There is a paradox sitting at the heart of technology risk audit: the function that examines the organization's technology is among the least technology-enabled in its own work. Data from a global survey of more than 200 internal audit leaders quantifies it.

The adoption numbers

  • Data analytics: only 33% of organizations use it in at least half of their audits — and it is the most mature and widespread of the three tools measured.
  • Generative AI: 13%.
  • Intelligent automation: 9%.

The study puts it elegantly: there is "plenty of room for improvement". The operational translation is harsher: most audit hours are still spent on tasks that current technology already knows how to do — locating information in long documents, reconciling populations, drafting repetitive work papers.

Where the real value of generative AI in audit is

According to the same study, the use cases with most potential are concrete and unglamorous — which is exactly what makes them valuable:

  • Document analysis: reviewing policies, contracts and extensive documentation in a fraction of the time.
  • Anomaly detection, including behavioural analysis to identify deviations across full populations rather than samples.
  • Technical translation: summarizing code and configuration files into understandable terms, letting auditors without deep technical profiles extract meaningful conclusions — what the report calls the "democratization of IT audit".
  • Automated compliance testing against regulatory standards, executable in real time.

The condition: use cases, not tools

The study's warning is equally clear: return is not guaranteed. Between licensing, support and training, adopting technology "because it's time" is expensive. Teams that capture value define the use case first — which task, which evidence, which output — and only then choose the tool.

And there is a line no adoption should cross:

Detection can be automated. Conclusions cannot. A tool that proposes findings without traceable evidence does not speed up the audit: it manufactures a quality liability someone will have to review twice.

The test for any tool

Three questions separate value from noise:

  1. Does it cut hours on repetitive tasks without taking the decision away from the auditor?
  2. Is every output traceable to the evidence that supports it?
  3. Can the team explain to a committee — or a regulator — how each conclusion was reached?

If all three answers are yes, the auditor's paradox has a solution. If any is no, the tool belongs to the risk universe, not to its coverage.