modern auditing

The reference

What is modern auditing?

Modern auditing is internal audit practised as a continuous, instrumented process: controls, testing and evidence live in systems that run all year, software agents perform the mechanical work, and auditors spend their judgment on scoping, exceptions and conclusions rather than on collecting screenshots.

Independence, objectivity and professional skepticism are unchanged. What changes is where the work happens, and who does the parts that were never judgment in the first place.

This site is the reference for that shift — the definition, amaturity model you can score yourself against, aglossary of the vocabulary, and alibrary of free working artifacts. Everything is ungated, and every number on the site is counted from artifacts we publish and maintain rather than estimated.

The five shifts

"Modern" is doing real work in that phrase, and it is not a synonym for "with AI in it". Five specific things change. A function that has done none of them has bought software; a function that has done all five has changed the job.

FromToWhat actually changes
01SamplingPopulationA sample of 25 was a concession to how long it took a person to open 25 files. When testing is executed by software against the system of record, the natural sample size is every item. The interesting question stops being “did we pick the right 25?” and becomes “what do we do with the 4,000 that failed?”
02Requesting evidenceReading systemsThe PBC list exists because auditors could not reach the systems themselves. Given read access and a stable interface, evidence is pulled rather than requested — which removes the single largest source of audit delay and, incidentally, the largest source of friction with the business.
03DocumentsStructured recordsA workpaper stored as a document is a screenshot of a conclusion. A workpaper stored as a structured record — control, assertion, population, exceptions, conclusion, approver — can be queried, rolled up, re-run next quarter, and handed to an agent. Most audit software digitised the filing cabinet without ever doing this.
04AnnualContinuousThe annual cycle is an artifact of effort, not of risk. Once a test is a repeatable definition rather than a person's week, the marginal cost of running it again approaches zero, and the reporting cadence becomes a policy choice instead of a capacity limit.
05Doing the workSupervising itThis is the shift that unsettles people, and it should be stated precisely: agents execute, humans approve. Scoping, risk judgment, the decision that something is a deficiency, and the conclusion signed at the end remain human and remain accountable. What moves is the fetching, tying out, formatting and chasing — none of which was ever professional judgment.

What modern auditing is not

The term is being used to sell things, so it is worth being blunt about the four most common substitutions.

It is not "AI writes the audit report"

A report is a conclusion, and a conclusion is an accountable human act. An agent that drafts the sections around a conclusion is useful; an agent that reaches the conclusion has produced an unsigned opinion, which is worth nothing to a regulator and less than nothing to an audit committee.

It is not buying a GRC platform

The industry has spent two decades installing platforms that were configured once, never adopted, and renewed anyway. Software that nobody opens is not modernisation; it is a subscription. The test is whether last quarter's testing actually ran in it.

It is not continuous monitoring, rebranded

This distinction matters more than any other on this page, and most vendor copy erases it. Continuous monitoring is amanagement activity — the first and second lines watching their own controls. Auditing is assurance over that activity. If internal audit builds and runs the monitoring, internal audit is now auditing its own work, and the independence that made the function worth having is gone. Modern auditing makes assurance continuous; it does not make auditors the operators.

It is not the end of the auditor

It is the end of the parts of the job that no one defended: chasing evidence, reformatting spreadsheets, re-performing last year's tie-out. What is left is the part the profession has always claimed was the point.

The map, in numbers

Most writing about audit modernisation is an opinion with a call to action attached. The figures below are counts, taken on 2026-07-29, from two artifacts we maintain in public: an enterprise compliance map and an open library of workflow templates. You can open both and check them.

Frameworks mapped
22
Framework controls
904
Unified controls
280
Risks
167
Workflow templates
138
Defined steps
1,502

The ratio worth sitting with is the third one. Those 904framework controls collapse into 280 unified controls — roughly a 3.2-to-1 reduction. That is the arithmetic behind "test once, satisfy many", and it is the single largest available saving in most compliance programmes. It is also why framework sprawl is survivable at all.

Framework coverage across the 138 published templates.
FrameworkControlsTemplates touching it
NIST SP 800-53 Rev 529570
NIST Cybersecurity Framework 2.010634
ISO/IEC 27001:2022 Annex A9343
IIA 2024 Global Internal Audit Standards6813
AICPA SOC 2 Trust Services Criteria6121
COBIT 20194013
ISO/IEC 42001:2023 (AI management)386
ISO 31000:2018229
SOX 404 / PCAOB AS 22012119
COSO ERM (2017)2015
NYDFS Part 5001810
COSO Internal Control (2013)1716
EU GDPR1615
HIPAA1611
EU AI Act1410
EU NIS2 Directive127
PCI DSS v4.0.11210
SOC 1 (SSAE 18 / ISAE 3402)126
CCPA/CPRA109
EU DORA68

Split the same templates by who runs them and the shape of the profession shows up immediately:

LineWhoTemplates
Operatefirst line — the control owner runs it90
Monitorsecond line — risk and compliance oversee it32
Assurethird line — internal audit tests it16

Sixteen of 138 templates are third-line work. Assurance is a thin layer sitting on top of a very large operating surface, which is exactly why auditors cannot test their way to coverage by hand and why the leverage is in reading the first line's systems directly.

Where to start

If you are trying to work out where your function actually sits, score yourself first — the model is five levels across six dimensions and takes about four minutes.

Recent notes

  • 904 controls, 280 obligations

    We mapped 22 frameworks control by control. They collapse into 280 unified controls — a 3.2-to-1 reduction. That ratio is the whole argument for how compliance programmes should be structured, and most of them are structured the other way.

    28 July 2026 · Rich Penfil

  • Your GRC platform added a chat panel. That isn't agent-native.

    Every incumbent now has an AI assistant in the corner of the screen. Almost none of them can let an agent complete a control test, because their data model stores documents for humans rather than work for machines. Here is the test that separates the two.

    23 July 2026 · Rich Penfil

  • Nobody's sample of 25 was ever statistical

    Conventional sample sizes are a customary quantity of work, not a statistical conclusion. That was a reasonable trade when opening 25 files took a day. It is now a choice to test less than you could — and it is increasingly a choice you will be asked to defend.

    16 July 2026 · Rich Penfil

All notes · RSS