Audit 审计
1. 介绍
1.1 背景
审计是风险合规组中交付物本身就是证据的方向。其他方向的 AI 输出(风控评分、审查意见、告警结论)通常只在被质疑时才需要还原过程;而审计的工作底稿从诞生的第一天起,就是为了被财政部门、注协质量检查、监管机构乃至法庭调阅而存在的。
2025 年至 2026 年,全球审计准则体系针对 AI 做出了密集回应:国际审计与鉴证准则理事会(IAASB)于 2026-08-05 提议修订 ISA 330、ISA 500、ISA 520 三项核心准则,将审计证据的定义扩展至数字技术背景;国际内部审计师协会(IIA)的《Global Internal Audit Standards》(2024 版)于 2025-01-09 生效,并在 2026 年密集发布面向内审的 AI 工具套件;中国注册会计师协会则在 2026-03-05 发布风险防范提示,给出了目前中国监管侧对"审计中使用 AI"最直接的成文表态。
这些文本有一个共同结论,也是本方向的全文锚点:中注协 2026-03-05 提示明确指出——"在审计中使用人工智能工具,不能替代注册会计师专业判断,不减轻注册会计师对审计意见承担的责任。"国际会计师职业道德准则理事会(IESBA)2026 年发布的指南给出同一逻辑:无论自动化或技术复杂程度如何,专业会计师仍对其判断与决策负责。
这句话对 Harness 设计的含义是:审计方向 AI 化的目标不是"让 AI 出审计结论",而是让注册会计师在 AI 参与的情况下,依然有能力、有材料、有程序去承担这份不可转移的责任。承载这份责任的具体载体,就是证据链与工作底稿。
1.2 定义
Audit 审计方向的 AI Harness,是指承载财务报表审计、内部控制审计、信息系统(IT)审计、内部审计、持续审计与数字取证等任务的工程化运行层。其核心职责是把 AI 参与审计的全过程固化为可调阅、可复算、可追责的证据链,而不是提升审计报告的产出速度。
本方向覆盖五类任务:
| 任务类别 | 典型任务 | 输出形态 |
|---|---|---|
| 财务报表审计 | 银行流水全量核对、余额重算、关联方与对手方筛查、异常交易识别 | 异常线索清单,非审计结论 |
| 内部控制审计 | 信息系统一般控制(ITGC)与自动化应用控制测试 | 控制测试底稿与缺陷清单 |
| 内部审计 | 风险评估、全量数据分析、关键风险指标持续监控 | 内审发现与建议,非处理决定 |
| 持续审计 | KRI 阈值监测、周期性规则扫描、早期预警 | 预警信号,触发后续审计程序 |
| 数字取证 | 日志时间线重建、证据固定、哈希校验、取证报告 | 取证时间线与证据包 |
关键界定:审计方向的所有 AI 输出都是待验证的审计线索。中注协 2026-03-05 提示要求对 AI 识别出的异常情况"采取进一步审计程序确认是否存在重大错报风险"——AI 给的是线索,审计程序给的才是证据。这条"线索与证据分离"的原则,是本方向区别于其他方向的定义性特征。
1.3 在 AI Harness 体系中的定位
图 1-1|审计方向 AI Harness 六层定位(L1–L6 · L4 瓶颈层)
数据来源:基于本文分析绘制的示意图。
| 层 | 审计方向的承载内容 | 关键工程要求 |
|---|---|---|
| L1 上下文工程 | 审计准则、问题解答、历史底稿、账套与序时账、银行流水 | 准则原文必须带文号与施行日期;模型记忆不得作为准则内容来源 |
| L2 工具与执行 | 审计工作台、GRC 平台、CAAT 数据分析工具、企业信息官方核验接口 | 底稿写入为受控写工具;官方核验类只读工具优先级最高 |
| L3 编排与控制 | 风险评估 → 程序设计 → 线索生成 → 进一步程序 → 结论的流程化编排 | 职业怀疑插桩:AI 结论与人工核验之间强制插入验证节点 |
| L4 记忆与状态 | 审计工作底稿、证据链、版本快照 | 不可篡改的 append-only 审计轨迹,支持监管调阅——本方向的瓶颈层 |
| L5 评估与观测 | 异常确认率、底稿完整性、线索精确率与召回率 | 评估集是"历史项目 + 已确认错报",而非通用基准 |
| L6 治理与安全 | 涉密信息不出域、职责分离、底稿留痕 | 双重性:自身受治理,同时治理其他方向的 AI 系统 |
瓶颈在 L4。
审计的交付物是工作底稿,底稿的本质是"过程证据的持久化"。中注协 2026-03-05 提示按照《中国注册会计师审计准则第 1131 号——审计工作底稿》的要求,明确在审计工作底稿中应"充分、适当地记录使用人工智能工具的过程和结果,以及对结果的分析与采纳过程"。这意味着 Audit Harness 的 L4 不是"记忆",而是不可篡改的审计轨迹:不仅记录模型输出了什么,还要记录人为什么采纳或不采纳。
这一要求比其他方向的"留痕"更严格:其他方向的日志主要用于内部追责,而审计轨迹的预设读者是外部审查者——监管调阅时,"AI 建议 + 人工分析与采纳记录"必须构成完整的证明材料,缺一段都不合格。
与其他方向的关键差异:审计是风险合规组的元审计方向——它同时是本组 L6 的"被治理者"(自身要数据不出域、要留痕)与"治理者"(对 Finance、Compliance、Legal、Security 四个方向的 AI 系统实施审计)。这使得 Audit Harness 的 L4 与 L6 必须"自我适用":审计 AI 系统自身的日志与权限,就是它出具内审发现时的第一号被审对象。
1.4 价值与局限
价值:
- 全量数据分析替代局部抽样。审计行业正在从"周期性、抽样式、事后回顾"转向"全量数据分析、异常检测、预测性洞察"(据国际内部审计技术采用调研,Eulerich、Eulerich 与 Bonrath,Maandblad voor Accountancy en Bedrijfseconomie 第 99 卷第 4 期,2025)。抽样审计的覆盖盲区,是 AI 化最直接的收益来源。
- 结构化数据处理能力升级。中注协《中国注册会计师审计准则问题解答第 19 号——运用信息技术识别与应对舞弊风险》(2025-01-07 发布施行)给出的技术示例表明:OCR 与 AI 模型可将各种格式的银行流水原始文件自动清洗合并,自动重算每笔交易后余额并与原始余额比对,识别流水缺失或不连续——这类此前需要大量人工的机械核对,是确定性工具的强项。
- 持续审计成为可能。以持续审计规划周期替代传统年度风险评估,可对关键风险指标(KRI)做实时监测,在减少审计时间与投入的同时提升审计覆盖率(据 RSM US 公开发表的行业分析)。
- 取证效率提升。Google 将其开源协作式数字取证平台 Timesketch 扩展为具备 agentic 能力,由 Sec-Gemini 驱动自动执行初始取证调查,显著缩短调查时间(Google 官方,2025)。
局限(必须正视):
- 责任不可转移是硬约束。中注协锚句与 IESBA 指南共同表明:AI 的参与不改变责任主体。任何试图以"AI 说了算"稀释注册会计师责任的安排,在现行准则框架下都不成立。
- AI 线索的精确率未经证明前不可替代审计程序。AI 标记的异常只是"值得关注的候选",必须通过进一步审计程序确认;两者之间的转换环节不可省略。
- 证据不一致必须触发职业怀疑。中注协提示明确:如 AI 获取的审计证据与从其他来源获取的审计证据不一致,应保持职业怀疑,确定需要修改或追加哪些审计程序,并考虑该情形对审计结论的影响。
- 数据不出域是前置条件。未经客户授权或法律法规允许,不得将涉密信息输入或上传至公共的人工智能平台;在使用 AI 工具处理客户数据之前,必须确保技术环境、数据流转和访问权限处于安全和严格受控的状态。这意味着审计方向的 AI 基础设施必须以私有化或受控部署为主,公共模型平台只能处理脱敏后的非涉密任务。
2. 名词解释
| 术语 | 英文/缩写 | 释义 |
|---|---|---|
| 审计工作底稿 | Audit Working Papers | 注册会计师对制定的审计计划、实施的审计程序、获取的相关审计证据以及得出的审计结论作出的记录;中国准则依据为《中国注册会计师审计准则第 1131 号——审计工作底稿》 |
| 职业怀疑 | Professional Skepticism | 以质疑的思维方式评价所获取审计证据的有效性,并对相互矛盾的证据、以及对导致怀疑的异常情形保持警觉 |
| 审计证据 | Audit Evidence | 注册会计师为了得出审计结论和形成审计意见而使用的信息;IAASB 2026-08-05 提议修订 ISA 500 以反映数字技术背景下的证据形态 |
| 重大错报风险 | Risk of Material Misstatement / RMM | 财务报表在审计前存在重大错报的可能性;AI 识别出的异常须通过进一步审计程序确认是否构成 |
| 信息系统一般控制 | IT General Controls / ITGC | 支持应用系统持续有效运行的总体控制,含访问控制、变更管理、运维控制等 |
| 自动化应用控制 | Automated Application Controls | 嵌入业务系统中的自动化控制(如系统强制校验、自动勾稽);内部控制审计的重点对象 |
| 计算机辅助审计技术 | Computer-Assisted Audit Techniques / CAAT | 利用软件工具对被审计单位电子数据进行采集、转换、分析与比对的审计技术 |
| 持续审计 | Continuous Auditing | 以自动化方式在接近实时或短周期内对交易与控制执行审计程序的方法,替代传统年度风险评估周期 |
| 持续监控 | Continuous Monitoring | 管理层或内审对关键风险指标(KRI)进行的持续监测与预警 |
| 关键风险指标 | Key Risk Indicator / KRI | 用于度量风险水平变化并触发预警的量化指标 |
| 全量数据分析 | Full Population Analysis | 对总体数据而非样本执行分析,消除抽样盲区;区别于传统抽样式审计 |
| 财务舞弊 | Financial Statement Fraud | 被审计单位管理层或员工通过造假手段实施的舞弊;中注协问题解答第 18 号、第 19 号的主题 |
| 第三方配合舞弊 | Third-party Facilitated Fraud | 供应商、客户等第三方配合被审计单位实施的财务舞弊;问题解答第 18 号定义的识别对象 |
| 序时账 | Journal / General Journal | 按交易发生时间顺序记录全部会计分录的账簿;银行流水与序时账一一匹配是资金分析的核心程序 |
| 证据链 | Chain of Custody | 证据从获取、传递、保管到提交全过程的责任与状态记录;取证有效性的前提 |
| 数字取证 | Digital Forensics | 对电子数据进行识别、固定、分析并以可被采信的方式呈现的调查活动 |
| 仅追加日志 | Append-only Log | 只允许写入、不允许修改与删除的日志存储;审计轨迹的工程实现形态 |
| 三道防线模型 | Three Lines Model | IIA 发布的治理模型:第一线业务管理、第二线风险与合规职能、第三线内部审计;2026-07-08 更新 |
| 全球内部审计准则 | Global Internal Audit Standards | IIA 2024-01-09 发布、2025-01-09 生效的准则体系;Standard 10.3 要求内审职能确保获取必需的工具与技术 |
| 元审计 | Meta-audit | 对其他系统(含 AI 系统)的审计;审计方向对本组其余四个方向 AI 系统的角色 |
| 持续专业发展 | Continuing Professional Development / CPD | 执业人员为保持专业能力持续开展的学习;AI 技能已纳入内审招聘与培训考量(据 Deloitte 2025 调查转引) |
3. 案例
以下案例均取自监管机构、标准组织或企业官方公开材料,并标注取证等级;转述类资料已注明"据 XX 报道/转引"。
3.1 行业转型:从抽样审计到全量数据分析与持续审计
3.1.1 背景
传统审计建立在抽样逻辑上:以风险评估确定重点科目,再对余额与交易执行抽样测试。抽样在统计上成立,但在舞弊识别上存在结构性盲区——刻意隐藏的交易恰好落在样本之外。随着企业业务流程全面信息化,被审计数据呈全量电子化,审计行业出现了"能否直接对全量数据做分析"的技术条件;同时,IIA《Global Internal Audit Standards》(2024 版)于 2025-01-09 生效,其 Standard 10.3 要求内部审计职能必须确保获取履行职责所必需的工具与技术(据 IIA 官网文件页),从准则层面确认了"内审必须用技术"的定位。
3.1.2 方案
行业层面的转型路径呈现三个层次:
- 方法论转向:据国际内部审计技术采用调研(Eulerich、Eulerich 与 Bonrath,2025),技术带来的转变是从"周期性、抽样式、事后回顾"的审计,转向"全量数据分析、异常检测、预测性洞察",内审职能由被动转为主动。该调研同时指出采用挑战集中在数据隐私、网络安全风险、算法偏见与专业技能缺口四项。
- 持续审计落地:RSM US 的公开行业分析建议,2024 IIA 全球准则支持以持续审计规划周期替代传统年度风险评估以实现实时风险响应;引入集成第三方数据(关税更新、政策公告)的仪表盘或基于 AI 的情感分析实时跟踪地缘政治、经济与监管指标作为早期预警信号;持续监控 KRI 可在减少审计时间与投入的同时提升审计覆盖率。
- 技能与治理配套:会计师事务所已探索将大模型应用于数据分析、异常交易识别、风险评估等环节,审计人员得以从"合规性审计"转向"风险导向审计"(据行业公开报道);Deloitte 2025 年调查转引显示,84% 的内审人员表示 AI 技能在招聘新审计师时很重要(原始报告未获取)。
3.1.3 效果
- 准则层面:IIA 2024 全球准则将技术资源列为内审职能的必备条件,2026 年又陆续发布 AI Prompting for Internal Auditors(2026-08-18)、审计委员会 AI 覆盖问卷(2026-06-16)、董事会 AI 治理问卷(2026-06-16)等成套工具,使"AI 进入内审"从技术选择变为准则配套动作(IIA 官网文件清单,A 级)。
- 行业层面:全量数据分析使审计覆盖从样本扩展至总体,KRI 持续监控使年度风险评估变为实时风险响应(据 RSM US 与上述调研,B 级)。
- 需要如实指出的局限:中国侧持续审计与持续监控的量化落地案例与指标未获取 A/B 级一手来源(见信息缺口声明);内审 AI 采用率的权威统计数据亦未取得。
对 Audit Harness 设计的启示:全量分析与持续审计把审计从"年度项目"变成"常驻系统",这直接决定了 Harness 的形态——它不是一个工具调用助手,而是一个常驻的、有状态的数据分析平台:L4 必须承载持续积累的证据链,L5 必须以历史确认结论作为回归集。
3.2 监管框架落地:中注协 AI 风险防范提示与舞弊识别技术示例
3.2.1 背景
中国注册会计师行业对 AI 的监管表态集中在两份文件:一是《中注协提示会计师事务所在 2025 年年报审计中使用人工智能技术的风险防范》(2026-03-05,A 级),二是《中国注册会计师协会关于做好上市公司 2025 年年报审计工作的通知》(2026-01,A 级)。前者确立了使用 AI 的四条底线,后者明确了新技术环境下的审计程序要求;加上 2025-01-07 发布施行的审计准则问题解答第 18 号与第 19 号,构成中国侧"AI 审计"的完整监管框架。
3.2.2 方案(监管框架的四个支点)
- 数据安全:严格按照《会计师事务所数据安全管理暂行办法》《中国注册会计师职业道德守则》等要求,对职业活动中获知的涉密信息保密;未经客户授权或法律法规允许,不得向事务所以外的第三方披露涉密信息,不得将涉密信息输入或上传至公共的人工智能平台;使用 AI 工具处理客户数据之前,必须确保技术环境、数据流转和访问权限处于安全和严格受控的状态。
- 职业怀疑:对 AI 识别出的异常情况,需采取进一步审计程序确认是否存在重大错报风险;对 AI 提供的信息,可以通过官方平台获取的信息数据进行核实;如 AI 证据与其他来源证据不一致,应保持职业怀疑,确定需要修改或追加的审计程序。
- 底稿留痕:按《中国注册会计师审计准则第 1131 号——审计工作底稿》要求,在工作底稿中充分、适当地记录使用 AI 工具的过程和结果,以及对结果的分析与采纳过程;必要时可在审计业务约定书中与被审计单位就信息技术使用约定相关条款。
- 信息技术审计:《关于做好上市公司 2025 年年报审计工作的通知》指出,业务流程与信息系统紧密结合,可能出现利用技术权限进行隐蔽性舞弊的风险;要加强对信息系统本身控制的审计,重点关注信息系统一般控制和自动化应用控制的有效性;对于采用新技术的领域,如业务流程自动化、人工智能、云平台、大数据分析等,需要执行针对性的审计程序;应重视基础数据的质量与完整性,必要时利用信息技术领域专家的工作。
配套的《问题解答第 19 号》给出可直接工程化的技术示例:资金分析方向,以 OCR 与 AI 模型将各种格式的银行流水原始文件自动清洗合并,自动重算每笔交易后余额并与原始余额比对,识别流水缺失或不连续;再执行银行流水与财务序时账的一一匹配,识别"账有流水无"或"流水有账无"的异常资金交易。行为分析方向,对互联网平台销售虚假收入构建用户及商户行为分析模型(注册数据集中性分析、0—6 点不应有大量消费订单、节促后期未发货即退款、单日大额消费等);对手方分析检查交易规模与购销规模明显不匹配的客户或供应商、与实控人及董监高等关联方的资金往来、非工作日频繁或大额交易。
3.2.3 效果
这套框架的实际效果不体现为某个效率数字,而是划定了"AI 审计"在我国的合规边界:
- 责任锚句成立:"在审计中使用人工智能工具,不能替代注册会计师专业判断,不减轻注册会计师对审计意见承担的责任"(中注协,2026-03-05,A 级原文)。
- 技术示例使舞弊识别从"依赖经验"变为"可复现程序":银行流水的清洗、重算、匹配三步全部是确定性操作,其结果可复算、可写入底稿——这恰好是 AIxCC"确定性工具判定"范式在审计侧的对应物(见本组 README 第 5 章)。
- 第 18 号聚焦"第三方配合实施财务舞弊"的识别(为何强调职业怀疑、常见手段、第三方特征、如何识别与应对),与第 19 号共同构成"人防 + 技防"的组合。
对 Audit Harness 设计的启示:中注协四条底线可直接翻译为 Harness 的四项机制——数据安全对应 L6 出域拦截与受控部署,职业怀疑对应 L3 的"线索 → 进一步程序"强制插桩,底稿留痕对应 L4 的 append-only 轨迹,信息技术审计对应 L2 工具契约中的 ITGC 与自动化控制测试工具。
3.3 数字取证智能化:Timesketch + Sec-Gemini 与 FACADE
3.3.1 背景
审计与调查场景的取证工作长期面临两个瓶颈:一是日志与事件数据量大,人工重建时间线耗时;二是内部威胁的异常行为缺乏历史攻击样本可学。取证要求"证据链可被采信"——哈希校验、操作留痕、时间线可复现,这与 AI 的概率性输出天然冲突,因此取证方向是检验"AI 能力 ↔ 取证合规"能否兼容的最佳试金石。
3.3.2 方案
- Timesketch + Sec-Gemini(取证协作):Google 将其开源协作式数字取证平台 Timesketch 扩展为具备 agentic 能力,由 Sec-Gemini 驱动,利用 AI 自动执行初始取证调查,显著缩短调查时间,让分析师聚焦其他任务;该能力于 2025 年 Black Hat USA 大会演示(Google 官方,A 级)。方案的关键分工是:AI 执行初始调查(时间线初排、事件聚类),分析师执行验证与结论——取证报告的最终责任人仍是人。
- FACADE(内部威胁检测):Google 自 2018 年起用于保护其内部系统的内部威胁检测系统,采用对比学习(contrastive learning)技术,每天处理数十亿条安全事件,无需历史攻击数据即可识别内部威胁(Google 官方,A 级)。其方法论价值在于:绕开了"必须有历史攻击样本"的监督学习前提,用"正常行为画像的偏离"作为检测信号。
- 证据管理机制:两个系统的共同点是 AI 负责产生候选与初排,人负责确认;所有进入正式报告的证据仍需固定哈希与来源,保证取证链(Chain of Custody)完整。
3.3.3 效果
- 调查时间显著缩短,分析师从初始取证调查中解放出来(Google 官方表述,未披露具体倍数)。
- FACADE 以无监督方式运行多年,验证了"全量 + 无监督 + 常驻"这一持续监控形态在超大规模环境的可行性。
- 与本组 README 第 5 章的贯穿性结论一致:AI 产生候选与初排,确定性工具与人负责判定与固定——取证方向的可采信性没有被 AI 削弱,因为判定环节始终未交给概率。
对 Audit Harness 设计的启示:取证场景给出了"AI 参与不影响证据效力"的工程样板——只要 AI 的输出停留在"候选与初排"层,且最终证据经过哈希固定与人工确认,证据链的采信性不受影响。审计方向的取证模块应照此分层:AI 做时间线初排与异常聚类,人做证据固定与结论签署。
4. 实践标准
4.1 AGENTS.md 规范
以下为 Audit 审计方向建议的 AGENTS.md 全文。本文为建议稿,业界无官方标准,可直接复制后按机构实际情况裁剪。本文件继承组级 AGENTS.md(
AGENTS.md)的全部底线条款,以下为审计场景的加严 SOP。
# AGENTS.md —— Audit 审计
> 本文为建议稿,业界无官方标准。引用准则与监管文件为真实文本,落地方式为工程建议。
> 本文件继承组级 AGENTS.md 全部底线条款(证据链五元组、职责分离、人在回路、数据分级、
> 审计留痕、禁止事项),以下仅列审计方向的加严项。
## 角色与边界
- 角色:底稿整理者、数据分析者、异常线索生成者、控制测试执行辅助者、取证初排者。
- 不是:审计意见出具人、审计报告签署人、重要性水平确定者、审计结论决定者。
- 关键角色(三身份分离,继承组级并加严):
- 生成者:执行数据抽取、清洗、重算、比对、异常评分。
- 复核者(项目复核人):对 AI 线索的采纳与否作出专业判断并记录理由。
- 底稿保管人:管理 append-only 底稿库与证据链哈希,不参与生成与复核。
- 边界判定:凡准则要求注册会计师亲自判断的事项(重要性、意见类型、错报定性),
智能体只提供材料,不提供结论。
## 环境假设
- 存在审计工作台(底稿系统)与 GRC 平台,支持底稿编制、复核流转与版本管理。
- 存在 CAAT 数据分析环境,可对账套、序时账、银行流水执行采集、清洗、重算与比对。
- 存在企业信息官方核验渠道(如国家企业信用信息公示系统等官方平台),用于核实
AI 提供的信息(对应中注协 2026-03-05 提示"通过官方平台获取的信息数据进行核实")。
- 存在 append-only 底稿存储;智能体对底稿仅有追加权限,无修改与删除权限。
- 客户数据在受控环境内处理;公共模型平台仅接收脱敏后的非涉密任务数据。
## 上下文加载顺序(Context Budget)
1. 任务契约(审计阶段、科目范围、重要性参考、允许工具、确认点)。
2. 现行有效审计准则与问题解答(必须带文号与施行日期;含《审计准则第 1131 号》、
问题解答第 18 号、第 19 号、中注协 2026-03-05 风险防范提示要点)。
3. 内部审计手册与历史底稿(同科目、同行业的既往程序与结论)。
4. 本次任务原始材料(账套、序时账、银行流水、控制测试清单、日志)。
5. 补充资料(预算不足时最先裁剪)。
硬约束:准则内容一律取自准则库检索,不得取自模型记忆;每条被引用准则携带
`现行有效 / 已修订 / 历史版本` 标记。
## 工具契约
| 工具 | 风险等级 | 说明 |
|---|---|---|
| 准则与问题解答检索 | R0 | 只读,必须返回文号与施行日期 |
| 企业信息官方核验 | R0 | 只读,用于核实 AI 提供的企业与对手方信息 |
| 账套与流水读取 | R0/R2 | 按数据分级;涉密账套仅在受控环境处理 |
| 数据清洗与余额重算 | R1 | 输出可复算的中间结果,写入手稿区 |
| 异常线索评分 | R1 | 输出候选清单,标注评分依据 |
| 底稿写入(手稿区) | R1 | 可追加、可回滚;正式底稿由复核人确认后固化 |
| 底稿定稿与归档 | R2 | 复核人确认后写入 append-only 存储 |
| 审计意见与报告签署 | R3 | **永久关闭**;由签字注册会计师完成 |
## 任务执行流程(SOP)
1. 任务登记:审计阶段、科目、数据范围、数据分级、复核人。
2. 语料装载:准则库版本快照 + 历史底稿 + 本次数据,记录哈希。
3. 程序设计:按风险评估结果匹配程序清单(对应问题解答第 19 号的
资金分析 / 行为分析 / 对手方分析 / 关联方分析四类程序模板)。
4. 数据执行:清洗、重算、匹配、比对——全部使用确定性工具,中间结果可复算。
5. AI 线索生成:对全量数据生成异常候选清单,逐条附评分依据与指向的原始记录。
6. **进一步审计程序插桩(强制环节)**:每条 AI 线索必须绑定至少一项进一步审计
程序方可进入底稿;未确认的线索标注"待确认",不得作为审计证据引用
(对应中注协"采取进一步审计程序确认是否存在重大错报风险")。
7. 证据一致性检查:AI 证据与其他来源证据不一致时,自动生成"职业怀疑提示单",
列明冲突点与建议追加程序。
8. 人工复核:复核人逐条作出"采纳 / 不采纳 / 追加程序"决定,并记录理由。
9. 归档:底稿固化,绑定五元组证据链与链哈希,支持监管调阅导出。
## 验证与证据要求
- 每条 AI 线索的底稿记录必须包含:线索内容、生成依据(数据版本 + 程序模板版本 +
模型与提示词版本)、进一步审计程序及结果、复核人分析与采纳记录——
对应 1131 号准则"充分、适当地记录……以及对结果的分析与采纳过程"。
- 余额重算、账实匹配等程序必须输出可复算的中间结果;复核人可一键重放。
- 证据不一致情形必须留痕(职业怀疑提示单编号 + 冲突说明 + 处置决定)。
- 智能体不得在底稿中出现"AI 认为存在重大错报"类定性表述;只能出现
"工具标记异常 X 项,经程序 Y 确认/未确认"。
## 失败与升级策略
- 数据质量缺陷(流水缺失、账套不平)→ 停止分析,生成数据质量备忘录,转人工。
- AI 线索与人工判断冲突且无法由追加程序解决 → 转项目合伙人层面判断(L2 升级)。
- 发现利用技术权限实施隐蔽性舞弊的迹象(如超级账户异常操作、变更日志缺失)→
立即冻结现场快照,上报项目合伙人与信息安全负责人(L3 升级)。
- 官方核验渠道返回与 AI 提供信息不一致 → 以官方渠道为准,AI 信息作废并留痕。
## 安全与合规红线
- 未经客户授权或法律法规允许,涉密信息不得出域,不得进入公共 AI 平台
(中注协 2026-03-05 提示原文要求)。
- 处理客户数据前,确认技术环境、数据流转和访问权限处于安全和严格受控状态。
- 遵守《人工智能生成合成内容标识办法》(2025-09-01 施行):生成内容保留显式标识
(第 6 条)与元数据隐式标识(第 7 条);不得恶意删除、篡改、伪造、隐匿标识(第 10 条)。
- 遵守《中华人民共和国网络安全法》新增第二十条(2026-01-01 施行)关于全生命周期
风险监测评估的要求;信息系统控制审计同时满足 GB/T 45654—2025 对模型安全
(安全审计与漏洞修复、训练与推理环境隔离)的参照要求。
- 底稿与证据链留存期按审计准则与事务所制度取较长者。
## 禁止事项
1. 禁止以 AI 线索替代进一步审计程序。
2. 禁止在未记录"分析与采纳过程"的情况下将 AI 输出写入正式底稿。
3. 禁止修改或删除已固化底稿;发现底稿错误走"补充底稿"程序。
4. 禁止由智能体出具或暗示审计意见类型(无保留 / 保留 / 否定 / 无法表示意见)。
5. 禁止把模型记忆中的准则条文写入底稿。
6. 禁止跨项目复用未脱敏的客户数据作为其他项目语料。
7. 禁止隐瞒 AI 参与底稿编制的事实;参与程度必须可从底稿还原。
8. 禁止在证据链五元组不完整时执行归档。
## 输出格式
- 异常线索清单:编号、科目、线索描述、原始记录指针、评分与依据、确认状态
(待确认 / 已确认 / 已排除)、绑定程序编号。
- 控制测试辅助结果:控制项、测试步骤、样本或全量范围、结果、偏差说明。
- 取证初排:时间线(事件、来源、哈希)、异常聚类、待人工确认项。
- 每份输出附带:数据版本哈希、程序模板版本、模型与提示词版本、复核状态。
## 评估与自检
- 回归集:历史项目 + 已确认错报(Golden Dataset)。
- 核心指标:线索精确率(AI 标记异常中被确认为重大错报的比例)、
线索召回率(已知重大错报中被 AI 捕获的比例)、底稿完整性(五元组齐备率)。
- 自检:禁止事项逐条对照;输出格式逐段对照;证据链五元组逐项对照;
每条正式底稿可定位到复核人及其采纳理由。 4.2 SKILL.md 规范
以下为 Audit 审计方向建议的 SKILL.md 全文。本文为建议稿,业界无官方标准。该技能以中注协《审计准则问题解答第 19 号》的资金分析技术示例为蓝本工程化。
---
name: audit-bank-statement-reconciliation
description: 银行流水全量核对与账实匹配。对各种格式的银行流水原始文件做自动清洗合并、余额重算与序时账一一匹配,输出异常资金交易候选清单。适用于财务报表审计的资金分析程序与舞弊风险识别场景。
version: 1.0
created: 2026-09-12
---
# 银行流水全量核对与账实匹配
## 适用场景
- 适用:年报审计与专项审计中的资金分析程序;识别银行流水缺失或不连续;
识别"账有流水无"与"流水有账无"的异常资金交易;对手方与关联方资金往来筛查。
- 不适用:出具审计结论;对异常交易定性;替代函证与监盘等准则程序。
## 前置条件
- 已获取被审计单位各账户的银行流水原始文件与财务序时账导出数据。
- CAAT 数据分析环境可用,支持 OCR、格式归一化、余额重算与批量匹配。
- 数据在受控环境内处理;涉密账套未出域。
- 复核人已指定;程序模板(问题解答第 19 号资金分析类)已加载。
## 输入
| 输入项 | 必填 | 说明 |
|---|---|---|
| 银行流水原始文件 | 是 | 覆盖审计期间全部账户,格式可为 PDF / Excel / CSV |
| 财务序时账 | 是 | 与流水同一审计期间,含科目与对方科目 |
| 客户与供应商清单 | 是 | 用于对手方筛查 |
| 关联方清单 | 是 | 实控人、控股股东、董监高及其控制企业 |
| 审计期间 | 是 | 流水与账套期间必须一致 |
| 数据分级 | 是 | 涉密数据仅限受控环境 |
## 输出
| 输出项 | 说明 |
|---|---|
| 清洗日志 | 各文件格式、页数、解析成功/失败记录、失败原因 |
| 余额重算表 | 每笔交易后余额(重算值)与原始余额的比对,差异标记 |
| 流水完整性检查 | 缺失期间、断号、重复交易清单 |
| 账实匹配结果 | 一一匹配成功项、仅账有项、仅流水有项 |
| 异常候选清单 | 异常类型、金额、日期、对手方、原始记录指针、评分与依据 |
| 留痕信息 | 数据版本哈希、程序模板版本、模型与提示词版本、复核状态 |
## 执行步骤
1. 校验审计期间一致性与文件清单完整性;缺失文件直接列入异常候选。
2. OCR 与格式归一化:将各格式流水转为统一结构,保留原文页码/行号指针。
3. 逐笔重算交易后余额,与原始余额比对;输出差异项(对应"识别银行流水
缺失/不连续")。
4. 银行流水与财务序时账按日期、金额、对手方做一一匹配;输出三类结果
(匹配成功 / 账有流水无 / 流水有账无)。
5. 异常筛查(按程序模板):交易规模与购销规模明显不匹配的对手方;第三方
销售回款;与关联方的资金往来;非工作日频繁或大额交易;某月/某日/某时段
交易量突增突减。
6. 生成异常候选清单,逐条附原始记录指针与评分依据;不得给定性结论。
7. 自校验:清洗成功率、重算差异覆盖率、匹配三类结果齐备、候选清单字段完整。
8. 交付复核人执行进一步审计程序;每条线索绑定程序与结论后进入底稿。
## 质量标准(DoD)
- 一票否决:使用未覆盖审计期间的数据;清洗失败的文件被静默跳过;
候选清单中出现"疑似舞弊"等定性表述;未绑定进一步审计程序即写入正式底稿。
- 余额重算覆盖率 100%(审计期间内全部流水逐笔重算)。
- 匹配结果三类齐备,"账有流水无""流水有账无"两项不得为空(可为零,须显式声明)。
- 每条候选可回溯到原始记录指针(文件名 + 页码/行号)。
- 清洗日志与失败记录 100% 保留。
## 常见失败与处理
| 失败模式 | 表现 | 处置 |
|---|---|---|
| OCR 识别错误 | 金额或日期错位导致虚假差异 | 抽样回验原文;错误率超阈值时转人工处理该文件 |
| 流水覆盖不全 | 账户清单与实际获取文件不符 | 列入异常候选并升级,不得默认按已获取数据分析 |
| 跨账户转账重复计入 | 关联账户互转被当作外部交易 | 依据账户清单去重;去重规则写入留痕 |
| 序时账口径不一致 | 账套科目与流水对手方无法对应 | 生成映射缺口清单,转人工补录,不得推测匹配 |
| 时段异常误报 | 正常业务季节性被标记 | 保留标记但降级,注明"待业务确认";不得静默删除 |
## 示例
输入:
- 某公司 2025 年 1—12 月 6 个银行账户流水(PDF / Excel 混合格式)
- 同期序时账导出(CSV)
- 关联方清单:实控人 1 人、控股企业 3 家、董监高 5 人
输出(节选):
| 候选编号 | 异常类型 | 日期 | 金额(¥) | 指针 | 评分依据 | 确认状态 |
|---|---|---|---|---|---|---|
| C-014 | 流水有账无 | 2025-03-17 | [待填写] | 流水文件 B 第 42 页第 7 行 | 非工作日大额支出 | 待确认 |
| C-021 | 关联方往来 | 2025-06-30 | [待填写] | 流水文件 A 第 118 页第 3 行 | 实控人控制企业转入 | 待确认 |
| C-035 | 账有流水无 | 2025-09-12 | [待填写] | 序时账第 2,031 行 | 银行付款无对应流水 | 待确认 |
> 说明:金额等实际值必须以分析结果填充,示例中统一使用 [待填写] 占位。
> 每条候选交付时必须绑定进一步审计程序编号;未经确认不得作为审计证据。 4.3 落地检查清单
| 序号 | 检查项 | 检查方法 | 通过标准 |
|---|---|---|---|
| 1 | 数据不出域 | 数据流核查 | 涉密信息 100% 未进入公共 AI 平台 |
| 2 | 受控环境验证 | 环境审计 | 处理客户数据前技术环境、数据流转与访问权限已确认为受控状态 |
| 3 | 准则来源 | 底稿抽检 | 底稿引用准则 100% 来自准则库检索,带文号与施行日期 |
| 4 | 线索-程序绑定 | 底稿全量检查 | 每条进入底稿的 AI 线索 100% 绑定进一步审计程序 |
| 5 | 分析与采纳记录 | 底稿抽检 | 100% 记录复核人对 AI 结果的分析与采纳过程 |
| 6 | 证据一致性处置 | 提示单核查 | 证据不一致情形 100% 生成职业怀疑提示单并留处置结论 |
| 7 | 官方核验 | 线索抽检 | AI 提供的企业/对手方信息 100% 经官方渠道核实后方可引用 |
| 8 | 底稿不可篡改 | 权限与存储核查 | 智能体对已固化底稿仅有追加权限;链哈希可复算 |
| 9 | ITGC 覆盖 | 审计计划核查 | 内控审计覆盖信息系统一般控制与自动化应用控制 |
| 10 | 新技术针对性程序 | 审计计划核查 | 对 AI、自动化、云平台、大数据领域已设计针对性审计程序 |
| 11 | 职责分离 | 身份与凭证核查 | 生成者、复核者、底稿保管人三身份分离 |
| 12 | 意见签署 | 流程核查 | 审计意见 100% 由签字注册会计师出具 |
| 13 | 生成内容标识 | 产物抽检 | 显式标识与隐式标识 100% 保留,无删除篡改 |
| 14 | 评估回归集 | 评估记录核查 | 回归集为历史项目 + 已确认错报,非通用基准 |
| 15 | 监管调阅支持 | 演练 | 任一历史结论可在约定时限内还原数据版本、程序版本与复核记录 |
5. 总结
审计方向的 AI Harness,本质是一套把"责任不可转移"工程化为证据链机制的系统。
三点结论:
第一,责任锚点是全篇设计的第一原则。 中注协 2026-03-05 提示的"不能替代注册会计师专业判断,不减轻注册会计师对审计意见承担的责任",与 IESBA"专业会计师仍对其判断与决策负责"构成中外呼应。这句话不是免责提醒,而是架构指令:它意味着 Harness 的每一个设计决策,都要回答"注册会计师凭什么、用什么材料去承担这个责任"。答案是证据链五元组——输入快照、工具调用日志、输出、人工确认记录、哈希。缺任何一段,责任就悬空。
第二,线索与证据必须严格分层。 中注协要求对 AI 识别的异常"采取进一步审计程序确认是否存在重大错报风险",问题解答第 19 号则给出了进一步程序的具体工程化形态(清洗、重算、匹配、筛查,全部确定性可复算)。两者的组合就是审计版的"AIxCC 范式":模型负责在全量数据中提出候选,确定性程序与人负责判定。识别率的提升来自"编排层学会了何时调用哪个确定性工具",而不是模型更聪明。
第三,底稿的预设读者是外部审查者。 Audit Harness 的 L4 必须按"监管调阅"标准建设:append-only、链式哈希、可按任务/时间/人员/依据版本四维检索。同时,审计方向作为元审计者,其自身系统的日志、权限与治理状况,就是对其他四个方向 AI 系统出具内审发现时的第一号被审对象——审计 AI 必须先通过自己的审计。
必须正视的局限:本方向引用的行业转型数据(内审技术采用调研、Deloitte 调查转引、RSM 行业分析)为 B 级转述或原始报告未获取状态;中国侧持续审计与取证的量化落地案例未取得一手来源。效率数字在审计方向的重要性本就次于合规有效性——任何"提效"宣称,在缺少已确认错报作为回归集的情况下,都无法验证其是否以漏报为代价。
信息缺口声明
以下内容未能取得 A/B 级一手证据,文中已按"不编造"原则处理,使用时须另行取证:
- Deloitte 2025 内审调查的原始报告——"84% 的内审人员表示 AI 技能在招聘时很重要""超过 45% 认为 AI 工具培训影响最大"等数字为转引,原始报告未获取,。
- IIA《Global Internal Audit Standards》Standard 10.3 的原文措辞——仅取得 B 级转述,未取得准则原文逐句引用。
- 中国侧持续审计与持续监控的量化落地案例与指标——未获取 A/B 级一手来源;中国会计师事务所 AI 应用的公开量化效果数据亦未获取。
- 《中国注册会计师审计准则问题解答第 19 号》的官方全文链接——报告中的全文链接为第三方转载站(docs.maoyanqing.com),官方渠道链接 [待填写];本文引用其要点时以中注协官网发布页(cicpa.org.cn)为准。
- 国际内部审计技术采用调研(Eulerich 等,2025)中中国样本的占比与分项数据——未获取分项数据。
- "线索精确率 / 召回率"的行业基准值——审计行业无公开的 AI 异常识别基准值,文中指标定义为工程建议,基准值 [待填写]。
6. 参考资料
- 中注协提示会计师事务所在 2025 年年报审计中使用人工智能技术的风险防范 — 中国注册会计师协会,2026-03-05。https://cicpa.org.cn/xxfb/news/202603/t20260305_65842.html
- 中国注册会计师协会关于做好上市公司 2025 年年报审计工作的通知 — 中国注册会计师协会,2026-01。http://n.bicpa.org.cn/u/cms/www/202601/04161209co7c.pdf
- 中注协发布审计准则问题解答第 18 号、第 19 号 — 中国注册会计师协会,2025-01-07 发布施行。https://cicpa.org.cn/xxfb/news/202501/t20250123_65229.html
- IAASB 发布全球技术质量管理圆桌会议反馈汇总(240 余名六大洲利益相关方) — IAASB,2026-02。https://www.iaasb.org/news-events/2026-02/iaasb-publishes-global-roundtable-feedback-technology-and-quality-management
- IAASB 准则与发布文件列表(含 ISA 330 / 500 / 520 修订提议、Technology Position Catalog v2) — IAASB。https://www.iaasb.org/?page=35
- Global Internal Audit Standards 与 AI 审计工具(AI Prompting for Internal Auditors、AI Governance 问卷等) — The Institute of Internal Auditors,2024—2026。https://www.theiia.org/en/standards/documents/?category=audit+tools
- Evolving Role of Internal Audit(持续审计与 KRI 持续监控) — RSM US。https://rsmus.com/insights/services/risk-fraud-cybersecurity/evolving-role-of-internal-audit.html
- Cybersecurity updates: Summer 2025(Timesketch + Sec-Gemini、FACADE、Big Sleep) — Google,2025。https://blog.google/technology/safety-security/cybersecurity-updates-summer-2025/
- International survey on technology adoption in internal audit — Eulerich, Eulerich & Bonrath,Maandblad voor Accountancy en Bedrijfseconomie 99(4),2025,pp.181–193。https://mab-online.nl/article/153598/download/pdf/1412064
- 《中华人民共和国网络安全法》修改决定(主席令第六十一号)新增第二十条 — 全国人民代表大会,2025。http://www.npc.gov.cn/c2/c30834/202601/t20260105_450980.html
- GB/T 45654—2025《网络安全技术 生成式人工智能服务安全基本要求》解读 — 全国网络安全标准化技术委员会(SAC/TC260)。https://www.tc260.org.cn/tc260/hygd1/202403/b429d868525e48c3b7d12a0ec8f82e5e.shtml
- 关于印发《人工智能生成合成内容标识办法》的通知(国信办通字〔2025〕2 号) — 国家互联网信息办公室等四部门,2025。https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm
Audit
1. Introduction
1.1 Background
Auditing is the track in the Risk & Compliance group where the deliverable itself is the evidence. For other tracks, AI outputs (risk-control scores, review opinions, alert conclusions) usually only need to reconstruct the process when challenged; but an audit's working papers have existed from day one to be inspected by finance authorities, institute quality reviews, regulators, and even courts.
From 2025 to 2026, the global audit standards system responded intensively to AI: the International Auditing and Assurance Standards Board (IAASB) proposed on 2026-08-05 to revise three core standards — ISA 330, ISA 500, and ISA 520 — extending the definition of audit evidence into the digital-technology context; the Institute of Internal Auditors (IIA)'s Global Internal Audit Standards (2024 edition) took effect on 2025-01-09 and released a suite of AI tools for internal audit throughout 2026; and the Chinese Institute of Certified Public Accountants (CICPA) issued a risk-prevention notice on 2026-03-05, giving the most direct written position on the Chinese regulatory side regarding "the use of AI in auditing".
These texts share a common conclusion, which is the anchor for the whole of this track: the CICPA 2026-03-05 notice states explicitly — "Using AI tools in auditing cannot replace the CPA's professional judgement, nor does it reduce the CPA's responsibility for the audit opinion." The guidance issued by the International Ethics Standards Board for Accountants (IESBA) in 2026 sets out the same logic: regardless of the degree of automation or technical complexity, professional accountants remain responsible for their judgement and decisions.
What this means for Harness design is that the goal of AI adoption in the audit track is not to "let AI issue audit conclusions", but to ensure that, with AI involvement, the CPA still has the capability, the materials, and the procedures to bear this non-transferable responsibility. The concrete carrier of this responsibility is the evidence chain and the working papers.
1.2 Definition
The AI Harness for the Audit track is the engineered operational layer that carries tasks such as financial statement auditing, internal control auditing, information system (IT) auditing, internal auditing, continuous auditing, and digital forensics. Its core responsibility is to solidify the entire process of AI participation in auditing into an evidence chain that can be inspected, recomputed, and held accountable, rather than to accelerate the production of audit reports.
This track covers five categories of tasks:
| Task Category | Typical Tasks | Output Form |
|---|---|---|
| Financial Statement Audit | Full reconciliation of bank statements, balance recomputation, screening of related parties and counterparties, identification of anomalous transactions | Anomaly lead list, not an audit conclusion |
| Internal Control Audit | IT general controls (ITGC) and automated application control testing | Control-testing working papers and deficiency list |
| Internal Audit | Risk assessment, full-population data analysis, continuous monitoring of key risk indicators | Internal-audit findings and recommendations, not handling decisions |
| Continuous Auditing | KRI threshold monitoring, periodic rule scanning, early warning | Warning signals that trigger subsequent audit procedures |
| Digital Forensics | Log timeline reconstruction, evidence fixation, hash verification, forensic reports | Forensic timeline and evidence package |
Key defining note: all AI outputs in the audit track are audit leads pending verification. The CICPA 2026-03-05 notice requires that for anomalies identified by AI, "further audit procedures be taken to confirm whether there is a risk of material misstatement" — AI provides leads; it is the audit procedures that provide the evidence. This principle of "separating leads from evidence" is the defining feature that distinguishes this track from others.
1.3 Positioning in the AI Harness System
图 1-1|审计方向 AI Harness 六层定位(L1–L6 · L4 瓶颈层)
数据来源:基于本文分析绘制的示意图。
| Layer | Carried content for the audit track | Key engineering requirement |
|---|---|---|
| L1 Context Engineering | Audit standards, Q&A, historical working papers, ledger and journals, bank statements | Standard text must be accompanied by document number and effective date; model memory must not serve as a source for standard content |
| L2 Tools and Execution | Audit workbench, GRC platform, CAAT data analysis tools, official enterprise information verification interfaces | Working-paper writing is a controlled write tool; official verification-type read-only tools have the highest priority |
| L3 Orchestration and Control | Orchestrated flow of risk assessment → program design → lead generation → further procedures → conclusions | Professional-skepticism instrumentation: a mandatory verification node is inserted between AI conclusions and human verification |
| L4 Memory and State | Audit working papers, evidence chain, version snapshots | Tamper-evident append-only audit trail supporting regulatory inspection — the bottleneck layer of this track |
| L5 Evaluation and Observation | Anomaly confirmation rate, working-paper completeness, lead precision and recall | The evaluation set is "historical projects + confirmed misstatements", not a generic benchmark |
| L6 Governance and Security | Confidential information stays in-domain, segregation of duties, working-paper audit trails | Dual role: itself governed, while also governing the AI systems of other tracks |
The bottleneck is at L4.
The deliverable of auditing is the working paper, and the essence of the working paper is the "persistence of process evidence". The CICPA 2026-03-05 notice, following the requirements of China Standards on Auditing No. 1131 — Audit Documentation, makes it clear that the working papers should record "fully and appropriately the process and results of using AI tools, as well as the process of analyzing and adopting the results". This means that the L4 of Audit Harness is not "memory" but a tamper-evident audit trail: it must record not only what the model output, but also why a person adopted or did not adopt it.
This requirement is stricter than the "audit trail" of other tracks: other tracks' logs primarily serve internal accountability, whereas the intended reader of the audit trail is the external reviewer — when regulators inspect, the "AI recommendation + human analysis and adoption record" must form a complete supporting document; missing any part fails the check.
Key difference from other tracks: auditing is the meta-audit track of the Risk & Compliance group — it is simultaneously a "governed party" of the group's L6 (it must keep data in-domain and keep audit trails itself) and a "governor" (it conducts audits of the AI systems of the four tracks: Finance, Compliance, Legal, and Security). This means that the L4 and L6 of Audit Harness must be "self-applicable": the logs and permissions of the audit AI system itself are the first object examined when it issues internal-audit findings.
1.4 Value and Limitations
Value:
- Full-population data analysis replaces partial sampling. The audit profession is shifting from "periodic, sample-based, retrospective review" toward "full-population data analysis, anomaly detection, predictive insight" (per the international survey on technology adoption in internal audit, Eulerich, Eulerich and Bonrath, Maandblad voor Accountancy en Bedrijfseconomie, Vol. 99, No. 4, 2025). The coverage blind spots of sampling audits are the most direct source of gains from AI adoption.
- Upgraded structured-data processing capability. The technical examples in CICPA's Audit Standards Q&A No. 19 — Using Information Technology to Identify and Respond to Fraud Risk (published and effective 2025-01-07) show that OCR and AI models can automatically clean and merge bank-statement source files in various formats, automatically recompute the balance after each transaction and compare it with the original balance, and identify missing or discontinuous statements — mechanical checks of this kind that previously required heavy manual effort are a strength of deterministic tools.
- Continuous auditing becomes feasible. Replacing the traditional annual risk assessment with continuous-audit planning cycles enables real-time monitoring of key risk indicators (KRIs), increasing audit coverage while reducing audit time and effort (per RSM US's published industry analysis).
- Improvement in forensics efficiency. Google extended its open-source collaborative digital forensics platform Timesketch with agentic capabilities, driven by Sec-Gemini to automatically perform initial forensic investigations and significantly cut investigation time (Google official, 2025).
Limitations (must be faced squarely):
- Non-transferability of responsibility is a hard constraint. The CICPA anchor statement and the IESBA guidance together show that AI participation does not change the accountable party. Any arrangement that attempts to dilute CPA responsibility on the grounds that "AI decides" is untenable under the current standards framework.
- AI leads may not replace audit procedures before their precision is proven. Anomalies flagged by AI are only "candidates worth attention" and must be confirmed through further audit procedures; the conversion step between the two cannot be omitted.
- Inconsistent evidence must trigger professional skepticism. The CICPA notice is explicit: if audit evidence obtained by AI is inconsistent with evidence obtained from other sources, professional skepticism must be maintained, the procedures that need to be modified or added must be determined, and the impact of that situation on the audit conclusion must be considered.
- Data staying in-domain is a precondition. Without client authorization or legal/regulatory permission, confidential information must not be entered into or uploaded to public AI platforms; before using AI tools to process client data, the technical environment, data flows and access permissions must be ensured to be in a secure and strictly controlled state. This means the AI infrastructure for the audit track must be predominantly privately deployed or controlled, and public model platforms can only handle de-identified, non-confidential tasks.
2. Glossary
| Term | English / Abbreviation | Definition |
|---|---|---|
| Audit Working Papers | Audit Working Papers | The CPA's records of the audit plan developed, the audit procedures performed, the relevant audit evidence obtained, and the audit conclusions reached; under Chinese standards, per China Standards on Auditing No. 1131 — Audit Documentation |
| Professional Skepticism | Professional Skepticism | Evaluating the validity of the audit evidence obtained with a questioning mindset, and staying alert to contradictory evidence and to anomalous circumstances that give rise to doubt |
| Audit Evidence | Audit Evidence | Information used by the CPA to reach an audit conclusion and form an audit opinion; IAASB proposed on 2026-08-05 to revise ISA 500 to reflect evidence forms in the digital-technology context |
| Risk of Material Misstatement | Risk of Material Misstatement / RMM | The possibility that the financial statements contain a material misstatement before the audit; anomalies identified by AI must be confirmed through further audit procedures as to whether they constitute such a risk |
| IT General Controls | IT General Controls / ITGC | Overall controls supporting the continued effective operation of application systems, including access control, change management, and operations control |
| Automated Application Controls | Automated Application Controls | Automated controls embedded in business systems (e.g. system-enforced validation, automatic reconciliation); a key focus of internal control audits |
| Computer-Assisted Audit Techniques | Computer-Assisted Audit Techniques / CAAT | Audit techniques that use software tools to collect, transform, analyze, and compare the audited entity's electronic data |
| Continuous Auditing | Continuous Auditing | A method of performing audit procedures on transactions and controls automatically on a near-real-time or short-cycle basis, replacing the traditional annual risk-assessment cycle |
| Continuous Monitoring | Continuous Monitoring | Ongoing monitoring and early warning by management or internal audit over key risk indicators (KRIs) |
| Key Risk Indicator | Key Risk Indicator / KRI | A quantitative indicator used to measure changes in the level of risk and to trigger early warning |
| Full Population Analysis | Full Population Analysis | Performing analysis on the entire population rather than a sample, eliminating sampling blind spots; distinct from traditional sample-based auditing |
| Financial Statement Fraud | Financial Statement Fraud | Fraud committed by the audited entity's management or employees through falsification; the subject of CICPA Q&A No. 18 and No. 19 |
| Third-party Facilitated Fraud | Third-party Facilitated Fraud | Financial statement fraud in which third parties such as suppliers and customers facilitate the audited entity; the identification target defined by Q&A No. 18 |
| Journal / General Journal | Journal / General Journal | The ledger recording all accounting entries in chronological order of the transactions; one-to-one matching of bank statements and journals is a core procedure of funds analysis |
| Chain of Custody | Chain of Custody | The record of responsibility and status of evidence throughout acquisition, transfer, custody, and submission; a precondition of the validity of forensic evidence |
| Digital Forensics | Digital Forensics | Investigation activity that identifies, fixes, analyzes, and presents electronic data in a way that can be accepted as evidence |
| Append-only Log | Append-only Log | Log storage that permits writes only and does not allow modification or deletion; the engineering implementation form of the audit trail |
| Three Lines Model | Three Lines Model | A governance model issued by the IIA: first-line business management, second-line risk and compliance functions, third-line internal audit; updated 2026-07-08 |
| Global Internal Audit Standards | Global Internal Audit Standards | The standards system issued by the IIA on 2024-01-09 and effective 2025-01-09; Standard 10.3 requires the internal audit function to ensure it obtains the tools and technology necessary to perform its duties |
| Meta-audit | Meta-audit | The audit of other systems, including AI systems; the audit track's role toward the AI systems of the group's other four tracks |
| Continuing Professional Development | Continuing Professional Development / CPD | Ongoing learning practitioners undertake to maintain professional competence; AI skills have been incorporated into internal-audit hiring and training considerations (per Deloitte 2025 survey, as relayed) |
3. Case Studies
The following cases are all drawn from public materials of regulators, standards bodies, or enterprises, and are labeled with their evidence grade; relayed materials are marked "per XX report / as relayed".
3.1 Industry Transformation: From Sample-Based Auditing to Full-Population Data Analysis and Continuous Auditing
3.1.1 Background
Traditional auditing is built on a sampling logic: risk assessment identifies key account areas, and then sample tests are performed on balances and transactions. Sampling is statistically sound, but it has a structural blind spot in fraud identification — deliberately hidden transactions happen to fall outside the sample. As enterprise business processes became fully informatized and the audited data became fully digital, the audit profession gained the technical conditions to ask "can we analyze the full population directly"; at the same time, the IIA's Global Internal Audit Standards (2024 edition) took effect on 2025-01-09, and its Standard 10.3 requires the internal audit function to ensure it obtains the tools and technology necessary to perform its duties (per the IIA's official document pages), confirming at the standards level that "internal audit must use technology".
3.1.2 Approach
The industry-level transformation path runs through three layers:
- Methodological shift: according to the international survey on technology adoption in internal audit (Eulerich, Eulerich and Bonrath, 2025), the change driven by technology is from "periodic, sample-based, retrospective review" auditing toward "full-population data analysis, anomaly detection, predictive insight", shifting the internal audit function from reactive to proactive. The survey also notes that adoption challenges concentrate on four items: data privacy, cybersecurity risk, algorithmic bias, and professional-skills gaps.
- Continuous auditing in practice: RSM US's public industry analysis recommends that the 2024 IIA global standards support replacing the traditional annual risk assessment with continuous-audit planning cycles to achieve real-time risk response; introducing dashboards that integrate third-party data (tariff updates, policy announcements) or AI-based sentiment analysis to track geopolitical, economic, and regulatory indicators in real time as early-warning signals; and continuously monitoring KRIs to increase audit coverage while reducing audit time and effort.
- Skills and governance support: accounting firms have explored applying large models to areas such as data analysis, anomalous-transaction identification, and risk assessment, allowing auditors to move from "compliance-based auditing" toward "risk-oriented auditing" (per industry public reports); a Deloitte 2025 survey as relayed shows that 84% of internal auditors said AI skills are important when recruiting new auditors (original report not obtained).
3.1.3 Results
- At the standards level: the IIA 2024 global standards list technical resources as a necessary condition of the internal audit function, and in 2026 successively released a suite of tools including AI Prompting for Internal Auditors (2026-08-18), the audit committee AI coverage questionnaire (2026-06-16), and the board AI governance questionnaire (2026-06-16), turning "AI in internal audit" from a technology choice into standard-backed supporting actions (IIA official document list, Grade A).
- At the industry level: full-population data analysis extends audit coverage from samples to the whole population, and continuous KRI monitoring turns the annual risk assessment into real-time risk response (per RSM US and the above survey, Grade B).
- A limitation that must be stated honestly: no A/B-grade primary source was obtained for the quantified adoption cases and indicators of continuous auditing and continuous monitoring on the China side (see the information-gap statement); nor were authoritative statistics on internal-audit AI adoption rates obtained.
Implications for Audit Harness design: full-population analysis and continuous auditing turn auditing from an "annual project" into a "permanent system", which directly shapes the form of Harness — it is not a tool-calling assistant but a permanent, stateful data-analysis platform: L4 must carry the continuously accumulated evidence chain, and L5 must use historically confirmed conclusions as its regression set.
3.2 Regulatory Framework in Practice: CICPA AI Risk-Prevention Notice and Fraud-Identification Technical Examples
3.2.1 Background
The Chinese CPA profession's regulatory position on AI is concentrated in two documents: first, the CICPA Notice on the Risk Prevention of Using AI Technology by Accounting Firms in the 2025 Annual Report Audit (2026-03-05, Grade A); second, the Notice of the Chinese Institute of Certified Public Accountants on Doing Well the 2025 Annual Report Audit of Listed Companies (2026-01, Grade A). The former establishes four bottom lines for the use of AI, and the latter clarifies audit-procedure requirements in the new-technology environment; together with Audit Standards Q&A No. 18 and No. 19 issued and effective on 2025-01-07, they form the complete regulatory framework for "AI auditing" on the China side.
3.2.2 Approach (the four pillars of the regulatory framework)
- Data security: in strict compliance with the Interim Measures for Data Security Management of Accounting Firms, the Code of Professional Ethics for Chinese Certified Public Accountants, and similar requirements, keep confidential information learned in professional activities secret; without client authorization or legal/regulatory permission, do not disclose confidential information to third parties outside the firm, and do not enter or upload confidential information to public AI platforms; before using AI tools to process client data, ensure the technical environment, data flows and access permissions are in a secure and strictly controlled state.
- Professional skepticism: for anomalies identified by AI, further audit procedures must be taken to confirm whether there is a risk of material misstatement; information provided by AI can be verified against data obtainable from official platforms; if AI evidence is inconsistent with evidence from other sources, professional skepticism must be maintained and the audit procedures to be modified or added must be determined.
- Working-paper audit trail: under the requirements of China Standards on Auditing No. 1131 — Audit Documentation, fully and appropriately record in the working papers the process and results of using AI tools, as well as the process of analyzing and adopting the results; where necessary, relevant terms on the use of information technology may be agreed with the audited entity in the audit engagement letter.
- Information technology audit: the Notice on Doing Well the 2025 Annual Report Audit of Listed Companies points out that as business processes are closely integrated with information systems, there may be a risk of covert fraud exploiting technical privileges; the audit of controls over the information systems themselves must be strengthened, with a focus on the effectiveness of IT general controls and automated application controls; for areas adopting new technologies, such as business-process automation, artificial intelligence, cloud platforms, and big-data analysis, targeted audit procedures must be performed; attention must be paid to the quality and completeness of underlying data, and when necessary the work of information-technology specialists should be used.
The accompanying Q&A No. 19 provides technical examples that can be engineered directly: on the funds-analysis side, OCR and AI models automatically clean and merge bank-statement source files in various formats, automatically recompute the balance after each transaction and compare it with the original balance, and identify missing or discontinuous statements; then a one-to-one matching of bank statements and financial journals is performed to identify anomalous funds transactions where "the journal has an entry but the statement does not" or "the statement has an entry but the journal does not". On the behavior-analysis side, user- and merchant-behavior analysis models are built for fictitious revenue on internet platforms (concentration analysis of registration data, no large volume of consumption orders expected between 0:00–6:00, refunds without shipment after promotional periods, large single-day consumption, etc.); the counterparty analysis checks customers or suppliers whose transaction scale obviously mismatches their purchase/sales scale, fund flows with related parties such as the actual controller and directors/supervisors/senior management, and frequent or large transactions on non-working days.
3.2.3 Results
The actual effect of this framework is not reflected in some efficiency figure, but in delineating the compliance boundary of "AI auditing" in China:
- The responsibility anchor statement holds: "Using AI tools in auditing cannot replace the CPA's professional judgement, nor does it reduce the CPA's responsibility for the audit opinion" (CICPA, 2026-03-05, Grade A original text).
- The technical examples turn fraud identification from "relying on experience" into "reproducible procedures": the three steps of cleaning, recomputation, and matching of bank statements are all deterministic operations, and their results can be recomputed and written into working papers — this is precisely the audit-side counterpart of the AIxCC "deterministic-tool determination" paradigm (see Chapter 5 of this group's README).
- No. 18 focuses on identifying "financial statement fraud facilitated by third parties" (why professional skepticism is emphasized, common means, third-party characteristics, and how to identify and respond), jointly forming with No. 19 a combination of "human defense + technical defense".
Implications for Audit Harness design: the CICPA's four bottom lines can be translated directly into four mechanisms of Harness — data security maps to L6's out-of-domain interception and controlled deployment, professional skepticism maps to the mandatory instrumentation of L3's "lead → further procedures", working-paper audit trails map to L4's append-only trail, and information-technology audit maps to the ITGC and automated-control testing tools in L2's tool contract.
3.3 Intelligent Digital Forensics: Timesketch + Sec-Gemini and FACADE
3.3.1 Background
Forensic work in audit and investigation scenarios has long faced two bottlenecks: first, the large volume of log and event data makes manual timeline reconstruction time-consuming; second, anomalous behavior from insider threats lacks historical attack samples to learn from. Forensics requires that the "evidence chain be admissible" — hash verification, operational audit trails, and reproducible timelines — which naturally conflicts with AI's probabilistic outputs, making the forensics track the best touchstone for testing whether "AI capability ↔ forensic compliance" can coexist.
3.3.2 Approach
- Timesketch + Sec-Gemini (forensic collaboration): Google extended its open-source collaborative digital forensics platform Timesketch with agentic capabilities, driven by Sec-Gemini, using AI to automatically perform initial forensic investigations, significantly shortening investigation time and letting analysts focus on other tasks; this capability was demonstrated at Black Hat USA 2025 (Google official, Grade A). The key division of labor is: AI performs the initial investigation (preliminary timeline sorting, event clustering), and analysts perform verification and conclusions — the ultimate person accountable for the forensic report remains human.
- FACADE (insider-threat detection): an insider-threat detection system Google has used since 2018 to protect its internal systems, employing contrastive learning, processing billions of security events per day, and identifying insider threats without historical attack data (Google official, Grade A). Its methodological value lies in bypassing the supervised-learning premise of "requiring historical attack samples", using "deviation from the normal-behavior profile" as the detection signal.
- Evidence-management mechanism: the common feature of the two systems is that AI produces candidates and preliminary sorting while humans confirm; all evidence entering the formal report still requires fixed hashes and sources to ensure the integrity of the chain of custody.
3.3.3 Results
- Investigation time is significantly shortened, freeing analysts from initial forensic investigations (per Google's official statements; the specific multiplier was not disclosed).
- FACADE has run in an unsupervised manner for years, validating the feasibility of the "full-population + unsupervised + permanent" form of continuous monitoring at extremely large scale.
- This is consistent with the cross-cutting conclusion of Chapter 5 of this group's README: AI produces candidates and preliminary sorting, while deterministic tools and humans are responsible for determination and fixation — the admissibility of the forensics track is not weakened by AI, because the determination step is never handed to probability.
Implications for Audit Harness design: the forensics scenario provides an engineering template showing that "AI participation does not affect the validity of evidence" — as long as AI's output stays at the "candidate and preliminary sorting" layer and the final evidence undergoes hash fixation and human confirmation, the admissibility of the evidence chain is unaffected. The forensics module of the audit track should be layered accordingly: AI does preliminary timeline sorting and anomaly clustering, and humans do evidence fixation and conclusion signing.
4. Practice Standards
4.1 AGENTS.md Specification
The following is the recommended full AGENTS.md for the Audit track. This document is a recommendation; there is no official industry standard. It can be copied directly and adapted to the organization's actual circumstances. This document inherits all the bottom-line clauses of the group-level AGENTS.md (
AGENTS.md); the following is the tightened SOP for audit scenarios.
# AGENTS.md —— Audit 审计
> 本文为建议稿,业界无官方标准。引用准则与监管文件为真实文本,落地方式为工程建议。
> 本文件继承组级 AGENTS.md 全部底线条款(证据链五元组、职责分离、人在回路、数据分级、
> 审计留痕、禁止事项),以下仅列审计方向的加严项。
## 角色与边界
- 角色:底稿整理者、数据分析者、异常线索生成者、控制测试执行辅助者、取证初排者。
- 不是:审计意见出具人、审计报告签署人、重要性水平确定者、审计结论决定者。
- 关键角色(三身份分离,继承组级并加严):
- 生成者:执行数据抽取、清洗、重算、比对、异常评分。
- 复核者(项目复核人):对 AI 线索的采纳与否作出专业判断并记录理由。
- 底稿保管人:管理 append-only 底稿库与证据链哈希,不参与生成与复核。
- 边界判定:凡准则要求注册会计师亲自判断的事项(重要性、意见类型、错报定性),
智能体只提供材料,不提供结论。
## 环境假设
- 存在审计工作台(底稿系统)与 GRC 平台,支持底稿编制、复核流转与版本管理。
- 存在 CAAT 数据分析环境,可对账套、序时账、银行流水执行采集、清洗、重算与比对。
- 存在企业信息官方核验渠道(如国家企业信用信息公示系统等官方平台),用于核实
AI 提供的信息(对应中注协 2026-03-05 提示"通过官方平台获取的信息数据进行核实")。
- 存在 append-only 底稿存储;智能体对底稿仅有追加权限,无修改与删除权限。
- 客户数据在受控环境内处理;公共模型平台仅接收脱敏后的非涉密任务数据。
## 上下文加载顺序(Context Budget)
1. 任务契约(审计阶段、科目范围、重要性参考、允许工具、确认点)。
2. 现行有效审计准则与问题解答(必须带文号与施行日期;含《审计准则第 1131 号》、
问题解答第 18 号、第 19 号、中注协 2026-03-05 风险防范提示要点)。
3. 内部审计手册与历史底稿(同科目、同行业的既往程序与结论)。
4. 本次任务原始材料(账套、序时账、银行流水、控制测试清单、日志)。
5. 补充资料(预算不足时最先裁剪)。
硬约束:准则内容一律取自准则库检索,不得取自模型记忆;每条被引用准则携带
`现行有效 / 已修订 / 历史版本` 标记。
## 工具契约
| 工具 | 风险等级 | 说明 |
|---|---|---|
| 准则与问题解答检索 | R0 | 只读,必须返回文号与施行日期 |
| 企业信息官方核验 | R0 | 只读,用于核实 AI 提供的企业与对手方信息 |
| 账套与流水读取 | R0/R2 | 按数据分级;涉密账套仅在受控环境处理 |
| 数据清洗与余额重算 | R1 | 输出可复算的中间结果,写入手稿区 |
| 异常线索评分 | R1 | 输出候选清单,标注评分依据 |
| 底稿写入(手稿区) | R1 | 可追加、可回滚;正式底稿由复核人确认后固化 |
| 底稿定稿与归档 | R2 | 复核人确认后写入 append-only 存储 |
| 审计意见与报告签署 | R3 | **永久关闭**;由签字注册会计师完成 |
## 任务执行流程(SOP)
1. 任务登记:审计阶段、科目、数据范围、数据分级、复核人。
2. 语料装载:准则库版本快照 + 历史底稿 + 本次数据,记录哈希。
3. 程序设计:按风险评估结果匹配程序清单(对应问题解答第 19 号的
资金分析 / 行为分析 / 对手方分析 / 关联方分析四类程序模板)。
4. 数据执行:清洗、重算、匹配、比对——全部使用确定性工具,中间结果可复算。
5. AI 线索生成:对全量数据生成异常候选清单,逐条附评分依据与指向的原始记录。
6. **进一步审计程序插桩(强制环节)**:每条 AI 线索必须绑定至少一项进一步审计
程序方可进入底稿;未确认的线索标注"待确认",不得作为审计证据引用
(对应中注协"采取进一步审计程序确认是否存在重大错报风险")。
7. 证据一致性检查:AI 证据与其他来源证据不一致时,自动生成"职业怀疑提示单",
列明冲突点与建议追加程序。
8. 人工复核:复核人逐条作出"采纳 / 不采纳 / 追加程序"决定,并记录理由。
9. 归档:底稿固化,绑定五元组证据链与链哈希,支持监管调阅导出。
## 验证与证据要求
- 每条 AI 线索的底稿记录必须包含:线索内容、生成依据(数据版本 + 程序模板版本 +
模型与提示词版本)、进一步审计程序及结果、复核人分析与采纳记录——
对应 1131 号准则"充分、适当地记录……以及对结果的分析与采纳过程"。
- 余额重算、账实匹配等程序必须输出可复算的中间结果;复核人可一键重放。
- 证据不一致情形必须留痕(职业怀疑提示单编号 + 冲突说明 + 处置决定)。
- 智能体不得在底稿中出现"AI 认为存在重大错报"类定性表述;只能出现
"工具标记异常 X 项,经程序 Y 确认/未确认"。
## 失败与升级策略
- 数据质量缺陷(流水缺失、账套不平)→ 停止分析,生成数据质量备忘录,转人工。
- AI 线索与人工判断冲突且无法由追加程序解决 → 转项目合伙人层面判断(L2 升级)。
- 发现利用技术权限实施隐蔽性舞弊的迹象(如超级账户异常操作、变更日志缺失)→
立即冻结现场快照,上报项目合伙人与信息安全负责人(L3 升级)。
- 官方核验渠道返回与 AI 提供信息不一致 → 以官方渠道为准,AI 信息作废并留痕。
## 安全与合规红线
- 未经客户授权或法律法规允许,涉密信息不得出域,不得进入公共 AI 平台
(中注协 2026-03-05 提示原文要求)。
- 处理客户数据前,确认技术环境、数据流转和访问权限处于安全和严格受控状态。
- 遵守《人工智能生成合成内容标识办法》(2025-09-01 施行):生成内容保留显式标识
(第 6 条)与元数据隐式标识(第 7 条);不得恶意删除、篡改、伪造、隐匿标识(第 10 条)。
- 遵守《中华人民共和国网络安全法》新增第二十条(2026-01-01 施行)关于全生命周期
风险监测评估的要求;信息系统控制审计同时满足 GB/T 45654—2025 对模型安全
(安全审计与漏洞修复、训练与推理环境隔离)的参照要求。
- 底稿与证据链留存期按审计准则与事务所制度取较长者。
## 禁止事项
1. 禁止以 AI 线索替代进一步审计程序。
2. 禁止在未记录"分析与采纳过程"的情况下将 AI 输出写入正式底稿。
3. 禁止修改或删除已固化底稿;发现底稿错误走"补充底稿"程序。
4. 禁止由智能体出具或暗示审计意见类型(无保留 / 保留 / 否定 / 无法表示意见)。
5. 禁止把模型记忆中的准则条文写入底稿。
6. 禁止跨项目复用未脱敏的客户数据作为其他项目语料。
7. 禁止隐瞒 AI 参与底稿编制的事实;参与程度必须可从底稿还原。
8. 禁止在证据链五元组不完整时执行归档。
## 输出格式
- 异常线索清单:编号、科目、线索描述、原始记录指针、评分与依据、确认状态
(待确认 / 已确认 / 已排除)、绑定程序编号。
- 控制测试辅助结果:控制项、测试步骤、样本或全量范围、结果、偏差说明。
- 取证初排:时间线(事件、来源、哈希)、异常聚类、待人工确认项。
- 每份输出附带:数据版本哈希、程序模板版本、模型与提示词版本、复核状态。
## 评估与自检
- 回归集:历史项目 + 已确认错报(Golden Dataset)。
- 核心指标:线索精确率(AI 标记异常中被确认为重大错报的比例)、
线索召回率(已知重大错报中被 AI 捕获的比例)、底稿完整性(五元组齐备率)。
- 自检:禁止事项逐条对照;输出格式逐段对照;证据链五元组逐项对照;
每条正式底稿可定位到复核人及其采纳理由。 4.2 SKILL.md Specification
The following is the recommended full SKILL.md for the Audit track. This document is a recommendation; there is no official industry standard. This skill is engineered from the funds-analysis technical example in CICPA's Audit Standards Q&A No. 19.
---
name: audit-bank-statement-reconciliation
description: 银行流水全量核对与账实匹配。对各种格式的银行流水原始文件做自动清洗合并、余额重算与序时账一一匹配,输出异常资金交易候选清单。适用于财务报表审计的资金分析程序与舞弊风险识别场景。
version: 1.0
created: 2026-09-12
---
# 银行流水全量核对与账实匹配
## 适用场景
- 适用:年报审计与专项审计中的资金分析程序;识别银行流水缺失或不连续;
识别"账有流水无"与"流水有账无"的异常资金交易;对手方与关联方资金往来筛查。
- 不适用:出具审计结论;对异常交易定性;替代函证与监盘等准则程序。
## 前置条件
- 已获取被审计单位各账户的银行流水原始文件与财务序时账导出数据。
- CAAT 数据分析环境可用,支持 OCR、格式归一化、余额重算与批量匹配。
- 数据在受控环境内处理;涉密账套未出域。
- 复核人已指定;程序模板(问题解答第 19 号资金分析类)已加载。
## 输入
| 输入项 | 必填 | 说明 |
|---|---|---|
| 银行流水原始文件 | 是 | 覆盖审计期间全部账户,格式可为 PDF / Excel / CSV |
| 财务序时账 | 是 | 与流水同一审计期间,含科目与对方科目 |
| 客户与供应商清单 | 是 | 用于对手方筛查 |
| 关联方清单 | 是 | 实控人、控股股东、董监高及其控制企业 |
| 审计期间 | 是 | 流水与账套期间必须一致 |
| 数据分级 | 是 | 涉密数据仅限受控环境 |
## 输出
| 输出项 | 说明 |
|---|---|
| 清洗日志 | 各文件格式、页数、解析成功/失败记录、失败原因 |
| 余额重算表 | 每笔交易后余额(重算值)与原始余额的比对,差异标记 |
| 流水完整性检查 | 缺失期间、断号、重复交易清单 |
| 账实匹配结果 | 一一匹配成功项、仅账有项、仅流水有项 |
| 异常候选清单 | 异常类型、金额、日期、对手方、原始记录指针、评分与依据 |
| 留痕信息 | 数据版本哈希、程序模板版本、模型与提示词版本、复核状态 |
## 执行步骤
1. 校验审计期间一致性与文件清单完整性;缺失文件直接列入异常候选。
2. OCR 与格式归一化:将各格式流水转为统一结构,保留原文页码/行号指针。
3. 逐笔重算交易后余额,与原始余额比对;输出差异项(对应"识别银行流水
缺失/不连续")。
4. 银行流水与财务序时账按日期、金额、对手方做一一匹配;输出三类结果
(匹配成功 / 账有流水无 / 流水有账无)。
5. 异常筛查(按程序模板):交易规模与购销规模明显不匹配的对手方;第三方
销售回款;与关联方的资金往来;非工作日频繁或大额交易;某月/某日/某时段
交易量突增突减。
6. 生成异常候选清单,逐条附原始记录指针与评分依据;不得给定性结论。
7. 自校验:清洗成功率、重算差异覆盖率、匹配三类结果齐备、候选清单字段完整。
8. 交付复核人执行进一步审计程序;每条线索绑定程序与结论后进入底稿。
## 质量标准(DoD)
- 一票否决:使用未覆盖审计期间的数据;清洗失败的文件被静默跳过;
候选清单中出现"疑似舞弊"等定性表述;未绑定进一步审计程序即写入正式底稿。
- 余额重算覆盖率 100%(审计期间内全部流水逐笔重算)。
- 匹配结果三类齐备,"账有流水无""流水有账无"两项不得为空(可为零,须显式声明)。
- 每条候选可回溯到原始记录指针(文件名 + 页码/行号)。
- 清洗日志与失败记录 100% 保留。
## 常见失败与处理
| 失败模式 | 表现 | 处置 |
|---|---|---|
| OCR 识别错误 | 金额或日期错位导致虚假差异 | 抽样回验原文;错误率超阈值时转人工处理该文件 |
| 流水覆盖不全 | 账户清单与实际获取文件不符 | 列入异常候选并升级,不得默认按已获取数据分析 |
| 跨账户转账重复计入 | 关联账户互转被当作外部交易 | 依据账户清单去重;去重规则写入留痕 |
| 序时账口径不一致 | 账套科目与流水对手方无法对应 | 生成映射缺口清单,转人工补录,不得推测匹配 |
| 时段异常误报 | 正常业务季节性被标记 | 保留标记但降级,注明"待业务确认";不得静默删除 |
## 示例
输入:
- 某公司 2025 年 1—12 月 6 个银行账户流水(PDF / Excel 混合格式)
- 同期序时账导出(CSV)
- 关联方清单:实控人 1 人、控股企业 3 家、董监高 5 人
输出(节选):
| 候选编号 | 异常类型 | 日期 | 金额(¥) | 指针 | 评分依据 | 确认状态 |
|---|---|---|---|---|---|---|
| C-014 | 流水有账无 | 2025-03-17 | [待填写] | 流水文件 B 第 42 页第 7 行 | 非工作日大额支出 | 待确认 |
| C-021 | 关联方往来 | 2025-06-30 | [待填写] | 流水文件 A 第 118 页第 3 行 | 实控人控制企业转入 | 待确认 |
| C-035 | 账有流水无 | 2025-09-12 | [待填写] | 序时账第 2,031 行 | 银行付款无对应流水 | 待确认 |
> 说明:金额等实际值必须以分析结果填充,示例中统一使用 [待填写] 占位。
> 每条候选交付时必须绑定进一步审计程序编号;未经确认不得作为审计证据。 4.3 Landing Checklist
| # | Check Item | Check Method | Pass Criterion |
|---|---|---|---|
| 1 | Data stays in-domain | Data-flow review | 100% of confidential information never enters public AI platforms |
| 2 | Controlled-environment verification | Environment audit | Technical environment, data flows and access permissions confirmed as controlled before processing client data |
| 3 | Standards source | Working-paper spot check | 100% of standards cited in working papers come from standards-library retrieval, with document number and effective date |
| 4 | Lead-to-procedure binding | Full working-paper check | 100% of AI leads entering working papers are bound to a further audit procedure |
| 5 | Analysis-and-adoption record | Working-paper spot check | 100% record the reviewer's process of analyzing and adopting the AI result |
| 6 | Evidence-consistency handling | Notice-slip review | 100% of evidence-inconsistency situations generate a professional-skepticism notice slip with a disposition conclusion |
| 7 | Official verification | Lead spot check | 100% of enterprise/counterparty information provided by AI is verified via official channels before being cited |
| 8 | Working papers tamper-proof | Permission and storage review | The agent has append-only permission over finalized working papers; chain hashes are recomputable |
| 9 | ITGC coverage | Audit-plan review | The internal-control audit covers IT general controls and automated application controls |
| 10 | Targeted procedures for new technologies | Audit-plan review | Targeted audit procedures designed for AI, automation, cloud platforms, and big-data domains |
| 11 | Segregation of duties | Identity and credential review | Three identities — generator, reviewer, and working-paper custodian — are separated |
| 12 | Opinion signing | Process review | 100% of audit opinions are issued by the signing CPA |
| 13 | Generated-content labeling | Output spot check | 100% of explicit and implicit labels are preserved, with no deletion or tampering |
| 14 | Evaluation regression set | Evaluation-record review | The regression set is historical projects + confirmed misstatements, not a generic benchmark |
| 15 | Regulatory-inspection support | Drill | Any historical conclusion can reconstruct the data version, procedure version, and review record within the agreed timeframe |
5. Conclusion
The AI Harness for the audit track is, in essence, a system that engineers "non-transferable responsibility" into an evidence-chain mechanism.
Three conclusions:
First, the responsibility anchor is the first principle of the entire design. The CICPA 2026-03-05 notice's "cannot replace the CPA's professional judgement, nor does it reduce the CPA's responsibility for the audit opinion" echoes the IESBA's "professional accountants remain responsible for their judgement and decisions" across Chinese and international contexts. This statement is not a disclaimer but an architectural directive: it means every design decision of Harness must answer "on what basis and with what materials does the CPA bear this responsibility". The answer is the five-element evidence chain — input snapshot, tool-call log, output, human-confirmation record, and hash. If any part is missing, the responsibility is left hanging.
Second, leads and evidence must be strictly layered. The CICPA requires that for anomalies identified by AI, "further audit procedures be taken to confirm whether there is a risk of material misstatement", and Q&A No. 19 provides the concrete engineering form of the further procedures (cleaning, recomputation, matching, and screening, all deterministic and recomputable). The combination of the two is the audit version of the "AIxCC paradigm": the model proposes candidates across the full population, while deterministic procedures and humans are responsible for determination. The improvement in identification rates comes from "the orchestration layer learning when to call which deterministic tool", not from a smarter model.
Third, the intended reader of the working papers is the external reviewer. The L4 of Audit Harness must be built to "regulatory inspection" standards: append-only, chain hashing, and searchable across four dimensions — task, time, personnel, and basis version. At the same time, as a meta-auditor, the audit track's own system logs, permissions, and governance status are the first object examined when it issues internal-audit findings on the AI systems of the other four tracks — the audit AI must first pass its own audit.
Limitations that must be faced squarely: the industry-transformation data cited in this track (the internal-audit technology-adoption survey, the Deloitte survey as relayed, and the RSM industry analysis) are Grade B relays or were not obtained as primary reports; no primary source was obtained for quantified adoption cases of continuous auditing and forensics on the China side. Efficiency figures are inherently secondary to compliance effectiveness in the audit track — any "efficiency" claim, in the absence of a regression set of confirmed misstatements, cannot be verified as not coming at the cost of missed reports.
Information-Gap Statement
The following items could not be verified against A/B-grade primary evidence; the text has been handled per the "no fabrication" principle, and further evidentiary work is required before use:
- Deloitte 2025 internal-audit survey's original report — figures such as "84% of internal auditors said AI skills are important when recruiting" and "over 45% said AI-tool training has the greatest impact" are relayed; the original report was not obtained.
- The exact wording of Standard 10.3 of the IIA Global Internal Audit Standards — only a Grade B relay was obtained; the exact sentence-level citation of the standard text was not obtained.
- Quantified adoption cases and indicators of continuous auditing and continuous monitoring on the China side — no A/B-grade primary source was obtained; public quantitative effect data on Chinese accounting firms' AI applications was also not obtained.
- The official full-text link of China Standards on Auditing (Q&A) No. 19 — the full-text link in the report points to a third-party mirror site (docs.maoyanqing.com); the official-channel link is
[To be filled]; where this document cites its key points, the CICPA official announcement page (cicpa.org.cn) is used as the reference. - The share and breakdown data of the China sample in the international survey on technology adoption in internal audit (Eulerich et al., 2025) — breakdown data was not obtained.
- Industry baseline values for "lead precision / recall" — the audit profession has no public AI anomaly-identification baseline; the indicators in this document are defined as engineering recommendations, and the baseline values are
[To be filled].
6. References
- CICPA Notice on the Risk Prevention of Using AI Technology by Accounting Firms in the 2025 Annual Report Audit — Chinese Institute of Certified Public Accountants, 2026-03-05. https://cicpa.org.cn/xxfb/news/202603/t20260305_65842.html
- Notice of the Chinese Institute of Certified Public Accountants on Doing Well the 2025 Annual Report Audit of Listed Companies — Chinese Institute of Certified Public Accountants, 2026-01. http://n.bicpa.org.cn/u/cms/www/202601/04161209co7c.pdf
- CICPA issues Audit Standards Q&A No. 18 and No. 19 — Chinese Institute of Certified Public Accountants, published and effective 2025-01-07. https://cicpa.org.cn/xxfb/news/202501/t20250123_65229.html
- IAASB publishes global roundtable feedback summary on technology and quality management (over 240 stakeholders from six continents) — IAASB, 2026-02. https://www.iaasb.org/news-events/2026-02/iaasb-publishes-global-roundtable-feedback-technology-and-quality-management
- IAASB list of standards and issued documents (including the ISA 330 / 500 / 520 revision proposals and the Technology Position Catalog v2) — IAASB. https://www.iaasb.org/?page=35
- Global Internal Audit Standards and AI audit tools (AI Prompting for Internal Auditors, AI Governance questionnaires, etc.) — The Institute of Internal Auditors, 2024—2026. https://www.theiia.org/en/standards/documents/?category=audit+tools
- Evolving Role of Internal Audit (continuous auditing and continuous KRI monitoring) — RSM US. https://rsmus.com/insights/services/risk-fraud-cybersecurity/evolving-role-of-internal-audit.html
- Cybersecurity updates: Summer 2025 (Timesketch + Sec-Gemini, FACADE, Big Sleep) — Google, 2025. https://blog.google/technology/safety-security/cybersecurity-updates-summer-2025/
- International survey on technology adoption in internal audit — Eulerich, Eulerich & Bonrath, Maandblad voor Accountancy en Bedrijfseconomie 99(4), 2025, pp.181–193. https://mab-online.nl/article/153598/download/pdf/1412064
- Decision to Amend the Cybersecurity Law of the People's Republic of China (Presidential Order No. 61), adding Article 20 — National People's Congress, 2025. http://www.npc.gov.cn/c2/c30834/202601/t20260105_450980.html
- Interpretation of GB/T 45654—2025 Cybersecurity Technology — Basic Safety Requirements for Generative AI Services — National Cybersecurity Standardization Technical Committee (SAC/TC260). https://www.tc260.org.cn/tc260/hygd1/202403/b429d868525e48c3b7d12a0ec8f82e5e.shtml
- Notice on the Issuance of the Measures for the Labeling of AI-Generated and Synthetic Content (Guoxinban Tongzi [2025] No. 2) — Cyberspace Administration of China and three other departments, 2025. https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm