NFRA sets 10 principles for technology use in audits, says AI cannot replace auditor judgement
Jul 24, 2026
The framework calls for pre-deployment validation, continuous monitoring and stronger data safeguards as audit firms increasingly use analytics, automated tools and AI, while warning against automation bias and over reliance on machine generated outputs.
The National Financial Reporting Authority (NFRA) has set out 10 principles for the use of technology in statutory audits, stressing that the growing adoption of data analytics, automated tools and techniques, artificial intelligence, generative AI and agentic AI cannot dilute the auditor’s responsibility for the audit opinion or the need to exercise professional scepticism.
In its first Staff Series on Technology in Audit, titled General Principles for Technology Adoption in Audit, NFRA has laid down a principles based framework covering the use of technology in audit planning and risk assessment, substantive and controls testing, evaluation of audit evidence and reporting.
The document says technology can improve audit efficiency by enabling entire population testing instead of sampling, speeding up risk identification and freeing auditors’ time for areas requiring professional judgement. At the same time, it flags risks arising from technology adoption, including automation bias, opaque or non deterministic outputs, model drift, data privacy exposure and the possibility that excessive reliance on technology could narrow rather than deepen professional scepticism.
The framework is technology neutral and outcome focused and applies across technologies ranging from conventional Computer Assisted Audit Techniques and data analytics to machine learning, generative AI and agentic AI. It applies equally to tools developed in house, licensed from third party vendors or embedded within a firm’s or network firm’s methodology.
Auditor responsibility remains non-delegable
A central principle in the document is that responsibility for the audit opinion remains with the auditor, irrespective of the sophistication of the technology used.
"Technology may inform and accelerate professional judgement; however, it cannot be a substitute for it and cannot be invoked to explain away an inappropriate conclusion," the document says.
It adds that "the audit report is signed by, and the opinion belongs to, an identified auditor and not to any technology or tool that has assisted in reaching it."
NFRA also makes clear that technology generated information does not carry a lower evidentiary threshold. Outputs from automated tools and techniques can be considered audit evidence, or an input to audit evidence, only after the auditor evaluates their relevance and reliability, understands the source, assesses the risk of manipulation or error and performs appropriate testing.
"There is no separate, lower evidentiary bar for technology generated information," the report says.
Professional scepticism cannot be delegated to technology
The document identifies automation bias as a key risk, noting that fluent and well presented machine output may encourage auditors to accept plausible looking results with less challenge than they would apply to human prepared information.
"Technology cannot be expected to exercise professional scepticism on the auditor's behalf," the report says, adding that it must be exercised by the person relying on the output, regardless of how convincing the technology generated result appears.
The document also cautions against assuming that full population testing conducted through a technology tool eliminates the need for substantive risk assessment.
It says auditors should not accept a tool’s classification of items as low risk without periodically testing that classification. It also cautions firms against relying on vendor claims regarding the accuracy or reliability of a tool without conducting an independent evaluation.
Risk based governance for audit technology
NFRA has called for validation, certification and review requirements to be applied in proportion to the risk a technology tool poses to audit quality.
The document distinguishes between low risk tools, such as translation aids, and higher risk applications, such as agentic tools that select and test samples, saying they should not be subjected to identical levels of scrutiny.
The report says a firm’s quality control or quality management system should identify technology use as a distinct risk area, with defined risk responses rather than treating technology generically as a resource.
Governance must come before deployment
The framework requires firms to validate and approve technology tools in accordance with their policies before they are used on live engagements.
It says material changes to a tool, including model updates, changes in data sources or vendor changes, should trigger revalidation. Initial validation before implementation, the document says, cannot be treated as the basis for continued reliability.
"Approval of a tool before deployment is only a starting point and not a complete exercise by itself," the report says.
Given the adaptive and non deterministic nature of some technologies, along with the pace of change in underlying systems, auditors are expected to monitor tool performance throughout its working life and reapprove tools when warranted.
The document also says the extent of explainability and documentation required for technology generated output should be proportionate to the materiality of that output to the audit opinion.
Data protection responsibility stays with audit firms
NFRA has stressed that audit firms remain responsible for protecting client and personal data processed through technology tools, including third party and cloud based systems.
The document says such data must be protected in accordance with firms’ confidentiality obligations under relevant ethical principles, the Digital Personal Data Protection Act, 2023, and other applicable sectoral requirements.
"A firm cannot rely on a vendor's terms of service (without validation) or on the convenience of a tool, as a substitute for its own responsibility to protect client and personal information," the report says.
The framework also calls for an appropriate information security framework covering cloud hosted and third party tools, with particular attention to cross border data transfers where a vendor’s infrastructure or model is hosted outside India.
Audit documentation and training to change
The document says technology adoption requires identifiable changes in how audit firms govern quality, document audit work, train personnel and monitor performance.
Audit documentation practices should move towards a structured format that allows an experienced auditor unconnected with the engagement to understand which tool was used to process a specific balance or assertion and the extent of human review applied to the resulting output.
NFRA also calls for technology literacy to be embedded in continuing professional development, with training differentiated by role.
Preparers should be trained in safe and effective use of technology, reviewers in critical evaluation and bias awareness, and engagement partners in governance and disclosure judgement.
The framework further calls for root cause analysis of technology related findings to feed into the annual evaluation of a firm’s system of quality management, with trends reported to leadership.
Greater scrutiny of technology vendors
NFRA has called on audit firms to strengthen oversight of third party technology providers.
Contracts with technology vendors should address data protection, intellectual property, access to explainability documentation, audit rights and business continuity, with particular attention to tools built on foundation models outside the firm’s direct control.
Where a tool is centrally contracted through a network or common technology platform, the firm must be able to demonstrate that network level due diligence and contractual protections meet the required substance, the document says.
The framework also calls for version control and internal communication whenever a material technology update could change a tool’s behaviour.
Technology does not replace existing audit standards
NFRA has clarified that the principles set out in the document do not create a separate technology based audit framework. The principles reiterate or clarify obligations that already exist under the Standards on Auditing, Standards on Quality Control and relevant ethical principles in the context of technology enabled audit processes.
The document says the overall objective is to ensure that audit opinions continue to rest on sufficient appropriate audit evidence obtained and evaluated with unimpaired professional scepticism, under a system of quality control or management that has absorbed the risks associated with the technology being used.
It does not mandate or prohibit the use of any specific tool, vendor or technique. However, auditors cannot treat the use of technology as a substitute for complying with the requirements of the underlying auditing standards.
NFRA has also clarified the status of the document. It says the Staff Series is intended to promote awareness of auditing standards and audit quality as part of its education, training, seminar and advocacy initiatives.
The document is not a policy, standard, recommendation or statement of the Executive Body of NFRA, the Authority or the Government, and is not issued as a substitute for any obligations of auditors or audit firms under applicable laws, rules and regulations.
[ET CFO]
