Using AI in Frauditing: How Artificial Intelligence Is Changing Fraud Detection and Internal Auditing
From Traditional Audit Testing to AI-Assisted Fraud Detection
Fraud schemes are becoming more sophisticated, and organizations are generating enormous volumes of financial and operational data.
Traditional audit techniques remain essential, but auditors increasingly need better ways to identify suspicious transactions, uncover unusual relationships, and evaluate fraud risks across large populations.
Artificial intelligence offers significant opportunities to improve this work.
Frauditing, the integration of fraud examination techniques with traditional auditing, provides a particularly useful setting for applying AI.
Instead of relying exclusively on limited transaction samples, auditors can use AI-assisted analytics to examine larger populations, identify anomalies, and prioritize transactions for further investigation.
However, AI does not determine whether fraud has occurred.
It identifies patterns, inconsistencies, and potential warning signs that require professional evaluation.
The greatest value of AI in frauditing is not replacing auditors. It is helping auditors ask better questions, examine more information, and identify risks that conventional procedures might overlook.
1. What Is AI-Assisted Frauditing?
AI-assisted frauditing applies artificial intelligence and advanced data analytics to fraud risk assessment, audit testing, and investigative procedures.
Relevant technologies include:
Machine learning: Identifies patterns and unusual transactions within large datasets.
Anomaly detection: Highlights transactions that differ significantly from expected behavior.
Natural language processing: Analyzes text in contracts, invoices, emails, and other records.
Generative AI: Assists with developing fraud scenarios, summarizing documents, drafting audit procedures, and organizing findings.
Network analytics: Identifies relationships among employees, vendors, customers, bank accounts, and transactions.
Predictive models: Estimate which transactions or relationships warrant additional review based on defined risk indicators.
Not every useful fraud analytics technique requires AI.
Duplicate-payment testing, approval-threshold analysis, and matching employee and vendor addresses can often be performed effectively with conventional rules-based analytics.
The objective should be to select the most appropriate technology for the fraud risk—not to use AI simply because it is available.
2. How AI Changes the Frauditing Process
AI can support multiple stages of a fraud-focused audit.
Frauditing activity | Traditional approach | AI-assisted approach |
Fraud risk assessment | Interviews, workshops, checklists | Analyze historical patterns and develop potential fraud scenarios |
Transaction testing | Selected samples and predefined rules | Analyze entire datasets and identify unusual combinations |
Vendor analysis | Manual comparison of vendor records | Detect hidden relationships and anomalous vendor behavior |
Journal entry testing | Filters based on selected risk factors | Identify unusual entries across multiple dimensions |
Document review | Manual examination | Extract and compare information from large document populations |
Investigation support | Manual timeline and relationship analysis | Organize transactions, documents, and connections |
Continuous monitoring | Periodic exception reports | Repeated risk scoring and anomaly detection |
These capabilities can improve efficiency and expand the scope of fraud risk analysis.
They also create new risks involving data quality, model reliability, explainability, and confidentiality.
3. Using AI to Identify Fraud Risks
A fraud-focused audit should begin by understanding how fraud could occur.
AI can assist auditors in developing and refining fraud risk scenarios.
For example, an auditor reviewing procurement may identify potential schemes involving:
Fictitious vendors.
Unauthorized vendor banking changes.
Duplicate invoices.
Split purchases designed to avoid approval limits.
Undisclosed employee-vendor relationships.
Inflated prices.
Payments for goods or services never received.
Generative AI can help organize these scenarios into a fraud risk matrix.
The matrix may identify the potential scheme, opportunity, control weakness, relevant data, planned procedures, and expected evidence.
However, the auditor must validate the scenarios against the organization's actual processes and control environment.
AI-generated fraud risks are hypotheses, not findings. It is a starting point that the professional auditor can then enhance with their knowledge of the situation.
4. AI and Vendor Master File Fraud
Vendor data is an especially promising area for AI-assisted frauditing.
A vendor master file may contain thousands of records with inconsistent names, addresses, banking information, tax identifiers, and payment histories.
AI and network analytics can help identify:
Shared bank accounts: Multiple vendors using the same bank account without an apparent legitimate explanation.
Employee-vendor relationships: Similar addresses, contact information, or other connections between employees and vendors.
Duplicate vendors: Different vendor names that may represent the same entity.
Unusual banking changes: Changes occurring immediately before large payments.
Dormant vendor activity: Previously inactive vendors receiving unexpected payments.
New vendor concentration: Recently created vendors receiving unusually large payments.
Unusual transaction timing: Vendor changes or payments occurring outside normal business hours.
A useful AI-assisted procedure would combine vendor master records, change logs, accounts payable transactions, and authorized employee data.
The system could then identify relationships or behaviors warranting additional review.
Importantly, auditors must comply with privacy, security, and applicable data protection requirements.
5. AI for Journal Entry Fraud Detection
Journal entry testing is an important component of fraud-focused auditing.
For financial statement auditors, PCAOB AS 2401 establishes requirements concerning journal entries and other adjustments as part of addressing management override.
AI-assisted analytics may help identify:
Unusual account combinations.
Entries posted late at night or on weekends.
Entries made by unexpected users.
Large manual adjustments near period-end.
Entries with unusual descriptions.
Transactions reversing shortly after posting.
Entries involving seldom-used accounts.
Patterns inconsistent with historical activity.
For example, a machine learning model might identify a manual entry that is unusual because of its amount, posting time, user, and account combination.
That does not establish fraud.
The auditor must examine the supporting documentation, authorization, business purpose, and accounting treatment.
AI-based selection should supplement, not displace, procedures specifically required by applicable auditing standards.
6. Detecting Procurement and Accounts Payable Fraud
Procurement fraud often involves patterns that are difficult to identify through individual transaction testing.
AI can help auditors evaluate purchasing and payment activity across departments, vendors, and time periods.
Potential indicators include:
Repeated purchases just below authorization thresholds.
Unusual concentration of purchases with one vendor.
Vendors consistently winning competitive bids.
Invoice prices that differ significantly from comparable purchases.
Multiple invoices with similar descriptions and amounts.
Payments inconsistent with purchase orders or receiving records.
Unusual relationships between purchasing employees and vendors.
Network analysis can be particularly useful.
For example, an auditor may discover that several supposedly independent vendors share contact information or bank accounts.
Further investigation may reveal a legitimate corporate relationship—or a potential fraud scheme.
The auditor must determine which explanation is supported by evidence.
7. Using Natural Language Processing to Review Documents
Fraud investigations frequently involve large volumes of unstructured information.
These may include:
Contracts.
Purchase orders.
Invoices.
Expense reports.
Management correspondence.
Meeting minutes.
Vendor communications.
Internal policies.
Natural language processing can assist with identifying inconsistencies, extracting key terms, and organizing documents for review.
For example, an AI system might compare contractual payment terms with actual payment transactions.
It might identify invoices referencing services not included in the underlying contract.
Generative AI can also help develop document chronologies and summarize relevant evidence.
However, AI-generated summaries must be checked against original source documents.
A plausible summary is not necessarily an accurate one.
8. AI and Fraud Risk Scoring
Organizations may use AI to assign risk scores to transactions or relationships.
A vendor payment might receive a higher risk score because it involves:
A newly established vendor.
A recent banking change.
An unusually large payment.
A manual approval override.
An employee with excessive system access.
Combining these factors may be more informative than evaluating each one independently.
However, risk scoring requires careful model design.
Auditors should understand:
Which factors affect the score.
Whether the underlying data is accurate.
Whether the model has been validated.
How false positives are handled.
Whether important fraud scenarios are missed.
Whether the model changes over time.
A high fraud risk score is a reason to investigate, not a conclusion that fraud occurred.
9. AI Can Create New Fraud Risks
Artificial intelligence is not only a fraud detection tool.
It can also be used by individuals attempting to commit fraud.
Examples include:
Business email compromise: AI-generated messages may convincingly impersonate executives or vendors.
Voice cloning: Fraudsters may imitate an executive's voice to request urgent payments.
Deepfake video: Synthetic video may be used to impersonate a trusted individual.
Fraudulent documentation: Generative AI may produce realistic but false invoices, letters, or supporting records.
Automated social engineering: Attackers may create personalized messages at scale.
These risks make independent authentication especially important.
Organizations should not rely solely on the apparent authenticity of an email, telephone call, or video meeting when authorizing high-risk transactions.
10. The Critical Importance of Data Quality
AI systems depend on the quality of their input data.
A model cannot reliably identify fraud patterns if the underlying data is incomplete, inaccurate, or improperly extracted.
Before using AI-assisted analytics, auditors should consider:
Whether the dataset includes the complete relevant population.
Whether records were omitted during extraction.
Whether fields were mapped correctly.
Whether transaction dates and amounts are accurate.
Whether duplicate records were introduced.
Whether data transformations were documented.
Whether access to sensitive information is controlled.
For example, an AI model analyzing vendor payments may miss important fraud indicators if vendor banking changes are excluded from the dataset.
Advanced analytics applied to unreliable data can produce sophisticated-looking but unsupported conclusions.
11. AI Outputs Are Not Automatically Audit Evidence
One of the greatest risks in AI-assisted frauditing is treating an AI-generated conclusion as established evidence.
Suppose a generative AI system identifies a transaction as suspicious and states that the vendor appears fictitious.
That statement alone is not proof.
The auditor should examine the underlying records, validate the model's observations, and obtain corroborating evidence.
A sound process follows this sequence:
AI-Generated Alert → Auditor Evaluation → Corroborating Evidence → Documented Conclusion
For PCAOB financial statement audits, AS 1105 addresses the sufficiency and appropriateness of audit evidence.
For internal audit engagements, the IIA's Global Internal Audit Standards establish requirements concerning the collection, analysis, and evaluation of information.
In either context, professional judgment remains essential.
12. Confidentiality and Data Security
Frauditing frequently involves highly sensitive information.
Examples include employee data, bank account information, confidential vendor records, allegations of misconduct, and privileged communications.
Auditors should not upload such information into unapproved public AI services.
Organizations should establish policies addressing:
Approved AI applications.
Data classification.
Access permissions.
Encryption and retention.
Vendor confidentiality obligations.
Model training and data reuse.
Human review of AI outputs.
Audit trails and accountability.
AI governance should be integrated with the organization's information security and internal control framework.
13. The Role of Internal Audit
Internal Audit can use AI-assisted frauditing to improve both assurance engagements and fraud risk evaluations.
Potential applications include:
Assessing management's fraud risk management program.
Evaluating procurement and payment controls.
Identifying unusual financial transactions.
Reviewing privileged system access.
Testing vendor master file controls.
Evaluating whistleblower reporting processes.
Monitoring significant corrective actions.
Internal Audit should also evaluate the organization's governance over AI systems.
This includes considering whether management has established controls over AI implementation, data quality, cybersecurity, model performance, and decision-making.
Internal Audit should avoid assuming responsibility for operating the fraud detection controls it will later independently assess.
14. The Role of the Audit Committee
Audit Committees should understand both the benefits and limitations of AI-assisted fraud detection.
Relevant oversight questions include:
Has management identified significant fraud risks involving AI?
Does the organization have an approved AI governance policy?
Are AI-assisted fraud detection tools validated?
Are high-risk alerts investigated by qualified personnel?
Are false positives and missed detections evaluated?
Is sensitive financial and personal information protected?
Does Internal Audit have sufficient expertise to evaluate AI-related risks?
Are significant fraud concerns reported promptly?
Are management's corrective actions tracked?
Is the organization prepared for deepfake and AI-enabled impersonation schemes?
The committee should understand whether AI strengthens the organization's fraud risk management program or introduces additional uncontrolled risks.
15. A Practical AI-Assisted Frauditing Exercise
Consider an organization with:
5,000 active vendors.
250,000 annual accounts payable transactions.
1,200 employees.
Multiple purchasing departments.
A centralized vendor master file.
The Internal Audit Department is asked to evaluate vendor payment fraud risks.
Step 1 — Identify Fraud Scenarios
Develop scenarios involving fictitious vendors, duplicate payments, unauthorized banking changes, and conflicts of interest.
Step 2 — Obtain Relevant Data
Obtain vendor records, payment transactions, vendor change logs, approval histories, and appropriately authorized employee information.
Step 3 — Validate the Data
Reconcile extracted totals and record counts to authoritative source systems.
Evaluate completeness, accuracy, and relevant data transformations.
Step 4 — Perform AI-Assisted Analysis
Use suitable analytics to identify unusual vendor relationships, suspicious payment patterns, and high-risk changes.
Step 5 — Investigate Exceptions
Examine selected transactions, supporting documentation, approvals, and independent confirmations.
Step 6 — Evaluate Controls
Determine whether the identified conditions indicate control design weaknesses, operating deficiencies, or potential misconduct requiring escalation.
Step 7 — Report Results
Document the procedures, evidence, conclusions, and recommended corrective actions.
This exercise demonstrates how AI can expand audit coverage without replacing the auditor's responsibility for evidence evaluation.
16. Common Mistakes When Using AI in Frauditing
Common implementation mistakes include:
Assuming AI can independently determine whether fraud occurred.
Using AI without a defined fraud risk assessment.
Failing to validate source data.
Relying on unexplained risk scores.
Treating AI-generated narratives as evidence.
Ignoring false positives and false negatives.
Uploading confidential data to unapproved services.
Failing to document model settings and procedures.
Allowing AI to replace professional skepticism.
Failing to establish accountability for investigation and corrective action.
These weaknesses can undermine the credibility of the audit process.
The Bottom Line
Artificial intelligence can significantly strengthen frauditing by helping auditors examine larger datasets, identify unusual patterns, uncover hidden relationships, and prioritize high-risk transactions.
It can also help organizations respond to increasingly sophisticated fraud schemes involving synthetic identities, voice cloning, deepfakes, and automated social engineering.
But AI is not a substitute for professional auditing judgment.
AI can identify an anomaly. The auditor must determine what the anomaly means.
The most effective approach combines AI-assisted analytics with fraud examination techniques, internal control knowledge, reliable evidence, and professional skepticism.
The future of frauditing is not artificial intelligence replacing auditors. It is auditors using artificial intelligence to become more effective at identifying and evaluating fraud risks.

Comments