LIVE · cybersecurity feed
Live wire
ai

Most chief audit executives can’t tell you what AI is worth yet

Auditors are using AI in their daily work, and their departments have mostly left them to figure it out alone. 93% of audit leaders and auditors report some level of AI use, while 15% say their department has deployed formal use cases and runs them routinely in audits, according to Gartner. Chief audit executives (CAE) have to defend that arrangement to stakeholders, and most of them cannot say wh

zeroday.news ·

A recent survey indicates that while artificial intelligence (AI) tools are widely adopted within audit departments, most chief audit executives (CAEs) are not yet measuring the value derived from these technologies. The survey, conducted in May, polled 142 CAEs and found that 54% have not begun to quantify the benefits of AI in their audit functions.

The findings highlight a significant gap between the widespread use of AI by auditors and the strategic oversight of these tools by department leaders. According to the survey, 93% of audit leaders and auditors report some level of AI use in their daily work. However, only 15% state that their department has deployed formal AI use cases that are routinely integrated into audits.

Only 38% of the 161 CAEs surveyed in May have an AI strategy in place, with most of these strategies being incorporated into the overall departmental strategy rather than existing as standalone plans for audit. Another 39% of CAEs are currently developing an AI strategy, suggesting a potential shift towards more formalized approaches.

When it comes to measuring value, a mere 7% of CAEs link AI use to cost metrics, such as reductions in external spending or avoided hiring. This indicates that the financial impact of AI on audit operations is largely unquantified by most departments.

The most common applications of AI in audit work involve drafting and planning. Sixty percent of 743 respondents use AI for engagement preplanning activities, including research and brainstorming potential risks. The same percentage also utilizes AI to draft audit issues, ratings, or reports. Smaller groups apply AI to develop planning deliverables like risk and control matrices, which map risks to their corresponding controls, and to review drafts before finalization.

Audit testing, a critical phase where auditors verify control effectiveness and which directly influences report conclusions, sees less AI adoption, with only 30% of respondents using it for this purpose. The potential for errors like hallucinations or omissions in this stage carries higher risks than in drafting, necessitating rigorous validation of AI-generated outputs and thorough documentation of how conclusions are reached, especially for regulatory or external auditor scrutiny.

The primary obstacles to effective AI integration are related to people and processes, rather than technology itself. Forty-eight percent of audit leaders and auditors cited unclear expectations for AI tool use as the most significant barrier. This was followed by variations in how individual auditors utilize the tools. Issues concerning technology, such as model selection and data access, ranked lower than human and process-related challenges.

The lack of standardized usage across individual auditors leads to inconsistent output and hinders the ability to compare performance across different engagements. To address this, Gartner suggests implementing structured use cases for high-value workflows, a practice currently being piloted by 12% of respondents.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s