Co-authored with The Institute of Internal Auditors Malaysia
From audit planning and risk assessment to reporting and governance, how leading Internal Audit teams are using AI to do more with less.
Most CAEs in Southeast Asia are not short of ambition. They are short of time, people, and budget to match what the business expects from them.
Audit committees want more coverage. Regulators want faster responses. Business units want shorter cycle times. And the IA team in the middle is, in many cases, still running on spreadsheets, shared drives, and manually compiled reports.
The question most IA leaders are actually trying to answer is not “should we adopt AI?” It is: “where will it actually save us time, and is it worth the risk of getting it wrong?”
Internal audit functions across Southeast Asia are being asked to do more without a proportional increase in resources. Regulatory expectations have expanded in every major SEA market. The risk landscape has shifted, with cyber risk, third-party exposure, ESG obligations, and digital operations now demanding audit attention alongside traditional financial and operational risks.
A typical IA team covering a mid-sized listed company in Malaysia might have six to ten auditors responsible for a universe of eighty or more auditable entities. Add annual planning, regulatory reporting, and Audit Committee deliverables, and the capacity gap becomes visible very quickly.
The answer is not always headcount. More often, it is a question of where time is going and whether that time is actually producing audit value.
Before evaluating any AI tool, it is worth being honest about the productivity problem in IA. The time lost is not usually in fieldwork. It is in the work around the work.
Audit planning consumes more cycles than it should. Building the risk-based audit universe, scoring risks, calibrating audit frequency, and producing a plan that can withstand scrutiny from the AC is a months-long process for many teams. Much of it is manual, and much of it is repeated every year with marginal changes.
Documentation and workpaper preparation is where auditors spend a disproportionate share of their time relative to the judgment value it creates. Formatting, cross-referencing, version control, and sign-off workflows are real drains.
Report drafting is frequently cited by CAEs as the most time-intensive part of the audit cycle. A first draft that normally takes two to three days to produce, reviewed across multiple levels before it reaches the Audit Committee, is a candidate for meaningful reduction.
Risk assessments are often rebuilt from scratch each year despite drawing on similar inputs: prior findings, industry benchmarks, business unit inputs, and regulatory changes. The structure is familiar. The effort to produce it is not proportional to the incremental judgment involved.
“The time lost is not usually in fieldwork. It is in the work around the work.”
The productivity gains from AI in internal audit are real, but they are concentrated in specific tasks. Understanding where AI adds value, and where it introduces risk, is the starting point for any serious adoption conversation.
Audit universe creation and risk scoring. AI can ingest a combination of prior audit history, business unit data, regulatory updates, and industry risk libraries to generate a structured risk-ranked audit universe. What previously took weeks of manual consolidation can be produced in hours as a working draft for the CAE to review and refine. The judgment about final priorities stays with the auditor. The assembly work does not have to.
Control testing and sample analysis. Where audit evidence exists in structured data, AI can flag anomalies, identify outliers, and surface transactions that warrant closer review. This does not replace auditor judgment. It concentrates auditor time on the items that actually need it.
Workpaper review and quality checks. AI can review workpapers against a defined quality standard, checking for completeness, consistency of evidence citation, and alignment between findings and conclusions. What an experienced reviewer might spend a full day on can be surfaced in minutes as a checklist for human confirmation.
Report drafting. AI drafting of audit reports, based on approved findings and conclusions, is one of the highest-value time-saving applications available today. A structured first draft that the audit manager then edits and refines is a materially different workflow from one where the manager writes from scratch.
Start with time. Identify the five most time-intensive recurring activities in your IA function. Estimate hours spent annually. Apply a conservative reduction estimate for what AI can realistically deliver today. Convert hours to capacity.
In a team of eight auditors, recovering 15% of productive time is equivalent to adding more than one auditor without a headcount increase. That is the ROI case. It does not need to be speculative. It needs to be grounded in your team's actual activity data.
AI adoption in internal audit carries a specific irony: the function responsible for governance is now adopting technology that itself requires governance.
Before deploying AI in any audit workflow, IA leaders should be able to answer four questions:
What data is the AI accessing? Internal auditors work with some of the most sensitive information in the organisation — financial records, control weaknesses, HR data, and unpublished findings. The key question is how that information flows through any third-party AI tool, where it is stored, and whether the tool's data security and confidentiality standards are ones your organisation can stand behind.
Who is accountable for the output? AI-assisted workpapers and reports carry the name of an audit function. The standard for what constitutes a reviewed, approved, and defensible output does not change because AI produced the first draft. Accountability stays with the auditor who signs it.
How is the model being maintained? AI tools are not static. A risk scoring model trained on 2022 data and applied to a 2025 audit universe without recalibration is a governance risk, not a productivity tool.
Is this documented in your IA methodology? Regulators and Audit Committees will ask. If the use of AI in fieldwork and reporting is not reflected in your methodology and disclosed appropriately, that gap will surface at the wrong moment.
None of these questions are reasons to avoid AI. They are the due diligence that makes adoption sustainable.
The CAEs making the most progress on AI adoption are not the ones who launched the biggest transformation programmes. They are the ones who identified one specific, high-friction task and fixed it.
Start with reporting. Pick the most recent audit report that took the longest to produce. Use an AI drafting tool on the next comparable audit. Compare time, quality, and what the editing process reveals about your current drafting standards.
Move to planning. Use AI to generate a working draft of next year's risk-based audit universe. Run it in parallel with your existing approach before relying on it. The gap between the two outputs will tell you what the AI is missing and what it is getting right.
Then document your methodology update. Before expanding AI use to fieldwork and testing, get the governance documentation right. What tools, what data, what oversight, what sign-off. This protects the function and gives the AC confidence that the adoption is managed.
There is no single right sequence. The right starting point is the one where your team has a concrete pain point and can produce a measurable before-and-after.
Find out where your IA function actually stands.
Flexcore have developed the Audit Discovery Assessment [PIN: 7RCB-HTXX] to help IA leaders understand where their team's time is going, where AI can make the most immediate difference, and how their function compares to peers across Malaysia.