Can audit firms use AI on client working papers?
Yes, when the AI runs inside the firm's perimeter, engagements are segregated, and every procedure writes to a verifiable sealed record.
Yes, audit firms can use AI on client working papers, under three conditions. The AI must run inside the firm's own perimeter, so client data never reaches infrastructure the firm cannot answer for. Each engagement's data must be segregated, so one client's papers never inform work on another. And every AI-assisted procedure must write to a sealed record that the engagement quality reviewer, and if asked the regulator, can verify. Without those conditions, AI on working papers is a confidentiality and quality management exposure rather than an efficiency gain.
The question is pressing in 2026 because adoption is running ahead of governance. Firms of every size use AI for extraction, tie-outs and drafting, while the FRC and international standard setters increasingly ask how AI-assisted procedures are controlled and evidenced. Firms that can answer with a record rather than a policy will be the comfortable ones.
What makes working papers different from ordinary business documents?
Working papers carry professional and contractual confidentiality obligations. They contain the client's ledgers, contracts, board minutes, forecasts and personal data, held under duties that attach to the firm and to individual professionals. They are also the audit's evidence: the record on which the opinion stands. That dual character sets the bar. Anything done to working papers must preserve confidentiality, and anything that contributes to the opinion must itself be evidenced. AI does not relax either requirement; it inherits both.
Is uploading client papers to a cloud AI service a disclosure?
It is a transfer of confidential client information to a third party, and the engagement letter may not cover it. Whether a particular upload amounts to a breach of duty depends on the terms, the service and the data, but the risk analysis is unattractive: the firm is placing a client's ledgers on infrastructure whose staff, jurisdiction and retention behaviour it does not control, on the strength of contractual assurances, and a contractual promise not to retain or train on the data is not a technical guarantee. Public cloud services such as ChatGPT or Microsoft 365 Copilot are designed for general productivity, not for the confidentiality class of a statutory audit file, and that difference is architectural rather than a question of vendor intent.
What does ISQM 1 require when AI enters the audit?
ISQM 1 makes the firm responsible for designing and operating a system of quality management, including the technological resources used in engagements. An AI system used in audit procedures is such a resource: the firm must identify the quality risks it introduces, respond to them, and monitor whether the responses work. In practice that means knowing which model version performed which procedure, on which data, with which review. A firm that cannot answer those questions for its AI usage has a gap in its quality management system, and the gap is discoverable in an inspection.
How should engagement data be segregated?
By boundary, not by label. Each engagement's working papers should be processed in an isolated context, so a model session serving one engagement holds nothing from another, and prompts, outputs and retrieval stores are partitioned per engagement. Segregation also applies over time: a model must not carry one year's confidential findings into the next year's fieldwork through accumulated context. Inside Mickai, our Sovereign Intelligence Operating System, engagement contexts are isolated by design, model weights are versioned and hashed, and no client data trains any model, which makes the segregation demonstrable rather than asserted.
What record should an AI-assisted procedure leave?
A record the reviewer can rely on and the regulator can verify. Every AI action inside Mickai writes to a post-quantum signed audit ledger, sealed with ML-DSA under FIPS 204: the document examined, the extraction or draft produced, the model version and weight hash, the engagement it belongs to, and the identity of the professional who reviewed and accepted the output, hardware-attested and bound to the chain. The record is verifiable offline. An engagement quality reviewer can trace any AI-assisted procedure end to end, and an FRC inspection can be answered with evidence rather than description. The sealing architecture behind this sits within the 104 filed UK patent applications owned by Mickai LTD, which contain 2,340 claims.
Where does AI genuinely help in audit work?
The strong use cases are procedures with high volume and clear review points.
- Extraction: pulling balances, terms and dates from contracts and invoices for the team to verify.
- Tie-outs: checking that figures in the financial statements agree to supporting schedules.
- Drafting: first passes of memos, confirmation requests and summaries from the engagement file.
- Consistency review: reading the file for contradictions between sections before the reviewer does.
In every case the professional signs the judgement. AI accelerates the mechanical layer of the audit; it does not hold the opinion, and the file should show that it did not.
“The audit profession's product is evidence, and the tooling it uses should meet the profession's own bar for evidence.”
How the perimeter, the ledger and the studios fit together is set out at /sovereign-ai, and the film at /film shows the interface in operation.
Frequently asked questions
Is it a breach of confidentiality to put client data into ChatGPT?
It creates a real risk that the firm should assess before any upload, because confidential client information is moving to a third party the engagement letter may not contemplate. Whether a duty is breached depends on the terms and the data involved, but the safer analysis is architectural: if the firm cannot verify where the data went or whether it was retained, it cannot evidence that confidentiality was preserved. Processing inside the firm's own perimeter removes the question.
What does the FRC expect from audit firms using AI?
The FRC has signalled growing interest in how firms control and evidence the technology used in audit procedures, within the quality management responsibilities that ISQM 1 places on the firm. The practical expectation is traceability: which system did what, on which engagement, with what human review. Firms should be able to show an inspector the record of an AI-assisted procedure, not merely a policy stating that AI is used responsibly.
Can AI-generated work go straight into the audit file?
No output should enter the file without professional review, and the file should record that review. AI can produce extractions, tie-outs and drafts, but the auditor's judgement is what the opinion rests on and it cannot be delegated. The defensible pattern is AI output plus documented human acceptance, both captured in a sealed record per engagement.
How do we stop one client's data influencing work for another client?
Isolate engagement contexts by architecture. Each engagement should run in its own partition with its own retrieval stores, and no client data should ever train or fine-tune the models in use. Verify the claim structurally: ask whether the system can run with zero egress and whether engagement isolation is enforced by the design or only by a policy document.
Do smaller audit firms need sovereign AI or is cloud acceptable?
The confidentiality duty does not scale down with firm size; a ten partner firm holds working papers under the same obligations as a national one. What changes is the practical route: a sovereign deployment on a single operator-owned server inside the firm's office is a realistic footprint for a smaller practice. The deciding factor is the data, not the headcount.