auditaitraceabilitytrust

Traceability in AI audit: why every figure must lead back to its source document

Traceability in AI audit: why every figure must lead back to its source document

An AI summary that says "it matches" is not audit evidence. Why every figure has to be traceable down to its source document, and how we solve it at G2-F.

Read in:Espanol|English|Catala

The problem: a summary is not evidence

An AI model can read thousands of invoices, payslips or bank statements and tell you, in one sentence, that everything matches. The problem is that an auditor does not sign a report based on a sentence. They sign based on documents they can open again, point at, and defend in front of a third party, a partner, a regulator or a client asking "where does this number come from?".

If the answer is "the model said so", there is no evidence. There is a very well written opinion.

Why "trust the model" is not an audit standard

Language models fail silently. They do not break like a corrupted spreadsheet, which at least shows a visible error. They fail with confidence: they give you a reasonable figure, nicely formatted, consistent with the rest of the text, even when it does not match the actual document.

In audit, that is exactly the risk the work exists to remove. Any process that replaces documentary review with a model's assertion, with no way to verify it, does not reduce audit risk. It quietly moves it, without telling anyone, from the paper to the model.

How we solve it at G2-F

Every cell in the workbook Jeff produces is not a loose value. It is a value with a direct link to the exact page of the PDF, the image or the spreadsheet it came from. If a payroll figure shows up in the working paper, one click takes you to the specific line of the original payslip where it was written.

A cell in the grant justification linked to the net pay figure in the original payslip
The amount in the sheet is not a loose value: it leads to the exact line of the document it came from

This is not a layer bolted on top of the AI's work. It is the condition for using it in audit at all. The model does the heavy lifting of reading and extracting at volume, but verification does not depend on believing it. It depends on being able to check it, cell by cell, in seconds instead of hours.

The reconciliation decision, step by step

Matching a payslip to its bank transfer is not a comparison of two numbers. It is a chain of decisions, and each one leaves a trail: which documents are read, where exactly you look inside each of them, and on what criterion you decide that two things are the same.

The three steps of the match: AI extraction, delegating the criterion to a subagent, and the final reconciliation
The area of interest changes at every step: first the amount, then the date and the description

Look at the second step. The amount matches in both documents from the very beginning, so it would be easy to call it a match right there. But that month there are three payslips with the same net pay, and the transfer lands two days after the accrual date. The criterion that resolves it, same amount plus a window of days plus the tax ID in the description, is a decision, and it is written down next to the result.

That is what separates a defensible reconciliation from a lucky coincidence.

The principle

AI speeds up reading. The evidence is still the document, not the summary. When those two things get confused, you lose precisely what makes an audit report mean something.

If you want to see how this works on real documentation from your firm, let's talk.

Sergio Garcia

Sergio Garcia

Let Jeff carrythe heavy work.