Guides

KPMG says auditors must assure AI systems behind financial statements

KPMG is pushing auditors past statement-level checks: if AI shapes reporting, the model, data and controls need assurance too.

Lauren Xu··6 min read
Published
Listen to this article0:00 min
KPMG says auditors must assure AI systems behind financial statements
Source: kpmg.com

In KPMG’s May 11, 2026 finance survey, 93% of US companies said they will be deploying or scaling AI in finance within the next 18 months. If AI is helping draft estimates, classify transactions or surface anomalies, the job is no longer just checking the final financial statements. The control question now reaches into the systems, data and model logic that produced the numbers in the first place.

Why the assurance boundary is moving

Half said they already plan to orchestrate or develop multi-agent AI systems across finance workflows. The underlying Global AI in Finance 2026 survey covered 1,013 senior finance leaders across 20 countries and 13 sectors, including 163 US finance leaders.

AI use in finance has more than doubled in two years, with more than three-quarters of organizations using it in planning, reporting or commercial analysis. The harder part is not adoption. It is trust. KPMG found 71% of organizations report AI is meeting or exceeding ROI expectations, but only 23% say it is exceeding expectations. That gap shows finance teams are getting utility from AI, but not yet enough confidence to treat every output as control-ready.

For auditors and finance leaders, that means the old mindset is too narrow. Ledger checks, close timelines and workflow approvals still matter, but they are now only one layer. The new layer is AI governance: how the model is trained, how exceptions are handled, how changes are approved and how humans review the results before they hit reporting, forecasting or controls testing.

The assurance questions that matter

If a finance team wants to rely on an AI output, the first question is not whether the answer looks smart. It is whether the system that produced it is stable, explainable and governed well enough for the risk involved.

A practical checklist starts here:

  • What task is the AI actually doing: drafting, classifying, predicting, flagging anomalies or making a recommendation?
  • What data trained or fed the model, and who approved that data?
  • Can the team explain why the model reached this output, in terms a finance reviewer can test?
  • What changes were made to the model, prompts, thresholds or workflow rules since the last review?
  • What human review happens before the output affects reporting, forecast assumptions or control conclusions?
  • What exception handling exists when the model is wrong, incomplete or outside its training range?
  • What evidence can be produced quickly if an auditor asks how the output was generated?

Those questions are especially important for multi-agent systems, which half of surveyed US companies already plan to build or orchestrate across finance workflows. Once several agents are handing work off to each other, the risk is no longer a single bad recommendation. It is an opaque chain of decisions that can be hard to reconstruct after the fact.

What good AI assurance looks like

KPMG’s September 2025 AI Trust launch is the clearest sign that the firm is treating AI assurance as a service line, not a side conversation. The offering includes AI model risk assessments, AI model validation, real-time systems assessments and AI assurance or attestation. It also points to standards and frameworks such as SOC, FedRAMP, SWIFT and HiTrust, which gives clients a familiar language for testing control design and control operation.

The important part for managers is not the product naming. It is the shape of the work. Model risk assessments ask whether the AI is fit for purpose and aligned to the business use case. Validation tests whether the model behaves as intended. Real-time systems assessments matter because AI-enabled workflows can change faster than quarterly control cycles. Attestation, meanwhile, turns internal confidence into a defensible external position.

How this changes audit and finance work on the ground

The clearest near-term impact is on busy-season judgment. If an AI tool helps draft estimates or surface unusual journal entries, the reviewer cannot stop at “this seems right.” The reviewer has to ask whether the model has been trained on relevant data, whether its outputs are documented, and whether the business has a repeatable process for exceptions and overrides.

KPMG’s research found the organizations that can produce AI audit evidence efficiently are seeing better results. They report 33% versus 6% on error reduction and 42% versus 14% on confidence in scaling, depending on whether evidence production is efficient. That is not just a technology metric. It is a staffing and process metric. The firms that can document AI use cleanly will spend less time reconstructing decisions later.

People who can test AI-enabled processes, translate model behavior into control language and explain risk to a finance director or audit committee will be more valuable than people who only know how to check the finished workbook. That is true in audit, but also in advisory, where clients increasingly want help defining where AI can be trusted and where it cannot.

What managers should insist on before trusting an AI output

The fastest way to operationalize the framework is to treat AI like any other control-bearing process, except with a stronger requirement for evidence.

Before relying on an AI output in reporting, forecasting or controls testing, managers should require:

  • A named owner for the model or tool
  • A written description of the use case and its limits
  • Version control for models, prompts and workflow rules
  • A documented human review step for material outputs
  • A clear record of exception handling and escalation
  • Test results showing the model performs as expected on relevant cases
  • Evidence that data inputs are current, authorized and complete
  • A process for retraining or revalidation when the business changes

Assurance must move from the statement level to the systems level. In a traditional close, you test the entries and the controls around them. In an AI-enabled close, you also have to test the logic that helped create them.

Regulators are moving in the same direction

The UK Financial Reporting Council issued generative and agentic AI guidance on March 30, 2026, focused on audit-quality risks, possible mitigations and the professional judgment needed to gain confidence in AI outputs. It also published AI-in-audit documentation guidance on June 26, 2025, including an example tied to AI-enhanced journal procedures.

When standard-setters start publishing guidance on GenAI and agentic AI, it becomes harder to treat AI use as an experimental side project. The direction of travel is toward documented use, testable controls and explainable outcomes.

KPMG’s finance research points to another constraint: this is as much a people problem as a technology problem. Barriers include a lack of role-specific use cases and a lack of hands-on practice environments. In other words, finance teams are not only short on tools. They are short on safe places to learn how to use them without weakening control discipline.

This article was produced by Prism’s automated news system from verified source data, official records, and press releases, then run through automated quality and moderation checks before publishing. The system is built and supervised by the people who set the standards it runs under. Read our full AI policy.

Did this article answer your question?

Discussion

More KPMG News

KPMG says auditors must assure AI systems behind financial statements | Prism News