In increasingly complex risk environments, traditional sequential and manual risk identification approaches are reaching their limits. Multi-agent systems offer an innovative and scalable architecture in which autonomous, specialized agents analyze distinct risk domains, such as financial stability, operational disruptions, and regulatory compliance, and synthesize their findings into a consolidated risk assessment. Drawing on a case study from a global logistics enterprise, complemented by practitioner insights from a workshop and a cross-organizational survey, we demonstrate how a multi-agent system enables holistic and near-instantaneous risk evaluations. Grounded in sociotechnical systems theory, the approach integrates technical capabilities with human, structural, and task factors to jointly optimize risk management outcomes. The system achieved comprehensive risk assessments in under 62 seconds and still offered domain-specific analytical depth. While multi-agent systems require careful orchestration of agent communication and knowledge integration, the approach enhances efficiency, consistency, and the ability to detect interdependencies between risk categories. During the preparation of this work, the authors used OpenAI ChatGPT in order to support language refinement, improve readability, and assist with the structuring and editing of selected text passages. After using this tool, the authors reviewed and edited the content as needed and take full responsibility for the content of the publication.
SYNOPSIS: Generative artificial intelligence (GenAI) is rapidly disrupting the business world. Although it is increasingly used, there are significant risks to this technology, and practitioners want help in managing GenAI risks. We use design science research methodology to develop and validate a GenAI governance framework designed to help companies manage the risks associated with GenAI. The framework outlines 69 control considerations across five governance domains and provides a maturity model to assess readiness for each control consideration. To develop and validate the framework, we conducted surveys, in-depth discussions, and structured interviews with more than 1,000 practitioners, including GenAI specialists, audit committee members, C-suite executives, internal and external auditors, and regulators. We also report on the experience of 18 diverse organizations that have used the framework since its release. Our evidence suggests that the GenAI governance framework is valuable to organizations of diverse sizes in helping them effectively manage GenAI risks.
In 1999, the internationally applicable role of the internal audit function was redefined to be a trusted advisor to the organization rather than a stereotypical "corporate watchdog." However, even today there is no clear understanding of what characteristics are associated with an internal audit function's adopting a trusted advisor role, nor of what benefits the trusted advisor role yields for the organization. Using survey data from 250 chief audit executives, we find that a mix of professional and interpersonal internal audit characteristics is associated with adopting a trusted advisor role. Additionally, we find associations between trusted advisor internal audit functions and perceived benefits to the organization such as audit effectiveness, efficiency, and usability of audit outputs. Our findings contribute to the academic knowledge on the evolution of internal audit functions and identify incentives for adopting trusted advisor roles.
Internal audit is increasingly expected to move from a retrospective "after the fact" stance to a proactive, risk-mitigating role. We introduce a predictive process-monitoring approach that lets internal auditors forecast late-payment risk while preserving the role separation mandated by the Three Lines Model. Using the 2018 BPI Challenge event log and a synthetic corporate invoice log, we (1) transform traces into deadline-centered, time-bucketed prefixes; (2) compare five classifiers; and (3) embed the resulting accuracy-timeliness profiles in a four-phase decision framework that aligns intervention timing with organizational context and governance guard rails. The study contributes by showing (1) a concrete use case for predictive monitoring, (2) statistical evidence clarifying the accuracy-timeliness tradeoff for audit use cases, and (3) a reusable, governance-anchored decision framework.
This paper provides a systematic synthesis of XAI research across financial risk assessment, fraud detection, auditing and compliance, business decision support, and methodological innovations. Our analysis shows that the literature attributes dual roles to XAI: improving predictive performance while supporting transparency, accountability, and documentation requirements. The trade-off between accuracy and explainability is shown to be contextdependent, and empirical evidence on how explanations support professional judgment remains limited. While research on XAI is advancing in risk assessment and fraud detection, its integration into accounting and auditing tasks is constrained by concerns related to bias, data privacy, overreliance, and the effective use of explanations by practitioners. We identify gaps in the literature, including the absence of standardized evaluation criteria, limited real-world validation, and insufficient attention to human use of explanations. The review positions XAI not as a technical solution, but as an institutional and socio-technical requirement for future human-AI collaboration.
Technological advancements, such as data analytics, artificial intelligence (AI), and robotic process automation (RPA), are reshaping internal audit practices. These innovations have driven significant improvements in efficiency, effectiveness, and performance. Traditional internal audit processes are evolving with the integration of advanced technologies. The 2024 Global Internal Audit Standards emphasize performance as a key factor in the success of modern internal audit functions (IAFs), which underscores the growing need to integrate advanced technologies into audit processes. However, adoption poses challenges, including data privacy concerns, cybersecurity risks, and the demand for specialized expertise. This paper reviews existing literature on technology-driven auditing, explores the impact of the 2024 Global Internal Audit Standards, and identifies key challenges in implementing different technologies.
Process Mining (PM) enhances the evaluation of the internal control system with corresponding tests of controls due to a comprehensive analysis of variants within business processes. It can be used by external and internal auditors to improve audit efficiency, effectiveness, and quality. Nevertheless, PM is still not an industry-wide best-practice standard, especially due to existing implementation barriers for practitioners. This study utilizes Design Science Research (DSR) to develop the Audit Process Mining (APM) Framework to implement PM into audit tasks and overcome existing implementation barriers. The APM Framework was designed using empirical insights extracted from interviews with subject matter experts across various audit firms and large industrial companies. Furthermore, 19 auditing professionals confirmed that the APM Framework is a valid and verified solution.
We provide the first, large scale, global study on the characteristics associated with an internal audit function’s involvement in IT and cybersecurity assurance. Using a unique dataset of 1,142 survey responses, we identify internal audit development (i.e., level of maturity) and two characteristics of internal audit knowledge availability (CAE IT certification and external sourcing) as being positively associated with the performance of IT assurance, cybersecurity assurance, or both. Our findings are informative to academia, laying the groundwork for further exploration of internal audit’s engagement in IT and cybersecurity assurance. They are also informative to practice, as they provide insight to standard setters, practitioners, management, and governance bodies about characteristics that can enhance internal audit’s ability to provide IT and cybersecurity assurance.
SYNOPSIS We discuss how the internal audit function (IAF) of a large multinational energy company, Uniper, is using ChatGPT to enhance internal auditing tasks. We investigate the benefits and challenges of integrating ChatGPT into internal audit processes and assess internal auditors’ perception of the impact on the efficiency and effectiveness of the IAF. Uniper has implemented ChatGPT into audit preparation, fieldwork, and audit reporting tasks. Based on initial tests, the IAF estimates efficiency gains ranging from 50 to 80 percent for various processes. We report key risks and challenges associated with using ChatGPT in internal auditing and identify key practices and rules adopted by Uniper for using ChatGPT. This study should help practitioners learn how ChatGPT can aid in auditing and help inform researchers about this emerging technology.
We analyze the relation between board-level codetermination and shareholder value. We use a unique dataset of listed German companies that enables us to identify heterogeneous aspects of codetermination and overcome otherwise common identification issues. We find that codetermination reduces firm value but does not have a corresponding negative effect on firm performance. However, we find that codetermination increases employee wages and employee count while decreasing dividends paid to shareholders, thus providing some justification for the decrease in firm value. Our findings highlight how heterogeneity of firm governance structures can result in tradeoffs in economic outcomes that are a function of the structure's economic characteristics. This study should improve policy makers' understanding of the economic consequences of codetermination.
For the past several years, internal audit functions (IAFs) have been significantly increasing their digitization efforts to enhance the efficiency and effectiveness of the IAF. The introduction of OpenAI's ChatGPT has increased the potential for IAFs to have a more significant impact; however, there is little guidance on how ChatGPT or other generative AI (GenAI) tools can influence the day-to-day work of internal auditors. This paper demonstrates with specific examples how GenAI can be used to enhance all aspects of the audit process for a broad variety of IAFs. Although not comprehensive in nature, the detailed, illustrative examples should help internal auditors see actionable steps they can take to be more efficient and effective and thus add more value to their organizations. Finally, this paper helps researchers to identify potential avenues for future research. Data Availability: The data used in this study are available upon request from the authors.
We investigate the effect that adherence to the Institute of Internal Auditors' Core Principles has on mission-based internal audit (IA) characteristics. Using 255 survey responses from Chief Audit Executives in Germany, Switzerland, and Austria, we find that adherence to the Core Principles is associated with a greater scope of IA work, alignment with the strategic goals of the organization, usage of IA work product by a greater number of stakeholders, and a greater extent of IA work product usage by those stakeholders. We find that only three of the Core Principles are associated with at least one of these characteristics and that no Core Principle is dominant in explaining all characteristics. Our results expand upon the fledgling academic literature on the globally mandated Core Principles, add to the existing literature on IA quality, and support practitioner adoption of the Core Principles as a means of IA effectiveness.
Although thought leaders assume audit technology will enhance internal audit quality, research has provided limited evidence. This study surveys 285 chief audit executives (CAEs) in 2020 and compares their responses with those of 447 CAEs in 2023 to explore changes of internal audit quality from using software and data analytics over time. From 2020 to 2023, internal audit functions (IAFs) showed a steady shift toward more sophisticated and digitalized data analytics, with increased integration and reduced reliance on paper-based and spreadsheet tools, although full optimization remains limited. The findings also show that the use of audit management software (data analysis software) is positively associated with improvements in internal audit efficiency (effectiveness) across both time points. Notably, internal auditing's data analytics maturity is associated with increased measures of internal audit quality, a trend that strengthens in the 2023 data. These findings provide evidence that software and data analytics are beneficial.
ABSTRACT Timely and accurate detection of fraudulent activities is important for understanding patterns and trends and implementing preventive measures. Accounting and Auditing Enforcement Releases (AAERs) are frequently used as a proxy for fraudulent financial reporting in accounting literature. However, manual processing makes analyzing these documents time-consuming and error-prone. Recognizing the standardized nature of AAERs, this paper presents an innovative automated approach using Python. Our methodology enhances the process of downloading AAER files from the U.S. Securities and Exchange Commission (SEC) website, introduces a structured categorization approach, and facilitates the alignment of the resulting AAER data with information from the EDGAR database. Our findings show improvements in the efficiency and accuracy of data access and categorization. The paper contributes to the field by providing a replicable, scalable approach for AAER retrieval and systematic categorization, enhancing the capacity of researchers to uncover insights into fraudulent activities and inform regulatory practices. Data availability: The datasets generated and analyzed during the study are publicly available.
One broadly accepted approach to structure the corporate governance of an organization is the so called “Three-Lines-Model” (TLM), which consists of different assurance providers like internal controls, risk management or internal auditing. While previous studies in the field of process mining showed different specific use cases in different related areas of this TLM, like e.g. internal controls, there is not approach that directly links process mining to the TLM. Thus, this paper directly links process mining to all three lines of the TLM and validates the conceptual use cases with real corporate data from a multinational company. The results show the benefits of a TLM-wide implementation of process mining. Thus, our study contributes to the ongoing practical and academic discussions in several ways. First, it leverages the power of the TLM to construct the company’s assurance lines through process mining. Second, the real-world application in a multinational company provides a deep understanding of existing controls and monitoring environment. Third, it offers a broad variety of validated use cases that are aligned with the different lines and can be used as a generic framework for using process mining for different assurance activities.
Adequately designing, effectively operating, and subsequently monitoring an internal control system (ICS), along with digitally transforming business and assurance processes, has become a major challenge in today's business environment. Deutsche Telekom has established a state-of-the-art ICS by using emerging technologies, such as artificial intelligence, robotic process automation, data analytics, including process mining, and blockchain. The purpose of our study is to explore how these technologies can be utilized to enhance the ICS. We describe and analyze use cases implemented by Deutsche Telekom to provide practical insights into how organizations can conduct a digital transformation of the ICS. We further present avenues for future research. Our findings are informative to ICS managers, other assurance functions, management, CFOs, audit committee members, and corporate governance researchers.
We designed, implemented, and evaluated a curriculum that trains accounting students and professionals in process mining, an important emerging technology that is not extensively taught in most degree programs. We partnered with a leading provider of process mining software to create the "Process Mining Audit Professional Badge." The badge's curriculum combines modules focused on generic process mining skills and modules focused on process mining applications in auditing settings. In 22 months, 1,532 individuals completed the curriculum. Learners were highly satisfied with the training, ranked it among the most effective training modalities they had experienced, and perceived that they learned a great deal about both process mining and the auditing process. We demonstrate an approach to developing materials on emerging technologies that is perceived as useful by learners. If adopted more broadly, the approach could facilitate curricular integration of skills demanded by the profession.