Blog

AI News & Use Cases for Internal Audit - September 13, 2026

Internal Audit Newswire

Subscribe now to join the Risk Register community:

Hero image

OpenAI launches Astra, its powerful (and controversial) new model

Source: TechCrunch

Summary: OpenAI unveiled Astra on September 3, 2026, its newest and most capable model. Astra targets complex reasoning, software engineering, research, document analysis, and long‑running agentic workflows. OpenAI claims gains in speed, accuracy, and alignment, calling it their most aligned model to date. Access is immediate for Daybreak cybersecurity customers and rolls out the following week to Pro, Plus, Enterprise, and Business plans and via the OpenAI API. For internal audit, the draw is Astra’s API availability and improved document analysis—useful for contract review, evidence triage, and large‑set document interrogation.

How Internal Audit Can Deploy This: Treat Astra as a force-multiplier for text-heavy audit work where precision citations matter. Start with a constrained pilot in one audit where documents drive conclusions. Three practical use cases: 1) Contract review for ICFR: analyze revenue or vendor contracts to extract nonstandard terms, variable consideration, and obligations tied to key controls; require page-level citations you can reperform. 2) Evidence triage in SOX testing: compare control descriptions to PBC evidence (approvals, timestamps) and flag gaps or inconsistencies for human follow-up. 3) Risk assessment synthesis: ingest policies, incident summaries, and meeting notes to surface themes and candidate entries for the risk register, separating operational risk signals from noise. Pilot steps this quarter: select a contained corpus (e.g., 50–100 contracts or a single audit’s PBC folder), run via a standard prompt that mandates structured outputs and quotations with page references, and route results through human review with a 20–30% reperformance sample. Use the API or Enterprise plan once available to your tenant. Safeguards: restrict access to the API key; transmit only data approved for external processing under your AI governance policy; apply data minimization or redaction for personal or sensitive terms; disable any model training on your prompts/outputs if your policy requires it; log prompts and outputs as workpaper evidence; mandate human sign-off before any findings enter the workpapers or the risk assessment.

✎ Try it yourself — Prompt template

Inputs: the attached documents (contracts, policies, or PBC evidence); your control description(s) or risk taxonomy.

Role: You are an internal audit AI reviewer performing document analysis for control testing and risk assessment.

Task: Read all provided documents. Extract facts, assess control coverage, and identify issues. Produce a structured, citable output for workpapers.

Instructions:
- Map findings to the supplied control descriptions or risk taxonomy categories.
- Quote exact text snippets with page/section IDs for every assertion.
- If evidence is missing, inconsistent, or unclear, flag it and state precisely what is needed to conclude.
- Do not invent facts. If uncertain, state “Insufficient evidence.”
- Prioritize ICFR-relevant items for SOX and material risk themes for the risk register.

Output format (JSON):
{
  "documents_reviewed": [ {"name": "...", "pages": n} ],
  "key_extractions": [ {"topic": "...", "value": "...", "source_quote": "...", "page": "..."} ],
  "control_coverage": [ {"control_id": "...", "assessment": "Effective / Gaps noted / Insufficient evidence", "rationale": "...", "citations": [{"quote":"...","page":"..."}]} ],
  "issues": [ {"severity": "High/Med/Low", "description": "...", "impact": "ICFR / operational risk / compliance", "required_evidence": "...", "citations": [{"quote":"...","page":"..."}] } ],
  "risk_register_candidates": [ {"risk_category":"...","statement":"...","drivers":"...","evidence_citations":[{"quote":"...","page":"..."}]} ],
  "open_questions": ["..."]
}

Quality rules:
- Cite at least one source_quote with page/section for each finding.
- Do not summarize without evidence.
- Flag any contradictions across documents.
- Use the exact language from the documents for key terms.
- Clearly separate fact (quoted) from interpretation (your assessment).

Hero image

DealHub MCP brings agentic control to quote-to-revenue

Source: TechCrunch (Press Release / Technology Wire distribution)

Summary: DealHub AI announced MCP for Admin on September 9, 2026, adding agentic capability to its Quote‑to‑Revenue platform. MCP for Admin automates configuration and management of revenue systems using autonomous workflows triggered by natural‑language prompts. The release emphasizes built‑in governance controls and business‑context awareness so changes align with corporate policies, promising faster implementation. It supports an agentic operating model for admin tasks and is slated for customer availability in October 2026. For internal audit, this is a testable environment for change‑management, configuration, and segregation‑of‑duties controls.

How Internal Audit Can Deploy This: Plan to place audit inside the governance loop of agentic admin changes. Three uses: 1) Change‑management testing: observe MCP-driven configuration proposals, verify required approvals, and reperform policy mapping before any change is applied. 2) Segregation‑of‑Duties: confirm that natural‑language prompts cannot bypass role boundaries; requests from business users should route to approvers and admins per policy. 3) Configuration control monitoring: compare authorized changes to the actual post‑change state (naming conventions, thresholds) to detect drift. Pilot this quarter: align with RevOps to define a safe, low‑impact parameter (e.g., a discount threshold in a noncritical tier). Enable MCP for Admin when available in October and run a supervised session: the admin issues prompts that explicitly state “do not apply changes—propose and show all governance checks.” Capture MCP’s proposed workflow, mapped policy references, and listed approvers; then approve one change during a maintenance window and confirm recorded approvals. Evidence: screenshots/exports of prompts, MCP governance steps, approval artifacts, and resulting configuration state. Safeguards: audit read‑only access where possible; no audit‑initiated prompts that can apply changes; enforce least privilege and change windows; ensure MCP’s governance controls are enabled; require business‑owner sign‑off before production changes; log all activity and store artifacts in workpapers. Align the test with risk governance by tying each prompt outcome to specific policy sections and risk ratings.

✎ Try it yourself — Build recipe

Build recipe: Supervised control test of DealHub MCP for Admin governance

1) Trigger and scope: When MCP for Admin becomes available in your tenant, select one low‑impact configuration parameter (e.g., a noncritical discount threshold) governed by a documented policy section.
2) Access and guardrails: Grant the test admin access to MCP for Admin; auditors receive view-only access to sessions and outputs. Document a hard rule: no changes may be applied without explicit written approval during a maintenance window.
3) Governance configuration: With RevOps, confirm MCP’s built‑in governance controls are enabled and mapped to your corporate policy (required approvers, change tickets, and business-context checks).
4) Test prompts (admin runs inside MCP):
   a) “Propose updating [the scoped parameter]. Do not apply any change. List every governance check you will enforce, the required approvers, and the corporate policy sections you rely on. Provide a step-by-step plan.”
   b) “Prepare the approval workflow you will trigger for this change. Do not execute. Show approver roles and evidence you will record.”
5) Human approval gate: Business owner reviews MCP’s proposed plan and governance checks. If acceptable, authorizes execution in a scheduled window.
6) Execution: During the window, admin issues: “Execute the approved change exactly as authorized.” Capture MCP’s approvals and evidence trail.
7) Test procedure: Reperform policy mapping, verify approver roles, and confirm the post-change configuration matches the authorized request.
8) Evidence pack: Save screenshots/exports of prompts, MCP governance outputs, approvals, and before/after configuration states to workpapers.
9) Go/No-Go criteria: Go if all approvals are enforced, evidence is recorded, and the final state matches authorization; otherwise escalate control deficiencies to management with required remediation steps.

Hero image

Salestrekker unveils Audit AI – delivering real-time file checks at the moment of lodgement

Source: Salestrekker (company news)

Summary: Salestrekker announced Audit AI on September 9, 2026 as part of its Salestrekker 2.0 AI suite. Audit AI performs automated, real‑time reviews of loan/client files at submission (lodgement), flagging issues that affect quality, accuracy, or lender requirements. It complements Compliance AI, Translate AI, and Policy AI. The company says Audit AI provides immediate visibility across broker submissions and reduces rework by surfacing missing or non‑compliant items at intake. Audit AI is available now within Salestrekker 2.0 and can be activated through approved aggregator partners.

How Internal Audit Can Deploy This: This is an intake control you can test and monitor—not a back-end afterthought. Deploy it where rework and lender rejections are operational risks. Three uses: 1) Control testing: submit test files with deliberate defects (missing IDs, mismatched income data) and confirm Audit AI flags them at lodgement, with evidence captured. 2) Continuous monitoring: review flagged exceptions across broker submissions to identify systemic gaps and target training or remediation. 3) Evidence gathering: attach Audit AI’s flags and broker corrections to audit workpapers as proof of control operation. Pilot steps this quarter: coordinate with broker operations and your approved aggregator partner to activate Audit AI for one region or channel. Define 5–7 defect archetypes aligned to lender requirements and run controlled lodgements to validate detection. Over two weeks, collect a daily snapshot of flagged issues and broker responses. Compare to historical rework to quantify impact and prioritize remediation. Safeguards: ensure only authorized staff can view flagged items; treat client data under your data-classification policy; retain exception evidence per your records policy; require human review before file submission proceeds; and document escalation thresholds for high‑risk exceptions. Fold this into risk oversight by mapping recurring flags to operational risk themes and updating the risk register accordingly.

✎ Try it yourself — Checklist

Control testing checklist: Salestrekker Audit AI at lodgement

1) Activation confirmed via approved aggregator partner (Pass/Fail): Evidence = screenshot of Salestrekker 2.0 settings showing Audit AI enabled and scope (region/channel).
2) Access controls enforced (Pass/Fail): Evidence = list of users with Audit AI visibility; verify least privilege and recent access review.
3) Test set prepared (Pass/Fail): Evidence = 5–7 anonymized lodgement files representing common lender requirement defects (e.g., missing document, expired ID, income mismatch, policy exception, unsigned declaration).
4) Real-time flagging works (Pass/Fail): For each test file, confirm Audit AI flags the intended issue at lodgement. Evidence = timestamped screenshots or exported flag details.
5) Broker response captured (Pass/Fail): Verify each flag results in broker action (add document, correct data, request exception). Evidence = activity log or screenshots.
6) Non-compliant items blocked or routed (Pass/Fail): Confirm that flagged high-risk issues require human review before submission proceeds. Evidence = workflow screenshot or routing rule description.
7) Visibility across submissions (Pass/Fail): Obtain a daily or weekly view showing aggregate flagged issues by broker/channel. Evidence = dashboard view or report.
8) Records retention (Pass/Fail): Verify flagged-item evidence is stored per policy with unique identifiers linking to lodgement IDs.
9) Metrics and remediation (Pass/Fail): Compare flags to historical rework metrics; document root causes and agreed remediation actions.
10) Governance tie-in (Pass/Fail): Map recurring exception types to operational risk categories and update the risk register entries and monitoring thresholds.

Disclaimer: This content is provided for general informational purposes only and does not constitute legal, accounting, tax, investment, or other professional advice. Portions were generated using AI tools from public web sources and may contain errors or omissions — verify important details against the primary sources linked above before relying on them. Any example prompts, scripts, templates, or other artifacts are provided “as is” without warranty of any kind, express or implied; test them on non-production data and apply your own professional judgement before use. Cherry Hill Advisory disclaims all liability for any loss or damage arising from the use of, or reliance on, this content or any artifact it contains.

Subscribe now to join the Risk Register community: