
Agentic Workflows Worked Examples Resource is the companion guide to the Northeast District Conference 2026 session on what agentic workflows actually do inside internal audit. It contains the complete prompt, the full source data, and the unedited agent output for each of the three runs shown in the session, so your team can reproduce them against your own data.
• Risk Assessment Refresh: Reviewed 60 audit universe entities against twelve months of incident and issue data. Eleven rescorings were proposed, 18% of the universe, with the seven evidence-based proposals capturing all six critical and all nine high-severity events. Two high-volume entities were correctly left unchanged, and no downgrades were proposed because the input set lacked control testing evidence to support one.
• User Access Termination Testing: Tested the full population of 64 terminations against a 24-hour disable policy. One exception was identified, a 73-hour gap traced to a delayed IT ticket. A 40-item sample had a 37% chance of missing it. The run also flagged a data quality caveat on its own finding.
• Issue Follow-Up: Checked 140 open issues across 22 audits in a single pass. Twelve completion claims had no supporting evidence and eighteen more carried evidence that did not match the agreed action, 40% of the register. Evidence requests were drafted for all twelve bare claims; escalation decisions stayed with the auditor.
• Each example closes with the judgment layer: what the auditor validated, decided, and signed.
Additional resources, including the CHA AI Internal Audit Encyclopedia, the AI Auditing Guide, and upcoming CPE sessions, are available via Cherry Hill Advisory.
The information provided in these materials is for general informational purposes only and does not constitute professional advice.
The information provided in these materials is for general informational purposes only and does not constitute professional advice.