Preprint
Article

This version is not peer-reviewed.

Information Technology Auditing Tools and Application to Audit Procedures

Submitted:

20 August 2026

Posted:

24 August 2026

You are already at the latest version

Abstract
Information Technology (IT), Information Systems (IS) and Computer Assisted Audit Techniques (CAAT) tools are common in auditing innovative environment. For instance, CAAT and associated auditing tools potentially enhance quality and enables auditors to achieve efficiency. However, audit firms still struggle to reduce resistance in the use of CAAT and other IT audit tools toward the plain compliance of the related standards. This study performs a comprehensive literature survey and analysis of frameworks of the main actors of the usage of IT audit tools. It toes the ISA 620 standard and the resistance theory. It further performs an in-dept analysis on the IT auditing tools in respect to application to auditing procedures. Findings show that the research concerning CAAT and IT auditing tools is increasing. So also, the networks of authors are going from the more traditional outlook spanning other frontiers. Findings also show that the application of IT tools generate more jobs and insights for the financial auditor while it spurs efficiency. We show that the adoption of the IT audit tools is strategically faced with conflicting priorities of the financial auditor inasmuch as the use of specialist is presently dominating the assurance services and it is hard to share from the acquired cake. The onus of application of innovative tools such as AI whose impact must be shared between the audit firm, and the client is yet under debate. We show that audit firms encourage compliance of ISA 620 where audit partners’ IT background strengthens the effective use of IT audit tools. We identified data from papers, frameworks and models that discusses the use of IT audit tools, in auditing. These constructed data were then categorised by technique, engagement phase, and attributes to enhance their effective usage. The analysis categorises into, IT auditing tools in lieu of dragged efficiency, ISA 620 adoption framework (620AF) resistance, overcoming regulatory and methodology hurdles, and identifying gaps for future research, and classifying topics mostly encountered in the literature. Overall, we contribute to the IT audit literature and practice by showing how engagement partners can be complaint with relevant standards and be less resistant and diffuse IT audit tools. The implications of this study to academia are apart from the traditional authors of IT/IS auditing and tools, other networks of authors need to be incentivised. Policy makers and assurance gatekeepers need to tighten their approaches to enhance compliance of ISA standards in the use of auditing tools in the auditing procedures.
Keywords: 
;  ;  ;  ;  ;  

1. Introduction

The Information Technology Audit Tools (ITAT) otherwise Information Systems Audit Tools (ISAT) serve to evaluate, monitor, and safeguard an organization's technology infrastructure. They ensure that systems are secure, available, and compliant with IT operational rules towards a goal congruence.
The ITAT among which Computer Assisted Audit Techniques (CAAT) stands out are meant to bridge the gap between the growing volume of accounting transactions and auditing tasks. ITAT ensure efficiency of auditing tasks in complex systems and databases. For instance, without sophisticated code auditing tools and code editors, it can be nearly impossible to track and examine vulnerable code or locate vulnerabilities within a large project [1].
De facto, they tend to ameliorate the time constraints and users’ pressure on the auditors in the era of technological innovation. Auditing has been technologically impacted by CAAT tools, capacity building of the IT auditor, Artificial Intelligence (AI), deep learning in auditing and emerging technological impact of continuous auditing [2]. Impact is also felt with the innovative technologies such as data analytics for data extraction and exception analysis, IoT, Drones monitoring with satellite imagery, Remote Sensing, Deep Learning and Robotic Process Automation [3]. So, a better understanding of the factors underlying effective CAATTs adoptions would be helpful to aid wider development of these technologies in internal audit [4]. This is also underscored by International Standard for Auditing (ISA) 620 in respect to utilising the expert services in independent auditing.
While IT audit tools add value to audit efficiency [5], auditors are often reluctant to use them in engagements for several reasons [6]. Many because of digital gap and probably reluctance in acquisition of the required competences. Or that it may be linked to the inability to get access to and maintain a workforce with the proper knowledge and experience in emerging technologies. Known as the digital skills gap, which is widening with changing technologies [7].
Ultimately, auditing risks have been heightened because of the wrong usage in adoption of AI. Deloitte Australia issued a partial refund to the Australian government over a $440,000 AUD ($290,000 USD) report on welfare compliance. The report, commissioned by the Department of Employment and Workplace Relations (DEWR), was found to contain AI "hallucinations," including nonexistent academic citations and a fabricated quote from a federal judge [8]. In fact, Deloitte used the Azure OpenAI GPT-4th Generation large language model (LLM) tool to compile "traceability and documentation gaps" in the government's welfare rules.
In fact, the adoption of technology in auditing is still crippling as a result of long relegated IT auditing technology competency development, which has been attributed to the experts. In another perspective, the pace at which technology is introduced into the business environment is different, compared to the auditing practice and the development of auditing teams. In effect, the breeding of the workforce does not follow suite. [9] affirms that capacity programmes can help auditors gain the skills they need to use IT audit tools and that these programmes contribute to a workforce more adept at using these tools effectively. To worsen the scenario, the introduction of AI is beginning to create adverse impact on the occupational categories, serving as a threat to auditing.
Although internal auditors are increasingly aware of the importance and value of audit analytics, prior research indicates that the use of audit analytics is below expectation [10]. In independent auditing, despite the many benefits that AI may provide to businesses, adoption of the technology is still in its infancy in Malaysia [11]. A follow up survey by the Malaysian Institute of Accountants (MIA) in 2019 indicated that high business cost as the main barrier to technology adoption, followed by lack of talents to use technology [12].
Thus, as portrayed by the current scenarios brought by the implementation of artificial intelligence (AI), there is the threat of various occupations losing their grounds. In the current moment [13] projects 10 most exposed occupations in Table 1.
De facto, exposing significantly occupations such as management & accounting, business & finance, computer & maths, architecture & engineering, life & social sciences, legal education arts and office administration to the tune of approximately 65% each. This comes to create more difficulties among the auditors in respect to workforce and acceptance of innovation and technologies, acquiring and maintaining it. Particularly, when it comes to terms of overhauling innovation technologies of the auditing process which is very important. To continually improve, we must examine not only our innovation performance, but the processes with which we develop and exploit these innovations [14].
Therefore, to better understand the relationships between the auditing standards and application of auditing tools, we group them into external and internal environmentally focused. In respect to external focus, the environmental pressures and aspect of being complaint with ISA 620, the regulating standards in the process of auditing, plays an important role. Also, the advancement of technological markets, and users’ dichotomy create a complex environment for diffusion in current digital economy environment. In the same vein, concerning internal lens, engagement partners play an important role in the process of diffusing IT resource application by recruiting experts to comply with ISA 620 standard that obliges auditor to use specialists to support audit in the areas they lack competence. At the executive level, top executives’ attention to and support for digitalization facilitate corporate digital innovation [15]. Firm’s digital strategic orientation and resource allocation constitute critical organizational conditions for advancing digital innovation [16].
Not undermining the recurring questions of the engagement management, apart from also recruiting experts to assist in verifying IT application, accounting estimates for items relating to tax and contingency risks, assess impairments, actuarial calculations, to mention just a few, turns crucial. The question thus surges as what is the preparedness of auditors, based on their budget, the engagement partners strategy for allocating sufficient hours to enable specialist to perform reasonable assurance that mitigates the technological risks? Resistance does surge as a natural defense of the engagement partners to reduce the participation of other groups, notwithstanding the synergy which is hammered within the firms.
[17] Audit partners of nonglobal influence the use of technology-based audit tools (TBATs) and the average partner, many pointed to partners’ resistance. This may be a postulate that the more elderly one in the audit firm strategically may have a backdrop for less compliance of technological requisites. Culturally, resistance in audit firms tend to be risk-averse and hierarchical. Also, this may lead to adopt myopic decision-making. Younger auditors push for analytics and automation and senior partners control methodology and may be slower to change.
Other motives which could be reflected upon is that the engagement partner is unwilling to share the budgeted hours with the specialists, or that this will draw down the profitability of the engagement, especially, impact on the Traditional Audit Business Model (TABM). De facto, automation can change how audits are billed. Many audits are billed based on hours worked and automation may reduce hours required. Partners may fear reduced revenue or pricing pressure ability of the engagement. Even though this synergy is always propagated amongst members of auditing teams a lag may create a stumbling block to operationalising these competencies in auditing assurance.
In the same vein, auditing profession in line with compliance standards exerts pressures on the auditors among various challenges faced by them in leading with the client environment such as Data Access Challenges [18], to use IT audit tools effectively, auditors often need large datasets directly from client systems. Others include client IT restrictions, data privacy concerns and compatibility issues with legacy systems. These barriers can make tools harder to deploy than promised. Unjustifiably, these factors may demotivate the auditors as this may be a hindrance to time constraints.
In general, we expect that auditors who intend to comply with ISA 620 (Utilising expert services) and ISA 540 (Auditing Accounting Estimates and Related Disclosures) also expand on the expectation gap on the diffusion of innovation technology will be more willing to be less resistant to implement emerging IT auditing tools.
Thus, we argue that engagement teams who sees application of IT tools as synergy for efficiency towards a goal congruence will be readily available to reduce the digital gap. Therefore, we conduct a comprehensive literature survey and analysis of frameworks of the main actors of the usage of IT audit tools. And further, performs an in-dept analysis with interviews on the tools in respect to application to auditing procedures.
Prior studies in IT auditing are multifaceted in their approaches, and the authors are also sparce. Author such as Don Wood took the lead in EDPACS from 1960 through 80s [19]. And a traditional author such as Vasarehelyi spearheaded publications in the area of information systems (IS) and information technology (IT) auditing since the 90s. The main contributions featured in Journal of information systems; International Journal of Accounting Information Systems; Journal of emerging Technologies in Accounting; International Journal of Auditing Technology; and a host of others. The author has also constructed a network with a base in Rutgers while breeding new authors such as [20], [21], [22], [23], [24], [25] & [26].
IT Auditing Tools have played a significant role in research involving Accounting and Auditing topics with the seminal text by [14], [27]. They presented an auditing methodology that went beyond performance measurement, highlighting problems and needs, while simultaneously providing information that could be used to develop action plans to improve performance.
The search in the Scopus database applied the type of analysis called bibliographic coupling in the unit of analysis: author. The objective was to identify the authors who used these concepts as keywords and which authors referenced the work of another author whose objective was the same, that is, to identify the documents that defended the thesis of an audit methodology beyond performance measurement.
In this search, 464 authors were found who used the keywords: Information Technology Auditing Tools and IT Auditing Tools. We did not refine or suppress any data such as supposedly abbreviated concepts or synonyms.
This database, generated by Scupus in .csv format, was used in the VOSviewer software to generate bibliographic coupling maps for the author unit of analysis.
This excerpt from the article utilizes the relational bibliometrics technique, which maps the connections within a research topic, going beyond mere quantitative information on publications. Therefore, this technique analyzes the networks of relationships between authors, institutions, countries, and the concepts described in keywords, citations, co-citations, co-authorship, and bibliographic coupling. This means that relational bibliometrics has a greater complexity than the conventional technique of evaluative bibliometrics. Thus, as per Table 2 out of 464 authors, 21 meet the minimum limit.
Table 2 shows the 21 authors indicated by the software who meet the minimum number of documents and how many times these authors are cited by other researchers in relation to the concepts Information Technology Auditing Tools and IT Auditing Tools.
The author [28], [29], [30] have 3 documents listed and a total of 109 citations of these documents, indicating that its content has been applied by other researchers in the same result of 109 times.
With this information from the selected abstract excerpt, it is possible to note the connection with the proposal of the concepts analyzed by this article: Information Technology Auditing Tools and IT Auditing Tools, as well as the strong connection between the research proposal of the author Vasarhelyi, Miklos A. and his co-authors, with the initial argument described in the seminal article by [14].
In the same vein, as an example of well cited publications arising from the current networks, Table 3 shows the impact in publication of IT auditing tools between 2002-2026.
Furthermore, in Search for IT auditing tools in VoiceViewer Table 3 showed that there is an expansion of authors transcending traditional boundaries notably [5], [31] and [32] daring to investigate IT auditing topics of the importance and aching topic of information technology covering the AI. In the same vein, the information technology tool and auditing application has gained professional appeal; notwithstanding that it has been little explored in research.
Our study is situated at the intersection of auditing, IT auditing tools, information systems, psychology and social-psychology making the following contributions. Firstly, we expand the literature on IT and IS auditing tools; Secondly, we speak to the auditing literature and standards in relation to auditing engagement; Thirdly, we sought to understand the reason for resistance in usage of IT tools in auditing engagement; Fourthly, we contribute to the literature on emerging Technologies; and Finally, we suggest aspects worth looking at by academia, policy makers and specialists to advance on discussion of IT auditing technology.
Therefore, we argue for the understanding of the auditing tools and their roles in auditing procedures by asking:
Q1 What are the current IT tools and applications and in which audit procedures do they feature?
Q2 What technological, organizational, and individual factors drive auditors’ resistance to the adoption of emerging technologies in the auditing process? To assist in answering this question we break it down as follows:
Q2 – 1, How do contextual and regulatory factors and professional standards influence auditors’ acceptance of IT auditing tools?
Q2 – 2, How do auditors’ experience level, technological competence, and generational differences affect resistance to emerging auditing technologies perceptions of usefulness, complexity, and risk mitigation?
Q2 – 3, How do team leadership support usage of IT emerging technologies and applications to auditing procedures in engagements?
This study is structured as follows. After this introduction it is followed by the background empirical literature review. Later we present the methodology which is subsequently followed by the analysis. In the next section we present the discussion of the results. To finalise, the study presents a conclusion.

2. Empirical Literature Review

2.1. The Landscape of Auditing Tools and Their Application

The landscape of auditing has shifted from manual testing and paper checklists to a tech-driven ecosystem innovative auditing. Driven by hyper-digitalization, the auditing profession has transitioned from traditional historical sampling toward continuous, real-time auditing and automated risk assessment [33].
The modern auditing tools spans several core categories, ranging from traditional software to cutting-edge AI and automation. As per VoiceViewer report Figure 1, CAATTs adoption and GAI have been intensely explored between 2020 - 2025.

2.2. Computer-Assisted Audit Tools & Techniques (CAATTs)

CAAT stands for Computer-Assisted Audit Techniques. It refers to the practice of using computers and specialized software to automate, simplify, and analyse data during an audit. Instead of checking records manually, auditors use CAATs to quickly scan, filter, and test entire volumes of financial data. CAATTs remain the foundational backbone of digital auditing, enabling practitioners to manipulate and analyse complex client data [4].
Apart from the traditional publications of EDPACS from the 80s, research on the term CAAT - Computer-Assisted Audit Techniques - is quite recent, dating back to 2014 with the publication at the Iberian Conference on Information Systems and Technologies (CISTI), and further publications in 2016, 2018, and 2020 respectively. The remaining publications are Lecture Notes in Network and Systems from the years 2022, 2023, 2024, and 2026. Refer Figure 2 according to the trends in publication about CAAT.
The increase occurred with the popularization of Artificial Intelligence in 2022, with GPT (Generative Pre-trained Transformer) being a driving force, launched by OpenAI in June 2018. From then onwards, several projects that needed integration between keywords and databases on a wide variety of topics were used to facilitate decision-making. This was the case with the term CAAT, which uses AI to facilitate the search and identification of errors in audit systems, thus creating a situation for decision-making on the problem in question in a shorter time frame, with a large margin of safety regarding interpretation or identification of the error.
The search on the term CAAT Figure 3 shows that the authors such as Handoko, B. L. and Pedrosa, I., both with seven published articles, the first of which was published in 2018 by Handoko, B. L., coincides with the introduction of the first AI. As for Pedrosa, I., he published the first article on the term in 2009, employing search software for errors in auditing, unlike what AI would do when it was released to the public in 2022.
In Figure 4 Pedrosa, I. becomes the most cited author due to the article published as a starting point for defining the topic, indicating a total of 69 citations, while Handoko, B. L., comes later, with 43 citations.
There are varieties of CAAT tools consisting of internally developed by the audit firms and ready-made tools existing in the market known as the generalised audit softwares (GAS). GAS such as IDEA, ACL (Galvanize), Arbutus allows auditors to extract, query, and analyse 100% of the data within a client’s database rather than relying on small samples portion relating to the transaction running inputs and outputs. It is heavily used for data formatting, high-volume data validation, missing-sequence detection (e.g., missing check numbers), and automated sampling. Also, duplicate entries could be sorted out from the data bases for exception analysis.
There may be implemented Embedded Audit Modules (EAM). Even though not very common because of the risk of polluting the client’s data, embedded modules are code segments written directly into a client’s application to catch and log high-risk transactions in real time. This EAMs are normally recommended for the internal auditors to build and run.
Recently, Artificial Intelligence (AI) and Machine Learning (ML) tools are transforming auditing by moving it from rule-based checking to context-based predictive analytics and anomaly detection. [32] stresses that it furnishes tools and larger models in detecting complex vulnerabilities and logical flaws, offering a practical, secure, and scalable solution for smart contract auditing.
Advanced Deep Learning Models are also recent tools. Examples: Mind Bridge AI Auditor, EY-Helix, KPMG-Clara, Deloitte-Omni. Their applications involve the platforms ingest millions of ledger entries and use machine learning algorithms to spot risk. Instead of just looking for standard duplicates, they detect behavioural anomalies. They are applied extensively in fraud detection, asset valuation testing, and assessment of risk of material misstatement.
Also, the Robotic Process Automation (RPA) act as software "robots" that replicate mundane, repetitive human actions across systems for instance: UiPath, Automation Anywhere, Blue Prism. RPA is applied to routine, standardized tasks to reduce human error [34]. Especially, to enhance the repetitive tasks in accounting information systems [35]. Auditors use RPA for reconciling data across disparate systems (like matching an e-invoice to a shipping ledger or tie up to the rules stipulated in contracts), population prep, and automated trial balance tie-ins.
The Continuous Auditing and Monitoring Systems is also very common. Being the traditional model, relied on a static point-in-time snapshot. Modern workflows require real-time verification to support a fast-moving economy [33]. They run in Integrated ERP audit controls (SAP GRC, Oracle Cloud Risk Management). Their applications consist in tools continuously scan internal systems for policy deviations, access control issues (Segregation of Duties violations), and unusual master data changes. They are widely applied in internal operational audits to catch risks the moment they manifest, rather than months later during an annual review.
The Blockchain and Distributed Ledger Technology (DLT) platforms, Ethereum/Bitcoin node explorers is also an efficient tool. Offers immutable databases, decentralized access to accounting data that significantly enhance data correctness and completeness and transparency. Instead of manually verifying third-party bank confirmations, auditors can validate ownership and transaction history directly against an immutable ledger, boosting reporting accuracy and stakeholder confidence [36].

2.3. Relevance of IT Audit Workforce and Relationships Between IT Audit Tools

The IT and IS audit workforce and IT audit tools hereinafter resources are turning increasingly relevant for the execution of auditing task. In so far as it enhances automation of auditing procedures, eliminating duplicate tasks, maintaining efficiency and effectiveness as it turns auditing systems to be agile. These resources assist in decentralising the participation of the members of auditing teams with the functions of preparers and reviewers easily segregated and also automating the documentation of working papers. However, the change in databases, programming languages for example: Natural languages, data volume built around Data Analytics could create a barrier to user-friendliness for the auditors.
Furthermore, the IT auditing career development hinges on the decision of the beginner whether to be identified as auditor or identified as systems analyst/computer specialist [5,37]. Those firms who need permanent expert force normally should build theirs or recruit from expert serve firms on a need-basis.
Many partners built their careers using manual sampling, spreadsheets, and documentation-based audits. Moving to automated tools requires changing well-established workflows and culture. They trust techniques that have worked for decades and develop a fear that automation might miss nuances they would catch manually.
Generally, auditors emphasize professional skepticism and judgment. Some partners worry that relying on technology could: Reduce human oversight; encourage “black-box” analysis where the logic is not fully transparent; and create regulatory issues if they cannot explain how a tool produced a result. De facto, Audit firms are heavily inspected by regulators like the Public Company Accounting Oversight Board (PCAOB) and similar bodies globally. Partners worry that regulators may not fully understand the methodological tool and inspection related findings could increase if tools are poorly documented.
In the same vein, with respect to learning curve and time constraints, Senior partners are extremely busy managing clients and engagement teams. Learning new tools requires training time and a short-term productivity may drop while teams learn the software; and some partners feel the ROI doesn’t justify the effort late in their careers.
Regarding Cost and Budget Concerns, IT audit tools can be expensive. This hinges on licensing fees; implementation costs; and training and integration with existing systems. So, Partners may worry that the cost cannot be easily passed on to clients.

2.4. Usage of IT Audit Tools and Technology Acceptance Model (TAM)

The usage of IT audit tools could also be termed the adoption of the technology. The audit firms culturally use the IT tools in the engagements which they consider that the IT environment and accounting information systems are significantly complex.
The Unified Theory of Acceptance and Use of Technology (UTAUT) formalize frameworks for adoption of IT resources. These frameworks help identify categories such as perceived usefulness, ease of use, social influence, and facilitating conditions that describe the mode of acceptance. Models such as UTAUT [38] view the individual level of technological adoption.
[39] investigates the factors influencing the intention of internal auditors to adopt big-data analytics (BDA), based on the unified theory of acceptance and use of technology (UTAUT). They note that performance expectancy influence adoption of IT resources.
TAM is fairly tied to the adoption of application systems. [40] expands on GAS acceptance and adoption by independent auditors; [41] Siew, Rosli & Yeowa (2020) on acceptance and adoption of CAAT in audit firms; while [42] comment on adoption of audit analytics for internal auditors.

2.5. Theory of Resistance

The resistance theory maintains the political, philosophical and sociological baseline for opposing an established, dominant cultural ideology or norms. Resistance theory is best understood as a foundational, albeit evolving, concept in psychology.
This theory is not exclusively psychological and is also deeply rooted in the sociology where it refers to the socio-political often conscious performatively.
In biology and medicine, a resistant individual is a person who possesses natural or acquired mechanisms that prevent them from developing a disease, infection, or adverse effect when exposed to a specific pathogen, toxin, or environmental stressor. In the like manner, resistance theory in management and organization studies (MOS) seeks to understand ways in which employees refuse to comply with power [43].
According to [44Lawlor and Nale (2014) Foucault explains that there is a plurality of resistances that are present everywhere in power relations and “play the role of adversary, target, support, or handle”. Points of resistance are the “odd term in relations of power” its blind spot or evading limit.
[45] develops a performative theory of resistance using Judith Butler’s and Karen Barad’s theories of performativity to explore how resistance (to organizational strategies and policies) and resistants (those who resist such strategies and policies) co-emerge, within and through complex intra-actions of entangled discourses, materialities, affect and space/time.
Overall, the effect of resistance on usage of IT audit tool has not been examined. So, this will boost the contribution to the academia and profession of auditing.

2.6. Usage of IT Audit Tools and Resistance

The inability to work with emerging technologies to assist engagement teams is sailing through transformations. De facto, audit procedures that need IT expertise is not new, and this keeps expanding in the era of artificial intelligence. At times audit partners assumes a higher risk working on the premise of merely complying with ISA 620 on the use of experts without detail verification of IT controls needed to proof the reliance. This status quo thinking naturally creates obstacles for auditor to themselves develop the competencies with IT audit tools. In line with the psychology point of view on status quo on technologies, where people prefer existing technologies to new ones [46].
Various factors hinder the use of IT audit and its tools, they range from external and internal to the auditing firms. The external factors include IT audit education, professional support provided by professional accounting and auditing bodies, external pressure and social factors. The internal factors include the firm’s organizational support, complexity of accounting information systems, IT audit competency, adoption risk, ease of use and readiness [9]. Also, the internal strategy that aligns with the firm’s methodology may play a part.
The implications of resistance to use of IT tools in auditing may be broader than just less diffusion of technology. It could constitute a noncompliance of auditing standards and invariably imply in reduction of auditing quality. Whereby the quality threshold of the reasonable assurance of a financial statement is not attained. Audit partners high in resistance are likely to debar the team from fully complying with the ISA 620 standards. Therefore, the efficiency of the audit could be at risk if quality review is unable to locate this perspective of auditing review. Additionally, auditors being resistant can pose a drawback to diffusion of technology.

2.7. International Standards for Auditing (ISA) 620 and Resistance

The ISA 620 broadly defined the standards for the use of expert services. IT expert is included in the list of professionals which could be integrated in the engagement team. In the current landscape, the noncompliance of this standard by the audit firm could be liable to punitive measures or fine.
If an individual audit partner is resistant to applying ISA 620 it usually means they are reluctant to involve or rely on specialists during an audit. This can create quality, compliance, and risk issues because ISA 620 requires auditors to use experts when specialized knowledge is needed (e.g., valuations, actuarial estimates, complex IT systems).
An audit partner resistant to ISA 620 may likely avoid engaging experts (valuation specialists, actuaries, IT specialists) even when the audit requires specialized knowledge may be as a result of: Over-rely on their own judgment in areas outside their expertise; Challenge or delay expert involvement to reduce costs or time; Downplay complex estimates (e.g., financial instrument valuation or impairment models); and Limit documentation of expert evaluation or competence.
Why this is problematic, resistance can lead to: Noncompliance with international auditing standards set by the International Auditing and Assurance Standards Board (IAASB); Audit quality deficiencies identified by regulators; Increased audit risk if specialized areas are not properly assessed; and potential issues in inspection reviews by regulators or internal quality monitoring.
What should happen instead under ISA 620, the partner should during the audit planning determine when expert work is necessary. Also, with the knowledge of the business evaluate the competence and objectivity of the expert and define the scope of the expert’s work to later evaluate the adequacy of the expert’s findings as audit evidence.
In internal (firm governance) and guidance series for practice, firms usually address resistance through audit methodology enforcement, quality review processes, engagement quality reviews and training on standards issued by the International Federation of Accountants framework.
Overall, an audit partner resisting ISA 620 risks performing an audit without sufficient expertise in complex areas, which can undermine audit quality and regulatory compliance.

3. Methodology

This study assumes a qualitative paradigm and the process of analysis is interpretative. It is also followed by thematic coding for the significances derived from the analysis of all sources of data including the interviews.
The study performs a comprehensive literature survey and analysis of frameworks of the main actors of the usage of IT audit tools such as National Institute of Standards and Technology (NIST) and General Data Protection Regulation (GDPR) standards. Other sources were COBIT, ISO/IEC 27001, ITIL standards and ISACA. In addition, data is sourced through the guidelines and methodologies gathered from the webpages of the big four audit firms and BDO. It further toed the content analysis of data constructed from various data bases such as Edgard databases and Sarbanes Oxley Act (SOX) and exercised on the narratives presented by their preparation and disclosures to the stakeholders.
The study also counts on interviews with 10 partners from the big four firms. We choose experienced auditors imbued with the power to exercise the audit strategy as participants because the discussions stimulated in this study may only provoke reflexivity among in-charge partners. Generally, based on a drill down of the pyramid of decision-makers to apply the IT tools in auditing engagement. Their interviews lasted approximately 50 minutes each and they were recorded. After which, it was transcribed and analysed with MAXQDA 24 qualitative analysis software.
In similar research [47] Alami and Alenezi (2026) employing a qualitative research approach, utilised semi-structured interviews with auditors and information technology (IT) managers from various experience levels and firm sizes. Also, this is seen as suitable for studies performed in areas of IT and information systems, as observed in [3].

4. Analysis

In categorically analysing the results, we consider the significances constructed from all sources of data and experiences shared by the auditing partners interviewed; their words serve as fabric scraps, and our role is simply to bring them together to create a large source of reflexivity. This being an image formed from these scraps aimed at thematically contributing to the field of IT auditing.
Approximately 35 subcategories were presented in Figure 5 and at the end 3 umbrella high-level categories were summarised as shown in the analysis. The classification is not necessarily deterministic however, recursive for the analysis in the context of this study.

4.1. IT Audit Tools in Lieu of Dragged Efficiency

The IT audit tools are further being summarised in five perspectives, characterised by the generalised, behavioural, organisational, technological, generational tool and regulatory and professional perspectives to support auditing practices. Hence, modern auditing relies significantly on Information Technology (IT) tools to improve efficiency and effectiveness of processes and track errors and probable fraud detection.
The Computer Assisted Audit Techniques are inherently constituted with core function to relief the auditors with the manual functions. Normally of the internal control tests and the substantive tests. This potentially enhance quality and enables auditors to achieve efficiency.
In a like manner, the main ERP systems are inbuilt with modules with different methodologies. Generally, used Data Analytics & Business Intelligence as resources to boost their operations. In fact, owing to the large data being maintained nowadays, the milking of this data requires the core of data analytics and business intelligence. Normally, they are Generalized Audit Software (GAS).
Also, there are Audit Management softwares in firm’s methodology (Deloitte 2026), of which some internally developed with third-party assistance and with engagement management inbuilt. In-house Audit Software may adopt the policies for mitigating the risks of IT assessment through the resources developed in-house. So, the competences for definition, design, analysis, programming, testing and implementation and also maintenance lies within these resources. These applications are generally very strategic and secret to the outside developers. Their objects and their programming logics are kept under lock and key, known to few and are internally maintained.
The Artificial Intelligence (AI) has shifted auditing from a "sampling-based" model to a "population-based" model. The IT resources used in auditing have evolved from simple data analytics to autonomous agents and generative systems that handle both structured and unstructured data.
Instead of using subjective judgment, AI identifies "outlier" entities or regions that deviate from historical norms, allowing auditors to allocate resources more effectively.
In the IT audit tools with AI embedded, anomaly detection algorithms scan every single transaction for "needles in the haystack," such as unauthorized weekend postings, unusual round-sum amounts, or duplicate payment. And NLP tools (e.g., DataSnipper) automatically reconcile PDF invoices against Excel workpapers. They can flag "change of control" clauses or non-standard termination dates that might require financial disclosure.
In the same line of thought, AI-powered dashboards monitor control deviations (like a user accessing a system they shouldn't) as they happen, rather than six months after the fact. And as an operational support, Generative AI tools take the findings from the fieldwork and draft professional, structured reports. They ensure consistent tone and can translate complex technical findings into executive summaries for the Board of Directors.
In all, after performing content analysis in all the databases and triangulating to the frameworks [48 [49]; [50] we identified a series of core areas and selected IT tools. They also pinpoint auditing applications which address practical auditing procedures. De facto, there are core areas that are aligned to specific IT tools and these in turn generates an association with certain auditing application for the operationalization of their objectives. They enhance the performance of numerous auditing procedures as shown in Figure 6.
Financial auditor use of IT Specialist and Tools is operational
We are constantly needing experts in almost all the industries we audit, thus IT specialist partaking in the budgetary estimates of our professional fees. This is increasing day in day out in the complex environments in which we live today (R-4)
Soonest, the specialist will consume a better part of the auditing fees since we are continuing to increase the need of them to review IT controls and expansion to other areas in which we are less skilled. (R-5).
In fact, with AI influencing the occupations, more untraditional occupations are being created and operational functions expands. This demands specialists to assist the financial auditors to review these new business functions.
Thus, referring to the occupational loss of ground, because of AI, explains this trend for the traditional auditing management cultivating resistance. Noteworthy, that these professionals are top launcher and well skilled, and their fees generally are higher than that of the financial auditors.
Big four firm are investment in IT auditing tools
To withstand the evolving trends of IT auditing tools the big four firms are investing in IT auditing tools to live up to the expectation of their clients.
Each of the Big Four has poured billions into building their own global, cloud-based ecosystems. These tools integrate advanced data analytics and generative AI to handle system walkthroughs, parse code, and automate evidence collection (R-10)

4.2. ISA 620 Adoption of Framework (620AF) and Resistance

Scenario of compliance with ISA 620 (Using the Work of an Auditor’s Expert)
The scenario of compliance around IT resources involves a delicate balance between leveraging necessary technological tools and managing human or structural resistance. (R-1)
Compliance focuses on three pillars. Firstly, evaluation of competence and Objectivity. The engagement partner must approve the IT expert’s technical credentials (e.g., CISA, CISSP certifications) and ensure that they have no conflicts of interest with the client. Secondly, written Agreements ISA 620 mandates aligning on the scope of work. For IT resources, this includes detailing exactly which servers, databases, or General IT Controls (GITCs) the expert will test, and the exact data extraction methods they will use. Lastly, evaluating the adequacy of the expert's work. In this case, the auditor must evaluate whether the IT expert's findings translate effectively into financial terms. Example: If the IT expert discovers a vulnerability in the database access controls, the financial auditor must translate that tech risk into a financial risk—specifically, whether unauthorized journal entries could have been made undetected.
Adequacy of adoption of ISA 620
To certify the adequacy of the use of IT tools, the partner must be able to monitor the usage. The partner must be able to explain how the tool worked and why its output is reliable to external regulators. This is very important to comply with the review processes.
ISA 620 explicitly requires the auditor to evaluate the relevance and accuracy of the source data used by the expert or tool. In the bottom line, under ISA 620, an IT tool or specialist can perform 99% of the heavy lifting, but if the audit partner cannot explain the tool's logic, check its inputs, or follow up on its exceptions, they are in direct violation of global auditing standards.
The Golden Rule of ISA 620 is the software, and the IT expert provide the data, but the Audit Partner owns the judgment (R-9)
The "Resistance" Scenario in Financial Auditing
Despite the technical necessity, implementing ISA 620 regarding IT resources frequently encounters resistance notably double-edged sides, auditor and auditees (R-2)
On client-side resistance, there may be Data Privacy and Security Objections. Clients frequently resist giving external IT experts deep administrative access to their production environments or proprietary source code, citing GDPR, data leaks, or proprietary trade secrets.
The "Black Box" Defense: Client IT departments may resist explaining complex algorithmic logic (e.g., proprietary AI or automated valuation models), claiming the auditor "wouldn't understand anyway."
Friction with Management's Experts: If the client used their own IT specialist to build a system, they may push back against the auditor's IT expert questioning their methodology.
The IT auditor use of tools is notorious for having a built-in level of friction, underlying grudges, and "turf wars in the big four firms amongst the partners (R-7).
On the auditor-side resistance, the engagement team may build a communication gap (The "Tower of Babel" Effect). Financial auditors and IT experts speak fundamentally different professional languages. Financial auditors may struggle to understand technical jargon (e.g., "SQL injections" or "regression anomalies"), leading to internal friction or a checkbox mentality toward compliance.
Concerning budget and time constraints, hiring external IT specialists adds significant cost and time to an audit. Engagement partners may subtly resist triggering ISA 620 to preserve profit margins, attempting instead to rely on insufficient manual workarounds.
IT auditors do complain that financial teams constantly push back on their budgets, cutting IT audit hours to the bone, which forces the IT team to work unpaid overtime to get the testing done safely (R-6)
Over-Reliance (The Passive Compliance Trap): Conversely, some auditors show "passive resistance" to understanding the tech by blindly accepting whatever the IT expert's report says. This violates ISA 620, which requires the auditor to actively challenge the expert’s assumptions and source data.
Thus, financial auditors are sceptical and seldom resist the use of IT auditing tools because of extra job their verification could pinpoint. Naturally, when they run 100% of the client's transactions through a data analytics tool, the tool might flag 5,000 "anomalies" or exceptions based on its programming logic.
Auditors resist using the tools because a tool's "insights" can accidentally create hundreds of extra hours of documentation work (R-7)

4.3. Auditors Overcoming Regulatory and Methodology Hurdles

Auditing is a highly regulated field governed by strict standards (like PCAOB or AICPA). Auditors are often hesitant to use new tech because they fear it won't pass regulatory scrutiny. This fear of test makes financial auditor to periodically, adjust their methodologies to suit the trends.
IT audit real-life regulatory reality of auditing firms
Financial accounting enforcement actions frequently highlight instances where the audit partner signed off on an opinion believing the IT system was "secure," while the IT specialists' actual workpapers only covered basic password policies—failing to test the complex automated application controls relevant to the financial statements. This breach of trust could occur when the budget is at the fletch of the IS auditor.
Team leadership support usage of IT emerging technologies and applications to auditing procedures in engagements
Team leadership plays a critical role in bridging the gap between cutting-edge tech and practical, compliant auditing. When a team is bogged down by traditional, manual sampling methods, it’s up to leadership to pave the way for tools like AI, robotic process automation (RPA), and advanced data analytics (R-2)
Leadership defines why the technology matters. Instead of viewing tools as an administrative burden, leaders reframe tech adoption as a way to enhance audit quality and value.
Training and Fostering a Culture of Upskilling and Innovation to Introducing new technology. Update on usage and creating an awareness program on how to use resources and not be intimidated.
Leading by Example (Active Engagement) in adoption of technology
True support isn't passive. Leaders must be actively involved in the tech-driven audit process (R-3)
In bottom-line, technology provides the tools, but leadership provides the permission, capability, and direction. Without active leadership support, emerging audit technologies remain expensive shelf-ware.

5. Discussion

First and foremost, it is important to state that arriving at the current findings in this paper was supported by the following tentacles: (a) the in depth discussion on literature bounding IT Auditing and IT auditing tools; (b) the up-to-date and understanding of the relevant IT auditing tools to assist assessment of auditing procedures (c) the opportunity to know what propels the IT audit tools resistance to usage in the auditing processes, and having a functional approach to enhance their adoption by the auditing partners. Findings of this study therefore presupposes that integrating auditing synergetic policy for adoption of IT tools, auditing methodologies, compliance with ISA standards and negotiation with clients, will collectively drive towards auditing efficiency.
Therefore, it is worthwhile to pinpoint the answers brought forward that satisfy the research questions.
Concerning Q1 - What are the current IT tools and applications and in which audit procedures do they feature? We found that the current IT tools are ACL, IDEAL, SAP ERP, PowerBI, Tableau, TeamMtate+, CaseWare, ISACA Resources, COSO Framework and PCI standard. Others are CAAT, RPA, UiPath, Data Lakes & Cloud Warehouse, Azure, Satellite Imagery, Remote Sensing, Generative AI & LLMs, among others.
The tools are applied in numerous audit procedures namely, data extraction for exception analysis, stratification and ageing analysis, gap detection, configuration analysis and predictive analytics. Others are regression analysis, statistical sampling, ITGC assessment, automated reconciliation, analytical review to mention just a few.
With respect to Q2 - What technological, organizational, and individual factors drive auditors’ resistance to the adoption of emerging technologies in the auditing process? The use of IT audit tools is operational therefore; it helps to include the IT specialists into the audit team. Additionally, the ISA adoption framework and scenario of compliance track the engagement management, thereby avoiding resistance to usage of tools. With such results, it is worthwhile to revisiting the discussion surrounding adoption of IT auditing tools and partner's resistance to adoption of ISA 620 standards.
Furthermore, the trend in voluptuous investment of the big four firms in development of IT auditing tools seem to be a necessity to boost their auditing methodologies. Thus, one would imagine that efficiency derived from the auditing process would pay back their effort. Left to know if the just resistant partners would think otherwise. Doesn’t extension and insights to perform more job after the use of IT tools characterise efficiency in auditing?
In another perspective, looking at the growth of IT tools, the wave of the clients demanding reduction in fees because of reduction of repetitive tasks of the auditors would need deliberation. This is because on one hand the engagement gains with the reduction of tasks formerly performed manually but increases in in-dept assessment with the IT auditing tools. This generally, demands investment on the side of the audit firm by upskilling the engagement team technologically.
From the thematic categorical analysis, the significances that emerge with 1st Order categories are IT audit tools in lieu of dragged efficiency; ISA 620 adoption of framework (620AF) and resistance; and Auditors Overcoming Regulatory and Methodology Hurdles.
The IT auditing tools mostly shown in 2nd Order categories are such CAAT, ERP Systems, BI Tools and their usages intend to address the manual limitations of data analysis, transaction processing and visualisation. Also, having focus on Substantive testing, Control testing and Risk assessment. For instance, the use of ACL, Idea, CaseWare solutions provide a streamlined approach for managing auditing and conducting internal control tests and performing substantive tests. They generally allow for non-sampling test of accounting databases by de facto, testing the whole population. Optical Character Recognition aligned with Robotic Process Automation is used to extract information from contracts, policies, invoices, forms to mention but few to validate entries. The usage of AI tools helps perform Journal Entry testing, ensures the verification of completeness among other assertions and detect suspicious accounting entries.
We show that application usage of IT audit tools is strategically faced with conflicting priorities since the use of specialist is predominantly dominating the assurance approach and it is hard to share from the acquired cake. Nonetheless, this seems to be the trend on the application of innovative tools such as AI whose cost must be shared among the various specialised teams of the audit firm and the client.
Similarly, serving as ethical guardrails and governance individual IT auditing is necessary, even though, using the innovative tools is sine qua non to the current environment. However, the "Human-in-the-Loop" mandate still proposes for the auditing assessment protocols. Despite the power of agents, the final audit opinion must still be signed by a human who has the repertoire for reflexivity towards decision making.
The potential point of resistance among the auditors are cost objections from partners; client delaying infrastructure mapping documentation; client IT withholding high-level access due to security or privacy policies and communication gaps; financial auditor blindly signing off on a technical report they do not comprehend. Therefore, to achieve true compliance with ISA 620 in modern tech landscapes, audit firms must cultivate "hybrid" professionals who understand both accounting frameworks and information systems, effectively bridging the gap between technical usage and systemic resistance.
With the use of AI methodology with talent reconning LLMs in auditing, naturally, cost reduction pressure will rise. On one side the Clients, have even begun demanding "AI discounts" on their audit fees, arguing that since the auditor is using less human labour, the price should drop. On the other side the auditors have started investing in their technologies and training their teams to be apt in areas of preparation of workable prompts. Thus, to enhance the development of AI prompts for auditing procedures, it is worthy to consider the following elements in Figure 7.
In respect of use of AI auditing methodologies, there is the "Big Four" Proprietary Ecosystems. Deloitte (Zora AI): An agentic AI platform that deploys autonomous agents to perceive, reason, and act. It handles everything from business expense management to complex financial statement analysis. PwC (AI Factory/OpenAI Partnership): PwC is one of the largest enterprise users of OpenAI’s models, integrating custom-built agents directly into their audit workflow to tailor guidance for auditors and accelerate software development. EY (AI Audit System): Focused heavily on the tax and audit practice, using massive in-house datasets to provide teams with "100 years of domain knowledge" via a conversational interface.
Overall, to use the AI tools in auditing, the auditor would have to bear the culture of auditor – Agent – Revisor / authorization and bury the old procedures of the relationships between the auditor – performing (repetitive tasks) – Review/sign off. Thus, the use of tools and particularly IA resources, “human intelligence problem" and the unreviewed outsourcing of core analysis to generative AI have to be monitored.

Conclusions

This study performs a comprehensive literature survey and analysis of frameworks of the main actors of the usage of IT audit tools. It toes the ISA 620 standard and the resistance theory. While following the interpretative and constructivist perspective.
The Golden Rule of ISA 620 is, the software, and the IT expert provide the data, but the audit partner owns the judgment. In the same vein, the engagement management owns the push for auditing innovation and consequently, the governance for the implementation of IT auditing tools.
The variability of IT auditing tools turns the adoption a mere operational decision. This could be developed by the audit firm with the assistance of third parties and could be acquired as ready-made packages are available to the auditors.
The big four firms are taking the bull by its horns in the implementation of auditing tools. This has been done with in-house resources with the assistance of third parties. Also, the integration of outsider IT specialist into the financial auditing team has propelled the use of IT auditing tools.
In real terms, the resistance is usually temporary. In many firms today, audit partners who initially resisted are now strong advocates once they see benefits such as testing 100% of transactions instead of samples, faster anomaly detection, improved error and fraud risk identification and guided auditing efficiency.
The qualitative paradigm and the interpretative perspective adopted to investigate the usage of IT auditing tool provides an exciting and productive framework for research, policy, and auditing practice. This further shed light on the breadth of empirical IT auditing ecosystem research and the variety of methodological approaches as well as the nature of the research. Through this interpretative and descriptive review, we show that the IT auditing and IT tools ecosystem adoption has sparked interdisciplinary discussions involving auditing operational, ISA standard issues and SEC/PCAOB regulatory compliance.
As a suggestion for future research, one would venture to recommend more studies with respect to AI needing further understanding about their influence in auditing. With IT auditing and tools as a focus, it projects a variety of research streams to generate new research questions about the auditing trends and consequences of IT auditing and assurance environment.

References

  1. Ji, Z.; Wu, D.; Jiang, W.; Zi, L.; Wang, S. Measuring and Augmenting Large Language Models for Solving Capture-the-Flag Challenges. CS '25: Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security 2025, 603–617. [Google Scholar] [CrossRef]
  2. Imoniana, J. O.; Filho, D. C. N.; Cornacchione, E. B.; Reginato, L.; Benetti, C. Impact of technological advancements on auditing of financial statements. Eur. Res. Stud. J. 2023, 26(4), 131–159. Available online: https://ersj.eu/journal/3277. [CrossRef]
  3. Vieira, V. Auditoria em tempos de Big Data & Analytics Requisitos Mínimos de Controlo; Instituto Superior de Contabilidade e Administração de Coimbra, 2016; Available online: http://hdl.handle.net/10400.26/18058.
  4. Mahzan, N.; Lymer, A. Examining the adoption of computer-assisted audit tools and techniques: Cases of generalized audit software use by internal auditors. Manag. Audit. J. 2014, Vol. 29(No. 4), 327–349. [Google Scholar] [CrossRef]
  5. Imoniana, J.O. Auditoria de Sistemas de Informação; Editora Atlas: São Paulo Brasil, 2005. [Google Scholar]
  6. Cao, T.; Duh, R. R.; Tah, H. T.; Xu, T. Enhancing auditos’ reliance on data analytics under inspection risk using fixed and growth mindsets. Account. Rev. 2022, 97(3), 131–153. [Google Scholar] [CrossRef]
  7. Association of Chartered Certified Accountants- ACCA. The digital accountant: Digital skills in a transformed world. 2020. Available online: https://www.accaglobal.com/gb/en.html.
  8. Paoli, N. Deloitte was caught using AI in $290,000 report to help the Australian government crack down on welfare after a researcher flagged hallucinations. Nature. 2025. Available online: https://fortune.com/2025/10/07/deloitte-ai-australia-government-report-hallucinations-technology-290000-refund/.
  9. Almaqtari, F.A. "The determinants of IT audit usage in Saudi Arabia with specific reference to computer audit assisted tools". Inf. Discov. Deliv. 2025, 53(3), 321–342. [Google Scholar] [CrossRef]
  10. Jun Dai, H. L.; Tatiana Gershberg, T.; Vasarhelyi, M. A. Understanding usage and value of audit analytics for internal auditors: An organizational approach. Int. J. Account. Inf. Syst. 2018, 28(1), 59–76. [Google Scholar] [CrossRef]
  11. Lee, C. S.; Tajudeen, F. P. Impact of Artificial Intelligence onAccounting: Evidence from Malaysian Organizations. Asian Journalof Bus. Account. 2020, 13(1). [Google Scholar] [CrossRef]
  12. Majid, W.Z.N. A.; Asat, S. N.; Tumiran, S. D.; Idris, N.A.; Muhammad, K.; Abdulatif, K. The Application of Artificial Intelligence in Audits: Evidence from Audit Firms in Malaysia. Manag. Account. Rev. 2025, 24(2), 329–359. [Google Scholar] [CrossRef]
  13. Anthropic. Labour market impacts of AI: A new measure and early evidence. 2026. Available online: https://www.anthropic.com/research/labor-market-impacts.
  14. Chiesa, V.; Coughlan, P.; Voss, C. A. Development of a Technical Innovation Audit. J. Product. Innov. Manag. 1996, 13, 105–136. [Google Scholar] [CrossRef]
  15. Lee, J.Y.; Wei, Y.Q.; Tang, R.W.; Choi, B.; Cooke, F.L. CEO narcissism, subsidiary top management team international diversity, and radical digital innovation in multinational enterprises. Res. Policy 2025, 54. [Google Scholar] [CrossRef]
  16. Verhoef, P.C.; Broekhuizen, T.; Bart, Y.; Bhattacharya, A.; Dong, J.Q.; Fabian, N.; Haenlein, M. Digital transformation: A multidisciplinary reflection and research agenda. J. Bus. Res. 2021, 122, 889–901. [Google Scholar] [CrossRef]
  17. Witte, A. L.; Hux, Candice T.; Earley, Christine E.; Jay, C. ThibodeauTechnological Stewards: How Partners Influence the Use of Technology-Based Audit Tools. Audit. A J. Pract. Theory 2025. [Google Scholar] [CrossRef]
  18. Imoniana, J. O.; Lovatte, J.; Everton, S.; Bomfim, N.; Alves, V. M. Relationships between rule-based and context-based data usage in processing of accounting information systems. Procedia Comput. Sci. 2026, 258, 1075–1083. [Google Scholar] [CrossRef]
  19. Singleton, T. A Tribute to IT Auditing Pioneer Don Wood. EDPACS 2002, 29(11), 16–18. [Google Scholar] [CrossRef]
  20. Alles, M. G.; Kogan, A.; Vasarhelyi, M. A. Putting continuous auditing theory into practice: Lessons from two pilot implementations. J. Inf. Syst. 2008, 22(2), 195–214. [Google Scholar] [CrossRef]
  21. Jans, M.; Alles, M.G.; Vasarhelyi, M. A. A field study on the use of process mining of event logs as an analytical procedure in auditing. Account. Rev. 2014, 89(5), 1751–1773. [Google Scholar] [CrossRef]
  22. Appelbaum, D.; Kogan, A.; Vasarhelyi, M.; Yan, Z. Impact of business analytics and enterprise systems on managerial accounting. Int. J. Account. Inf. Syst. 2017, 25, 29–44. [Google Scholar] [CrossRef]
  23. Nehmer, R.A.; Appelbaum, D. Using Drones in Internal and External audits: An Exploratory Framework. J. Emerg. Technol. Account. 2017, 14(1), 99–113. [Google Scholar] [CrossRef]
  24. Moffitt, K.C.; Rozario, A.M.; Vasarhelyi, M.A. Robotic process automation for auditing. J. Emerg. Technol. Account. 2018, 15(1), 1–10. [Google Scholar] [CrossRef]
  25. Huang, F.; Vasarhelyi, M.A. Applying robotic process automation (RPA) in auditing: A framework. Int. J. Account. Inf. Syst. 2019, 35, 100433. [Google Scholar] [CrossRef]
  26. Munoko, I.; Brown-Liburd, H.L.; Vasarhelyi, M. The Ethical Implications of Using Artificial Intelligence in Auditing: I. Munoko et al. J. Bus. Ethics 2020, 167(2), 209–234. [Google Scholar]
  27. Imoniana, J.O. Segurança de informação como sustentabilidade de controladoria. Tese de doutorado, FEA/USP, 1992. [Google Scholar]
  28. Vasarhelyi, M.A.; Alles, M.G.; Kogan, A. Principles of Analytic Monitoring for Continuous Assurance. J. Emerg. Technol. Account. 1 2004, 1–21. [Google Scholar] [CrossRef]
  29. Vasarhelyi, M.A.; Teeter, R.; Krahel, J.P. Audit Education and the Real-Time Economy. Issues Account. Educ. 25 2010, 405–423. [Google Scholar] [CrossRef]
  30. Sun, T.; Vasarhelyi, M.A. Embracing Textual Data Analytics in Auditing with Deep Learning. Int. J. Digit. Account. Res. 18 2018, 49–67. [Google Scholar] [CrossRef]
  31. Liu, Y.; Xue, Y.; Meng, G.; Tan, H.T.; Chen, H.; Sun, J. Auditing Anti-Malware Tools by Evolving Android Malware and Dynamic Loading Technique. IEEE Trans. Inf. Forensics Secur. 2017, 12(7), 1529–1544. [Google Scholar] [CrossRef]
  32. Wei, Z.; Sun, J.; Zhang, Z.; Hou, Z.; Zang, X. HKT-SmartAudit: Distilling Lightweight Models for Smart Contract Auditing. IEEE Trans. Inf. Forensics Secur. 2026, vol. 21, 4446–4459. [Google Scholar] [CrossRef]
  33. Lombardi, D. R.; Bloch, R.; Vasarhelyi, M. A. The Current State and Future of the Audit Profession. Curr. Issues Audit. 2014, 9(1), P10–P16. [Google Scholar] [CrossRef]
  34. Jedrzejka, D. Robotic process automation and its impact on accounting. Zesz. Teoretyczne Rachun. 2019, 105(1), 137–166. [Google Scholar] [CrossRef]
  35. Imoniana, J. O.; Curras, H.; Kawahara, M. I. The Impact of Robotic Process Automation on accounting information systems French Multiple case studies. Rev. Organ. Em Contexto 2024, Vol 20(Issue 39), p519. [Google Scholar]
  36. Moretti, M.; Wamba, S.F. Blockchain technology in financial reporting: Evidence from European companies. Int. J. Account. Inf. Syst. 2024, 53, 100609. [Google Scholar]
  37. Imoniana, J.O.; BBS Imoniana, B. B. S. Auditors’ Career Development and Personal Identity Crisis. Eur. Res. Stud. J. 2020, 23(1), 565–586. [Google Scholar] [CrossRef]
  38. Venkatesh, V.; Morris, M. G.; Davis, G. B.; Davis, F. D. User Acceptance of Information Technology: Toward A Unified View. MIS Q. 2003, 27(3), 425–478. [Google Scholar] [CrossRef]
  39. Iguma, M.K.; Riccio, E. L. Factors influencing Brazilian internal auditors' behavioural intention to adopt big data analytics. Int. J. Audit. Technol. 2021, 4(3), 217–239. [Google Scholar] [CrossRef]
  40. Widuri, R.; O`Connell, B.; Yapa, P.W.S. Adopting generalized audit software: na Indonesian perspective. Manag. Audit. J. 2016, 31(8/9), 821–847. [Google Scholar] [CrossRef]
  41. Siew, E.; Rosli, K.; Yeow, P.H.P. Organizational and environmental influences in the adoption of computer-assisted audit tools and techniques (CAATTs) by audit firms in Malaysia. International Journal of Accounting Information Systems 2020, vol. 36(C). [Google Scholar]
  42. Li, H.; Dai, J.; Gershberg, T.; Vasarhelyi, M. A. Understanding usage and value of audit analytics for internal auditors: An organizational approach. Int. J. Account. Inf. Syst. 2018, 28(1), 59–76. [Google Scholar] [CrossRef]
  43. Spicer, A.; Fleming, P. Working at a cynical distance: Implications for power, control and subjectivitiy. Organization 2003, 10, 157–179. [Google Scholar] [CrossRef]
  44. Lawlor, L.; Nale, J. Resistance. The Cambridge Foucault Lexicon; Cambridge University, 2014; pp. 432–437. [Google Scholar] [CrossRef]
  45. Harding, N. H.; Ford, J.; Lee, H. Towards a Performative Theory of Resistance: Senior Managers and Revolting Subject(ivitie)s. Organ. Stud. 2017, 38(9), 1209–1232. [Google Scholar] [CrossRef]
  46. Smiley, A.H.; Fisher, M. The golden age is behind us: How the status quo impacts the evolution of technology. Psychol. Sci. 2022, 33(9), 1605–1614. [Google Scholar] [CrossRef]
  47. Alajmi, A.E.; Alenezi, A. Exploring the impact of machine learning tools on auditor decision-making: a qualitative analysis. Int. J. Audit. Technol. 2026, 5(2), 77–90. [Google Scholar] [CrossRef]
  48. ISACA. Humanistic Leadership in the age of, A.I. 2026. Available online: https://www.isaca.org/.
  49. KPMG. Future-ready audits powered by technology and insight. 2026. Available online: https://kpmg.com/ch/en/services/audit/auditing-software-kpmg-clara.html.
  50. Deloitte. Conheça o Deloitte Way e saiba como a maior organização de serviços profissionais do mundo entrega uma experiência diferenciada aos seus clientes de auditoria. 2026. Available online: https://www.deloitte.com/br/pt/services/audit-assurance/services/ferramentas-auditoria.html.
Figure 1. The map of current trends of studies on IT Auditing Tools.
Figure 1. The map of current trends of studies on IT Auditing Tools.
Preprints 229314 g001
Figure 2. Trends of publications on CAAT.
Figure 2. Trends of publications on CAAT.
Preprints 229314 g002
Figure 3. Spanning of authors from new frontiers.
Figure 3. Spanning of authors from new frontiers.
Preprints 229314 g003
Figure 4. Authors Document Citations and Strength.
Figure 4. Authors Document Citations and Strength.
Preprints 229314 g004
Figure 5. List of the derived categories and their groups.
Figure 5. List of the derived categories and their groups.
Preprints 229314 g005aPreprints 229314 g005b
Figure 6. core methodologies of IT auditing, Tools, applications and procedures.
Figure 6. core methodologies of IT auditing, Tools, applications and procedures.
Preprints 229314 g006aPreprints 229314 g006bPreprints 229314 g006c
Figure 7. Guideline to construct prompts.
Figure 7. Guideline to construct prompts.
Preprints 229314 g007aPreprints 229314 g007b
Table 1. Most occupations exposed as per AI.
Table 1. Most occupations exposed as per AI.
Occupation Observed exposure Leading automated task
Computer programmer/Systems Developers 74.5% Who write, update, and maintain software programs
Customer service representatives 70.1% Confer with customers to provide info, take orders, handle complaints
Data entry keyers and Bookkeepers 67.1% Read source documents and enter data into systems
Medical record specialists 66.7% Compile abstract, and code patient data
Market research analysts and marketing specialists 64.8% Prepare reports of findings, illustrating data graphically and translating complex findings into written text
Sales representative, wholesale and manufacturing, except technical and scientific products 62.8% Contact customers to demonstrate products and solicit orders
Financial and investment analysts 57.2% Inform investment decisions by analysing financial statements to forecast business, industry, or economic conditions
Software quality assurance analysts and testers 51.9% Modify software to correct errors or improve performance
Information security analysts 48.6% Perform risk assessments and test data processing security
Computer user support specialists 46.8% Answer user inquiries regarding computer software or hardware operation to resolve problems.
Adapted Anthropic (2026).
Table 2. Minimum number of documents of author and citation per documents.
Table 2. Minimum number of documents of author and citation per documents.
author documents citations
vasarhelyi, miklos a. 3 109
thottoli, m. muneerali 2 66
al-aroud, shaher falah 2 65
eu-gene, siew 2 41
rosli, khairina 2 41
alpuim, ana 2 9
esteves, marisa 2 9
pereira, sónia 2 9
santos, manuel 2 9
hartcher, m.g. 2 5
al-khasawneh, reem oqab 2 4
maciejewska, izabela 2 3
atymtayeva, lyazzat 2 2
nurmyshev, serik 2 2
tulemissova, gulfarida 2 2
ribeiro, maria céu 2 1
chattaraj, durbadal 2 0
mayyas, ahmad 2 0
omar, mohammed a. 2 0
shashank, b.s. 2 0
zhou, qilun 2 0
Table 3. IT Auditing tools Co-authorship.
Table 3. IT Auditing tools Co-authorship.
id author documentscite total link strength
618 "eslami, motahhare" 3 125 0
1103 "król, karol" 3 9 0
1134 "labib, ashraf" 3 32 0
1234 "liu, yang" 4 149 2
1717 "rosli, khairina" 3 56 0
2095 "vasarhelyi, miklos" 3 115 0
2186 "wu, daoyuan" 3 12 2
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.