
Written by:
Editorial Team
DSG.AI
This glossary defines the terms internal auditors encounter when evaluating, deploying, or governing audit automation and AI-assisted audit systems. Each term includes its working definition, operational context, and a reference to the authoritative standard or source where one exists.
The goal is a single reference that cuts through the terminology collision between vendor marketing, academic research, and practitioner standards. Definitions below reflect IIA Standards, ISACA guidance, and NIST AI Risk Management Framework where applicable.
A
Agentic audit system An AI system that executes complete audit procedures autonomously: it reads a control's design, pulls evidence from source systems, applies test logic across the full population, and assembles a workpaper for human review. Distinct from AI-assisted tools (see below), which require a human to initiate and complete each step. The ISACA AI Auditing Framework (2026) defines agentic AI as systems that "plan and execute multi-step tasks with minimal human intervention per task." (ISACA AI Auditing Framework)
Agentic GRC The use of autonomous AI agents to execute governance, risk, and compliance workflows: continuous control monitoring, evidence collection, exception surfacing, and workpaper generation. Distinguished from traditional GRC software (which records and tracks) by the agent's ability to initiate and complete tasks without a human trigger. Related: Agentic GRC, Defined.
AI audit agent An AI model or system configured to perform a specific audit procedure, typically including: reading a data source or system of record, applying defined test logic, recording a result for each item in the population, and flagging exceptions. Not a chatbot; a chatbot summarizes information on request. An audit agent changes the state of an audit by producing tested evidence.
AI-assisted audit A human-led audit in which AI tools handle specific sub-tasks: generating draft questions, summarizing policy documents, classifying risk items, or flagging statistical outliers for human review. The auditor directs each step. Distinct from agentic audit systems, which execute complete procedures without human direction at each step. The practical distinction is whether the AI completes the testing or assists the auditor in completing it.
Assured evidence Evidence that has been collected directly from a source system, timestamped at collection, and tied back to its origin with a traceable chain of custody. The standard applicable to audit-grade workpapers requires that evidence be reproducible: a third party re-running the same collection procedure should get the same result. Contrast with "uploaded evidence" (a screenshot or export provided by the auditee, which is not assured because its provenance is unverified).
Audit automation The use of software agents, scripts, or AI systems to perform audit procedures without human execution at each step. Audit automation is distinct from audit management software (which organizes and tracks audit activity) and from audit AI assistants (which help humans complete tasks). Full audit automation: the agent executes the test. Partial automation: the agent handles evidence collection or document assembly, but a human executes the test logic. Related: Audit Management Software Tracks Audits. Audit Automation Performs Them.
Audit coverage The percentage of auditable entities (processes, controls, systems, business units) tested in a given audit cycle. The IIA's 2025 North American Pulse reports that 64% of internal audit functions cover fewer than 40% of auditable entities per year, typically due to capacity constraints. Full-population automated testing removes the headcount constraint on coverage. (IIA North American Pulse 2025)
Audit-as-a-Service (AaaS) A subscription model in which a third-party provider delivers executed internal audit services on a standing engagement: continuous control testing, evidence collection, findings, and workpapers. AaaS is structurally different from co-sourcing (which provides capacity for the auditee's team to use) and from audit management software (which provides a platform). AaaS delivers outcomes (tested controls, audit-grade workpapers) rather than hours or licenses. Related: Audit-as-a-Service: What It Is, What It Costs, and When It Beats Hiring
Audit management software A platform category that organizes, assigns, tracks, and reports on internal audit activity. Workiva, TeamMate+, Diligent HighBond, AuditBoard/Optro, and LogicGate are examples. Audit management software does not execute audits; it manages the workflow around them. Evidence is uploaded into the platform by auditors, not collected autonomously.
Audit trail (for AI systems) A logged, timestamped, tamper-evident record of the actions taken by an AI system during an audit procedure: which data sources were accessed, what logic was applied, which exceptions were flagged, and when. Required for audit-grade assurance on AI-executed tests. The EU AI Act requires that high-risk AI systems maintain audit logs for at least 6 months (EU AI Act, Annex III provisions).
C
Compliance-as-a-Service (CaaS) A subscription model for regulatory compliance delivery. Substantive CaaS delivers executed compliance work: controls tested, evidence collected, findings issued, regulatory obligations tracked. Compliance automation platforms (Vanta, Drata, Sprinto) are sometimes marketed as CaaS but are more accurately described as compliance readiness software: they maintain audit readiness without executing audits. Related: What Compliance-as-a-Service Actually Includes
Continuous auditing An audit methodology in which testing occurs on an ongoing basis, not in periodic cycles. In practice, continuous auditing requires automation: a human team cannot continuously test controls across a full population. The IIA defines continuous auditing as "a method used by auditors to perform audit-related activities on a more continuous or continual basis" (IIA Glossary). Related: The 9 Continuous Auditing Tools Worth Evaluating in 2026 (and Four to Skip)
Continuous controls monitoring (CCM) An automated process that monitors controls in real time or near-real time, generating alerts when a control deviates from its defined parameters. CCM is a management function (monitoring controls the organization operates) while continuous auditing is an audit function (testing whether controls are effective). The distinction matters for governance: CCM alerts go to the control owner; continuous audit findings go to the audit committee. Related: Continuous Auditing vs. Continuous Controls Monitoring
Control effectiveness The assessment of whether a control achieves its intended objective. Control effectiveness testing answers the question: "Did this control actually prevent or detect the risk it was designed to address?" Distinct from control existence (whether the control is documented) and control operation (whether the process described in the documentation is followed). Automated testing addresses control operation and some aspects of effectiveness; human judgment is required to conclude on control effectiveness.
Control testing The procedure by which an auditor evaluates whether a control operates as designed over a defined period. In traditional auditing, control testing involves selecting a sample of items from a population, pulling supporting evidence, evaluating each item against the control objective, and documenting the result. Automated control testing applies the same procedure to the full population.
Co-sourcing An internal audit delivery model in which an organization's in-house audit team works alongside external specialists provided by an audit or professional services firm. The in-house team retains audit program ownership; the co-sourced team provides capacity or specialist skills on specific engagements. Distinct from outsourcing (where the external provider manages the full audit function). Related: Co-Sourcing vs. Outsourcing Internal Audit: Decision Framework and Real Costs
E
Evidence automation The use of software agents to collect audit evidence directly from source systems: ERP records, access control logs, change management tickets, cloud security configurations. Automated evidence collection replaces manual evidence requests (auditors asking system owners to pull and share exports) with direct agent access to authoritative sources. Evidence gathered by agent from source is more defensible than evidence provided by the auditee because it eliminates the chain of custody gap.
Exception flagging The identification by an automated system of items in a population that deviate from defined control parameters. Exception flagging is a candidate list for human review, not a finding. The auditor reviews flagged items, applies judgment, and decides which exceptions constitute control failures. A system that "decides what is a finding" without human confirmation is outside accepted audit standards; a system that surfaces candidates for auditor review is within them.
Explainability (AI systems) The degree to which the logic of an AI system's output can be traced and understood. For audit applications, explainability means a third party can examine how a conclusion was reached: which inputs were used, what logic was applied, what the intermediate results were. The IIA's Artificial Intelligence-Based Auditing guidance recommends that audit AI systems maintain explainable outputs (IIA AI Governance Framework, 2025). The EU AI Act requires it for high-risk AI applications.
F
Finding (audit) A formally documented deviation from a control's design or expected operation, with severity, management response, and remediation timeline. A finding is distinct from an exception (a flagged deviation not yet evaluated) and from an observation (a noted condition that does not rise to a finding). IIA Standards require that a named, accountable auditor conclude on each finding; this conclusion cannot be delegated to an automated system.
Full-population testing Control testing applied to every item in a population, rather than a statistical sample. Full-population testing became economically viable with automated evidence collection: running the same test procedure on 40,000 records costs materially less than running it on a manually selected sample of 25, once the evidence collection and test execution is automated. Full-population testing removes the statistical risk inherent in sampling (a 25-item sample from 40,000 records has a non-trivial risk of missing systematic control failures concentrated outside the sample). Related: Full Population Testing Is Now Cheaper Than Sampling. Stop Sampling.
G
GRC (Governance, Risk, and Compliance) The integrated management discipline covering organizational governance structures, enterprise risk management, and regulatory compliance obligations. GRC platforms (Optro, Diligent, LogicGate, ServiceNow GRC) provide tools to track and report on GRC activities. Agentic GRC extends this by deploying AI agents to execute governance and compliance work, not merely record it.
H
Human-in-the-loop (HITL) A system architecture in which a human review and approval step is required before an AI system's output becomes final. In audit contexts, human-in-the-loop requirements cover: scope and materiality decisions, control effectiveness conclusions, finding severity and rating, and reporting to the audit committee. These remain non-delegable to AI systems under IIA Standards and most regulatory frameworks. A system described as "human-in-the-loop" should specify exactly which decisions require human approval, not just assert that oversight exists.
I
Internal audit automation software See: Audit automation software. The term is used interchangeably with "audit management software" in vendor marketing; the operational distinction is whether the product executes tests or manages the humans who execute tests.
ISO 42001 The international standard for Artificial Intelligence Management Systems (AIMS), published by ISO in December 2023. Provides a framework for organizations that develop, provide, or use AI systems to manage AI-related risks and implement responsible AI governance. For internal auditors, ISO 42001 creates a new audit domain (auditing the AI management system) and a benchmark against which existing AI governance practices can be evaluated. Related: ISO 42001 for Internal Auditors
P
Population (audit) The complete set of items from which an auditor draws a sample or tests. For an access control test, the population might be all user access provisioning events in the past quarter. For a segregation of duties test, the population is all users with conflicting access rights. Defining the population correctly is a judgment call that remains with the human auditor; testing the population is a task that automation handles efficiently.
R
Risk-based audit plan An audit plan that prioritizes auditable entities based on assessed risk level rather than organizational structure or rotation schedule alone. The IIA's International Standards for the Professional Practice of Internal Auditing require risk-based planning (IIA Standard 2000, Managing the Internal Audit Activity). Automation supports risk-based planning by providing continuous monitoring data that informs risk scoring; it does not replace the CAE's judgment in setting audit priorities.
S
Sampling (audit) The practice of selecting a subset of items from a population to draw conclusions about the full population. Attribute sampling and statistical sampling apply defined statistical thresholds to determine sample size and acceptable deviation rates. Sampling exists because full-population testing was historically impractical at human execution speeds. Automated full-population testing removes this constraint for controls where the test logic is deterministic. Sampling remains appropriate for controls requiring physical inspection, interview, or qualitative judgment.
Segregation of duties (SoD) A control principle requiring that no single individual has the ability to both initiate and authorize a transaction, or access both assets and the accounting records for those assets. SoD conflict testing is one of the highest-volume audit automation applications: an agent can test SoD compliance across an entire ERP user population in minutes, replacing a manual review process that typically takes days. An ISACA white paper on SoD automation provides implementation guidance (ISACA Segregation of Duties Framework).
Shadow AI (audit context) AI systems operating within an organization that were not deployed through the organization's formal procurement, governance, or risk management processes. For internal auditors, shadow AI creates two risks: unmonitored AI systems making consequential decisions, and AI systems in scope for regulatory requirements (EU AI Act, NIST AI RMF) that the organization does not know it has. Related: Shadow AI Audit: How Internal Auditors Should Govern AI Agents They Didn't Deploy
W
Workpaper The contemporaneous documentation of an audit procedure: what was tested, the test procedure applied, the population and sample (or confirmation of full-population testing), the evidence collected, the exceptions identified, the human review of exceptions, and the conclusion on control effectiveness. Workpapers are the audit trail the audit committee, external auditors, and regulators rely on to verify that an audit occurred and its conclusions are supported. The IIA Standards require that workpapers be retained for a period sufficient to support audit conclusions and respond to regulatory inquiries (IIA Standards 2330). AI-generated workpapers must meet the same standard as human-generated ones: if the output would not survive external review, it is not a workpaper.
Related Resources
- The 9 Continuous Auditing Tools Worth Evaluating in 2026 (and Four to Skip)
- AI in Internal Audit: Adoption Statistics and Research (2026 Library)
- Internal Audit Sourcing Cost Reference (2026)
- Continuous Controls Monitoring Implementation: Five Steps to Replace Periodic Spot-Checks
- Full Population Testing Is Now Cheaper Than Sampling. Stop Sampling.
- Audit Management Software Tracks Audits. Audit Automation Performs Them.
Related
- Internal Audit Sourcing Cost Reference (2026): In-House vs. Mid-Tier vs. Big 4 vs. AaaS
- AI in Internal Audit: Adoption Statistics and Research (2026 Library)
- Internal Audit Engagement Benchmarks: Cycle Times, Hours, and Rates by Provider Tier (2026)
- Audit-as-a-Service: What It Is, What It Costs, and When It Beats Hiring
- Co-Sourcing vs. Outsourcing Internal Audit: Decision Framework and Real Costs
- What Compliance-as-a-Service Actually Includes: Execution, Not Software
- AI Agents for Internal Audit: How They Work, What They Can't Do Yet
- How AI Is Compressing Internal Audit Fees (and What Buyers Should Do)
- The 9 Continuous Auditing Tools Worth Evaluating in 2026 (and Four to Skip)
- Audit-as-a-Service vs. Internal Audit Outsourcing: They Are Not the Same Thing
- Big 4 Internal Audit Alternatives: Five Models Ranked by Cost and Coverage
- Audit Management Software Tracks Audits. Audit Automation Performs Them.
- ISO 42001 for Internal Auditors: What the AI Management System Standard Means for Your Audit Plan
- Compliance-as-a-Service for Mid-Market Companies: A Buyer's Checklist
- You're Paying Senior Rates for Junior Auditors. Here's the Math.
- Continuous Auditing vs. Continuous Controls Monitoring: Different Tools, Different Jobs
- How to Govern an AI Audit Agent: The Explainability Gap No One Is Solving
- Audit-as-a-Service Pricing Models Explained: Per-Audit, Retainer, and Outcome-Based
- Shadow AI Audit: How Internal Auditors Should Govern AI Agents They Didn't Deploy
- Why We Deliver Audits as a Service, Not Software Licenses
- Full Population Testing Is Now Cheaper Than Sampling. Stop Sampling.
- Agentic GRC, Defined: What Separates an Audit Agent from a Chatbot
- Internal Audit Staffing Models: In-House, Co-Source, Outsource, or Automate
- AI Workflow Automation for Internal Audit: What Production Deployment Looks Like
- Continuous Controls Monitoring Implementation: Five Steps to Replace Periodic Spot-Checks
- When Co-Sourcing Stops Making Sense: Three Signals from 250+ Engagements


