IntelliAudit Uses LLMs for IT Audit Control Evaluation

Allison Wilson, Sina Moradi Sabet, Diar Shakimov, Panteha Shahrivar, Mohammad Reza Bagheri, Dean Konenkamp, Mohammad A. Tayebi· August 11, 2026 View original

Key takeaways

  • IT audits are complex, requiring semantic judgment beyond keyword matching.
  • IntelliAudit is a multi-agent system using LLMs for evidence-grounded audit control evaluation.
  • It retrieves evidence, assesses controls, and provides recommendations with rationale.
  • Human oversight remains crucial for calibrating judgments and ensuring accuracy.

Who benefits

Financial ServicesCybersecurityConsultingGovernmentHealthcare

Summary

IntelliAudit is a retrieval-grounded multi-agent system that uses large language models (LLMs) to evaluate IT audit evidence against security and compliance controls. It retrieves relevant artifacts, generates evidence-grounded assessments, handles disagreements, and provides auditor-facing recommendations with citations, rationale, and remediation guidance, demonstrating its utility as a decision-support tool.

IT audits are complex, requiring auditors to assess whether diverse organizational evidence, such as policies, records, and operational artifacts, satisfies semantic security and compliance controls. Automating this process is challenging because audit conclusions depend on the sufficiency of evidence, not just keyword matching. Researchers have developed IntelliAudit, a retrieval-grounded multi-agent system designed to assist with IT audit evidence evaluation. Given a control and a corpus of evidence, IntelliAudit intelligently retrieves pertinent artifacts, generates an assessment grounded in that evidence, and can even challenge adverse findings and adjudicate disagreements. The system then produces a comprehensive recommendation for the auditor, complete with cited evidence, a clear rationale, an analysis of missing evidence, and actionable remediation guidance. Evaluated against ISO/IEC 27001 in simulated organizations, IntelliAudit proved effective in supporting control interpretation and audit preparation workflows, though it highlighted the ongoing importance of human oversight for calibrating sufficiency judgments and correcting overly permissive recommendations. It functions best as a decision-support tool rather than an autonomous certification system.

Why it matters

For audit professionals, compliance officers, and IT security teams, IntelliAudit offers a powerful tool to streamline and enhance the efficiency and accuracy of IT audit evidence review, reducing manual effort and improving consistency.

How to implement this in your domain

  1. 1Pilot a retrieval-grounded multi-agent system for a specific IT audit control framework (e.g., ISO 27001, SOC 2).
  2. 2Curate a comprehensive evidence corpus including policies, records, and operational artifacts for the system to access.
  3. 3Integrate LLMs to interpret controls, assess evidence sufficiency, and generate evidence-grounded findings.
  4. 4Design a workflow that incorporates human oversight for calibrating sufficiency judgments and reviewing AI-generated recommendations.
  5. 5Develop clear reporting mechanisms that provide cited evidence, rationale, and remediation guidance for audit findings.

Original post by Allison Wilson, Sina Moradi Sabet, Diar Shakimov, Panteha Shahrivar, Mohammad Reza Bagheri, Dean Konenkamp, Mohammad A. Tayebi

"arXiv:2608.07688v1 Announce Type: new Abstract: IT audits require auditors to judge whether heterogeneous organizational evidence satisfies semantic security and compliance controls. This judgment is difficult to automate because relevant evidence is distributed across policies,…"

View on X

Originally posted by Allison Wilson, Sina Moradi Sabet, Diar Shakimov, Panteha Shahrivar, Mohammad Reza Bagheri, Dean Konenkamp, Mohammad A. Tayebi on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses