Report on internal controls compliance: what to automate and what to keep human

Software and AI can already gather control evidence, fill auditor request lists, draft cycle memos and track remediation. A person still has to judge whether a deficiency is significant, sign the assertion, and decide what regulators and investors are told. None of it works until evidence is complete and traceable.

Where software already carries the load

Evidence gathering is the easiest win. Automated controls leave records behind: approval logs from the invoice workflow, match exceptions where an invoice failed to agree with its order and receiving report, user access listings, funds control blocks that stopped a posting from exceeding its budget. A tool can pull these on a schedule and file them against the right control.

The auditor's request list is another good candidate. Each "prepared by client" item can be mapped to a folder or system query. Software then shows what is ready, what is late and who owes it. That alone removes most of the chasing.

Sample selection and assembly also automate well. Once the population is defined, a tool can draw the sample and attach the supporting documents for each item.

AI is useful for first drafts of cycle memos and walkthrough narratives. Fed with system configuration, workflow rules and last year's memo, it produces a readable description that a control owner can correct. It can also turn test results into a status view for internal management, grouped by process or by owner.

Remediation tracking belongs in software too. Findings, agreed actions, owners and retest results should live in one place, linked to the control they affect.

Where a person has to decide

Classifying a failure is judgment. Whether an exception is an isolated slip, a deficiency, a significant deficiency or a material weakness depends on compensating controls, the size of what could go wrong and how the failure was found. No model should make that call alone.

Signing the management assertion is personal accountability. The same applies to the controls section of an annual report, a certificate to lenders or a filing with a regulator or exchange. The words chosen there carry legal weight.

Conversations with external auditors stay human. When they propose an adjustment or disagree with a severity rating, someone has to argue the position, concede where it is weak and agree the record.

Third parties ask for different things. A customer's due diligence questionnaire, an insurer's renewal form and a lender's covenant certificate each need a decision about what to disclose and how much. Software can prefill answers. A person decides what goes out.

What has to be true about the data first

The control library must be the single source. Every control needs an identifier, an owner, a frequency, the risk it addresses and the place its evidence lives. If the library exists in a spreadsheet that differs from the audit file, automation will report on the wrong set.

Preparer and reviewer identities, with dates, must be captured inside the system. A review recorded in an email thread cannot be pulled automatically and is hard to defend.

Reports used as populations need proof of completeness. Auditors will ask how anyone knows the listing of payments or journal entries contains everything. Without parameters and record totals that reconcile to the ledger, an automated sample means little.

Names must match across systems. The control referenced in the request list, the test workpaper and the remediation log should carry the same identifier.

Retention matters. Logs and approvals have to survive until the audit closes, and system upgrades often purge them quietly.

Questions to ask the people who run it

  • Which controls are performed exactly as the memo says, and which have drifted?
  • When a reviewer signs off, what do they actually look at?
  • Which evidence is rebuilt after the fact because the original was never saved?
  • Where do auditor requests arrive, and who decides who answers them?
  • Which reports are exported, filtered by hand and then used as a population?
  • What happens when a funds control or payment block fires? Who overrides it, and is that recorded?
  • Which third parties ask for controls information, and is the same answer given to each of them?
  • How does management hear about a failed test today, and how late?

The answers usually reveal workarounds that no document mentions. Those are the steps most likely to break once automated.

Where automation tends to go wrong

An AI drafted memo will describe the process as configured, not as performed. If nobody checks it against the floor, the error becomes official.

Auditors may also want to test the tool. A system that selects samples or classifies exceptions becomes part of the control environment, so its logic, access and change history need the same discipline as any other key report.

Dashboards for management can hide judgment. A green status that only means "evidence uploaded" tells a controller nothing about whether the control worked.

Sources

APQC's Process Classification Framework® (PCF) is an open standard developed by APQC, a nonprofit that promotes benchmarking and best practices worldwide. To download the full PCF or to view definitions and measures, please visit www.apqc.org/pcf.