The reference
What is modern auditing?
Modern auditing is internal audit practised as a continuous, instrumented process: controls, testing and evidence live in systems that run all year, software agents perform the mechanical work, and auditors spend their judgment on scoping, exceptions and conclusions rather than on collecting screenshots.
Independence, objectivity and professional skepticism are unchanged. What changes is where the work happens, and who does the parts that were never judgment in the first place.
This site is the reference for that shift — the definition, amaturity model you can score yourself against, aglossary of the vocabulary, and alibrary of free working artifacts. Everything is ungated, and every number on the site is counted from artifacts we publish and maintain rather than estimated.
The five shifts
"Modern" is doing real work in that phrase, and it is not a synonym for "with AI in it". Five specific things change. A function that has done none of them has bought software; a function that has done all five has changed the job.
| From | To | What actually changes | |
|---|---|---|---|
| 01 | Sampling | Population | A sample of 25 was a concession to how long it took a person to open 25 files. When testing is executed by software against the system of record, the natural sample size is every item. The interesting question stops being “did we pick the right 25?” and becomes “what do we do with the 4,000 that failed?” |
| 02 | Requesting evidence | Reading systems | The PBC list exists because auditors could not reach the systems themselves. Given read access and a stable interface, evidence is pulled rather than requested — which removes the single largest source of audit delay and, incidentally, the largest source of friction with the business. |
| 03 | Documents | Structured records | A workpaper stored as a document is a screenshot of a conclusion. A workpaper stored as a structured record — control, assertion, population, exceptions, conclusion, approver — can be queried, rolled up, re-run next quarter, and handed to an agent. Most audit software digitised the filing cabinet without ever doing this. |
| 04 | Annual | Continuous | The annual cycle is an artifact of effort, not of risk. Once a test is a repeatable definition rather than a person's week, the marginal cost of running it again approaches zero, and the reporting cadence becomes a policy choice instead of a capacity limit. |
| 05 | Doing the work | Supervising it | This is the shift that unsettles people, and it should be stated precisely: agents execute, humans approve. Scoping, risk judgment, the decision that something is a deficiency, and the conclusion signed at the end remain human and remain accountable. What moves is the fetching, tying out, formatting and chasing — none of which was ever professional judgment. |
What modern auditing is not
The term is being used to sell things, so it is worth being blunt about the four most common substitutions.
It is not "AI writes the audit report"
A report is a conclusion, and a conclusion is an accountable human act. An agent that drafts the sections around a conclusion is useful; an agent that reaches the conclusion has produced an unsigned opinion, which is worth nothing to a regulator and less than nothing to an audit committee.
It is not buying a GRC platform
The industry has spent two decades installing platforms that were configured once, never adopted, and renewed anyway. Software that nobody opens is not modernisation; it is a subscription. The test is whether last quarter's testing actually ran in it.
It is not continuous monitoring, rebranded
This distinction matters more than any other on this page, and most vendor copy erases it. Continuous monitoring is amanagement activity — the first and second lines watching their own controls. Auditing is assurance over that activity. If internal audit builds and runs the monitoring, internal audit is now auditing its own work, and the independence that made the function worth having is gone. Modern auditing makes assurance continuous; it does not make auditors the operators.
It is not the end of the auditor
It is the end of the parts of the job that no one defended: chasing evidence, reformatting spreadsheets, re-performing last year's tie-out. What is left is the part the profession has always claimed was the point.
The map, in numbers
Most writing about audit modernisation is an opinion with a call to action attached. The figures below are counts, taken on 2026-07-29, from two artifacts we maintain in public: an enterprise compliance map and an open library of workflow templates. You can open both and check them.
- Frameworks mapped
- 22
- Framework controls
- 904
- Unified controls
- 280
- Risks
- 167
- Workflow templates
- 138
- Defined steps
- 1,502
The ratio worth sitting with is the third one. Those 904framework controls collapse into 280 unified controls — roughly a 3.2-to-1 reduction. That is the arithmetic behind "test once, satisfy many", and it is the single largest available saving in most compliance programmes. It is also why framework sprawl is survivable at all.
| Framework | Controls | Templates touching it |
|---|---|---|
| NIST SP 800-53 Rev 5 | 295 | 70 |
| NIST Cybersecurity Framework 2.0 | 106 | 34 |
| ISO/IEC 27001:2022 Annex A | 93 | 43 |
| IIA 2024 Global Internal Audit Standards | 68 | 13 |
| AICPA SOC 2 Trust Services Criteria | 61 | 21 |
| COBIT 2019 | 40 | 13 |
| ISO/IEC 42001:2023 (AI management) | 38 | 6 |
| ISO 31000:2018 | 22 | 9 |
| SOX 404 / PCAOB AS 2201 | 21 | 19 |
| COSO ERM (2017) | 20 | 15 |
| NYDFS Part 500 | 18 | 10 |
| COSO Internal Control (2013) | 17 | 16 |
| EU GDPR | 16 | 15 |
| HIPAA | 16 | 11 |
| EU AI Act | 14 | 10 |
| EU NIS2 Directive | 12 | 7 |
| PCI DSS v4.0.1 | 12 | 10 |
| SOC 1 (SSAE 18 / ISAE 3402) | 12 | 6 |
| CCPA/CPRA | 10 | 9 |
| EU DORA | 6 | 8 |
Split the same templates by who runs them and the shape of the profession shows up immediately:
| Line | Who | Templates |
|---|---|---|
| Operate | first line — the control owner runs it | 90 |
| Monitor | second line — risk and compliance oversee it | 32 |
| Assure | third line — internal audit tests it | 16 |
Sixteen of 138 templates are third-line work. Assurance is a thin layer sitting on top of a very large operating surface, which is exactly why auditors cannot test their way to coverage by hand and why the leverage is in reading the first line's systems directly.
Where to start
If you are trying to work out where your function actually sits, score yourself first — the model is five levels across six dimensions and takes about four minutes.
- The Modern Auditing Maturity Model — score your function, get a level and the next concrete move.
- The glossary — the vocabulary, defined without vendor gloss.
- The library — free workflow packs, control maps and datasets you can import and run.
Recent notes
904 controls, 280 obligations
We mapped 22 frameworks control by control. They collapse into 280 unified controls — a 3.2-to-1 reduction. That ratio is the whole argument for how compliance programmes should be structured, and most of them are structured the other way.
Your GRC platform added a chat panel. That isn't agent-native.
Every incumbent now has an AI assistant in the corner of the screen. Almost none of them can let an agent complete a control test, because their data model stores documents for humans rather than work for machines. Here is the test that separates the two.
Nobody's sample of 25 was ever statistical
Conventional sample sizes are a customary quantity of work, not a statistical conclusion. That was a reasonable trade when opening 25 files took a day. It is now a choice to test less than you could — and it is increasingly a choice you will be asked to defend.