Internal Audit Tools, Analytics & Governance Portfolio

Colby Kellersberger, CIA, CFE, CICA LinkedIn GitHub

Prompt Engineering + AI Governance

Prompt engineering for review-ready internal audit documentation.

A governed prompt engineering framework designed around structured inputs, audit methodology guardrails, sampling discipline, non-fabrication rules, clarification triggers, and auditor review.

Prompt Engineering AI Governance Audit Methodology Documentation Standards Human Review
Governed prompt workflow Audit documentation support
01
Auditor-provided facts

Scope, evidence, samples, exceptions, and known limitations.

02
Prompt controls applied

Role limits, artifact type, non-fabrication rules, and clarification triggers.

03
Review-ready draft

Structured output remains subject to auditor review, validation, and judgment.

Demo note: This project is for demonstration and discussion purposes only. It uses generalized, synthetic, or public data. No proprietary company data, confidential audit documentation, internal systems, or client information are included.

Why this matters

AI-supported audit documentation needs controls, not just better writing.

Internal audit teams are increasingly likely to encounter AI-enabled drafting, summarization, and documentation support. The risk is not AI usage itself; the risk is uncontrolled prompting, unsupported assumptions, inconsistent workpaper language, and unclear accountability.

01

Reduce unsupported assumptions

Prompts should prevent invented controls, systems, populations, exceptions, conclusions, or management responses.

02

Improve documentation consistency

Reusable prompt patterns can standardize narratives, walkthroughs, test plans, testing results, and issue drafts.

03

Preserve auditor judgment

AI output should support drafting and structure, not replace evidence evaluation, conclusions, or final review.

Prompt quality demonstration

Generic prompts sound polished. Controlled prompts are more reviewable.

The issue is not whether AI output sounds professional. The issue is whether the output is supported, scoped, reviewable, and aligned with audit methodology.

Generic Prompt
“Write an audit issue for missing approvals.”

Output risks:

  • May invent policy criteria or control requirements
  • May assume root cause without support
  • May exaggerate impact or risk
  • May omit standard audit issue structure
  • May present unsupported conclusions confidently
Audit-Controlled Prompt
“Using only the facts provided, draft an internal audit issue using the structure: condition, criteria, cause, effect, risk, recommendation, and management response placeholder. Do not invent policy requirements, sample sizes, exceptions, root causes, monetary impact, or management intent. If required facts are missing, list clarification questions before drafting.”

Control benefits:

  • Uses a consistent audit issue format
  • Separates facts from assumptions
  • Prevents unsupported conclusions
  • Identifies missing information before drafting
  • Improves reviewer readiness

Key takeaway: Better prompts do not just create cleaner writing. They create more controlled, supportable, and review-ready audit documentation.

Framework workflow

Prompt design becomes a control point before drafting begins.

The framework defines inputs, constraints, output format, and review expectations before an AI-supported draft is generated.

1

Auditor-Provided Facts

Scope, process details, control descriptions, evidence, sample results, and known exceptions.

2

Prompt Controls Applied

Role limits, artifact type, scope boundaries, non-fabrication rules, and clarification triggers.

3

AI-Supported Draft

Structured narrative, walkthrough, test plan, testing summary, or issue draft.

4

Auditor Review

Auditor validates facts, revises language, evaluates support, and finalizes judgment.

Prompt control matrix

Controls that reduce unsupported or fabricated audit content.

The framework uses prompt-level controls to constrain AI behavior and improve consistency across audit documentation activities.

Role Definition

Defines AI as documentation support, not an auditor, decision-maker, or evidence evaluator.

Artifact Classification

Requires the user to identify the output type before drafting begins.

Scope Control

Limits outputs to the selected activity and prevents combining multiple audit artifacts.

Reference Hierarchy

Prioritizes audit methodology and user-provided facts over general AI assumptions.

Sampling Discipline

Prevents invented sample sizes, unsupported population assumptions, or inflated testing rationale.

Non-Fabrication Rules

Prohibits invented controls, systems, evidence, populations, exceptions, conclusions, or management responses.

Clarification Triggers

Requires follow-up questions when necessary information is missing, unclear, or inconsistent.

Human Review Requirement

Positions AI output as a draft that must be reviewed, validated, and finalized by an auditor.

Example use case

Issue drafting from auditor-provided testing results.

A practical application of this framework is converting auditor-provided facts and testing results into a structured issue draft while preventing unsupported conclusions.

Issue drafting Testing results Clarification triggers Review-ready output
Scenario

An access review identified four exceptions from a sample of twenty-five users where documented manager approval was not retained.

Controlled drafting approach

The prompt requires the auditor to provide policy criteria, testing period, population, sample basis, evidence reviewed, exception details, and known limitations before drafting.

Governance result

If criteria, cause, impact, or management response details are missing, the prompt asks clarification questions instead of inventing conclusions.

Prompt patterns demonstrated

Reusable prompt patterns for common internal audit documentation needs.

Narratives

Process narrative prompts

Structure end-to-end process descriptions using auditor-provided facts and defined scope boundaries.

Walkthroughs

Walkthrough prompts

Document control design understanding without inventing missing control details or unsupported observations.

Testing

Test plan prompts

Organize population, sample, attributes, evidence, and testing rationale into a repeatable structure.

Results

Testing result prompts

Summarize procedures performed, exceptions identified, and conclusions based only on provided results.

Issues

Issue drafting prompts

Support consistent finding language using condition, criteria, cause, effect, recommendation, and response structure.

Review

Clarification prompts

Ask targeted follow-up questions when facts are missing, unclear, inconsistent, or not supportable.

Audit value

Efficiency without compromising documentation discipline.

By embedding audit methodology and controls into prompt design, this framework shows how AI can support audit efficiency without compromising documentation quality, independence, or auditor accountability.

Consistency

Improves consistency in AI-supported audit documentation across narratives, walkthroughs, test plans, results, and issues.

Efficiency

Reduces drafting time while maintaining review discipline and supportability.

Governance

Demonstrates practical AI governance at the prompt-design level through defined constraints and human review.

Methodology alignment

Strengthens adherence to audit methodology, sampling expectations, documentation standards, and review requirements.

Important scope note

AI output supports drafting. It does not make audit decisions.

This project demonstrates prompt engineering concepts for internal audit documentation. It does not make audit decisions, approve controls, perform testing, evaluate evidence, or override auditor judgment.

Review requirement: Any AI-supported output should be reviewed, validated, and finalized by qualified audit professionals before use in formal audit documentation.

Prompt engineering

Structured prompts can make AI-supported audit documentation more controlled and review-ready.

Explore audit analytics, audit tools, or connect with me on LinkedIn.