← Back to Blog
AI & AuditAugust 22, 2026 · 9 min read · By Vikash Kumar

Can Auditors Use AI Without Sending Confidential Audit Data to the Cloud?

Why private, on-device AI could change how IT auditors approach ITGC, SOX, SAP and audit evidence analysis.

It is week three of fieldwork. Sitting in your working folder you have:

You could work through it manually. Or you could ask an AI to help — so you open a browser tab, and your cursor hovers over the upload button.

Would you upload all of that to a public AI chatbot?

Most auditors hesitate at exactly that moment. The hesitation is correct — it is professional instinct doing its job.

AI Has a Huge Opportunity in IT Audit

AI is genuinely good at the work that consumes audit hours:

The question is no longer whether AI can help auditors. The question is where the audit data is processed.

The Confidentiality Problem

Audit evidence is unusually sensitive, even by enterprise standards. In a single engagement you routinely handle:

Many organisations restrict where this material may be sent — not because cloud AI is reckless (it is not), but because those restrictions predate AI and AI did not repeal them. The honest framing is not "cloud AI is unsafe." It is a question every auditor should be able to answer about any tool they use:

Where does my data go?

If you cannot answer that in one sentence, you are not ready to upload.

Cloud AI vs Private AI

AspectCloud AIPrivate / On-Device AI
Data processingExternal infrastructureUser's device or browser
External APIOften requiredCan operate without an external AI API
Internet dependencyOften requiredCan support offline operation
Sensitive evidenceRequires governance and approvalCan remain on the device
Data boundaryExternal provider involvedLocal processing boundary
Audit use caseDepends on organisational policyUseful for privacy-sensitive workflows
Cloud AI versus on-device AI for IT audit Two data flows side by side. On the left, cloud AI: the auditor supplies audit evidence to a browser or application, which calls an external AI API running on cloud infrastructure, and a response returns. A dashed external boundary encloses the API and the cloud infrastructure. On the right, private on-device AI: the auditor supplies audit evidence to a browser or application containing a local AI model that returns a response, with a dashed local processing boundary enclosing everything on the auditor's device. The question underneath both is: where is the audit data processed? CLOUD AI PRIVATE / ON-DEVICE AI EXTERNAL BOUNDARY BELOW LOCAL PROCESSING BOUNDARY Auditor Audit Evidence Browser / Application External AI API Cloud AI Infrastructure Response Auditor Audit Evidence Browser / Application Local AI Model Response The key question: where is the audit data processed? Both models are legitimate. The difference is the boundary, not the safety.
Cloud AI and on-device AI differ in where audit evidence is processed, not in whether one is inherently safe.

One caveat, stated plainly

On-device AI does not mean "100% secure." Anyone who tells you otherwise is selling something.

It changes where your data goes. It does not remove the need for:

It narrows the data boundary. It does not eliminate the need to think.

What Is a Private AI Auditor?

Not a product category — a working pattern:

Private AI Auditor = AI assistance + local processing + audit-specific workflows + human validation

The third is the one people underrate: a generic chatbot does not know that SAP_ALL is a finding, that a bridging letter has required contents, or that a CUEC is the reader's problem. You can explain that every session — or the tool can already know it.

The private AI auditor workflow A seven-stage workflow. Audit evidence feeds private AI processing, which produces analysis, which produces potential exceptions and insights. Those pass to human auditor review, which produces the final audit conclusion, which becomes the workpaper and documentation. The first three stages are machine work; from human auditor review onwards the auditor is accountable. The governing principle is that AI assists and the auditor decides. AI ASSISTS THE AUDITOR DECIDES AuditEvidence Private AIProcessing on device Analysis PotentialExceptions hypotheses HumanAuditor Review Final AuditConclusion Workpaper AI assists. The auditor decides. Accountability does not move with the analysis.
The workflow shifts from machine analysis to auditor judgment at the review stage — and accountability stays there.

What Could an Auditor Actually Do With Private AI?

1. ITGC Testing

Upload your population and sample, and ask the AI to flag rows that look like exceptions against your test attributes. You decide what is actually an exception.

2. SAP Access Review

Analyse user and role information to surface potentially risky access — privileged profiles, dormant accounts with live authorisations, standard users that should have been locked. You confirm against the system.

3. SOD Analysis

Identify potentially incompatible access combinations and — more usefully — have the conflicting business activities explained, not just the technical role names. Our guide on what SOD analysis is and why it matters for SOX compliance covers the fundamentals, and the 15 S/4HANA conflict pairs external auditors flag first covers the ones that come up repeatedly. You validate every conflict.

4. Change Management

Review change tickets for approval, testing evidence, implementation records and separation between developer and implementer. You judge whether the evidence is sufficient.

5. SOC Report Analysis

Locate relevant controls, exceptions and complementary user entity controls, and get the audit implications summarised. If a period gap is involved, bridging letters have specific requirements worth checking against. You read the exceptions yourself.

6. Audit Evidence

Analyse screenshots, documents and tables — extracting a SUIM output into a table you can actually work with, rather than retyping it. You verify the extraction is faithful.

7. Risk Assessment

Summarise risk indicators across an environment and prioritise where auditor attention should go first. You own the risk conclusion.

8. Audit Documentation

Convert analysis into structured observations and workpaper content — condition, criteria, cause, effect, recommendation. You sign the workpaper.

AI assists the auditor. The auditor makes the final judgment.

A Realistic SAP ITGC Example

You are testing ITGC over an SAP S/4HANA environment, with the user listing, privileged access extract, role assignments, change tickets and configuration screenshots in hand. Here is what you might actually ask:

"Identify users with highly privileged SAP access and explain the potential audit risk for each."
"Review these change tickets and identify changes where approval evidence appears incomplete, or where the developer and implementer are the same person."
"Identify potential SOD conflicts in this role assignment extract and explain the conflicting business activities in plain language."
"Review this SAP screenshot and identify the evidence relevant to the control objective 'password parameters are configured in line with policy'."
"Summarise which of these 40 change tickets are emergency changes, and what retrospective approval evidence exists for each."
SAP ITGC evidence through AI analysis to auditor validation and workpaper Four columns. Input: SAP user listing, SAP roles, privileged access, change tickets and screenshots. Private AI analysis: access risk, segregation of duties indicators, change evidence, control-relevant information and potential exceptions. Human validation: review source evidence, confirm context, assess the control and apply professional judgment. Output: validated finding, audit documentation and workpaper evidence. A return arrow shows that anything not confirmed during validation goes back for further analysis. INPUT PRIVATE AI ANALYSIS HUMAN VALIDATION OUTPUT SAP User Listing SAP Roles Privileged Access Change Tickets Screenshots Access Risk SOD Indicators Change Evidence Control-Relevant Info Potential Exceptions candidates, not conclusions Review Source Evidence Confirm Context Assess the Control Apply Professional Judgment auditor is accountable here ValidatedFinding AuditDocumentation WorkpaperEvidence not confirmed → back for further analysis Nothing reaches a workpaper without passing through validation.
An SAP ITGC pipeline: AI narrows 4,000 rows to a shortlist; the auditor confirms each one against source evidence.

Every answer is a hypothesis, not a finding.

If the AI says user DDIC holds SAP_ALL, you open SUIM and confirm it. If it says a change lacks approval, you open the ticket. If it flags an SOD conflict, you check the actual authorisation objects — not just the role names.

The AI moved you from 4,000 rows to 12 candidates in a minute. That is the value. The last mile is yours, and it always was — anything you put in a workpaper, you can defend.

Where NextGen GRC GrcAI Fits

This is the problem NextGen GRC is trying to solve with the GrcAI Assistant.

The design premise: auditors should not have to choose between using AI and respecting the sensitivity of their evidence.

GrcAI is built so that the AI model runs in the browser, on the auditor's own machine. The model is downloaded once and the analysis modes are designed to work locally, so that for document and evidence analysis the content is processed on the device rather than sent to an external AI service.

That is the design intent, and it is the kind of claim you should confirm for yourself rather than take from an article — including this one. The checklist in the next section is written to be used that way.

It is built around audit work rather than general conversation. The workspace is organised into audit-shaped modes rather than a single chat box — among them Audit Prep, Workpaper Autopilot, Exception Triage, SOD Analysis, SAP Dev, Risk Score, Data Extraction & Generation, Data Analysis, Summarize and Code Review, with a separate SOC report analyser.

There is a longer write-up of the architecture in GrcAI: the private, on-device AI assistant for audit and GRC teams if you want the detail.

Why Purpose-Built AI Matters for Auditors

AspectGeneric AI chatbotGRC-focused AI workspace
Audit terminologyExplain it each timeAssumed
ITGC workflowsYou design the promptBuilt around the control cycle
SAP knowledgeGeneralTransaction codes, user types, authorisation objects
SODReasons from first principlesConflict logic already framed
SOC reportsReads it as a documentReads it as an audit artefact
Evidence analysisGeneric OCRTuned to audit evidence formats
Risk assessmentGeneric frameworksAudit risk language
WorkpapersYou reformat everythingStructured toward documentation
Privacy architectureProvider-dependentA design constraint from the start

The distinction is not intelligence — it is context. A general model is often perfectly capable; it just does not know your engagement, standards or evidence conventions until you tell it.

Which suggests the future may not be auditors using chatbots, but auditors working inside AI-powered audit environments. How generative AI is reshaping the ITGC testing lifecycle covers what changes stage by stage.

The Auditor Is Still in Control

AI should not replace professional judgment, evidence evaluation, control interpretation, sampling decisions, exception validation, risk conclusions, or auditor accountability.

That last one is not negotiable. When a regulator asks why a control was concluded effective, "the AI said so" is not an answer. PCAOB AS 2201 guidance on evaluating ITGCs has not changed because a model got faster.

AI can accelerate the work. It should not own the conclusion.

7 Questions Auditors Should Ask Before Using AI

Run any tool — including ours — through this:

  1. Where is my data processed?
  2. Does the tool send data to an external AI API?
  3. Is my data retained, and for how long?
  4. Can the tool work offline?
  5. What happens to uploaded audit evidence after the session?
  6. Can I validate the AI output against source evidence?
  7. Does my organisation have an AI acceptable-use policy — and does this comply with it?

If a vendor cannot answer 1 to 5 clearly and specifically, that is your answer.

The Future of AI in IT Audit

AI will become ordinary in audit work — not a pilot or an innovation initiative, just part of how testing gets done, the way data analytics did. But enterprise adoption will turn on two things together:

Capability + Trust

Capability alone produces demos that never clear the security review. Trust alone produces a tool nobody opens. The audit AI that succeeds will help auditors work faster while respecting the sensitivity of what they are working with — and be honest about what it cannot do.

In audit, an unverifiable answer is not a fast answer. It is a liability delivered sooner.

Want to explore private AI for IT audit and GRC?

You can try the NextGen GRC GrcAI Assistant and see how it handles your own evidence — the model is designed to run in your browser, so you can put it through the seven questions above, on your own evidence, before committing to anything.