Audit Analytics Without a Data Science Team - Full Methodology, Prompts, and Results for Six Worked Examples
Audit Analytics Worked Examples Resource is a companion guide designed for internal audit teams using artificial intelligence and analytics to improve efficiency.Overview of ExamplesThe resource provides six practical audit scenarios, including methodologies, prompts, and result sets:
- Duplicate Payment Detection: Analyzed 840 accounts payable transactions to identify duplicates. Out of 18 flagged pairs, manual review confirmed 15 true duplicates, totaling $144,767, with 3 false positives.
- Revenue Recognition Trend Analysis: Reviewed 180 region-months of data. Six months were flagged for movement >15% above the trailing 3-month average; two were attributed to known business drivers, one was referred for investigation, and three were dismissed as noise.
- User Access Termination Testing: Tested 64 terminations. Only one exception was identified—a 73-hour gap in disabling access caused by a delayed IT ticket.
- Segregation of Duties (SOD) and Privileged Access: Tested 120 users. Identified 14 SOD conflicts across 13 users and one privileged access exception involving four high-risk roles.
- SOC 2 Report Review: Evaluated a SOC 2 Type II report for Northwind Cloud Services, resulting in a "Moderate" risk rating due to two timeliness failures in access reviews and one subservice organization carve-out.
- Third-Party Contract Compliance: Reviewed a professional services agreement and recommended five audit procedures, including recomputing escalated fees and testing SLA reporting and service credit issuance.
Additional resources, including templates and upcoming CPE sessions, are available via Cherry Hill Advisory.
The information provided in these materials is for general informational purposes only and does not constitute professional advice.