MICKAI®ArticlesAudit working papers, client conf…
Article · 31 July 2026

Audit working papers, client confidentiality and AI

Audit firms can use AI on client working papers without breaching confidentiality, but only when the review runs on hardware the firm owns, with nothing leaving the building and a sealed record of every action.

Author
Micky Irons
Published
31 July 2026
Follow Micky Irons
LinkedInX
sovereign-aiaudit-working-papersclient-confidentialitydocument-reviewaudit-quality
Audit working papers, client confidentiality and AI

Audit firms can use AI on client working papers without breaching confidentiality, but only when the review runs on hardware the firm owns, with no document leaving the building and a sealed record of every action taken. Professional codes and engagement terms demand strict confidentiality over working papers, while the Financial Reporting Council keeps pressing UK firms on the quality and completeness of their audit evidence and documentation. AI genuinely helps with the second demand. Most of the AI on offer fails the first, because it works by sending the client's papers to somebody else's computer.

Why is client confidentiality the binding constraint on AI in audit?

Because working papers are among the most sensitive documents a professional firm holds. An audit file contains management accounts, board minutes, contracts, forecasts and tax positions, often commercially or price sensitive. Confidentiality is a fundamental principle of the professional codes that govern accountants, owed as a matter of contract and professional duty, not courtesy. Routing that material through a third party cloud AI service places client information on infrastructure the firm does not control, subject to another organisation's staff, subprocessors, retention policies and jurisdiction, and some engagement letters prohibit exactly that. The constraint is not that AI is unhelpful in audit. It is that the mainstream delivery model of AI is incompatible with the duty firms owe over the papers.

What has the FRC pressed firms on, and why does it matter here?

The Financial Reporting Council inspects audit quality at the largest UK firms and publishes its findings, and documentation discipline is a recurring theme. The regulator has repeatedly pushed firms to improve the consistency and completeness of evidence on file, because the auditing standards require the file to let an experienced auditor understand what was done, what was found and what was concluded. Work that is not evidenced on the file might as well not have happened. That pressure draws firms towards AI, because assembling, cross referencing and tying out evidence is laborious and unforgiving of gaps. The trap is reaching for a tool that solves the evidence problem by creating a confidentiality problem.

Can working papers go through a cloud AI service at all?

For most firms the honest answer is no, or not without a risk acceptance that the general counsel and the ethics partner will find difficult to sign. Once a working paper leaves the firm's estate, the firm cannot fully answer the questions a client or regulator may ask. Who could read it, where was it stored, how long was it retained, was it used to improve someone else's system. Confidentiality obligations follow the information wherever it goes, while the firm's control ends at its own boundary. The defensible position keeps the boundary and the processing in the same place.

What does sovereign working paper review actually look like?

It looks like the review a meticulous junior would perform if that junior never tired, never skimmed and never lost the thread, running on servers the firm owns. Our document review capability runs on premise and air gapped, and no prompt, schedule or working paper ever leaves the estate. On the file itself, the system works the way engagement teams already think:

  • Reads working paper packages and the supporting evidence behind them, page by page and without fatigue
  • Cross references figures, dates, names and references across lead schedules, confirmations, contracts and underlying records
  • Performs first pass tie outs between the schedules, the supporting documents and the draft financial statements
  • Flags inconsistencies, missing support and unresolved cross references, and holds each one for a person to disposition
  • Drafts review notes and evidence summaries for the engagement team to accept, amend or reject
  • Seals every review step and every disposition into the Open Audit Record before the action runs

How does a sealed record help a firm answer its regulator?

Because it converts the firm's own quality story from recollection into evidence. The Open Audit Record is sealed before each action executes, cryptographically signed with post quantum algorithms, tamper evident and verifiable offline years later. It shows what was reviewed, when, what the machine flagged, and how a named person dispositioned each finding. A sealed record produces evidence about the audit itself as a byproduct of doing the work.

Machines are patient enough to check every cross reference on a file. People keep the judgement, the disposition and the signature. That division of labour is the entire design.

Mickai

Where does the human auditor stay in charge?

Everywhere it matters. The system never concludes on the sufficiency of audit evidence, never signs anything and never takes a consequential action without a person's clearance. Voice biometric gating and a hardware held root of trust mean clearance genuinely comes from the individual it claims to come from. Professional scepticism, materiality judgements and the audit opinion remain exactly where the standards put them, with the auditor. This is what our platform does on the firm's own hardware, accepted by the firm's own people. It is not a suggestion that a machine can audit.

The direction for the profession seems clear to us. Regulators will keep raising the bar on evidence, clients will keep tightening confidentiality terms, and firms will not be permitted to trade one duty against the other. The firms that resolve that tension will bring the machine to the papers rather than send the papers to the machine, on hardware they own, with a record they can prove. In our view that is the only shape of audit technology that survives contact with both the client and the regulator.

Frequently asked questions

Does using AI on client working papers breach confidentiality?

Not inherently. The risk comes from where the processing happens. Review that runs on hardware the firm owns, inside its own security boundary, with no data sent to any third party, is materially the same as any other internal software the firm operates. The exposure arises when working papers leave for services the firm does not control.

Can AI sign off audit work?

No, and it should not. Auditing standards place judgement and conclusions with the auditor. The system performs first pass reading, cross referencing and drafting, then holds its findings for the engagement team. Every consequential step waits for a person's clearance, and the sign off is always human.

What happens when the system finds an inconsistency?

It holds the item. The anomaly is presented to the reviewer with the documents and the specific mismatch, the person decides the disposition, and both are sealed into the Open Audit Record. Nothing is silently corrected and nothing proceeds without clearance.

What is the Open Audit Record?

It is our tamper evident audit trail. Every review step and action is sealed into a cryptographically signed record before the action runs, using post quantum signatures, and the record can be verified offline years later. It shows what was proposed, what policy permitted it and who cleared it, the difference between evidence and recollection.

Does this replace the firm's audit methodology?

No. The methodology, the materiality judgements and the professional scepticism remain the firm's. Our capability does the patient reading and cross referencing underneath, so the engagement team spends its time on judgement rather than on tying documents out by hand.

What is MICKAI?

MICKAI is a Sovereign Intelligence Operating System, a SIOS, that runs entirely on the customer's own hardware, on premise and air gapped. Multiple AI models work in cooperative consensus, consequential actions wait for a person's clearance, and every action is sealed into the Open Audit Record, a cryptographically signed, post quantum, tamper evident record that can be verified offline. MICKAI comprises 87 studios, with ten production ready at launch and 77 in development, and the architecture is protected by 104 filed UK patent applications across 2,340 claims, filed rather than granted.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/audit-working-papers-confidentiality-ai. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles