Skip to content
Literature · Accounting and Auditing EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

From the EU AI Act to Audit Practice: A Governance-to-Controls Framework for Quality Management and Evidence

János Kálmán — Accounting and Auditing

Accounting and Auditing
DOI

How it connects

Full text

Artificial intelligence (AI) tools—including audit data analytics, robotic process automation, machine-learning models, and generative AI—are changing how audit teams identify risks, select procedures, and evaluate evidence. At the same time, Regulation (EU) 2024/1689 (the EU AI Act) establishes a risk-based governance architecture built around risk management, data governance, technical documentation, logging, transparency, human oversight, robustness, cybersecurity, and post-market monitoring. The Act is not an auditing standard and does not directly regulate every tool used by audit firms. Nevertheless, its governance logic is relevant where audit firms develop, procure, or rely on AI-enabled systems that process sensitive client data, influence professional judgement, or become part of audit-relevant client systems. This conceptual study uses doctrinal requirements-to-controls mapping and design-oriented analysis to translate selected AI Act governance objectives into firm-level and engagement-level quality-management controls and into criteria for evaluating AI-enabled audit evidence. The paper specifies three modes of AI Act relevance: direct legal relevance where a regulated AI Act role is engaged; indirect relevance where AI compliance documentation becomes audit-relevant information; and benchmark relevance where the Act supplies governance objectives for quality management without creating an audit-law duty. The resulting artefacts are a traceable AI Act/IAASB standards crosswalk, an evidence-risk typology, a quality-management integration model, a documentation and review checklist, and a proportional maturity model. The framework clarifies when AI outputs remain triage or risk-assessment tools, when they provide directional or corroborative evidence, and the narrower conditions under which they may contribute to substantive evidence. It links reliance to data completeness, reconciliation, versioning, validation, false-positive and false-negative behaviour, explainability, logging, source-document corroboration, and reviewer challenge. The contribution is a scalable governance-to-controls framework that supports defensible reliance and inspection readiness without overstating the AI Act’s direct legal applicability. Empirical validation in audit firms remains a priority for future research. It further explains how quantitative risk features and anomaly-detection outputs feed into qualitative audit judgement: models can route attention to unusual transactions or documents, but evidential weight still depends on base-rate-aware error analysis, source-document corroboration, and reviewer challenge.

Similar Content