AGENTIC AUDIT

The New Economics of Audit Evidence

Audit sampling exists because auditor attention is expensive. As that stops being true, evidence has to come from the running system rather than a folder assembled before fieldwork.

RuleMesh · 26 September 2026 · 6 minute read

Abstract diagram for “The New Economics of Audit Evidence”: a population grid with a sample highlighted.

The auditing sector is automating increasing portions of the process that involve direct interaction with your organisation, and this transformation is occurring more rapidly than many companies are prepared for.

In April 2026, EY introduced a multi-agent system to its audit platform, granting access to 130,000 assurance professionals. Initially, administrative agents adopted the system, followed by agents responsible for drafting audit work and, ultimately, those assisting with reviews. EY anticipates this system will support all of its audits by 2028. Concurrently, startups are developing similar tools with the backing of investors. For instance, Audrey AI secured $1.8 million in April to enhance smart data requests, evidence collection, and transaction testing. Fieldguide raised $75 million in February 2026 at a $700 million valuation to develop agents that manage data collection and routine audit tasks. Currently, half of the top 100 US accounting firms, including some members of the Big Four, use Fieldguide.

All these tools concentrate on the same aspect of the audit: gathering and testing evidence. This stage is the only part of the audit that depends on the company being audited rather than the report or engagement letter.

From the perspective of the audited company, an audit primarily consists of a series of evidence requests. The audit team asks for evidence, and employees within the company are responsible for locating and providing it. All other elements, including planning, scoping, sampling decisions, and the final report, are handled by the audit firm. Evidence requests are the part of the process that companies experience directly, and historically, these requests have been managed at a human pace and in manageable quantities, as each request and response required individual attention.

For companies, the central question is not whether their requirements are documented. Most regulated organisations maintain a policy library, a control framework, and extensive documentation. The real issue is whether those obligations have been translated into actionable guidance for each audience: requirements that engineers can implement, controls that operations teams can manage, and clear evidence expectations for those responding to auditors. Where this translation exists, companies can accommodate faster audit queries because the answers are readily available. Where it does not, organisations must rely on a few individuals to reconstruct each response, a process that does not scale as the volume of questions increases.

Sampling was a workaround

Audit practices have always been constrained by the limits of human attention. Auditors cannot feasibly review every access grant, every vendor file, or every deletion request. As a result, the profession developed a methodology centred on sampling and thoughtful analysis of selected items. This is the image most people associate with an audit: reviewing a sample of twenty-five items, applying a materiality threshold, following an annual cycle, conducting walkthroughs with process owners, and compiling a folder of screenshots prepared just before fieldwork by a team well aware of the schedule.

Each of these practices is a reasonable response to real constraints, primarily the limited and costly nature of audit attention. This dynamic shifts significantly with the introduction of agents. As the cost of asking questions decreases, the justification for sampling becomes less compelling, as does the rationale for limiting audit activities to a single week each year.

It is unlikely that sampling will disappear in the immediate future. Professional standards evolve gradually, firms exercise caution for valid reasons, and a human auditor remains responsible for signing the opinion. However, the overall trajectory is clear. The first assumption to change is the idea that the number of questions posed to a company is limited by human capacity. An agent does not tire after the fortieth request, nor does it settle for last year's benchmarks simply out of convenience. Even when responses arrive weeks later in a different format or from another team, the original question remains unchanged.

What counts as evidence

The standards governing evidence have not changed. Professional audit practice has long required evidence to be both sufficient in quantity and appropriate in quality, meaning relevant and reliable. The fact that a machine reads the evidence does not alter these requirements. What does change is the extent to which the reader can interpret or infer meaning from the evidence provided.

A policy document demonstrates that a policy exists, while a screenshot confirms that a screen appeared a certain way on a specific day. An auditor reviewing a small sample within a limited timeframe will often accept both forms of evidence, as the judgement is based on a manageable set of data points. In contrast, an agent assessing an entire population applies the same focused question to every item: which obligation is relevant, who is responsible, which artefact serves as evidence, when the artefact was generated, and whether it pertains to the period under review.

Retention offers a clear example. When using a sampling approach, the main concern is whether the five records selected by the auditor were deleted on time, and a screenshot of an empty table is often sufficient. In a population test, the question shifts to whether every record that reached its retention date was deleted, something the system must log consistently. The underlying obligation and regulatory article remain the same. The difference lies in whether the answer can be provided by checking on a given day or requires ongoing, system-based evidence.

When translating GDPR into specific requirements, we anticipated that designing the controls would be the most challenging aspect. In reality, the greater challenge was articulating, for each requirement, the type of evidence a supervisor would expect. This task requires specialised expertise, which most organisations apply only narrowly and reactively, typically in the weeks surrounding an audit and only within its defined scope. As a result, evidence expectations for areas outside the audit scope are rarely documented. This is not due to negligence but rather reflects that such expertise was engaged only for a specific, limited period.

There is a strong business case for clearly defining evidence expectations, and it extends beyond audit fees. When an obligation's evidence requirements are unclear, compliance becomes an open-ended cost that finance teams cannot accurately estimate. Once requirements are well-defined and assigned to specific owners, costs become predictable, and work falls into two categories: tasks that are part of the project plan regardless of regulation, and work that is performed solely to meet regulatory requirements. An audit that can be answered directly from the running system results in predictable costs, whereas assembling evidence folders after the fact introduces uncertainty.

Both sides keep a human

The division of labour remains consistent on both sides of the engagement, by design. EY clearly states that its auditors are the essential human element, maintaining professional scepticism and legal responsibility for every workpaper an agent drafts. We follow the same principle from our perspective. While an agent can review environments, collect evidence signals, and submit them, only a person is authorised to mark anything as verified.

This structure is intentional. GDPR Article 5(2) assigns the responsibility to demonstrate compliance to the controller, a legal person. NIS2 similarly holds named members of the management body accountable. No supervisor has accepted a machine as the accountable party, and I do not foresee that changing.

Agents are responsible for gathering, testing, and drafting, while people are responsible for judgement and final approval. Any product marketed as an agent that certifies compliance is offering something that does not exist.

In my view, this evolution will change the nature of disagreements between auditors and companies. Currently, much of the audit process involves negotiating over facts, such as whether the sample was representative, whether an exception was isolated, or whether a log covers the required period. As these factual disputes diminish, interpretation will take centre stage. The critical discussions will focus on whether a particular control satisfies the requirement it is meant to meet, and whether an organisation's reading of a word like 'appropriate' matches what a supervisor expects. These have always been more challenging debates, and they are likely to become a larger part of the audit process in the future.

What a company should have in place

Answering audits from the running system requires more than traditional audit preparation. Obligations should become clear, testable requirements with specific owners, and evidence expectations should be set during system development, not left for later reconstruction. The system should generate evidence automatically as it operates, with each requirement traced back to its original source for transparency.

These steps are not just for auditors. They are the basics of running a compliant, regulated system.

While firms may take different routes, the goal is common: make audit questions easy to ask and ensure evidence is available within the running system.

Everything above concerns the audits a company commissions and pays for, where both parties have an interest in a process that stays manageable. The same capability is not limited to audit firms. A supervisory authority reviewing a breach notification, or a regulator following up on an incident report, can apply the same tools to the same evidence, and its questions carry statutory deadlines rather than an engagement timetable. The evidence expectations that make a commissioned audit manageable are the same ones that matter in a regulatory examination.

If your organisation is on an annual audit cycle, now is the time to prepare your evidence expectations for the future. This work can start immediately, without waiting for new tools or industry deadlines.

Industry sources: EY newsroom, April 2026 · ICAEW, September 2026 · Tech.eu, April 2026 · Goldman Sachs Asset Management · Accounting Today.

Audit standards: Evidence sufficiency and appropriateness follow ISACA ITAF 4th edition (2020), Standard 1205, consistent with ISA 500. Neither is named in the article.

Primary law: GDPR Article 5(2) · NIS2 Article 20.

Back to top