From “AI-Assisted Auditing” to “Redrawing the Boundaries of Audit”
By Scott Shields – Contributing Writer – Capitol Times Media - From Conversations and Material of Zhu Weisha. Learn more about Zhu Weisha here at Capitol Times Media's July Magazine Issue
A Commentary on How Should Auditing Work in the AI Era?
The most noteworthy feature of How Should Auditing Work in the AI Era? is not the number of AI audit tools it proposes, but the way it reframes the question.
Most discussions of AI and auditing naturally focus on efficiency: Can machines read more documents, examine more transactions, detect anomalies faster, and reduce manual sampling? The article does not deny these changes but treats them as surface effects. It asks a different question: if a growing share of facts can be continuously recorded, comprehensively checked, and independently verified by machines, should the boundaries of an audit system built on information opacity and high verification costs also change?
Once that question is accepted, the discussion is no longer limited to “What can AI do for auditors?” It becomes “What still requires auditors?” That is the article’s decisive turn.
I. The Article’s Contribution Lies Less in AI Than in Re-explaining Why Audit Exists
The article places traditional auditing back within the architecture of credit. Enterprises possess the underlying facts; outside users cannot verify them directly. An independent third party therefore enters the organization, obtains records, examines evidence, and provides reasonable assurance to society. Sampling was not a sign of intellectual backwardness. It was a rational response to the cost of examining enormous volumes of activity.
AI changes precisely that cost condition. When machines can read large volumes of source documents, match them to ledgers, connect separate systems, and identify inconsistencies, many procedures that once depended on sampling can move toward comprehensive checking, while some low-frequency reviews can become continuous verification. From this, the article develops a useful two-axis structure:
Risk determines how much assurance is required; verifiability determines how that assurance is obtained.
The significance of this formulation is that it does not discard risk-based auditing in order to make room for a new theory. Risk remains, and the level of assurance is not reduced. What the article adds is a second variable: where facts already possess strong independent verifiability, there is less reason to repeat the same assurance work through the same human procedures.
The expression “audit work to be supplied = required assurance - existing verifiability” is not a directly computable formula. It describes an institutional relationship: audit effort need not automatically cover everything; it can increasingly concentrate on what has not already become independently verifiable.
II. “Audit Is Compensation for Unverifiability” Is the Article’s Strongest Proposition
The article closes with a concise proposition:
Audit is compensation for unverifiability.
This is more than a summary. It redefines the relationship among audit, transparency, and verification.
Bitcoin provides the article’s limiting case. For facts on a public ledger that anyone can independently verify under open rules, the value of having another institution sample the same records and ask society to trust its conclusion declines sharply. What must remain is verification, not necessarily repetitive audit in its traditional form. At the same time, exchanges, custodians, funds, and companies operating around Bitcoin may remain opaque and therefore still require audit.
The object of audit therefore no longer follows an industry label, asset class, or institutional name. It moves with unverifiability. The point can be compressed into one sentence:
Audit follows not the ledger, but the remaining black box.
This also explains why the article does not reach the simplistic conclusion that AI will eliminate auditors. As the boundary of direct verifiability expands, audit does not disappear as a whole. It retreats from what can already be verified and concentrates on completeness, significant judgment, system rules, controls, residual black boxes, and responsibility. The subject is therefore not merely a technical upgrade to auditing, but a redistribution of how credit is produced.
III. The Five-Level Scheme Turns an Abstract Idea into a Discussable Institutional Framework
If the article had stopped at “audit follows unverifiability,” it would still have offered a strong insight. The five levels of verifiability turn that insight into a framework that can be
developed further: natively verifiable; provable but not suitable for public disclosure; verifiable after authorization; low-verifiability black box; and unverifiable.
More important than the number five is the unit of classification. The article classifies facts, accounts, and business processes - not entire companies. A single company can contain several levels at once.
This avoids a major misreading. If a company were simply labeled “transparent” or “opaque,” the framework would quickly become crude. In practice, a public market price may be natively verifiable; customer data may be verifiable only under authorization; some internal processes may have incomplete evidence; and certain historical facts may no longer be verifiable at all. A financial statement is itself a combination of facts with different levels of verifiability.
The five levels are therefore not a new corporate rating system. They are a way to reallocate audit resources. Many practical questions remain unresolved, including the recognition criteria, evidence thresholds, and legal effects of each level. Those are matters for future standards and engineering work; they do not prevent the framework from being useful at the institutional level today.
IV. The Article’s Most Disciplined Move Is Refusing to Let AI Substitute for Evidence
AI auditing easily invites technological overconfidence. If AI can analyze enormous amounts of information, it can appear capable of reconstructing what must have happened in the past. The final article draws a firm boundary against that temptation:
The ledger is the index, source documents are the evidence, and the business process is the verification chain.
For an opaque organization, AI can use the ledger to locate a question, match it to source documents, and follow the surviving evidence step by step. But it cannot manufacture a past simply because a result looks plausible. Where the evidence stops, verification stops.
Reasoning cannot substitute for facts; plausibility cannot substitute for evidence.
The same discipline appears in the treatment of comprehensive checking. AI may check all ten million transactions that entered a system, but this proves only that all data inside the system were checked. It does not prove that every fact that should have entered the system actually did. A system can be internally 100 percent consistent while omitting transactions outside it.
“Complete data is not the same as complete facts” is one of the article’s most professionally important boundaries. The more comprehensive machine checking
becomes, the easier it is for people to forget to ask what the machine never saw in the first place.
V. AI Does Not Become the Answer; It Becomes a New Object of Audit
Once AI participates in bookkeeping, valuation, risk control, or audit itself, AI naturally enters the audit perimeter. The article calls for retaining model information, rules, permissions, versions, human overrides, and the basis for significant judgments. It goes further: even if logs are complete and execution is consistent, a system whose rules, permissions, or data entry points were maliciously designed cannot generate trustworthy conclusions merely by operating transparently.
This separates transparency from correctness. A flawed institutional design can be executed perfectly, and a defective rule set can leave impeccable logs. Verifiable thinking is therefore not a form of faith in technical traceability. Human beings must still judge whether rules are reasonable, evidence is complete, and responsibility is properly assigned.
The article also separates institutional roles: organizations bear responsibility for transparency and evidence retention; internal audit performs continuous internal checking; external audit provides independent verification; regulators set minimum transparency and verification requirements and supervise compliance; and final judgment and legal responsibility remain with people and institutions. Direct regulatory verification can reduce duplicated checking, but it cannot automatically replace independent assurance over significant judgments and residual black boxes.
The appendix’s five minimum review questions give this division of labor a practical floor: which facts are already directly verifiable; what “comprehensive checking” actually covers; which independent sources support completeness; which conclusions remain matters of professional judgment; and who controls, reviews, and ultimately takes responsibility for the AI used in verification and audit.
AI can therefore expand the radius of verification, but it cannot become the endpoint of legal responsibility.
VI. How Should the Article’s Innovation Be Assessed?
Internal coherence alone cannot prove that an idea has never appeared anywhere in the world. A rigorous originality claim still depends on prior literature searches, comparison with neighboring approaches, and conceptual tracing.
A more careful assessment is that adjacent directions already exist: continuous auditing, process mining, digital audit evidence, and verifiability in blockchain environments. The
article does not invent auditing from nothing. Its contribution is to reorganize these dispersed developments around verifiability as an institutional variable and to consolidate them into a coherent framework that can be debated.
Within that framework, verifiability is no longer merely an attribute of information quality; it becomes a second axis alongside risk. The central question is no longer only whether AI can replace sampling, but which facts no longer justify repetitive audit. Transparency is no longer measured simply by how much is disclosed, but by the level at which a fact can be independently verified. The value of audit, accordingly, shifts away from “seeing the black box on behalf of outsiders” and toward residual unverifiability, significant judgment, and responsibility.
The article’s value therefore lies not in a new slogan, but in bringing several technological and institutional developments into a bounded framework that can be tested, challenged, and refined by professional practice.



