modern auditing

Glossary

Supervised autonomy

Also known as: human-in-the-loop autonomy

An operating model where software agents execute audit work end-to-end but no conclusion becomes part of the record until a named human approves it.

Supervised autonomy is the answer to the objection that agentic auditing cannot be squared with professional accountability. It splits the work along a line the profession already understands: execution versus judgment.

Agents execute. They pull the population, run the test steps, tie evidence to assertions, and assemble what they found. Humans judge. Scoping, risk assessment, the decision that an exception is a deficiency, and the conclusion signed at the end stay with a named, accountable person.

What makes it supervised rather than merely reviewed is that the approval is a gate rather than a rubber stamp applied later. The agent’s output is a proposal until a human accepts it, the acceptance is recorded with who and when, and the agent’s trail — what it read, what it did, what it skipped — is part of the workpaper. That is a higher standard of documentation than most manual audit work currently meets, which is the quiet argument in its favour.

The failure mode to watch for is autonomy without the supervision: agents writing directly into the record because the approval step was “slowing things down”. At that point the function has automated its way out of assurance.


Related


Part of the Modern Auditing glossary. See also the maturity model and theartifact library.