{"resourceId":"oecd-public-audit-ai","versions":[{"version":"legacy/2026-08-29/oecd-public-audit-ai","resource":{"id":"oecd-public-audit-ai","title":"Public audit institutions are testing AI, but pilots rarely scale","organization":"Organisation for Economic Co-operation and Development","sector":"Public audit and oversight","geography":"Fourteen countries and the European Union","publishedAt":"May 7, 2026","sourceName":"The state of artificial intelligence in public audit: Evidence from selected countries and the European Union","sourceLabel":"OECD Artificial Intelligence Paper No. 58","sourceUrl":"https://www.oecd.org/en/publications/the-state-of-artificial-intelligence-in-public-audit_f4a6c658-en.html","evidenceClass":"independent-research","outcomeClass":"emerging","topics":["knowledge-work","developers-agents","infrastructure","data-security","governance-procurement","accessibility-workforce","operating-model"],"finding":"OECD consultations with 15 public audit institutions found growing experimentation in anomaly detection, document processing, knowledge management, and predictive risk assessment, but a persistent gap between pilots and scalable operational deployment.","sledRelevance":"State auditors, inspectors general, internal audit teams, grant overseers, and education-system assurance functions share the same document-heavy, risk-prioritization workload and the same duty to preserve defensible evidence and independence.","evidence":"The 58-page working paper documents use cases and common constraints across 15 institutions in 14 countries and the EU. It finds fragmented data, limited internal technical expertise, and evolving governance frameworks repeatedly blocking scale.","architectureImplications":"Build governed access to audit data, repeatable document and anomaly pipelines, reproducible model versions, evidence lineage, and analyst review into the audit platform rather than relying on ad hoc desktop use.","governanceImplications":"Preserve auditor independence, document model-assisted judgments, validate risk-scoring methods, segregate development from assurance where appropriate, and require accountable sign-off before AI-generated leads become findings.","securityPrivacyImplications":"Audit data can include investigations, personnel records, financial details, and security weaknesses; deployments need least privilege, compartmentalization, retention controls, tamper-evident logs, and secure model or retrieval hosting.","caveats":"The paper describes exploration and institutional experience rather than controlled productivity or audit-quality outcomes. Participating institutions are not a statistically representative sample of all public audit bodies."}},{"version":"enrichment/2026-09-05T02:33:27.019Z/oecd-public-audit-ai","resource":{"id":"oecd-public-audit-ai","title":"Public audit institutions are testing AI, but pilots rarely scale","organization":"Organisation for Economic Co-operation and Development","sector":"Public audit and oversight","geography":"Fourteen countries and the European Union","publishedAt":"May 7, 2026","publicationDate":"2026-05-07","eventDate":null,"sourceName":"The state of artificial intelligence in public audit: Evidence from selected countries and the European Union","sourceLabel":"OECD Artificial Intelligence Paper No. 58","sourceUrl":"https://www.oecd.org/en/publications/the-state-of-artificial-intelligence-in-public-audit_f4a6c658-en.html","evidenceClass":"independent-research","outcomeClass":"emerging","topics":["knowledge-work","developers-agents","infrastructure","data-security","governance-procurement","accessibility-workforce","operating-model"],"finding":"OECD consultations with 15 public audit institutions found growing experimentation in anomaly detection, document processing, knowledge management, and predictive risk assessment, but a persistent gap between pilots and scalable operational deployment.","sledRelevance":"State auditors, inspectors general, internal audit teams, grant overseers, and education-system assurance functions share the same document-heavy, risk-prioritization workload and the same duty to preserve defensible evidence and independence.","evidence":"The 58-page working paper documents use cases and common constraints across 15 institutions in 14 countries and the EU. It finds fragmented data, limited internal technical expertise, and evolving governance frameworks repeatedly blocking scale.","architectureImplications":"Build governed access to audit data, repeatable document and anomaly pipelines, reproducible model versions, evidence lineage, and analyst review into the audit platform rather than relying on ad hoc desktop use.","governanceImplications":"Preserve auditor independence, document model-assisted judgments, validate risk-scoring methods, segregate development from assurance where appropriate, and require accountable sign-off before AI-generated leads become findings.","securityPrivacyImplications":"Audit data can include investigations, personnel records, financial details, and security weaknesses; deployments need least privilege, compartmentalization, retention controls, tamper-evident logs, and secure model or retrieval hosting.","caveats":"The paper describes exploration and institutional experience rather than controlled productivity or audit-quality outcomes. Participating institutions are not a statistically representative sample of all public audit bodies.","streamIds":["state-government","local-government","campus-operations"],"roles":{"sales":"Interpretation — Customer problem: audit institutions experimenting with document processing or anomaly detection may struggle to turn pilots into defensible operations. Stakeholders: auditors, inspectors general, internal assurance, audit-data owners, IT/security, and workforce leaders. Discovery: which evidence-heavy task is bounded; how fragmented is the data; who can validate model-assisted leads; and where is technical capacity missing? Value hypothesis: governed data access and reproducible analyst support may improve a selected audit workflow without weakening independence. Potential engagement: readiness assessment and a limited document or risk-prioritization pilot. Unsupported claims: consultations with 15 institutions describe experience, not controlled productivity or audit-quality improvements; they do not support automated findings or a representative estimate of adoption barriers.","engineering":"Interpretation — Fit: restrict the initial system to a defined analyst-support task such as document processing or anomaly triage. Architecture and integration: connect governed audit data, repeatable pipelines, model versions, evidence lineage, and human review to existing audit workpapers. Prerequisites: usable data, a validation set, audit-method expertise, and clear separation of leads from findings. Constraints: fragmented records and limited technical skills may prevent a pilot from scaling; reproducibility matters more than a compelling demo. Security: compartmentalize investigations and personnel/financial records with least privilege, retention controls, secure hosting, and tamper-evident logs. Proposed proof: reproduce outputs on known cases, inspect false leads and missed evidence, and verify that reviewers can trace each suggested conclusion to source material.","delivery":"Interpretation — Work: prepare and authorize data, implement a reproducible pipeline, train analysts, and integrate sign-off into the audit method. Dependencies: data access agreements, technical support, methodological review, and time for analyst evaluation. Ownership: audit leadership preserves independence and accepts methods; data/IT teams operate access and versions; accountable auditors decide whether leads become findings. Skills and adoption: combine audit judgment with evidence-lineage and model-limit training, and segregate development from assurance where appropriate. Governance checkpoints: data authorization, method validation, pilot review, and any change affecting risk scoring. Proposed acceptance: sampled outputs are reproducible and traceable, reviewers identify and handle erroneous leads, and no finding bypasses accountable sign-off. Risks include automation bias, sensitive-data exposure, and a pilot without sustainable staffing."},"retrievedAt":null,"enrichedAt":"2026-09-05T02:33:27.019Z","enrichmentBasis":"archived evidence"}}]}