CRX | October 13-15, 2026 | Up to 17 CPEs | In-person & virtual options available | Register Now!

Customers
Login
Optro's logo

August 11, 2026 9 min read

Agentic AI in internal audit: which controls should you automate first?

logo image

Optro staff

For internal audit teams, most agentic audit tools clear the first hurdles easily. The demo works, the integration goes fine, and your first controls come back clean. The friction shows up a few controls later, when you point the agent at your most judgment-heavy work and watch the time savings vanish into configuration and exceptions. That plateau traces back to one decision: which work you gave the agent, and in what order.

Audit budgets are tightening even as the mandate to employ autonomous AI agents grows. In the Institute of Internal Auditors (IIA)'s 2026 North American Pulse of Internal Audit, only 23% of teams reported a budget increase, while 19% faced a cut.

So the real work starts with a question most pilots skip: which audit tasks is an agent actually suited for? An AI agent can work through a routine control test on its own. It cannot tell you whether the failure it surfaces is a minor gap or a material weakness. That line, between the work an agent can finish and the work that still needs your judgment, is the most useful thing an audit leader can understand about agentic AI right now.

Some audit work sits cleanly on one side. Most sit somewhere in between, and the teams getting the most from agents are the ones who can tell which is which before they start. Sequencing is where pilot projects succeed or stall. Point an agent at work it can finish, and you earn early wins and the trust to expand. Point it at work that needs judgment it cannot supply, and you get that same plateau, and the skeptics who doubted the tool feel proven right.

The cleanest way to sort the two comes out of software engineering, where agentic tools have already reshaped the work.

The distinction that does the sorting

Every task an AI agent could take on falls somewhere between two poles.

A closed-world task is bounded. The information needed to complete it is finite and known, and the rules for handling it are stable. Chess is the textbook example. The board is complex, yet the pieces, the moves, and the win conditions never change. That is why software could beat grandmasters decades ago.

An open-world task is unbounded. The information that might matter has no clear edge, and much of it is never written down at all. It lives in the judgment and memory of the people doing the work. Predicting how a geopolitical event will move a market is open world. No one can read every relevant input, so the work depends on experience to weigh a wide and shifting field of evidence.

Agents are already strong at closed-world work and will keep getting stronger. They struggle with open-world work for two reasons that are built into how the models operate. First, an agent can only consider a bounded amount of information at once, so a problem with no edges overruns it. Second, new information takes time to reach the model, which is a problem when the ground is shifting under the task.

Two tests that tell you what to automate

To place any audit task on that spectrum, ask two questions.

  1. Can you draw a boundary around the evidence? If the task depends on a finite, known set of documents, it leans closed world. If the relevant evidence could come from anywhere, including someone's recollection, it leans open.
  2. Do the rules hold still while you work? If the procedure is defined and the criteria change slowly, it leans closed. If the task requires reading a fast-moving business context, it leans open.

A task that passes both tests is a candidate to automate now. A task that fails either needs a human to frame it first, or it stays human-led.

Sorting your own control portfolio

Run a few common tasks through the two tests, and the sequencing becomes obvious.

  • Verifying a three-way match passes cleanly. The purchase order, the receipt, and the invoice are a fixed set of documents, and the comparison follows a defined rule. You can hand it over.
  • Standard IT general controls behave the same way. User access reviews and password controls are uniform and well defined, which is why teams tend to automate them first and see results fast.
  • Root causing a test exception sits at the other pole. The explanation could involve almost anything, and the deciding detail is often unwritten. That work stays with a person.

Classifying a deficiency as a control gap or a material weakness only becomes tractable for an agent once a human supplies the enterprise context. Framed that way, an auditor and an agent can work it together. Sent cold to a general model, it will return a confident answer with no reliable grounding in your environment.

The pattern holds across the testing lifecycle. Teams using Midship, now part of Optro, report saving 60% of the time it takes to prepare a first draft of a work paper, precisely because that step can be bounded: a defined sample, a set procedure, and a fixed set of evidence.

Design the escape hatch before you automate

Closed-world tasks do not always stay closed. An exception surfaces, a document goes missing, or the evidence points somewhere the procedure did not anticipate, and the task quietly becomes open world.

Plan for that before you deploy. The agent should recognize when a problem has moved outside its bounds and route it to a person, with the context already assembled. Human oversight works best as a designed step in the workflow rather than a rescue you improvise later. It is also what keeps the auditor accountable for the judgment that matters.

You can widen the set of automatable work

The closed-world set is not fixed. Two habits expand it.

Tighten your evidentiary standards. Much of what pushes a task toward the open world is vague criteria. "Approval is required" leaves too much unsaid, which forces the agent to guess and the reviewer to step in. When the standard for good evidence lives only as tribal knowledge, every cycle relitigates it. Specify the exact form that approval must take, and where it must appear, and you close the world around the task so an agent can own more of it.

Document your testing deviations centrally. Every time an exception turns out to be acceptable for a reason, capture that reason in one place. Over time, you build a repository that an agent or a reviewer can check new exceptions against, turning scattered institutional memory into bounded, usable evidence.

Where the reclaimed hours go

As agentic controls testing takes on more of the bounded work, what remains for you is the open-world work. The judgment calls, the root cause analysis, and the risk questions that depend on enterprise context are exactly where auditors are hardest to replace, and exactly where most teams wish they spent more time.

In the on-demand webinar Move fast and control things, Kieran Taylor, who co-founded Midship and now serves as Senior Director of Engineering at Optro, and Urmi Vora, Chief Audit Executive at Confluent, work through live examples of the closed-world test, including a poll that puts the distinction to the audience. It is worth an hour if you are deciding where your own automation should start.

Watch the webinar
Register now

About the authors

logo image

Optro is the leading AI-powered GRC platform, transforming the way the world’s biggest companies manage risk. More than 50% of the Fortune 500 trust Optro to elevate their audit, risk, and compliance management.

You may also like to read

reflective light
Internal Audit

The agentic audit era: What CAEs must rethink now

LEARN MORE
colleagues collaborating on sticky notes
Internal Audit

The SEC just named its financial reporting watchdog. Is your CFO ready?

LEARN MORE
Krista Moller at Valneva
Internal Audit

How Valneva gave its SOX program a shot of efficiency

LEARN MORE

Discover why industry leaders choose Optro

SCHEDULE A DEMO
upward trending chart
confident business professional
Agentic AI in Internal Audit: What to Automate First