arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

IntelliAudit:使用大语言模型评估审计控制

IntelliAudit: Using Large Language Models to Evaluate Audit Controls

Allison Wilson, Sina Moradi Sabet, Diar Shakimov, Panteha Shahrivar, Mohammad Reza Bagheri, Dean Konenkamp, Mohammad A. Tayebi

arXiv 2608.07688首次发表:更新:

发表机构

Coca-Cola; Telus(可口可乐公司; 德达斯电信公司)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出基于检索的多智能体系统IntelliAudit,用于辅助IT审计证据评估,在ISO/IEC 27001上的评估显示其可支持审计工作,需作为决策支持工具使用。

AI 中文摘要

IT审计要求审计人员判断异构的组织证据是否满足语义安全和合规控制要求,由于相关证据分布在政策、记录、电子表格和操作工件中,且审计结论依赖于证据充分性而非关键词匹配,该判断难以自动化。本文提出IntelliAudit,一种基于检索的多智能体IT审计证据评估系统。给定一项控制和一个证据语料库,IntelliAudit会检索相关工件、生成基于证据的评估、质疑不利发现、裁决分歧,并生成面向审计人员的建议,包含引用的证据、理由、缺失证据分析和补救指导。我们在ISO/IEC 27001上实例化IntelliAudit,并使用专业审计人员评审和审计准备用户反馈在多个模拟组织中对其进行评估。评估显示,IntelliAudit可支持控制解读、基于证据的推理和审计准备工作流程,同时也揭示了人工监督对于校准充分性判断和纠正过于宽松的建议的重要性。这些结果表明,基于检索的多智能体系统可辅助审计证据审查,但应作为决策支持工具而非自主认证系统。

英文摘要

IT audits require auditors to judge whether heterogeneous organizational evidence satisfies semantic security and compliance controls. This judgment is difficult to automate because relevant evidence is distributed across policies, records, spreadsheets, and operational artifacts, and because audit conclusions depend on evidentiary sufficiency rather than keyword matching. We present IntelliAudit, a retrieval-grounded multi-agent system for IT audit evidence evaluation. Given a control and an evidence corpus, IntelliAudit retrieves relevant artifacts, generates an evidence-grounded assessment, challenges adverse findings, adjudicates disagreements, and produces an auditor-facing recommendation with cited evidence, rationale, missing-evidence analysis, and remediation guidance. We instantiate IntelliAudit on ISO/IEC 27001 and evaluate it across multiple simulated organizations using expert auditor review and audit-readiness user feedback. The evaluation shows that IntelliAudit can support control interpretation, evidence-grounded reasoning, and audit-preparation workflows, while also revealing the importance of human oversight for calibrating sufficiency judgments and correcting overly permissive recommendations. These results suggest that retrieval-grounded multi-agent systems can assist audit evidence review, but should remain decision-support tools rather than autonomous certification systems.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑