Skip to main content
CAAIforCAs

Using AI for Audit Planning and Risk Assessment

P

CA Prateek Agarwal ·

AI planning tools speed up two things in audit planning — materiality calculation once you have chosen the benchmark, and risk-flagging from financial-data patterns — while the auditor's understanding of the entity, its environment, and its control culture under SA 315 has to come from the auditor's own enquiry. This article stays specifically at the planning and risk-assessment stage, before any fieldwork or sampling begins; for the testing and sampling stage that follows, see how to use AI for audit sampling and data analysis.

Why planning is where audit quality is actually decided

Audit quality is disproportionately determined at the planning stage, not during fieldwork. A poorly scoped risk assessment means fieldwork tests the wrong things thoroughly and the right things not at all — no amount of AI-assisted sampling later fixes a planning miss. That makes planning a high-stakes place to introduce AI carefully: get the tool's role right here, and everything downstream benefits; get it wrong, and you have automated a flawed starting point.

Engagement acceptance and continuance

Before planning begins, most firms run an acceptance or continuance check — independence, competence, integrity of management, and fee adequacy. AI adds real value here in one narrow way: pulling together public-domain background on a prospective client (director details, related entities, litigation history where publicly available) that would otherwise take a junior an afternoon of manual searching. It adds no value, and carries real risk, if used to make the actual acceptance decision — that decision weighs firm-specific risk appetite and relationship factors no external tool has visibility into.

Materiality: what AI can compute vs what the auditor must choose

Materiality-setting has two distinct parts, and only one belongs to a tool.

The mechanical part: once you have selected a benchmark (revenue, total assets, profit before tax) and a percentage within the range typically used for that benchmark, calculating the resulting materiality figure and the performance materiality is arithmetic. AI does this instantly and consistently, and can flag when a chosen percentage looks unusually high or low against the entity's own historical volatility.

The judgement part: choosing which benchmark best reflects what users of the financial statements care about — profit-based for a business focused on results, asset-based for an asset-heavy or early-stage entity — and choosing where in the acceptable range to set the percentage given the entity's risk profile, is not something a tool should decide. If a materiality memo reads like a template with only the client name changed, that is a sign the judgement step was skipped, whether AI was involved or not.

SA 315 risk assessment: where AI genuinely widens the net

SA 315 requires identifying and assessing the risks of material misstatement through understanding the entity, its environment, and its internal control. AI contributes most clearly at the analytical layer of this requirement:

  • Ratio and trend analysis across multiple years, not just current vs prior year, surfacing drift that a two-year comparison misses — a margin that has been eroding steadily for four years reads very differently from one that dropped once.
  • Peer or industry benchmarking where data is available, flagging where the entity's ratios sit outside a typical range for its sector.
  • Account-level risk flagging from the trial balance — unusual account combinations, new general ledger accounts opened mid-year, or balances that moved sharply without an obvious operational driver.
  • Assertion-level risk mapping, turning flagged accounts into a structured draft risk matrix (account, assertion, inherent risk, planned response) rather than a blank template the team fills from memory.

Betel Audit Platform structures exactly this kind of centralised planning and risk workflow, turning scattered planning inputs into a working risk matrix the team can then edit. Finspectors similarly automates a first-pass risk assessment as part of its broader workpaper-generation workflow, feeding directly into the evidence and testing stages that follow.

What SA 315 still requires from the auditor directly

The standard is explicit that understanding the entity includes its industry, regulatory environment, business model, and internal control — much of which is qualitative and relationship-based, not derivable from a trial balance:

  • Discussions with management and those charged with governance about business developments, new contracts, or upcoming changes that have not yet shown up in the numbers.
  • Observation of the control environment — whether segregation of duties is real in practice or only on an org chart, whether management actually reviews exception reports or just receives them.
  • Industry and regulatory knowledge — a sector-specific risk (say, a change in an RBI or SEBI requirement affecting the client) that a general-purpose AI tool trained on broad financial patterns has no reason to flag.
  • Fraud risk discussion among the engagement team, which SA 240 requires as a team exercise involving professional scepticism and brainstorming — not something a tool can conduct on the team's behalf.

A risk assessment built entirely from AI-flagged financial-data patterns, with no qualitative enquiry layered on top, will systematically miss the risks that come from how a business is actually run rather than what its numbers show.

Building a hybrid planning workflow

A workflow that uses AI well typically runs in this order:

  1. AI-driven analytics first — ratio movement, peer comparison, account-level flags — generated before the team's planning meeting, so everyone walks in with the same data-driven starting point instead of a blank page.
  2. Team risk-assessment discussion, informed by the AI output but not bound by it — this is where the fraud-risk brainstorm and qualitative enquiry happen, and where flagged items get contextualised against what the team actually knows about the client.
  3. Draft risk matrix generated or updated from the discussion, capturing both the AI-flagged quantitative risks and the qualitative risks the team identified independently.
  4. Materiality set and documented, with the benchmark and percentage choice explained in the auditor's own words, not left as an unexplained tool output.
  5. Audit strategy and plan finalised, allocating fieldwork effort toward the higher-risk areas identified through both channels — not just the areas the software happened to flag.

This sequencing matters: running the AI analytics before the team discussion means it informs the conversation rather than replacing it, and running the qualitative enquiry regardless of what the tool flagged protects against the tool's blind spots.

The planning-stage habit worth building

The single most useful discipline is documenting, for every AI-flagged risk item, whether the team's own enquiry confirmed, modified, or dismissed it — and why. A file that shows this reasoning demonstrates real engagement with the tool's output; a file that just attaches the tool's report with no team commentary looks, on review, exactly like what it is — an unread report sitting in the plan. For the fieldwork and testing methods that follow from a well-built risk assessment, continue to how to use AI for audit sampling and data analysis and browse the audit category for planning-focused tools.

Frequently asked questions

Can AI set audit materiality for me?

No. AI can calculate materiality using standard benchmarks (percentage of revenue, assets, or profit before tax) once you tell it which benchmark and percentage to apply, but choosing the benchmark and the percentage is a judgement about the entity and its users that the auditor makes, not the tool.

Does AI-based risk assessment satisfy SA 315 on its own?

No. SA 315 requires the auditor to obtain an understanding of the entity, its environment, and its internal control, and to use that understanding to identify and assess risks of material misstatement. AI can analyse financial data to surface candidate risk areas, but the understanding of the business itself has to come from the auditor's own enquiry and observation.

Is AI-generated risk assessment more reliable than a manual one?

It is more consistent and faster at flagging financial-data-based risk signals like unusual ratio movement, but it has no access to qualitative signals — management's tone, industry gossip, a lender's informal comment — that often drive the highest-risk findings. Treat it as a wider net for the quantitative layer, not a replacement for the qualitative one.

Should every audit engagement use AI for planning, regardless of size?

Not necessarily. For a very small entity with simple, stable operations, a manual planning memo may take less time than configuring a tool. AI planning support earns its keep on engagements with enough data volume and complexity that pattern-based risk flagging genuinely surfaces things a manual review would take much longer to find.

Primary sources

None of this moves where audit responsibility sits. Documentation, sampling judgement and the opinion remain the engagement partner's, governed by:

  • ICAI — Standards on Auditing, guidance notes and announcements
  • Income Tax Department — tax-audit provisions, Form 3CA/3CB/3CD and utilities
  • CBIC-GST — GST provisions that surface during fieldwork

Related software