AI is already part of assurance. Are we talking enough about how we use it?
August 14, 2026
AI is already part of assurance. Are we talking enough about how we use it?
Clara Segón, TDi Standards Manager
Over the last year, through my work as a consultant supporting standards, assurance and certification schemes, and through conversations with people across the industry, I have noticed something interesting: AI is no longer something we are discussing as a future possibility. People are already using it. It is being used to review documents, compare requirements, analyse information, identify gaps and support different parts of audit and assurance processes.
I use AI in my own work too, and I can see the opportunities it brings. It can save time, help navigate large amounts of information and provide another way of looking at complex problems. But I have also noticed something else: we don’t always seem very comfortable talking openly about exactly how we are using it.
And I wonder if part of the reason is that, in many cases, we haven’t yet had those conversations properly. Have organisations agreed internally where the boundaries are? Do they have policies and procedures that are clear enough for people using these tools in their day-to-day work? Have assurance providers discussed with scheme owners what uses are acceptable? And, as an industry, are we talking enough with our peers about what good practice should look like?
Without that clarity, people are left to make individual decisions about what information can be put into these tools, how much they can rely on the outputs, what needs to be checked by a person, and where the boundary should sit between AI support and professional judgement.
For me, as someone who works daily with standards and assurance systems, this raises an important question. AI is already here, but have our assurance systems caught up with the way people are actually working and using it?
Where does AI fit into the assurance process?
When we design an assurance programme, we define clear requirements around competence, confidentiality, evidence, review and decision-making. But what happens when AI becomes part of those processes?
An auditor could use AI to review large amounts of evidence and identify potential gaps against a standard. This could save significant time, but it also raises questions. What information can be uploaded? How much can we rely on the analysis? What level of human verification is needed? And importantly, where does AI support end, and professional judgement begin?
There is also a question around competence. We define what auditors need to know, the experience they need and the training they must complete. But have we trained them to use AI? Using an AI tool is one thing. Understanding when to trust it, when to challenge it and what information should never be shared with it, is something different entirely.
So, how should AI be used in assurance?
We are beginning to see these questions reflected in formal standards and audit governance. ISO/IEC 17024:2026, published earlier this year, introduced specific provisions around AI in certification of persons, including human oversight, validation of AI-generated outcomes and competence in the use of AI tools. The UK’s Financial Reporting Council has also issued guidance on generative and agentic AI use in audits, while professional bodies are discussing questions around confidentiality, audit quality, training and human oversight.
These are important developments, but for assurance schemes the practical challenge is how to translate these principles into the way assurance is actually delivered.
I don’t think the answer is to prevent auditors and assurance providers from using AI. Quite the opposite. Used properly, it could help us analyse more evidence, identify patterns and inconsistencies, and allow auditors to spend more time on areas where human interaction and professional judgement really matter.
But scheme owners need to understand how it is being used. Some of the questions I think we should be asking are:
- Do we know where and how AI is being used within our assurance processes?
- Are auditors clear about what information they can and cannot put into these tools?
- Do our confidentiality requirements adequately cover AI?
- How much human verification should be required when AI has analysed evidence?
- Should the use of AI during an assessment be documented?
- Do auditor competence requirements need to change?
- Where is the line between AI supporting professional judgement and AI effectively making the judgement?
I don’t think we have all the answers yet. And with the technology developing so quickly, perhaps we shouldn’t expect to.
I am positive about what AI can bring to assurance. But if we want to benefit from it, we also need to become more comfortable talking about how we are using it and agree where the appropriate controls should sit.
If assurance is ultimately about trust, we need to be able to explain not only the conclusion we reached, but how we reached it.
How can TDi help?
At TDi Sustainability, we help organisations design, review and strengthen standards, assurance programmes and audit systems so they remain credible as technologies and working practices evolve. This includes helping scheme owners and assurance providers define appropriate governance, confidentiality safeguards, competence requirements, documentation processes and human oversight for the responsible use of AI. If your organisation is considering how AI should be integrated into its assurance processes without compromising trust, rigour or professional judgement, contact us to discuss how we can help.