Auditors: would you trust an AI-drafted finding if every claim had to cite its source?
I've spent years as an ISO lead auditor, and the part that never got faster is
paperwork - the same finding re-typed into the checklist, the NC report, and the
audit report. Hours per audit, zero added judgment.
AI can obviously draft that text now. The real question isn't "can it write" -
it's "can a regulated profession trust it." Two things I keep coming back to:
1. Citations-or-flagged: an AI finding with no cited source doc is worthless (worse,
dangerous). If it can't cite, it should say "unsupported — verify," never invent.
2. Who decides: drafting ≠ deciding. Conformity, severity, certification — those
stay with the human. The moment software makes a cert decision, accreditation
trust is gone.
Curious how other auditors / consultants / compliance folks see it:
Would a cited-or-flagged draft actually save you time, or would you re-check
everything anyway?
Where would you NOT let AI near the audit?
(Full disclosure: I'm building in this space, so I'm biased - but I'm more
interested in where this breaks than where it works.)
Replies