Audit, Sustainability and AI - Trust Redefined

Today, the world is evolving rapidly, and we, as trust providers, must evolve with it. Some of the changes we are witnessing today include the advent of Artificial Intelligence (AI) and the increasing relevance of sustainability. With these thematic changes growing day by day, the business world will be certain to adopt and commit to AI and Sustainability, respectively. For any change to be successful, trust is paramount. We as trust providers for this society will have to understand the ebbs and flows of these changes and ensure that we are able to act as a bridge between the businesses and the stakeholders. In some sense we must become the common language between businesses and stakeholders.

Introduction

As we move towards the goal of “Viksit Bharat”, the strategic imperatives for making India a “Developed Nation” are Sustainability and Artificial Intelligence. These are the same priorities that are making entrepreneurs and CXOs “Rethink” and “Reimagine” how to conduct businesses.

So, how will this impact our world – The Audit world? Auditing is a profession that follows business. The evolution of auditing over the last few decades is a testament to the fact that all the changes in the business world equally impact on us in the form of three major questions:

  1. How do we audit?
  2. What do we audit?
  3. What do we report?

In this changing world where businesses are “Rethinking” and “Reimagining”, let’s see how trust will be “Redefined”.

What is changing in audit?

Now let us try to answer the three questions that we set out to answer.

  1. 1) How do we audit?
  2. 2) What do we audit?
  3. 3) What should we report?

How do we audit?

In the traditional sense of auditing, we execute engagements having technology as an adjacent. As we see the world embracing the applications of Artificial Intelligence, it raises the question: should we revisit how we are going to deliver the audit? What will “Auditing” look like in the future?

Let us take a few examples and examine how these areas could potentially change.

AreaCurrent methodReimagined approach using AI
Risk assessment

Risk assessment is one of the major requirements of Auditing, where we

  • understand the business,
  • understand the sector,
  • compare past results with current performance,
  • perform management discussions and board minutes reviews, etc.,

Using the outcomes of the above, we identify which areas are prone to higher risk and design the audit programme accordingly.

  1. An AI-integrated audit tool could contain industry-wide risks that are predefined and updated based on market and economic changes.
  2. Using the summary of management discussions, past results, board minutes and current financial statements, AI will be able to make connections and identify the indicative risk factors.

Based on the above, we can narrow down the potential risks with more precision and design the audit programme accordingly.

Sample verificationEngagement teams compute “Materiality” and based on the account balances, the engagement teams identify a subset of the total population for testing. This is what we call “Sampling”. The outcome of such samples will be projected to the overall population to arrive at a conclusion.

As technology progresses, companies will reach a situation where all client documents are maintained digitally. As we grow nearer to that scenario, the concept of “Sampling” might become more and more redundant.

The future tools will have access to the entire population and audit the same by reviewing the supporting documents.

Eg: Think of a client where all the Purchase Orders, Invoices and Goods Receipt Notes (GRNs) are uploaded into their accounting system, and we as auditors have access to such a system. If an audit tool can scan all purchase transactions, map the relevant documents, and generate exceptions or insights, the utility of sampling as a methodology may reduce significantly.

There might be new auditing standards updated to align with new techniques.

Income taxes

The management team provides:

  1. Tax computation – Current and deferred
  2. Maintains a year-on-year assessment summary
  3. Provides TDS and advance tax receipts and challans, etc.

We then go through all the computations, review the assessment orders, verify the challans/receipts and provide their observations.

What might the future audit of taxes look like?

  1. There may be an API for the companies to directly gather all the data with respect to assessment orders, challans, notices, etc., where the data will flow from the tax website, which can be imported into the audit tool and processed in minutes.
  2. Tax computations will be automated, and the audit will also follow suit. We will have access to the repositories of tax that are built into the audit tool, which will provide comments on positions taken by the company on various matters.
Current audit methods and how AI could reimagine them

The examples above may look far-fetched now but imagine a scenario where the future audit tool is based on a Large Language Model trained in accounting standards, auditing standards, tax laws and other regulations. Such a tool is not just capable of analysing some of the data but can provide insights from the entire data set of a company.

In such scenarios, the role of the auditor is to look at the outputs and come to appropriate conclusions. Professional scepticism and judgement will take a new shape as the auditor considers the outputs from such tools.

The rapid pace of technological advancement poses challenges for regulatory frameworks to keep up with the integration and governance of AI technologies. This regulatory uncertainty creates an onus on businesses and auditors to be agile and proactive in adopting AI and managing its outcomes.

A word of caution

The new ICAI Code of Ethics (effective April 01, 2026)5 requires chartered accountants to apply professional judgement when using the output of technology, actively evaluating the appropriateness of the inputs to the technology, including data. To maintain professional scepticism, accountants must guard against automation bias by questioning whether the automated output is reliable or fit for purpose, especially when dealing with contradictory information or unsubstantiated facts.

Some of the factors to be considered by the professionals intending to use the output of technology (as indicated in the code of ethics) are as follows:

  • The nature of the activity to be performed by technology.
  • The expected use of, or extent of reliance on, the output of the technology.
  • Whether the accountant has the ability or has access to an expert with the ability to understand, use and explain the technology and its appropriateness for the purpose intended.
  • Whether the technology used has been appropriately tested and evaluated for the purpose intended.
  • Prior experience with technology and whether its use for specific purposes is generally accepted.
  • The employing organisation’s oversight of the design, development, implementation, operation, maintenance, monitoring, updating or upgrading of the technology.
  • The controls relating to the use of technology, including procedures for authorising user access to the technology and overseeing such use.
  • The appropriateness of the inputs to the technology, including data and any related decisions, and decisions made by individuals in the course of using the technology.

Hence, it should be noted that while AI/technology can do a lot of heavy work and improve efficiency, the final responsibility for the audit opinion will always remain with the chartered accountant. We must document how we used the tool and apply our own judgement and checks.

It should be noted that while AI/technology can do a lot of heavy work and improve efficiency, the final responsibility for the audit opinion will always remain with the chartered accountant.

What do we audit?

As we look at the past decades, the audit world has continuously adapted to the changes in the business environment. One such change in the business world is the incorporation of “Sustainability” as a business risk.

Let us try to analyse this with an example of “Impairment of Property, Plant and Equipment (PPE) in a manufacturing unit”:

What are the potential questions that we ask when assessing the “Impairment of PPE”?

  • What is the value of the assets in the “Cash Generating Unit (CGU)”?
  • Is the CGU generating sufficient cash to cover the value of assets?
  • Is there any fall in prices of the products?
  • Any changes to the regulatory environment? Etc.,

Are these questions sufficient?

Taking this example forward, the management has made a public commitment in its “Sustainability report” that they will invest in new technologies to ensure that the products they manufacture are more sustainable and gradually replace the existing machinery.

In the scenario, all the questions above may take us to the conclusion that there are no impairment indicators. But when we bring the knowledge of organisation’s commitment to sustainability into the mix, the outcomes may look significantly different. We may be required to have further conversations with the clients on their plans for how this will be dealt with from a financial reporting perspective.

Hence, it becomes important that while planning the audits, the engagement teams should be more vigilant to address the newer risks and design the audit procedures to mitigate the same.

Some of the newer risks might be:

  • The impact of climate change on business continuity and asset impairment
  • Risks of regulatory non-compliance with climate-related laws
  • The threat of greenwashing and inconsistencies between sustainability and financial reporting
  • Disruptions from tariffs, sanctions, and supply chain vulnerabilities. etc.,

What do we report?

If there is a potential change in how we audit and what we audit, it would be safe to say that there will be an impact on “What we report”.

The past is often a useful starting point to understand how the future may evolve. If we look at how the reporting has evolved over a period, we can understand that our reporting has embraced the changes of the macro environment. Some of the examples are:

  • Reporting on internal financial controls on financial reporting6;
  • Disclosure of key audit matters for listed companies7;
  • Specific reporting aspects like pending litigations, long-term contracts, regulatory compliance, audit trails, and backup requirements for books of accounts8.

All these developments reflect the evolving requirements of the new world order. Now, if the new world order includes “Sustainability” and “Artificial Intelligence”, the Audit reporting will also follow suit.

As we know today, SEBI has introduced BRSR reporting and mandated assurance/assessment for BRSR Core indicators3 through a glide path. There is little alignment between the financial statements and BRSR reporting and the respective assurances. We can anticipate in the future that there will be a linkage established between these reports which can provide a comprehensive understanding of financial and sustainability reporting.

Also, with the advent of Artificial intelligence, it may not be surprising if the reporting moves from a singular outcome based “True and Fair” reporting to a more qualitative reporting or grading-based reporting.

Sounds unlikely? Let’s ask ourselves, - “A company which has highly sophisticated AI-integrated systems and controls vis-à-vis a company whose controls are completely manual” - Can both these companies be assessed similarly? What is the differentiation? Can we add more value if we can provide a different reporting outcome which can help the users to make better judgements on criteria like – Processes & Controls, Cybersecurity, quality of financial reporting, sustainability etc.? Can our audit report move from being called as a “post-mortem report” to a more “futuristic report”?

These are the potential questions that we as a profession should think about NOW. India, as a growing market, will attract a lot more investments from all over the world. Can we offer them something more in terms of Trust?

An indicative future

The International Auditing and Assurance Standards Board (“IAASB”) has approved and issued International Standard on Sustainability Assurance (ISSA) 5000, General Requirements for Sustainability Assurance Engagements and ICAI’s own standard SSA 5000 is aligned with it.

This standard addresses the requirements covering the end-to-end process of a sustainability assurance engagement.

Some of the excerpts are as follows:

  • This standard introduced the requirement of reporting obligations on other information, i.e., sustainability information not subject to assurance, historical financial information, any other non-sustainability information or non-historical financial information.
  • If the practitioner identifies that there is a material inconsistency between the financial statements information and the sustainability information, the practitioner is required to communicate the matter to the entity’s financial statements auditor, unless restricted by law, regulation, or professional requirements.
  • Additionally, it explains that when there are sustainability matters that may also relate to matters disclosed in the entity’s financial statements, communication between the sustainability assurance practitioner and the auditor of the financial statements on topics of mutual interest relevant to both engagements may be useful at the planning stage of the assurance engagement.
  • Standard acknowledges that there may be circumstances where the practitioner in a sustainability assurance engagement may intend to obtain evidence from work performed by the financial statement’s auditor. In these circumstances, the requirements addressing using the work of another practitioner apply, including communication, to the extent necessary in the circumstances, about the findings from the financial statements’ auditor’s work.

The future of assurance professionals is clearly heading towards greater collaboration and integration between sustainability and financial assurance experts.

What does it mean for us?

As a profession we should consider the following:

  1. Creating a sandbox for developing comprehensive AI-integrated audit tools. This will elevate the profession as a whole.
  2. Firms can start with small, controlled pilot projects using AI tools on selected audits, note down what works and what doesn’t, and share learnings.
  3. Professionals can refer to the work already done by the AI Committee of ICAI (Use Cases for CAs, hackathon materials, published books, etc.).
  4. Revisit our auditing standards in light of changing micro and macro environments. For example: Risk assessment, audit methodology, reporting, etc.
  5. Upskilling ourselves to become more fluent in technology. We should not be mere users of technology, but as a profession we should have the foresight to integrate the changes in technological spheres into our profession.
  6. As business risks cut across various aspects like technology, sustainability, etc., we must be more collaborative to ensure that we have an in-depth understanding of these aspects and their impact on financial statements.

Having said that, ICAI has already been very proactive in exploring various use cases for the profession. It is visible from the fact that there is an AI committee of ICAI that has already published use cases for CAs, hackathon materials, published books, etc.

Also, ICAI has been instrumental in dispensing the knowledge of AI to professionals by setting up webinars, seminars, summits, etc. One such recent event is the AI Innovation Summit held on 26-27 June 2026 in New Delhi.

Therefore, some of the key takeaways for us, as professionals, are as follows:

  • We should be open to learning new concepts like Sustainability or embrace changes in technology.
  • Assess the risks associated with these changes from both micro and macro perspectives.
  • Create our own opportunities by building new-age tools.
  • Be aligned with the latest reporting requirements.
  • Be willing to work with people across professions.

Conclusion

The convergence of trust, sustainability, and artificial intelligence is redefining the role of auditors and professionals. By embracing change, investing in new skills, and proactively adapting to global trends, the profession can continue to deliver value and foster trust in an increasingly complex world.

Author may be reached at eboard@icai.in

Rack the Brain

Five riddles from the world of professional ethics and assurance. Can you name each one?

  1. I discover a possible breach of law while performing my professional role;
    What ethical framework tells me how to respond rather than simply remain silent as my goal?
  2. The figures may balance, the explanations may sound right;
    But I still ask, “Where is the evidence?” before I sign.
  3. I enter with no pen, yet influence every line I write;
    When what I expect shapes what I see, what am I hiding from sight?
  4. When truth sits behind a veil, the Code asks, “Must it be shown?”;
    I weigh duty, relevance and confidentiality before the fact is known.
  5. Carbon claims may be polished, but evidence cannot be painted green;
    When assurance tests the story behind the numbers, what am I called between?
Answers to the September 2026 puzzle
  1. Dividend
  2. Arbitrage
  3. Phishing
  4. Real Estate Investment Trust (REIT)
  5. Advanced Tax

References

  1. UNFCCC — Paris Agreement text: https://unfccc.int/sites/default/files/english_paris_agreement.pdf ↩
  2. Prime Minister’s address at COP26 (India’s pledge statement): National Statement by PM at COP26 Summit in Glasgow | Prime Minister of India ↩
  3. SEBI circular / BRSR guidance (format, applicability and timelines) - SEBI/HO/CFD/CFD-SEC-2/P/CIR/2023/122: SEBI | BRSR Core - Framework for assurance and ESG disclosures for value chain ↩
  4. RBI — pages/reports touching on sustainable finance and climate risk (general entry point): Master Directions - Reserve Bank of India ↩
  5. CODE OF ETHICS (Volume II) ↩
  6. Companies Act, 2013 — Section 143 (audit duties and reporting) and related rules (Ministry of Corporate Affairs / bare act): Report on the Internal Financial Controls with reference to Financial Statements under clause (i) of sub-section 3 of Section 143 of the Act ↩
  7. ISA 701 — Communicating Key Audit Matters in the Independent Auditor’s Report: https://resource.cdn.icai.org/44095aasb33841-sa701.pdf ↩
  8. Rule 11 of the Companies (Audit and Auditors) Rules, 2014 ↩

The Chartered Accountant, October 2026, pages 106–111 (566–571). www.icai.org