Guide for firmsAudit software evaluation

Audit automation software: how to test it before your firm relies on it

Ask the supplier to show you, on test data, how a conclusion traces back to its evidence. Then score only what you saw.

By A4 TeamPublished 6 October 2026Reading time 14 min

Short answerHow should an audit firm evaluate audit automation software?

Evaluate audit automation software by running one real procedure through it on fictional data. Trace the population from source to working paper, plant an exception, replace a document after review, then check sign-off, export and data terms. Rate each point by the evidence you saw, not the evidence you were promised. Under ISQM 1 the firm remains responsible for whether a tool it buys is appropriate to use, so a demo starts the evaluation. It does not finish it.

Key takeaways

  • Under ISQM 1, a firm that buys audit software remains responsible for whether it is appropriate to use on engagements.
  • Test one procedure end to end on fictional data, including a broken file, a planted exception and a change after review.
  • A working paper should show the work, the result, who prepared it and who reviewed it, as ISA 230 requires.
  • Rate what you saw, not what you were told. A claimed feature counts for half until it is shown.
  • Weighted coverage organises your follow-up. It is not a certification and it does not rank suppliers.

01What does audit automation software mean for an audit firm?

The phrase covers very different products. Search results for it mix external audit platforms with internal audit management, compliance automation for frameworks such as SOC 2, document-matching add-ins and general data analytics. A firm buying for statutory audit work needs to know which kind it is looking at before it compares anything.

For external audit, the useful question is narrow: which part of an engagement does the tool prepare, and what record does it leave for the auditor? Some tools import and test data. Some match documents to ledger lines. Some hold the whole engagement file, from planning to sign-off. Newer tools use AI agents to prepare the work. The more of the file a tool prepares, the more your evaluation should look at review, change control and exit.

Types of tool sold as audit automation, and the first thing to check for external audit work
Type of toolWhat it usually doesFirst thing to check
Engagement file platformHolds planning, programmes, working papers, review notes and sign-off for each engagementWhether a reviewer can follow every conclusion to its evidence, and whether an archived file stays locked and retrievable
Data analytics and testing toolImports ledgers or transaction data and runs tests across whole populationsHow the tested population reconciles to the source, and how exceptions are followed up
Document matching toolReads figures from invoices, statements or confirmations and ties them to schedulesWhat happens when a document cannot be read or a figure does not match
AI agents that prepare workDraft plans, run procedures and assemble working papers for a person to reviewWhat the agent may do alone, where a person must approve, and how each step is recorded
Internal audit or compliance platformManages audit plans, controls and evidence for an organisation's own assurance workWhether it suits external audit at all; many are built for internal audit or compliance frameworks

02What do the standards expect when a firm buys audit software?

Where a firm applies the IAASB's quality management standard, ISQM 1, buying a tool does not move responsibility to the supplier. ISQM 1 sets a quality objective that appropriate technological resources are obtained or developed, implemented, maintained and used (paragraph 32(f)), and another that resources from service providers are appropriate for use (paragraph 32(h)). Its examples of a service provider's resource include commercial software used to perform audit engagements, and it states that the firm remains responsible for its system of quality management.

ISQM 1 also lists matters a firm may consider for an IT tool (paragraph A100): complete and appropriate data inputs, confidentiality of the data, whether the tool operates as designed, whether its outputs achieve their purpose, the general IT controls behind it, the skills and training users need, and procedures that set out how it works. Paragraph A101 allows a firm to prohibit a tool, or some of its features, until it has been approved for use. That is a ready-made evaluation plan.

ISA 230 sets the bar for the working paper itself. Documentation must let an experienced auditor with no previous connection to the audit understand the procedures performed, the results and evidence, and the significant matters and judgements (paragraph 8). It must record who performed the work and when, and who reviewed it, when and to what extent (paragraph 9). Software that hides those facts behind a completion tick makes the requirement harder to meet, whatever its other strengths.

Guidance on audit technology is moving quickly, so check the status and date of anything you rely on. The table separates standards from guidance and from proposals. Which standards bind your firm, and from when, depends on the rules adopted where you practise. Confirm that with your technical lead.

Sources on audit technology, by status (checked 6 October 2026)
SourceStatusWhat it means for your evaluation
IAASB ISQM 1, paragraphs 32(f), 32(h), A100, A101, A105 and A107Standard. Systems of quality management had to be designed and implemented by 15 December 2022, where ISQM 1 appliesThe firm decides whether a purchased tool is appropriate and stays responsible for that decision
IAASB ISA 230, Audit Documentation, paragraphs 8, 9 and 14 to 16Standard, effective for audits of periods beginning on or after 15 December 2009Working papers must show the work, the results, the preparer, the reviewer and any later changes
IAASB support material on audit documentation with automated tools (23 April 2020)Non-authoritative. Does not amend the standards. Written before ISQM 1 took effectUseful examples; read them alongside the current standards
IAASB FAQ on the risk of overreliance on technology (18 March 2021)Non-authoritative. Does not amend or override the ISAsA prompt to question tool output and information produced by a client's systems
FRC Generative and Agentic AI Guidance (30 March 2026)UK regulator guidance aimed at firms' central technical teams. The FRC says it codifies good practice and does not change who is accountable.Three risk categories you can test in any AI-assisted tool
IESBA snapshot on ethics, independence and technology (11 June 2026)Explanatory publication on the existing CodeNames automation bias as a risk to professional judgement
IAASB exposure drafts revising ISA 330, ISA 500 and ISA 520 (5 August 2026)Proposals. Comments close 15 December 2026Not a requirement. Signals closer attention to the relevance and reliability of information used as evidence
IAASB board papers on technology quality management guides (meeting of 14 to 17 September 2026)Proposed guide and working draftNot final. One draft covers firm-level quality management before a tool is deployed
01Demo script

Run one procedure through the demo in five steps

Use the same fictional file with every supplier. Each step tests something a reviewer will rely on later.

  1. 01

    Load

    Import a fictional population. Reconcile what the tool tested to the source, including exclusions and mappings.

    Read this step: Load
  2. 02

    Break

    Feed it a broken file: a missing field, a duplicate, an out-of-period date. Note what is flagged and what is ignored.

    Read this step: Break
  3. 03

    Chase

    Plant a discrepancy and follow it to a person, the client's answer and a reviewer's decision.

    Read this step: Chase
  4. 04

    Review

    Open the working paper as the reviewer. Trace one result, then replace a document and watch the work reopen.

    Read this step: Review
  5. 05

    Score

    Check sign-off and the export of a completed file, then rate every criterion on what you saw.

    Read this step: Score

The scorecard further down turns these steps into ten weighted criteria and a list of gaps, heaviest first.

03How do you check the data and the population a tool tested?

Most automated testing starts with an import. Ask which records were included, which were excluded and how the imported population reconciles to the client's system. Ask to see the mappings and any transformations: changed account codes, merged fields, converted currencies or reformatted dates. A reviewer should be able to see the population actually tested, not assume it is the file someone uploaded earlier.

Where the data comes from the client's own systems, ISA 500 already requires the auditor to evaluate whether the information is reliable enough for the purpose, including evidence about its accuracy and completeness where necessary (paragraph 9). A tool that tests every line of an incomplete ledger has tested an incomplete ledger. Whole-population testing helps only when the population is right.

Then break the input on purpose. Use a fictional file and note what the tool does with each fault below. A good response is visible: the item is flagged, held back or sent to a person. A poor response is silence.

  • A missing mandatory field, such as a blank date or amount.
  • An exact duplicate transaction.
  • An entry dated outside the period under audit.
  • A file in the wrong format, or with a broken column header.

04What happens when the tool finds, or misses, an exception?

Plant a discrepancy in the demonstration data and follow it. Does it appear as an exception? Who receives it? Can the client's answer or a replacement document be attached to that item? Does the item stay open until a person with the right role accepts the explanation? Ask the supplier to show what happens when the explanation is not good enough.

A clean dashboard proves nothing until you have planted an exception yourself. The absence of alerts only tells you that the tool's rules found nothing. You still need to know what those rules test and what they cannot see. IESBA describes the opposite habit as automation bias: favouring what technology produced even when other information raises questions.

For tools that use generative or agentic AI, the FRC's March 2026 guidance gives a useful frame. It is UK guidance written for firms' central technical teams, and the FRC says it codifies good practice; it does not change who is accountable. It sorts the risks to audit quality into three categories, and each one turns into a demonstration question.

The FRC's three AI risk categories, turned into demonstration questions
FRC risk categoryWhat it meansAsk the supplier to show
Deficient outputThe output itself is wrong or incomplete, for example invented, omitted or distorted informationA case where the tool was wrong or unsure, and how the reviewer could see that
Misuse of outputThe output is appropriate, but people use it for something it was not designed to supportWhat the output is for, what it does not cover, and where the tool states its limits
Non-compliant methodologyThe firm's methodology lets the tool be used in a way that fails auditing standards, even when the output is rightHow the tool's procedures map to your methodology, and who in your firm approves that mapping
A clean dashboard proves nothing until you have planted an exception yourself.
From section 04 of this guide.

05Can a reviewer follow the working paper, its changes and its archive?

Open a prepared working paper as the reviewer would. Trace one result to its source, the procedure and the exception history. Check that it shows who prepared it and when, and who reviewed it, when and how far. Those are ISA 230 paragraph 9 facts, not extras. Comments and corrections should still make sense after a new version is created.

Then change something after review. Replace a source document or alter an input the procedure relied on. Ask how the tool flags the affected work, what it records about the change and how it sends the work back for review. A feature name in a sales deck does not settle this. The behaviour on screen does.

Finish at the end of the engagement. ISA 230 requires the final file to be assembled on a timely basis after the auditor's report, and the standard's explanatory guidance puts an appropriate limit at ordinarily not more than 60 days. After assembly, documentation must not be deleted before its retention period ends, which that guidance says is ordinarily at least five years from the date of the auditor's report, or of the group auditor's report if that is later. Any later change needs its reason, and a record of when it was made and reviewed and by whom. Ask how the tool locks a completed file, logs later changes and lets you retrieve an archived file years from now, including after the contract ends.

Ask the same about updates. ISQM 1 suggests considering how often a provider updates a tool and how it handles confidentiality of data (paragraph A107). The FRC treats version control of AI components as a mitigation, because an updated model can behave differently. You want to know how the supplier tells you before a change reaches live engagements.

06How do you score a supplier demonstration fairly?

Score evidence, not impressions. For each criterion, record one of three levels: ‘Evidence seen’, ‘Claimed, not shown’ or ‘Not available’. The scorecard below gives each criterion a weight from 1 to 3 and counts a claim at half its weight. The result is the share of weighted points you have actually seen, plus a list of gaps with the heaviest first.

A total can hide a problem. One weight-3 gap, such as no way to export a completed file, can matter more than several minor points. Decide each heavy gap on its own: ask for more evidence, test it in a pilot, accept it with a recorded reason, or stop. Keep the test file, what you observed and the follow-up owner in your notes.

Use the same scorecard and the same test file for every supplier. Keep the procurement paperwork alongside it: service terms, data processing terms, subprocessors, hosting, retention and exit. Ask for evidence behind any claimed assurance report or certification. A statement about where data is stored is not evidence of how it is protected.

02Supplier evidence scorecard

Score a supplier on the evidence you saw

After a demonstration or pilot, rate each criterion ‘Evidence seen’, ‘Claimed, not shown’ or ‘Not available’. Weights run from 1 to 3. A gap at weight 3 needs its own decision whatever the total.

  1. Purpose, limits and methodology fit (weight 2 of 3)

    The supplier shows what audit work the output supports, what it leaves to the auditor, and how its procedures map to your methodology.

  2. Source population traceable (weight 3 of 3)

    You can see which records were imported, excluded or transformed, and reconcile the tested population to the source system.

  3. Broken input gets a visible response (weight 2 of 3)

    A missing field, duplicate, out-of-period date or unreadable file is flagged, held back or sent to a person, not silently processed.

  4. Exceptions stay open until resolved (weight 3 of 3)

    A planted discrepancy is routed to a person, holds the client's answer, and closes only on a reviewer's decision.

  5. Working paper a reviewer can follow (weight 3 of 3)

    One result traces to source, procedure and exception history, showing who prepared and who reviewed it, and when.

  6. Changed evidence reopens review (weight 3 of 3)

    Replacing a document after review flags the affected work and records what changed, when and by whom.

  7. Roles and sign-off enforced (weight 2 of 3)

    Who can prepare, amend, review and sign off is set by role, and sign-off cannot be skipped or done by the wrong role.

  8. Automated and AI steps bounded and logged (weight 2 of 3)

    What runs without a person, where a person must approve, how each step is recorded, and how updates are announced before they reach live files.

  9. Data terms in writing (weight 3 of 3)

    Hosting, access, subprocessors, confidentiality, retention and whether your data trains any model, set out in the contract or data processing terms.

  10. Export, archive and exit (weight 3 of 3)

    A completed file exports in a usable format, and archived files stay locked and retrievable for your retention period, including after the contract ends.

How the result is worked out

Each criterion has a weight from 1 to 3. Each rating counts as a share of that weight: Evidence seen × 1, Claimed, not shown × 0.5, Not available × 0. A criterion you have not rated counts as no evidence.

Coverage is the sum of weight × share, divided by the sum of all weights. Gaps are every criterion below full evidence, highest weight first. It measures how much evidence you have seen, not how good a provider is.

07Where does Vacei fit?

Vacei describes itself as the operating system for accounting and audit firms. Its published audit workflow covers planning, testing by specialist agents, working papers with the evidence attached, and review and sign-off. VEE, the AI inside Vacei, prepares the audit plan for the auditor's approval, specialist agents run the procedures, and the auditor reviews every working paper and signs. Vacei's pages also describe preparer, reviewer and partner sign-off on every file, and a record of every step VEE takes.

Those are Vacei's own descriptions, not results of a test, and this guide does not rate Vacei. Its firm demo is a 30-minute walkthrough of the operating system, shown on sample data.

Vacei also offers outsourced audit support, which is a separate service: fieldwork and working papers prepared in your methodology for your review, with engagement acceptance, professional judgement, the opinion and the signature staying with your firm. Be clear whether a demonstration concerns the software, the service or both, because scope and responsibilities differ.

QuestionsAsked before you start

Common questions

What is the best audit automation software?

There is no single best tool for every firm. The right one depends on your engagements, your methodology and how much of the file you want a tool to prepare. Score each candidate on the same test file and the same criteria, then compare the gaps rather than the marketing. This guide does not rank suppliers.

Should a smaller firm use the same audit software as the largest firms?

Which software a large firm uses tells you little about what suits yours. Its methodology, engagement mix and in-house technical team are different. Judge any tool on whether it fits your methodology, your clients' data and your review process, using the same test file for every supplier.

Does audit automation software change who is responsible for the audit?

Responsibility stays where it was. ISQM 1 keeps the firm responsible for its system of quality management when it uses resources from a service provider, including commercial audit software. The FRC's March 2026 announcement says it plainly for AI: the human auditor is always accountable.

Can automated testing of every transaction replace sampling?

It can test every item in a population against a rule, but the result is only as good as the population and the rule. You still need evidence that the data is complete and accurate, and every exception still needs follow-up. Whether whole-population testing replaces other procedures on an engagement is a methodology judgement for your firm.

How should we document work done with an automated tool?

Apply ISA 230 as you would for any procedure: record what was tested, the specific items or population, the results, who did the work and when, and who reviewed it. The IAASB's 2020 support material gives examples for automated tools. It is non-authoritative and predates ISQM 1, so read it with the current standards.

What should we ask about AI features in audit software?

Ask what the AI may do without a person, where a person must approve and how each step is recorded. Ask how the supplier controls model and component updates and how you are told before behaviour changes. Then ask for one example where the AI was wrong or unsure, and how the reviewer could see it.

Can we use real client data in a supplier demo?

Start with fictional or properly anonymised data, and agree data handling in writing before any client records leave your firm. Confidentiality of data is one of the matters ISQM 1 lists for an IT tool. A realistic fictional file with the faults you want to test planted in it usually tells you more than a live client file.

Is a high score a certification or a recommendation?

Neither. The score is the weighted share of criteria where you recorded evidence. It does not assess audit quality, security or compliance, and it does not compare suppliers with each other. Use the gap list to decide what to ask for next.

MethodSources, limits and review

How this guide was prepared

Method and limits

This guide turns IAASB standards (ISQM 1, ISA 230 and ISA 500), IAASB support material, the FRC's March 2026 AI guidance and an IESBA snapshot into a demonstration script and a scorecard. Each source is listed with its status and date. Support material and the FRC guidance are not standards, and UK guidance does not set requirements elsewhere. Which standards apply to your firm depends on the rules adopted where you practise.

The scorecard multiplies each criterion's weight by the share for your rating (seen 1, claimed 0.5, not available or not rated 0) and divides by the total weight. The weights are this guide's editorial view of what matters most for external audit work. The result measures how much evidence you recorded, not how good a supplier or product is.

Statements about Vacei come from its published pages as checked on 6 October 2026. This guide does not test, certify or rank any product, Vacei included.

Related Vacei pages: How an audit runs on Vacei · Outsourced audit support · Pricing for firms.

Who prepared it

Author
A4 Team
Published
6 October 2026
Last substantive update
6 October 2026
Sources checked
6 October 2026

Sources

Next stepVacei

See how an audit runs on Vacei

A 30-minute firm demo of the operating system, shown on sample data. On Vacei, VEE plans the audit for your approval, specialist agents test, and the auditor reviews every working paper and signs.