top of page
Search

Using AI in Frauditing: How Artificial Intelligence Is Changing Fraud Detection and Internal Auditing

12 hours ago
9 min read

From Traditional Audit Testing to AI-Assisted Fraud Detection


Fraud schemes are becoming more sophisticated, and organizations are generating enormous volumes of financial and operational data.


Traditional audit techniques remain essential, but auditors increasingly need better ways to identify suspicious transactions, uncover unusual relationships, and evaluate fraud risks across large populations.


Artificial intelligence offers significant opportunities to improve this work.


Frauditing, the integration of fraud examination techniques with traditional auditing, provides a particularly useful setting for applying AI.


Instead of relying exclusively on limited transaction samples, auditors can use AI-assisted analytics to examine larger populations, identify anomalies, and prioritize transactions for further investigation.


However, AI does not determine whether fraud has occurred.


It identifies patterns, inconsistencies, and potential warning signs that require professional evaluation.


The greatest value of AI in frauditing is not replacing auditors. It is helping auditors ask better questions, examine more information, and identify risks that conventional procedures might overlook.


1. What Is AI-Assisted Frauditing?

AI-assisted frauditing applies artificial intelligence and advanced data analytics to fraud risk assessment, audit testing, and investigative procedures.


Relevant technologies include:

  • Machine learning: Identifies patterns and unusual transactions within large datasets.

  • Anomaly detection: Highlights transactions that differ significantly from expected behavior.

  • Natural language processing: Analyzes text in contracts, invoices, emails, and other records.

  • Generative AI: Assists with developing fraud scenarios, summarizing documents, drafting audit procedures, and organizing findings.

  • Network analytics: Identifies relationships among employees, vendors, customers, bank accounts, and transactions.

  • Predictive models: Estimate which transactions or relationships warrant additional review based on defined risk indicators.


Not every useful fraud analytics technique requires AI.


Duplicate-payment testing, approval-threshold analysis, and matching employee and vendor addresses can often be performed effectively with conventional rules-based analytics.


The objective should be to select the most appropriate technology for the fraud risk—not to use AI simply because it is available.


2. How AI Changes the Frauditing Process

AI can support multiple stages of a fraud-focused audit.

Frauditing activity

Traditional approach

AI-assisted approach

Fraud risk assessment

Interviews, workshops, checklists

Analyze historical patterns and develop potential fraud scenarios

Transaction testing

Selected samples and predefined rules

Analyze entire datasets and identify unusual combinations

Vendor analysis

Manual comparison of vendor records

Detect hidden relationships and anomalous vendor behavior

Journal entry testing

Filters based on selected risk factors

Identify unusual entries across multiple dimensions

Document review

Manual examination

Extract and compare information from large document populations

Investigation support

Manual timeline and relationship analysis

Organize transactions, documents, and connections

Continuous monitoring

Periodic exception reports

Repeated risk scoring and anomaly detection

These capabilities can improve efficiency and expand the scope of fraud risk analysis.


They also create new risks involving data quality, model reliability, explainability, and confidentiality.


3. Using AI to Identify Fraud Risks

A fraud-focused audit should begin by understanding how fraud could occur.


AI can assist auditors in developing and refining fraud risk scenarios.


For example, an auditor reviewing procurement may identify potential schemes involving:

  • Fictitious vendors.

  • Unauthorized vendor banking changes.

  • Duplicate invoices.

  • Split purchases designed to avoid approval limits.

  • Undisclosed employee-vendor relationships.

  • Inflated prices.

  • Payments for goods or services never received.


Generative AI can help organize these scenarios into a fraud risk matrix.


The matrix may identify the potential scheme, opportunity, control weakness, relevant data, planned procedures, and expected evidence.


However, the auditor must validate the scenarios against the organization's actual processes and control environment.


AI-generated fraud risks are hypotheses, not findings. It is a starting point that the professional auditor can then enhance with their knowledge of the situation.


4. AI and Vendor Master File Fraud

Vendor data is an especially promising area for AI-assisted frauditing.


A vendor master file may contain thousands of records with inconsistent names, addresses, banking information, tax identifiers, and payment histories.


AI and network analytics can help identify:

  • Shared bank accounts: Multiple vendors using the same bank account without an apparent legitimate explanation.

  • Employee-vendor relationships: Similar addresses, contact information, or other connections between employees and vendors.

  • Duplicate vendors: Different vendor names that may represent the same entity.

  • Unusual banking changes: Changes occurring immediately before large payments.

  • Dormant vendor activity: Previously inactive vendors receiving unexpected payments.

  • New vendor concentration: Recently created vendors receiving unusually large payments.

  • Unusual transaction timing: Vendor changes or payments occurring outside normal business hours.


A useful AI-assisted procedure would combine vendor master records, change logs, accounts payable transactions, and authorized employee data.


The system could then identify relationships or behaviors warranting additional review.

Importantly, auditors must comply with privacy, security, and applicable data protection requirements.


5. AI for Journal Entry Fraud Detection

Journal entry testing is an important component of fraud-focused auditing.


For financial statement auditors, PCAOB AS 2401 establishes requirements concerning journal entries and other adjustments as part of addressing management override.


AI-assisted analytics may help identify:

  • Unusual account combinations.

  • Entries posted late at night or on weekends.

  • Entries made by unexpected users.

  • Large manual adjustments near period-end.

  • Entries with unusual descriptions.

  • Transactions reversing shortly after posting.

  • Entries involving seldom-used accounts.

  • Patterns inconsistent with historical activity.


For example, a machine learning model might identify a manual entry that is unusual because of its amount, posting time, user, and account combination.


That does not establish fraud.


The auditor must examine the supporting documentation, authorization, business purpose, and accounting treatment.


AI-based selection should supplement, not displace, procedures specifically required by applicable auditing standards.


6. Detecting Procurement and Accounts Payable Fraud

Procurement fraud often involves patterns that are difficult to identify through individual transaction testing.


AI can help auditors evaluate purchasing and payment activity across departments, vendors, and time periods.


Potential indicators include:

  • Repeated purchases just below authorization thresholds.

  • Unusual concentration of purchases with one vendor.

  • Vendors consistently winning competitive bids.

  • Invoice prices that differ significantly from comparable purchases.

  • Multiple invoices with similar descriptions and amounts.

  • Payments inconsistent with purchase orders or receiving records.

  • Unusual relationships between purchasing employees and vendors.


Network analysis can be particularly useful.


For example, an auditor may discover that several supposedly independent vendors share contact information or bank accounts.


Further investigation may reveal a legitimate corporate relationship—or a potential fraud scheme.


The auditor must determine which explanation is supported by evidence.


7. Using Natural Language Processing to Review Documents

Fraud investigations frequently involve large volumes of unstructured information.


These may include:

  • Contracts.

  • Purchase orders.

  • Invoices.

  • Expense reports.

  • Management correspondence.

  • Meeting minutes.

  • Vendor communications.

  • Internal policies.


Natural language processing can assist with identifying inconsistencies, extracting key terms, and organizing documents for review.


For example, an AI system might compare contractual payment terms with actual payment transactions.


It might identify invoices referencing services not included in the underlying contract.

Generative AI can also help develop document chronologies and summarize relevant evidence.


However, AI-generated summaries must be checked against original source documents.


A plausible summary is not necessarily an accurate one.


8. AI and Fraud Risk Scoring

Organizations may use AI to assign risk scores to transactions or relationships.


A vendor payment might receive a higher risk score because it involves:

  • A newly established vendor.

  • A recent banking change.

  • An unusually large payment.

  • A manual approval override.

  • An employee with excessive system access.


Combining these factors may be more informative than evaluating each one independently.


However, risk scoring requires careful model design.


Auditors should understand:

  • Which factors affect the score.

  • Whether the underlying data is accurate.

  • Whether the model has been validated.

  • How false positives are handled.

  • Whether important fraud scenarios are missed.

  • Whether the model changes over time.


A high fraud risk score is a reason to investigate, not a conclusion that fraud occurred.


9. AI Can Create New Fraud Risks

Artificial intelligence is not only a fraud detection tool.


It can also be used by individuals attempting to commit fraud.


Examples include:

  • Business email compromise: AI-generated messages may convincingly impersonate executives or vendors.

  • Voice cloning: Fraudsters may imitate an executive's voice to request urgent payments.

  • Deepfake video: Synthetic video may be used to impersonate a trusted individual.

  • Fraudulent documentation: Generative AI may produce realistic but false invoices, letters, or supporting records.

  • Automated social engineering: Attackers may create personalized messages at scale.


These risks make independent authentication especially important.


Organizations should not rely solely on the apparent authenticity of an email, telephone call, or video meeting when authorizing high-risk transactions.


10. The Critical Importance of Data Quality

AI systems depend on the quality of their input data.


A model cannot reliably identify fraud patterns if the underlying data is incomplete, inaccurate, or improperly extracted.


Before using AI-assisted analytics, auditors should consider:

  • Whether the dataset includes the complete relevant population.

  • Whether records were omitted during extraction.

  • Whether fields were mapped correctly.

  • Whether transaction dates and amounts are accurate.

  • Whether duplicate records were introduced.

  • Whether data transformations were documented.

  • Whether access to sensitive information is controlled.


For example, an AI model analyzing vendor payments may miss important fraud indicators if vendor banking changes are excluded from the dataset.


Advanced analytics applied to unreliable data can produce sophisticated-looking but unsupported conclusions.


11. AI Outputs Are Not Automatically Audit Evidence

One of the greatest risks in AI-assisted frauditing is treating an AI-generated conclusion as established evidence.


Suppose a generative AI system identifies a transaction as suspicious and states that the vendor appears fictitious.


That statement alone is not proof.


The auditor should examine the underlying records, validate the model's observations, and obtain corroborating evidence.


A sound process follows this sequence:


AI-Generated Alert → Auditor Evaluation → Corroborating Evidence → Documented Conclusion


For PCAOB financial statement audits, AS 1105 addresses the sufficiency and appropriateness of audit evidence.


For internal audit engagements, the IIA's Global Internal Audit Standards establish requirements concerning the collection, analysis, and evaluation of information.


In either context, professional judgment remains essential.


12. Confidentiality and Data Security

Frauditing frequently involves highly sensitive information.


Examples include employee data, bank account information, confidential vendor records, allegations of misconduct, and privileged communications.


Auditors should not upload such information into unapproved public AI services.


Organizations should establish policies addressing:

  • Approved AI applications.

  • Data classification.

  • Access permissions.

  • Encryption and retention.

  • Vendor confidentiality obligations.

  • Model training and data reuse.

  • Human review of AI outputs.

  • Audit trails and accountability.


AI governance should be integrated with the organization's information security and internal control framework.


13. The Role of Internal Audit

Internal Audit can use AI-assisted frauditing to improve both assurance engagements and fraud risk evaluations.


Potential applications include:

  • Assessing management's fraud risk management program.

  • Evaluating procurement and payment controls.

  • Identifying unusual financial transactions.

  • Reviewing privileged system access.

  • Testing vendor master file controls.

  • Evaluating whistleblower reporting processes.

  • Monitoring significant corrective actions.


Internal Audit should also evaluate the organization's governance over AI systems.


This includes considering whether management has established controls over AI implementation, data quality, cybersecurity, model performance, and decision-making.


Internal Audit should avoid assuming responsibility for operating the fraud detection controls it will later independently assess.


14. The Role of the Audit Committee

Audit Committees should understand both the benefits and limitations of AI-assisted fraud detection.


Relevant oversight questions include:

  1. Has management identified significant fraud risks involving AI?

  2. Does the organization have an approved AI governance policy?

  3. Are AI-assisted fraud detection tools validated?

  4. Are high-risk alerts investigated by qualified personnel?

  5. Are false positives and missed detections evaluated?

  6. Is sensitive financial and personal information protected?

  7. Does Internal Audit have sufficient expertise to evaluate AI-related risks?

  8. Are significant fraud concerns reported promptly?

  9. Are management's corrective actions tracked?

  10. Is the organization prepared for deepfake and AI-enabled impersonation schemes?


The committee should understand whether AI strengthens the organization's fraud risk management program or introduces additional uncontrolled risks.


15. A Practical AI-Assisted Frauditing Exercise

Consider an organization with:

  • 5,000 active vendors.

  • 250,000 annual accounts payable transactions.

  • 1,200 employees.

  • Multiple purchasing departments.

  • A centralized vendor master file.


The Internal Audit Department is asked to evaluate vendor payment fraud risks.


Step 1 — Identify Fraud Scenarios

Develop scenarios involving fictitious vendors, duplicate payments, unauthorized banking changes, and conflicts of interest.

Step 2 — Obtain Relevant Data

Obtain vendor records, payment transactions, vendor change logs, approval histories, and appropriately authorized employee information.

Step 3 — Validate the Data

Reconcile extracted totals and record counts to authoritative source systems.

Evaluate completeness, accuracy, and relevant data transformations.

Step 4 — Perform AI-Assisted Analysis

Use suitable analytics to identify unusual vendor relationships, suspicious payment patterns, and high-risk changes.

Step 5 — Investigate Exceptions

Examine selected transactions, supporting documentation, approvals, and independent confirmations.

Step 6 — Evaluate Controls

Determine whether the identified conditions indicate control design weaknesses, operating deficiencies, or potential misconduct requiring escalation.

Step 7 — Report Results


Document the procedures, evidence, conclusions, and recommended corrective actions.


This exercise demonstrates how AI can expand audit coverage without replacing the auditor's responsibility for evidence evaluation.


16. Common Mistakes When Using AI in Frauditing

Common implementation mistakes include:

  • Assuming AI can independently determine whether fraud occurred.

  • Using AI without a defined fraud risk assessment.

  • Failing to validate source data.

  • Relying on unexplained risk scores.

  • Treating AI-generated narratives as evidence.

  • Ignoring false positives and false negatives.

  • Uploading confidential data to unapproved services.

  • Failing to document model settings and procedures.

  • Allowing AI to replace professional skepticism.

  • Failing to establish accountability for investigation and corrective action.


These weaknesses can undermine the credibility of the audit process.


The Bottom Line

Artificial intelligence can significantly strengthen frauditing by helping auditors examine larger datasets, identify unusual patterns, uncover hidden relationships, and prioritize high-risk transactions.


It can also help organizations respond to increasingly sophisticated fraud schemes involving synthetic identities, voice cloning, deepfakes, and automated social engineering.


But AI is not a substitute for professional auditing judgment.


AI can identify an anomaly. The auditor must determine what the anomaly means.


The most effective approach combines AI-assisted analytics with fraud examination techniques, internal control knowledge, reliable evidence, and professional skepticism.


The future of frauditing is not artificial intelligence replacing auditors. It is auditors using artificial intelligence to become more effective at identifying and evaluating fraud risks.


 
 
 

Recent Posts

See All
Audit Committee Charter: What Should Be Included?

A Practical Guide to Building an Effective Audit Committee Charter An Audit Committee Charter is one of the most important documents in an organization's corporate governance framework. It establishes

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

​

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

​

National Registry of CPE Sponsors ID #108983

​

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366; davem@cseminars.com) and/ or John Blackshire (479-200-4373; johnb@cseminars.com)

 

​

bottom of page