
Everyone who has run an engagement knows what a prepared-by-client (PBC) list is. A PBC list is the audit team's request to the business under review, naming every report, extract and document needed to test a control. What it actually does is translate the test the auditor is running into language the owner can act on. That translation is where most engagements quietly lose a week, not in the sending or waiting, but in the imprecise phrasing that leaves control owners guessing.
AI agents can assist audit teams with drafting, routing, chasing and screening PBC requests. While modern agents can perform initial evidence sufficiency checks against specified control requirements, ultimate responsibility remains with the practitioner, it is the auditor who must apply professional skepticism and final judgment.
Throughout my career, I find that most teams naturally start by pointing an agent at automated reminders and escalations. While automating follow-ups yields quick wins, it merely scratches the surface. The greatest value lies further upstream in refining request specs and validating intake early, preventing delays before chasing even becomes necessary.
That upside matters more this year than it did two years ago. Internal audit functions reporting budget cuts nearly doubled between 2024 and 2025, from 11% to 19%, with staff cuts climbing from 11% to 18% over the same span, according to the 2026 North American Pulse of Internal Audit. Teams have less headcount and less room now to lose a week to an ambiguous request, which makes getting the request right the first time worth far more than it used to.
KEY TAKEAWAY An agent can draft, route, chase and screen a PBC request, and perform initial sufficiency checks against defined parameters. However, Standard 14.1 puts the final evaluation of sufficiency squarely on the auditor, tying it directly to professional skepticism. This division of labor allows the agent to clear the mechanical workload while the practitioner's judgment is focused where it matters most; on day one when a fix costs a simple clarification, rather than in week four during compressed testing.
Ask any audit team where the friction lives and three operational answers come up on repeat. Only one of them is strictly a technology problem, which is good news for what thoughtful automation can address.
1. The request is written in the auditor's head, not the owner's.
Take a real line item, the kind that shows up on work programs every quarter:
"Q3 user access review evidence."
The auditor knows exactly what that means: Which population, cutoff and export format are required. But the owner receives eight words carrying unstated assumptions and responds to the text literally. Here is the same request written as the auditor was actually thinking it:
Q3 user access review, all active accounts as of the 9/30 close, pulled from the system of record and not a cached export. Include reviewer name and approval date for each account. For any account flagged for removal, show the disposition. Reconcile against the HR termination report for the same period. Q3 means July 1 to September 30 on the fiscal calendar; confirm if the system reports on a different one.
This level of clarity yields two completely different outcomes. The detailed specification gets answered correctly the first time far more often. When clarification is still needed, such as addressing a cached export instead of a live pull, that conversation happens on day one rather than late in fieldwork. This translation work is where AI agents excel, removing the burden from control owners to reverse-engineer test requirements.
2. Follow-up becomes structured and reliable.
Once a request list goes out, manual chasing depends on who happens to have time to send a reminder. An agent that tracks and escalates on a schedule configured by the auditor closes that gap cleanly, ensuring responses are timely and complete.
3. Intake screening catches sufficiency issues early.
Standard 14.1 sets the benchmark: information must allow a competent person to re-perform the work and reach the same conclusion. Modern agents can execute initial sufficiency screens on intake, verifying parameters, dates and population boundaries immediately so missing elements can be rectified well before testing starts.
This isn't hypothetical anymore. According to the IIA’s 2026 North American Pulse of Internal Audit survey, generative AI has become a primary focus for internal audit, with functions increasingly prioritizing integration strategies that balance operational efficiency with robust practitioner oversight. For many functions, the core question is no longer whether to integrate AI agents into the PBC workflow, but how to deploy them securely while ensuring adherence to the Global Internal Audit Standards.
Four places, all work around each other. The first is the one that pays off the most.
Specification is where time is saved. Given a work program step and its control, an agent expands concise notes into complete attribute requirements: system, population, date range, approvals, format and rationale. The agent then routes requests directly to verified control owners, manages follow-up schedules and screens incoming files for initial sufficiency against those defined attributes.
Here's the same cycle, before an agent and after, with the column that matters most on the right.
Here is how the engagement workflow shifts when supported by AI agents:
The agent's role is to handle repetitive administrative steps. The auditor's role is the critical evaluation above it: Is this evidence truly sufficient and reliable? Even as agents (like AuditAI) conduct sophisticated sufficiency checks against parameters, determining context, underlying integrity and overall relevance remains an essential human judgment.
Consider a user access listing pulled from a staging environment. It may pass an automated check across every specified column, yet fail to represent true production controls. Catching those nuances requires practitioners who understand the system environment and business context.
This also highlights why attribute definitions require thoughtful preparation. Automated screening relies on the quality of its underlying rules, which is why prudent workflows require engagement leads to review and sign off on attribute templates before requests go out.
A balanced design is key: leverage agents to enforce consistency and complete preliminary checks, while empowering auditors to exercise final professional judgment. Each element serves its proper purpose.
Sound governance discipline applies here just as it does to any audit tool: Evaluating workflows against IIA and NIST frameworks ensures technology strengthens rather than compromises control standards. Four practical safeguards help ensure a smooth implementation:
The real goal isn't eliminating human effort from evidence gathering; it's addressing bottlenecks early so requests are well-defined from day one.
By allowing AI agents to manage mechanical tasks, audit teams gain valuable bandwidth to focus on core assurance priorities: Deep risk analysis, professional evaluation and strategic insights.
Mike Levy is a former Chief Audit Executive and CEO of Cherry Hill Advisory, a practitioner led internal audit, risk and assurance firm focused on helping organizations build modern, standards-aligned audit and risk functions, built on a human-led, AI-enabled approach to modern assurance.