09/02/2026
Boards now expect audit to weigh in on AI governance, cybersecurity, ESG, and third-party risk, all on top of financial controls and regulatory compliance. 42% of audit teams say they lack the skills to cover those emerging areas. The mandate expanded, but the team didn't.
That usually turns into a headcount conversation. But when you look at where the hours actually go, the picture changes.
Before any testing begins, someone has to pull one dataset from the ERP, another from a reporting export, track down a key document buried in email, and clean up support files that arrived late or in the wrong format. Senior auditors get pulled into that coordination because they know what the evidence should look like.
Planning slows down without a clean view of the data. Fieldwork slows down chasing support. Reporting slows down reassembling everything into something defensible.
One engagement running late is manageable. Across a full annual plan, that friction becomes a structural capacity problem.
Here’s what useful automation looks like in audit, and why lineage and traceability are non-negotiable: https://savantlabs.io/blog/ai-audit-automation/