AI Made Compliance Cheaper. It Didn’t Make Assurance Cheaper.

By Richard Rieben Published on September 23, 2026
In this Article
AI made compliance cheaper, but it didn't make assurance cheaper

This is the short version; AI has brought compliance down to pennies a pop. It has not brought auditing down to pennies a pop. Anybody telling you differently is trying to sell you one for the price of the other.

These two concepts are distinct and separate. The industry has spent three years doing its best to confuse them. Compliance is the process of establishing controls, documenting that they have been established, and providing evidence of both processes. Assurance is the process of an independent third party reviewing the evidence, making an evaluation of it, and stamping his name on it. AI has transformed the former, but not the latter, and that’s how you achieve bargain-basement auditing.

What Actually Got Cheaper

Certainly, give the compliance platforms their due. Continuous monitoring, automated data gathering, policy repositories, and gap identification. They have turned an effort spanning several months into a dashboard. Ten years ago, I watched as a compliance officer took two entire weeks to take screenshots of the user list. Today, that population can be provided in a spreadsheet before I even make the request. If you have a platform like that in place, then congratulations.

AI is used in auditing. Good auditors are also using it and showing you how. In my organization, we are using AI for client acceptance, sampling of results, reviewing reports, and scheduling concurrent audits. AI does not save us any time. We are using it to do a thorough job, to do it better, and to identify those things that you are missing on page 140 of your report.

 

Paperwork approved; building unsafe

The Building Inspector

Imagine an inspector signing a Certificate of Occupancy without having inspected the building at all. The checklist was completed by interns who had never even seen a load-bearing wall. The documentation is perfect. No one will move in.

That’s what a rubber stamp audit looks like. It’s not something that AI created. But it sure isn’t something that AI has any trouble running.

When the Evidence Looks Too Clean

Here is an example of how different it is in just one case study. The platform fulfilled its duties perfectly well. It gathered the evidence. It does not know what the evidence means to you, and it is not its job to ask whose hand was behind the mouse. The article “The Audit Evidence Crisis” of June 2026 by ISACA starts with almost the same story: an auditor received a document of such immaculate perfection that it triggered his training, not the trust that, in the end, turned out to be AI-generated with artificial signatures. The conclusion drawn by the author was that “trust but verify” was obsolete and the profession had to begin with zero trust from now on. I would phrase it a bit more sharply: The better the evidence looks, the more thoroughly it is scrutinized.

 

Spotting a cheap audit

What a Bargain-Basement Audit Looks Like

It is quite simple to recognize the scheme once you know what to look for. Fixed rate. Timely execution. Compliance platform. And the statement that must raise concerns: no auditor engagement required.

Behind the offer, there is a business model that is quite typical. Testing may be outsourced/offshored to someone who is unqualified, lacks experience, and cannot conduct a technical discussion beyond the checklist. There is no room for healthy skepticism on the checklist, and no one with an untainted mind will think of putting it there. No walkthroughs, no interviews. Everything said by the platform is taken as it is, without any verification of the integration that produced that information. The report is not even reviewed by the partner before it is released.

As my experience goes, most of the clients in such a model have not been looking for that model. All they wanted was the price and the timeline. Two cases, with minor changes.

In the other case, the company scoped the SOC 2 Type I to their data center operations. The firm refused to use the control set prepared by the client in the readiness stage and issued the report without even going to the company’s data center. SOC 2 Type I is an opinion on the design of the controls as of a certain date. It is not possible to give such an opinion on the design of the physical controls that you have not examined, and it is beyond my comprehension how people can sign such reports.

A European company chose a reporting services provider for the relatively low price and the promise of an EU-based auditor. However, they were given an auditor based in California, who was somewhat slow in responding to emails, and then reassigned to two auditors based overseas who could not answer even the most basic technical questions about the company’s environment. They decided to abandon the project and start over with another firm, after investing much time and effort in a failed audit.

 

AI audit compliance red flags

Two Red Flags You Can Check Today

1) The signature on the opinion is from the company that did NOT audit your financial statements. The company that signed off on your opinion is the firm responsible for that opinion. Unless this firm is the one you hired to perform the work, you do not know who performed your audit work, and neither does anyone else who will review your audit report.

While auditing a client’s HITRUST assessment along with another vendor performing a budget SOC 2 report, the client never communicated directly with the auditor throughout their SOC 2 audit process. All communication was made via chat; their evidence collection process was extremely unprofessional and took months to generate the report. When the report was finally generated, there were errors in the report, and it bore the signature of a firm they had never heard of before and had no agreement with. They only found out who audited them when they reached the last page of the report.

2) They have never heard of the company that published the report. Think about an unlicensed food cart that sells food in an area that the government has not inspected for some seasons and then disappears before being inspected. There you go; that is what pop-up audit firms are all about. Pop-up audit firms publish their reports for a few seasons and then fold their tents before the time comes for peer review. Peer review, as mentioned above, is the tool used to get another CPA firm to inspect your work on a three-year basis.

 

AI compliance limitations

What AI Can’t Do & Where the Line Is Drawn

AI will analyze everything quicker than I can, and AI will never miss the detail hidden in the report on page 140. AI will not analyze whether the control actually reduces the risk for which it was designed. AI will not notice whether it was just too easy to get the answer. AI will not sit down with the engineer who said “we always do that” and ask for a case in which that does not happen.

The skill of understanding that something is off has a name. In the field of auditing, it is referred to as professional skepticism, and it is not a light switch that you turn on or off. Years of experience in seeing controls fail will teach you that. Professional skepticism will help you understand which access review with no exceptions raises a red flag. It will make you hear a perfect answer but still ask the follow-up question, since the previous three times when a perfect answer was provided, there was a problem behind that answer. AI will learn from all the audit reports ever written, but it will never know how it feels to lie politely.

2025 Guidance on AI in Assessments

But that is not just me thinking about it like that. The rulemakers think the same way. As stated in the guidelines of PCI Security Standards Council in 2025 on the use of artificial intelligence in assessments, the AI system cannot be an assessor, cannot make the final decision on the matter of compliance or authorize the release of the report, and the responsibility of the human assessor for all findings stays with the human assessor. And AICPA thought the same way back in 2021 about using tools for compliance: the service auditor must not rely solely on the findings made by the tool but must also conduct other procedures outside of the tool. These are my lines, and these are the lines of the whole profession. There is no AI independently assessing the findings, and there is no AI independently communicating with the client.

Six Questions to Ask Before You Sign

  1. Whose name will show up on the report, and will it be my company’s that you will be working for?
  2. Who conducts the tests, their location, and credentials?
  3. How many walkthroughs and interviews will there be, and with whom?
  4. In case of physical controls, will anyone from your company come to our site?
  5. What tests do you conduct outside the compliance portal, and how do you confirm the findings of the compliance portal?
  6. How often do you get your peer review, and can I see your letter, please?

 

AI compliance vs assurance FAQs

AI Compliance vs. Assurance: Common Questions, Answered

Here are the questions I hear most once a client realizes compliance and assurance aren’t the same purchase. Keep this list handy the next time someone offers you both for the price of one.

Can AI Replace Auditors?

Not at all. The SOC 2 is an audit done by a CPA’s company and signed by the one accountable for said report, according to AICPA standards. AI could help in the process of collecting the evidence, performing the testing, and reviewing the report. AI, however, would not be the auditor, and the opinion could not be signed by AI. This was also confirmed by the PCI Security Standards Council.

AI Compliance vs. Assurance: What’s the Difference?

AI compliance refers to the use of AI and automation tools in order to be in compliance and prove it – gather data, write policies, and identify gaps. AI assurance refers to a third-party individual who will use the tools of AI in order to examine the data and come up with an opinion on it. The former refers to something that you do for yourself. The latter is what a qualified third party does for you.

What Is Continuous Compliance vs. Continuous Assurance?

Continuous compliance means monitoring your controls in near real-time and notifying you of any deviations from the norm. Continuous assurance will be a continuous audit conducted independently and supported by an independent auditor. The first one is available and operates just fine. The latter is mostly just a buzzword for marketing purposes at the moment. The SOC 2 Type II report is still done during a specified reporting period and is only issued once. Continuous compliance will make your yearly audit much easier. But it won’t replace it.

Can AI Collect Audit Evidence?

Yes, that’s right, and it does that in an excellent way. The compliance platforms and the agents perform the functions of collecting the list of users, configuration snapshots, change tickets, and approvals from the source systems. However, what they cannot do is verify the completeness, validity, and sufficiency of this evidence. Review of access where all the rows have been approved in ninety seconds is a good example of evidence, but not of control evidence.

What Is a Rubber-Stamp Audit?

A rubber-stamp audit is where the organization provides an opinion without performing adequate work to form that opinion. Indicators of this type of audit include lack of interviews and walk-throughs, failure to visit the site when physical controls are applicable, and failure to verify platform output. Even though the report appears to be thorough, no one responsible for the report made a judgment call about what was in the report.

How Do I Know If a SOC 2 Audit Firm Is Legitimate?

Make sure that the company is a licensed CPA firm in your state, find out when the last AICPA peer review took place, and get the letter. Also, make sure that the firm providing the opinion is the same firm that you hired. If the firm has operated for fewer than three years and does not have a peer review letter, then remember that no one other than that firm has reviewed their work.

The High Cost of the Cheap Audit

It is a report that no one wishes to be accountable for but was required to be purchased to meet the procurement criteria, and it will serve its purpose up until the client, regulator, or the plaintiff’s lawyer takes time to read it. With the use of AI in preparing the report, the price of someone being accountable for the report is exactly what it used to be.

Using AI at Linford & Company, we test more and test better, but never let AI make the judgments that require decades of experience. To discuss how that impacts your next PCI, SOC 2, HITRUST, or HIPAA assessment, contact us.

About The Author

Richard Rieben
Richard Rieben

Richard Rieben is a Partner and HITRUST practice lead at Linford & Co., where he leads audits and assessments covering various frameworks including HITRUST, SOC, CMMC, and NIST. With over 20 years of experience in IT and cybersecurity and various certifications including PMP, CISSP, CCSFP, GSNA, and CASP+, Richard is skilled in helping growing organizations achieve their information security and compliance goals. He holds a Bachelor of Science in Business Management and an MBA from Western Governors University.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
I understand and agree to the Linford & Company LLP privacy policy.**