arXiv:2608.07688cs.AIcs.CL2026-08

用大模型辅助审计证据评估,自动分析合规性并生成可解释建议。

IntelliAudit: Using Large Language Models to Evaluate Audit Controls

论文配图:IntelliAudit: Using Large Language Models to Evaluate Audit Controls
图 1 · 摘自论文原文
  • 基于检索的多智能体系统,整合分散证据生成评估结论。
  • 在模拟组织中表现良好,支持控制解读与准备流程。
  • 适合审计人员使用,需人工校准判断以避免误判。

IT审计需要审计人员判断异构组织证据是否满足语义安全与合规控制要求。这一判断难以自动化,因为相关证据分布在政策、记录、表格和操作文档中,且审计结论依赖证据充分性而非关键词匹配。我们提出IntelliAudit,一个基于检索的多智能体系统,用于评估IT审计证据。给定一项控制和证据文集,IntelliAudit会检索相关文档,生成基于证据的评估,质疑不利结论,调解分歧,并输出面向审计人员的建议,包含引用证据、推理过程、缺失证据分析及整改指导。我们在ISO/IEC 27001框架下对多个模拟组织进行评估,采用专家审计员评审和审计准备用户反馈。结果表明,IntelliAudit能有效支持控制解读、基于证据的推理和审计准备流程,同时揭示了人工监督在校准充分性判断和纠正过度宽松建议中的重要性。这说明基于检索的多智能体系统可辅助审计证据审查,但应作为决策支持工具,而非自主认证系统。

原文摘要 · Abstract (English)

IT audits require auditors to judge whether heterogeneous organizational evidence satisfies semantic security and compliance controls. This judgment is difficult to automate because relevant evidence is distributed across policies, records, spreadsheets, and operational artifacts, and because audit conclusions depend on evidentiary sufficiency rather than keyword matching. We present IntelliAudit, a retrieval-grounded multi-agent system for IT audit evidence evaluation. Given a control and an evidence corpus, IntelliAudit retrieves relevant artifacts, generates an evidence-grounded assessment, challenges adverse findings, adjudicates disagreements, and produces an auditor-facing recommendation with cited evidence, rationale, missing-evidence analysis, and remediation guidance. We instantiate IntelliAudit on ISO/IEC 27001 and evaluate it across multiple simulated organizations using expert auditor review and audit-readiness user feedback. The evaluation shows that IntelliAudit can support control interpretation, evidence-grounded reasoning, and audit-preparation workflows, while also revealing the importance of human oversight for calibrating sufficiency judgments and correcting overly permissive recommendations. These results suggest that retrieval-grounded multi-agent systems can assist audit evidence review, but should remain decision-support tools rather than autonomous certification systems.

审计系统大模型应用多智能体

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。