or predictive analytics. Others also questioned how auditors challenged management’s estimates regarding impairments. The following quotes illustrate these concerns:

What analytical procedures are done? (Audit Partner 6, 21 years of experience) Analytical procedure: No mention of what/how reasonable test is performed. Was this a substantive analytical procedure or just risk assessment analytics? What kind of analysis (trend, KPI analytics, predictive analytics etc.?) (Audit Partner 5, 24 years of experience) It is not clear how the auditor has challenged management’s estimates regarding impairments. (Audit Partner 7, 25 years of experience)

Scenario 2: Interpretation of audit standards for Cash and cash equivalents.

Three audit partners rated the interpretation as highly complete and correct, while three others considered it moderately complete and correct. However, those who rated it as complete (ranging from moderately to highly complete) emphasised the need to incorporate the financial reporting framework into the analysis. Specifically, they highlighted the importance of determining whether cash items should be classified as cash and cash equivalents based on the applicable reporting framework, and whether they are readily available for use or subject to restrictions.

The ISA list referred to seems to be more or less complete. However, when planning specific financial statements captions, such as cash, you should also always include the financial reporting framework. For cash in particular financial statement frameworks (e.g. IFRS) would prompt considerations around presentation in Financial statement: − presentation as cash and cash equivalents − Presentation as short term or long term (is it locked in or available for immediate use) − any restrictions for use, pledge etc. (Audit Partner 5, 24 years of experience)

Two audit partners rated the interpretation as either incomplete or incorrect, while one audit partner considered it moderately incomplete and moderately incorrect. One of the partners who found the interpretation incorrect and incomplete criticised the overly broad nature of the report and noted that it did not reference key audit standards covering planning and risk assessment (ISA 315/330). These standards are fundamental to other audit areas, including audit evidence (ISA 500), external confirmations (ISA 505), and potentially going concern (ISA 570). The following quotes illustrate these concerns:

In my opinion- the answer is too broad and not specific enough. Also, it did not include ISA 315/330 on planning of audit and risk assessment. In my view this is the starting point, based on that you will probably end in ISA 500 and ISA 505. And it may impact ISA 570. (Audit Partner 6, 21 years of experience)

One audit partner, who rated the interpretation as moderately incorrect and incomplete, emphasised the potential need to consider almost all audit standards. This viewpoint reflects auditors’ general expectation that such reports should be comprehensive.

I think almost all ISAs should be considered depending of the circumstances. (Audit Partner 4, 20 years of experience)

Scenario 3: Summarising of auditing standards – ISA 240. Six audit partners noted that ChatGPT’s summary of ISA 240 was complete and correct, while two considered it moderately correct and complete. Participants acknowledged that the summary incorporated key findings, although some wished it provided more detail. One audit partner, who rated the summary as moderately correct and complete, noted that it should have addressed ISA 240′s requirement to plan for elements of unpredictability in audits. Additionally, they highlighted the need for required journal entry testing for high-risk entries.

Should perhaps add certain elements such as: − ISA 240′s requirement to plan for elements of unpredictability in the audit − Required Journal Entry testing for high-risk entries. (Audit Partner 5, 24 years of experience)

The audit partner who rated the response as strongly incomplete and incorrect noted that risks and actions were not clearly defined and also pointed out the necessity of specific tests. The quote below captures this:

Risks/actions are not clearly defined, and specific tests are needed. (Audit Partner 2, 24 years of experience)

Scenario 4: Risk assessment within the energy sector.

Six audit partners noted that the risk assessment provided by ChatGPT was either highly correct and complete or moderately correct and complete. Even though audit partners found the risk assessment relevant, they highlighted its lack of comprehensiveness, noting that the nature of the item being audited is crucial in determining appropriate risk considerations. Some partners also emphasised that risk assessments should consider strategic, legal, and reputational risks, depending on the circumstances of the audit. Additionally, they recommended incorporating elements of predictability in audits and testing high-risk journal entries to enhance risk assessments.

The auditor’s actions to address risk do not appear to fully cover the identified risks. (Audit Partner 1, 17 years of audit experience)

As a standpoint this seems relevant to take into consideration regarding risks. But it depends on circumstances regarding the object being audited. Strategic risks, legal risks, reputational risks could also be important to take into reconsiderations. (Audit Partner 4, 20 years of experience)

Should add comments on including element of predictability in the audit and test of high-risk journal entries. (Audit Partner 5, 24 years of experience)

Auditors who rated the risk assessment as moderately incomplete and incorrect noted that risks should be identified at the financial statement line-item level and for each assertion. They also expected a more specific risk description, tailored to the particular energy company.

The risk should be at a financial statement line and per assertion. (Audit Partner 7, 25 years of experience) I had expected a more specific description of the risks, tailored to what is relevant for the energy company in question. (Audit Partner 2, 24 years of experience)

An audit partner who neither agreed nor disagreed on ChatGPT’s potential to facilitate risk assessment noted that, although it incorporated relevant factors, it did not provide clear insight into where the risk lies for the entity.

These are all relevant factors − it does not however give so much input to where the risk is for this entity. (Audit Partner 6, 21 years of experience)

Scenario 5: Recency of Knowledge.

ChatGPT’s knowledge is often limited to the information available up to its last update. This information may lack domain-specific detail and may be out of date, particularly on recent events or rapidly changing topics. To illustrate this, we engaged ChatGPT with an enquiry to assess its ability to interpret recent regulatory changes relevant to auditors’ considerations when auditing financial institutions (Appendix E). As shown in Appendix E, ChatGPT explicitly recognised the time constraints of its knowledge base. It even recommended consulting more up-to-date sources and provided only general trends and background information.

Scenario 6: Generating specific audit opinions and reports.

ChatGPT is an AI text-based model trained on vast quantities of data, which do not include specific real-time financial information such as financial statements. The lack of access to financial statements and entity-specific data limits the applicability of ChatGPT in audit scenarios. For example, ChatGPT cannot generate audit reports or issue audit opinions, as these are based on a thorough analysis of sufficient and appropriate audit evidence. LLMs often lack access to clients’ specific financial data required for such analysis. We asked ChatGPT to generate an audit opinion for DNB (Appendix F). As shown in Appendix F, ChatGPT acknowledged that it cannot issue an audit opinion or perform audit tasks due to its limited access to specific company financial data.

It also acknowledged that auditing is complex and highly regulated; hence, such tasks are typically carried out by qualified auditors.

Scenario 7: Accuracy of information

Responses from ChatGPT are probabilistic in nature, and this has raised significant concerns about the possibility of ‘hallucination’, a common phenomenon in which LLMs produce fabricated, false, or misleading information. To illustrate the problem of audit hallucinations, we asked ChatGPT whether it was familiar with International Standards on Auditing (ISA) 620 without mentioning the content of the standard. ChatGPT responded in the affirmative and indicated that the standard was relevant to fair value measurement and disclosure audits (see Appendix G). However, ISA 620 refers to the work of experts. Although such responses may improve as the technology is trained with new and updated data, hallucination remains a fundamental problem.

5. Discussion.

The quantitative findings of this study align with emerging literature, which underscores the potential of Large Language Models (LLMs) to perform simple, mundane, and repetitive tasks, including those prone to error. Such tasks include generating human-like responses and preparing audit working papers and reports. However, the qualitative findings from Scenario 1 suggest that auditors require more detailed and comprehensive reports covering the nature and scope of inventory audits—elements that ChatGPT does not adequately address, likely because the prompts did not explicitly request them. Notably, ChatGPT’s output included conclusions not specified in the initial prompt,9 indicating that it made assumptions and judgements to arrive at those conclusions.

Its failure to identify or recommend the areas highlighted by audit partners suggests an inability to generate comprehensive, audit domain-specific reports. Instead, it primarily produces basic reports, which may serve as a guide but lack the depth auditors require for standard audit reports. This finding supports the argument that LLMs should function as co-pilots, serving as audit assistants to support rather than replace the auditor. Consequently, auditors are expected to retain full responsibility for steering audit procedures, crafting adequate prompts, and reviewing the output generated by these models.

Therefore, in the context of generating audit reports, LLM outputs should be regarded as preliminary guides rather than comprehensive reports.

Furthermore, non-Big Four auditors provided their highest ratings for LLMs’ time-saving potential, corroborating contemporary literature, which suggests that LLMs save time by performing manual and routine tasks. The time saved can be redirected towards value-added activities and complex tasks requiring judgement. Beyond time-saving efficiency, the findings affirm emerging research that highlights LLMs’ potential to facilitate audit planning by identifying areas where auditors may lack expertise and knowledge, enhancing internal control assessment and recommending improvements, and performing particular tasks traditionally handled by auditors.

Despite participants’ positive perceptions of LLMs in performing particular audit planning procedures, findings in Scenario 4 reveal that while audit partners generally agreed that external LLMs can facilitate risk assessment, they raised concerns regarding the comprehensiveness, depth, and contextual relevance of LLM-generated risk assessments. Consequently, while external LLMs can assist with risk assessment, auditors’ contextual knowledge remains crucial for enhancing its value.

Similarly, in Scenario 2, which concerns the interpretation of audit standards, audit partners expect LLM-generated interpretations to be more in-depth and comprehensive. While external LLMs can assist in interpreting auditing standards, the findings suggest that completeness alone does not equate to sufficiency, as audit partners emphasised the need for more detailed interpretations incorporating multiple auditing standards. These insights reinforce the argument that LLMs should complement rather than replace auditors, which necessitates auditors’ supervision. Ian Pay, Head of Data Analytics and Tech at ICAEW, echoes this view:

It is easy to envisage a world where, rather than trawling through endless pages of auditing standards, methodology guidance or taxation policy, a simple question to a chatbot like ChatGPT returns the relevant information in a factual way. But we must remember that it will never be able to deliver contextual, personal advice in the way that a trusted accountant can, or design audit procedures that are relevant to the specifics of the business being audited.

A recurring theme across the qualitative scenarios is the necessity for in-depth and comprehensive LLM outputs, reinforcing the importance of auditors’ supervision and judgement in determining the sufficiency of such reports. Scenario 3 further illustrates the gap between LLM-generated outputs and audit expectations. While external LLMs were generally rated positively for summarising auditing standards, a key criticism was their failure to clearly define risks and actions related to the standard, aligning with prior studies recommending auditor oversight. Although participants believe that LLMs can enhance audit efficiency, effectiveness, and the quality of audit procedures, aligning with contemporary findings, they also expressed concerns about potential legal liabilities associated with audit failures linked to LLM use.

This concern may constrain the adoption of these technologies due to insufficient regulatory guidance, as auditors strive to conduct regulatory-compliant audits.

The challenges observed in Scenario 5, particularly regarding the occasional outdated nature of external LLM-generated outputs, align with prior literature. The issue of outdated information is a prevalent limitation of LLMs, raising concerns about accuracy and reliability. Consequently, auditors must verify LLM-generated outputs to ensure their relevance and recency. Similarly, Scenario 6, which underscores the limitations of external LLMs in generating audit reports, reinforces the argument that external LLMs are tools rather than substitutes for human auditors, who are responsible for assessing the sufficiency and appropriateness of audit evidence and determining the extent of substantive audit procedures required for forming an audit opinion. Consistent with extant studies, Scenario 7 highlights the issue of hallucination, a known limitation of LLMs.

Despite the seemingly convincing nature of LLM outputs, they may be based on misinterpretations or false data, necessitating auditors’ awareness of the potential for misinformation and the need to maintain professional scepticism when dealing with LLM-generated content.

Overall, the challenges associated with LLMs in external auditing can be categorised into technical limitations, practical audit risks, and ethical challenges, as shown in Table 5. The findings also underscore that the successful deployment of external LLMs in auditing requires careful prompt engineering, auditor oversight, and a clear delineation of their supporting role in audit procedures (see Gu et al., 2024). Additionally, positioning LLMs as ‘co-pilots’ in audit engagements—supporting rather than replacing auditors—remains critical for their effective integration into external audits.

6. Ethical implications of using LLMs in external audits.

Auditors currently face challenges in adopting LLMs due to a lack of ethical guidance. Firstly, it lacks ethical reasoning. Several ethical considerations must be taken into account, including the impact on auditor objectivity. Objectivity is a fundamental principle that ensures auditors remain free from undue influences that could compromise their professional judgement. The Code of Ethics specifically requires auditors to ‘exercise professional or business judgment without being compromised by: (a) bias; (b) conflict of interest; or (c) undue influence of, or undue reliance on, individuals, organizations, technology or other factors’. A lack of objectivity can impair auditors’ judgement. Maintaining objectivity strengthens public confidence in the profession and enhances the reliability of audited financial statements.

Previous research has found that the use of automated audit evidence can result in auditors relying both too heavily and too little on such evidence.

Confidentiality, data protection and information security are crucial ethical considerations in auditing, especially when using AI. The Code of Ethics requires auditors to comply with the principle of confidentiality of information arising from

Challenges associated with LLMs in external auditing.

their professional and business relationships. Confidentiality refers to the auditor’s obligation to protect client information obtained during the audit. This ensures that sensitive data such as financial information, business strategies and client data is not disclosed to unauthorised persons or entities unless required by law or professional standards. When using LLMs, confidentiality can become a concern if the chat history function is not disabled10 because auditors must input sensitive, proprietary, and confidential information about the audited entity to generate responses. Even when the chat history function is disabled, there are concerns regarding the security of LLMs, data storage, and privacy. Therefore, auditors should maintain scepticism and avoid imputing clients’ data in such LLMs.

Such confidential information can be used as training data, potentially leading to subsequent outputs that mimic sensitive information, which can be context-specific. In addition, artificial intelligence systems, including LLMs, learn and evolve through the information they are exposed to. This poses the risk that information input by auditors about a specific client in LLMs can be incorporated into the system’s self-evolving process, potentially resulting in a breach of confidentiality. Commenting on the potential implications of sharing clients’ data with technology, Kristen Beadle, CPA Australia’s Public Practice Manager, notes:

However, users of the technology need to be cautious and understand the implications of what client information they may be sharing with the technology that can be used by malicious actors who may use the data in a cyberattack.

Therefore, auditors who plan to use LLMs should carefully consider the risks and ethical implications associated with sharing sensitive information and take measures to safeguard them. Confidentiality, privacy, and information security thus become significant ethical considerations when using LLMs in the audit process.

Another important ethical consideration is accountability for information generated by LLMs. Accountability is a core principle in auditing, as it promotes transparency and ensures that auditors are held responsible for their actions. This ensures that auditors fulfil their duties conscientiously and comply with professional standards. The auditing profession is characterised by its commitment to serving the public interest. In addition, auditors must demonstrate professional behaviour by complying with the relevant laws and regulations and refraining from actions that could bring the profession into disrepute. When using LLMs to support decision-making, auditors remain accountable. However, LLMs do not always provide reliable and accurate information, posing accountability challenges for auditors who rely uncritically on their output.

In particular, autonomous AI—technology that acts independently with minimal human intervention—raises significant ethical concerns and may compromise audit quality. Furthermore, it is difficult to trace the sources of the information generated by LLMs. In the absence of clearly identified sources, it is essential to establish clear accountability channels to determine who is responsible for the information produced by LLMs. Improving both accountability and transparency in the development and deployment of advanced AI technologies is therefore imperative. Transparency requires that the capabilities and limitations of LLMs and similar technologies are disclosed, so that users understand the extent of security they can provide. In addition, concerns around error handling and misinformation must also be addressed.

Finally, there are intellectual property rights concerns associated with the output generated by LLMs. This raises the question of who owns the rights to content produced by LLMs. Since LLMs are trained on vast amounts of data—some of which may include copyrighted material—without clear explanations of how outputs are derived, there is a risk that the results may infringe upon as they carry legal implications for audit firms. Based on the foregoing discussion, auditors should exercise professional judgement and scepticism when using LLM-generated content. Like other emerging technologies, LLMs are tools that should support, not replace, auditors’ professional expertise. Outputs from LLMs should be treated as preliminary reference points, and their accuracy and reliability must be verified before being relied upon in auditing.

7. Conclusions and implications for future research.

This study explored the impact of LLMs on external audits and their associated ethical implications. To achieve this, we conducted a small-scale survey with non-Big Four auditors to assess their general perceptions of LLMs, followed by a qualitative evaluation of ChatGPT’s responses to seven audit-specific tasks. The findings highlight both the potential and the limitations of LLMs in external audits. The survey reveals that non-Big Four auditors generally perceive LLMs as valuable for performing routine tasks, particularly those prone to error, generating audit working papers and reports, enhancing audit planning, saving time, strengthening internal control assessments, and assisting with certain audit procedures. Overall, LLMs are seen as improving audit efficiency, effectiveness, and potentially audit quality.

However, concerns persist regarding the potential legal liabilities audit firms may face if audit failures result from LLM use. The qualitative evaluation underscores significant challenges in applying external LLMs to auditing. While LLMs can assist in summarising and interpreting auditing standards and facilitating risk assessments, they struggle to generate comprehensive, audit-specific, and contextually appropriate reports that meet professional expectations. Key limitations include a lack of depth in interpreting auditing standards, outdated information, and hallucinations, reinforcing the need for auditor oversight. Additionally, ethical concerns arise regarding auditors’ objectivity, confidentiality, privacy, information security, accountability, and intellectual property rights.

Despite the current benefits of LLMs, existing challenges and ethical concerns must be thoroughly addressed for audit firms to fully realise their potential. Auditors must exercise a high degree of professional scepticism and judgement when assessing LLM-generated information. Contrary to claims that artificial intelligence could replace certain audit tasks, our findings reinforce that LLMs cannot fully replicate the expertise of human auditors, highlighting the continued necessity of professional judgement.

These findings contribute to the academic literature and offer practical implications for auditors and regulators seeking to understand the role of LLMs in external audits. From a theoretical perspective, this study extends the current discourse on LLMs in auditing by distinguishing between general perceptions of LLMs and evaluating LLM-generated outputs through audit partners’ qualitative assessments. Given that the Big Four audit firms have been vocal about adopting LLMs in auditing, this study offers an alternative perspective by incorporating the views of non-Big Four auditors. Additionally, it initiates a discussion on the ethical considerations surrounding LLM use in auditing, particularly regarding auditors’ objectivity, confidentiality, the intellectual property rights of LLM outputs, privacy concerns, and legal liabilities associated with their adoption.

From a practical perspective, the study provides insights for audit firms and practitioners by identifying specific areas where LLMs add value to audits and where their limitations remain significant. It informs auditors of the risks and shortcomings of external LLM-generated outputs, while reinforcing the recommendation that LLMs should serve as co-pilots rather than replacements for human auditors. Finally, this study serves as a foundation for future research, encouraging further exploration of LLMs in auditing and their broader implications for the profession.

Future research questions

Most of the benefits associated with LLMs in auditing are similar to those offered by other AI tools. However, LLMs are an innovative approach that not only harnesses the capabilities of existing AI tools but also uncovers potential avenues for improvement. Consequently, the primary question within the auditing context shifts from “What can be done with LLMs?” to “How can LLMs be used for external auditing?”

This pivotal question raises other pertinent questions, including but not limited to

• How will LLMs impact auditors’ audit processes?

• What influence will LLMs have on the collection of audit evidence?

• How will LLMs affect the quality of both audit evidence and overall audit outcomes?

• Existing research has indicated that auditors rely excessively on automated audit evidence. Will a similar pattern emerge with LLMs? If so, what implications does this have for professional scepticism? What strategies can auditors employ to mitigate potential biases associated with such reliance?

• LLMs require specific contextual information to generate relevant responses. What training initiatives should audit firms implement to equip auditors with the skills necessary for the optimal use of LLMs?

These questions underscore the need for further research into the practical and theoretical implications of LLMs in auditing, particularly how they could enhance audit quality, while also requiring due consideration of the ethical challenges associated with their adoption.

Declaration of Competing Interest influence the work reported in this paper.

Appendix A:. Request for ChatGPT to write a working paper

Response to scenario 1

Date: December 31. 2022 Prepared by: John Johnsson Subject: Year-End inventory Count for A&B Inc. Background:

As part of our audit procedures, we conducted the year-end inventory count for A&B Inc located in Stockholm, Sweden. The company Is a paper manufacturing firm, and we were engaged to perform the audit of the financial statements for the year ended

The authors declare that they have no known competing financial interests or personal relationships that could have appeared to

December 31. 2022.

Objective:

The objective of our audit procedures was to obtain sufficient and appropriate evidence to support the inventory balances presented in the financial statements. Scope:

Our audit procedures included:

• Reviewing the inventory count instructions provided by management

• Observing the Inventory count process

• Performing test counts

• Confirming the inventory quantities with the client’s inventory records

• Performing analytical procedures to assess the reasonableness of inventory balances

• Assessing the condition of inventories

Findings:.

The inventory count was conducted on December 31. 2022. and we were present during the count. The inventory count instructions provided by management were adequate, and we did not Identify any material issues during the count. We performed test counts and confirmed the Inventory quantities with the client’s inventory records, and we did not identify any discrepancies.

We also performed analytical procedures to assess the reasonableness of inventory balances and compared the balances to the prior year’s balances. We noted that the Inventory balances were consistent with our expectations and that the changes were immaterial. In addition, we assessed the condition of inventories and noted that the condition of inventories was generally good. We did not observe any problems that were identified during the prior year’s inventory count.

Conclusion.

Based on our audit procedures, we obtained sufficient and appropriate evidence to support the inventory balances presented in the financial statements. We noted one immaterial error during the count, which management promptly corrected. Overall, we did not identify any material misstatements in the Inventory balances.

Note: This working paper was prepared by John Johnsson and reflects the procedures performed, evidence obtained, and conclusions reached as of December 31, 2022.

Appendix B:. Request for ChatGPT to provide relevant standards for auditing cash and cash equivalents

Response to scenario 2

Sure, when auditing cash and cash equivalents, auditors should consider the following audit standards:

1. ISA 200: Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance with International Standards on.

Auditing − This standard sets out the overall objectives of the auditor and provides guidance on the conduct of an audit in accordance with International Standards on Auditing.

2. ISA 240: The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements − This standard requires the auditor.

to plan and perform the audit with an attitude of professional skepticism, and to consider the risks of material misstatement due to fraud.

3. ISA 500: Audit Evidence − This standard provides guidance on obtaining sufficient and appropriate audit evidence to support the.

audit opinion.

4. ISA 501: Audit Evidence − Specific Considerations for Selected Items − This standard provides guidance on obtaining sufficient and.

appropriate audit evidence for specific items, such as cash and cash equivalents.

5. ISA 505: External Confirmations −.

This standard provides guidance on using external confirmations to obtain audit evidence, which may be applicable to confirming cash and cash equivalents balances with banks.

6. ISA 520: Analytical Procedures − This standard provides guidance on using analytical procedures to evaluate financial information.

which may be applicable to identifying unusual or unexpected trends or transactions related to cash and cash equivalents.

7. ISA 570: Going Concern − This standard requires the auditor to evaluate the entity’s ability to continue as a going concern, which.

may be applicable to assessing the entity’s ability to meet its cash and cash equivalents obligations.

8. Overall, when auditing cash and cash equivalents, auditors should consider the risks of material misstatement, obtain sufficient and.

appropriate audit evidence, and evaluate the entity’s ability to continue as a going concern.

Appendix C:. A response from ChatGPT of ISA 240

Response to scenario 3

Certainly! ISA 240, titled “The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial Statements,” is an international auditing standard that provides guidance to auditors on their responsibilities when it comes to detecting and addressing fraud in financial statements during an audit. Here’s a summary of its key points:

1. Responsibility for Detecting Fraud: The standard emphasizes that the primary responsibility for the prevention and detection of.

fraud rests with management and those charged with governance of the entity. However, the auditor has a responsibility to consider the risk of fraud and design their audit procedures accordingly.

2. Understanding Fraud: Auditors are required to have an understanding of fraud and its characteristics, including the types of fraud.

risks that may be present in the entity’s industry and specific circumstances.

3. Assessing Fraud Risks: Auditors should assess the risk of material misstatement due to fraud by considering various factors, such as.

the entity’s internal controls, management’s attitude toward fraud, and historical fraud incidents.

4. Professional Skepticism: Auditors are required to maintain professional skepticism throughout the audit process, which involves.

being alert to the possibility of fraud and not being overly trusting of management representations.

5. Audit Procedures for Detecting Fraud: Auditors should perform specific audit procedures designed to detect fraud, including.

evaluating the appropriateness of accounting estimates, assessing journal entries, and considering the potential for management override of controls.

6. Communication and Reporting: If auditors identify or suspect fraud during the audit, they have a responsibility to communicate.

their findings to appropriate levels of management and, in some cases, to those charged with governance. If fraud is material, the auditor should consider whether it necessitates a modification of the auditor’s report.

7. Documentation: Auditors should document their understanding of fraud risks, the assessment of those risks, and the audit procedures performed in response to those risks.

8. Consideration of Laws and Regulations: Auditors should consider whether noncompliance with laws and regulations related to.

fraud has a material effect on the financial statements and whether it requires disclosure or reporting to relevant authorities.

9. Professional Judgment: ISA 240 recognizes that the assessment of fraud risk and the detection of fraud of ten involve the exercise of.

professional judgment by the auditor.

In summary, ISA 240 outlines the auditor’s responsibilities regarding fraud in financial statements, emphasizing the need for a proactive approach to assess and address the risk of fraud during the audit process. It highlights the importance of professional skepticism. communication, and documentation in fulfilling these responsibilities.

Appendix D:. A summary of the risk factors relevant to a company in the energy sector in Norway

Response to scenario 4:

When auditing a company in the energy sector in Norway. It’s essential to consider specific risk factors that are relevant to the industry and the local market. Here are some key risk factors that auditors should be mindful of in the Norwegian energy sector:

1. Regulatory and Policy Changes: Changes in Norwegian energy policies, regulations, and subsidies can have a significant impact.

on the energy sector. Auditors should stay updated on any new legislation affecting energy production, distribution, and pricing.

2. Market Price Volatility.

Energy prices, especially in the electricity market, can be highly volatile. Fluctuations in energy prices can affect revenue and profitability. Auditors should assess how the company manages price risk and its hedging strategies.

3. Environmental and Sustainability Risks: The energy sector is under increasing pressure to reduce carbon emissions and transition to renewable energy sources. Auditors should evaluate the company’s environmental compliance. sustainability reporting, and its strategies for mitigating climate-related risks.

4. Supply Chain Risks: Energy companies often rely on complex supply chains for equipment, fuels, and maintenance. Disruptions.

in the supply chain can impact operations and financial performance. Auditors should assess the company’s supply chain resilience.

5. Foreign Exchange Risk: If the company operates internationally or trades in multiple currencies, fluctuations in exchange rates.

can affect financial results. Auditors should review the company’s foreign exchange risk management practices.

6. Infrastructure and Technology Risks: Energy companies may have substantial investments in infrastructure and technology.

Auditors should consider the risk of asset impairment or technological obsolescence. and the adequacy of maintenance and upgrades.

7. Market Competition: Intense competition in the energy sector can put pressure on prices and profit margins. Auditors should.

assess the company’s competitive position and strategies for maintaining market share.

8. Government Incentives and Subsidies: Many energy companies in Norway benefit from government incentives and subsidies for.

renewable energy projects. Auditors should verify compliance with incentive programs and assess the impact of changes in subsidy levels.

9. Energy Transition Risks: As the world shifts toward cleaner energy sources, fossil fuel-based companies may face risks related to.

stranded assets and the need to transition their business models. Auditors should consider the company’s long-term strategy in light of this transition.

10. Political and Geopolitical Risks: Political instability, trade disputes, and international tensions can impact the energy sector.

especially for companies with international operations. Auditors should evaluate how the company monitors and manages geopolitical risks.

Appendix E:. A response to the prompt of providing relevant risk factors as of 2023

Response to scenario 5

As of my last knowledge update in September 2021, I can provide you with some general considerations that auditors of banks typically need to be mindful of regarding regulatory changes. However, please note that regulations are subject to change, and you should consult the most up-to-date sources and regulatory bodies relevant to your jurisdiction for specific updates applicable to your audit in 2023. Here are some general areas and trends to be aware of:

1. COVID-19-Related Regulations: The COVID-19 pandemic has had a significant impact on the banking industry. There may be.

ongoing or new regulatory changes related to loan forbearance, credit risk management, and capital adequacy requirements as banks continue to navigate the pandemic’s effects.

2. Basel Ill Reforms: Basel Ill is an international framework for banking supervision and regulation.

Be aware of any updates or changes to Basel Ill requirements, particularly related to capital adequacy, risk-weighted assets, and liquidity.

3. Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) Regulations: Regulations related to AML and CTF.

continue to evolve. Banks are often subject to stricter reporting and customer due diligence requirements. Ensure that the bank’s AML and CTF compliance is thoroughly assessed during your audit.

4. Consumer Protection Regulations: Consumer protection regulations are important for banks, especially those dealing with retail.

customers. Keep an eye on any changes to regulations concerning fair lending, customer data privacy, and disclosure requirements.

5. Cybersecurity and Data Protection Regulations: The ban king sector is a prime target for cyberattacks. Regulatory bodies may.

introduce, or update regulations related to cybersecurity and data protection. Ensure that the bank has appropriate measures in place to address these risks.

6. Environmental, Social, and Governance (ESG) Reporting: ESG considerations are becoming increasingly important in the.

financial industry. Banks may be required to disclose more information about their ESG practices and risks. Assess the ban Rs ESG disclosures and risk management practices during your audit.

7. LIBOR Transition: The transition away from LIBOR (London Interbank Offered Rate) to alternative reference rates is a significant change in the financial industry. Ensure that the bank has a plan in place for this transition and is complying with relevant regulatory guidance.

8. Digital Banking and Fintech Regulations: As digital banking and fintech continue to grow, regulatory authorities may introduce.

or update regulations specific to these areas. Be mindful of how the bank is adapting to the changing landscape and complying with relevant regulations.

9. Climate Risk and Sustainability Reporting: Climate-related financial risks and sustainability reporting are becoming important.

topics for regulators. Assess the bank’s exposure to climate risk and its sustainability reporting practices.

10. Regulatory Reporting and Stress Testing: Banks are often required to submit regulatory reports and undergo stress testing.

Ensure that the bank’s reporting is accurate and that it can demonstrate its ability to withstand adverse economic conditions.

11. Capital Adequacy and Liquidity Management: Adequate capital and liquidity are essential for a bank’s stability. Review the.

bank’s capital adequacy and liquidity management practices in light of regulatory requirements.

To stay up-to-date with regulatory changes, consider subscribing to relevant regulatory updates, attending industry conferences, and consulting with experts in banking regulation. Additionally, work closely with the bank’s management and compliance team to ensure that your audit is aligned with the latest regulatory requirements.

Appendix F:. A response of weather ChatGPT can provide high judgemental analyses for instance issuing an audit opinion

Response to scenario 6

I’m sorry for any confusion, but I cannot issue an audit opinion or perform auditing tasks as I am a text-based Al model and do not have access to real-time financial data or the ability to perform auditing procedures.

Auditing is a complex and highly regulated process that requires a thorough examination of a company’s financial statements, internal controls, and compliance with accounting standards. It is typically conducted by certified public accountants (CPAs) or auditing firms with the necessary expertise and access to the company’s financial records.

To issue an audit opinion for DNB Bank for the year ending 30 August 2023 you would need to follow the appropriate auditing standards and procedures, which may vary depending on the jurisdiction and regulatory requirements. It’s important to engage a qualified auditing firm or auditor to perform this task in accordance with the relevant standards and regulations.

Appendix G:. An example of ChatGPT hallucination

Response to scenario 7

Yes, ISA 620 is a standard issued by the International Auditing and Assurance Standards Board (IAASB) that provides guidance to auditors on the audit of fair value measurements and disclosures.

The objective of ISA 620 is to provide guidance to auditors on how to design and perform audit procedures to obtain sufficient and appropriate audit evidence regarding the fair value measurements and disclosures presented in the financial statements.

The standard sets out the requirements and guidance for the auditor in the following areas:

1. Understanding the Entity and its Environment: The auditor should obtain an understanding of the entity’s processes and controls.

related to fair value measurements and disclosures, as well as the nature of the entity’s assets and liabilities that are measured at fair value.

2. Assessing Risks and Responding to Risks of Material Misstatement: The auditor should assess the risks of material misstatement.

related to fair value measurements and disclosures, and design and perform audit procedures to respond to those risks. 3. Obtaining Sufficient and Appropriate Audit Evidence: The auditor should obtain sufficient and appropriate audit evidence regarding the fair value measurements and disclosures in the financial statements.

4. Evaluating the Fair Value Measurements and Disclosures: The auditor should evaluate the fair value measurements and disclosures.

presented in the financial statements for completeness, accuracy, and consistency with the applicable accounting standards.

5. Communicating with Those Charged with Governance: The auditor should communicate with those charged with governance.

regarding the significant findings and issues related to fair value measurements and disclosures.

Overall, ISA 620 is an important standard for auditors who perform audits of financial statements that contain fair value measurements and disclosures, as it provides guidance on how to design and perform audit procedures to obtain sufficient and appropriate audit evidence regarding the fair value measurements and disclosures presented in the financial statements.

Data availability.

Data will be made available on request.

Download transcript