Audit Evidence Graph
The result of the past fifty to seventy five years of constructing accounting information systems is craft-based processes where data integrity depends on human discipline, human bucket brigades which move information, rather than based on good system design.
The question is not whether there are better alternatives; there are. The question is why the accounting and audit profession has tolerated this current situation for so long, and what it will take to transition to something fundamentally more sound.
Imagine being able to click on a link to view the audit evidence knowledge graph which attests to the fairness of a financial statement. Imagine an artificial intelligence (AI) agent or a human being able to interpret that information reliably. Why imagine it? Why not build it?
The Nature of the Problem
Gartner points out (page 2) that the typical Fortune 1000 company uses about 800 electronic spreadsheets to create its compliance report. Each of those 800 spreadsheets is, in essence, a self-contained silo of data, logic, and institutional knowledge. It contains:
- Data: numbers pulled from the general ledger, sub-ledgers, external sources, or other spreadsheets
- Logic: formulas, calculations, allocations, and transformations encoded in cell references and functions
- Assumptions: judgment calls, estimates, and policy choices embedded in the structure of the spreadsheet
- Institutional knowledge: the unwritten understanding of why the spreadsheet is structured the way it is, what the tabs mean, which cells are hard-coded overrides versus calculated values, and how it connects to the 799 other spreadsheets
- Error rates: Academic research consistently finds material errors in a significant percentage of operational spreadsheets. The European Spreadsheet Risks Interest Group (EuSpRIG) has cataloged hundreds of cases where spreadsheet errors led to material financial misstatements, regulatory failures, and operational losses. In the context of those 800 spreadsheets used by those Fortune 1000 companies, even a low per-spreadsheet error rate compounds into a near-certainty of material errors somewhere in the chain.
- Opacity: No single person understands all 800 spreadsheets. Each is typically maintained by a different individual or team, with its own conventions, its own undocumented logic, and its own fragilities. The knowledge of how they interconnect is distributed across dozens of people, many of whom may have left the organization.
- Version control failures: Spreadsheets are copied, emailed, modified, and re-saved. At any given moment during the close process, multiple versions of the same spreadsheet may exist, with no reliable mechanism to determine which is current or authoritative. The result is a process where data integrity depends on human discipline rather than system design.
- Fragile interconnections: The 800 spreadsheets are not independent; they are linked via cell references, copy-paste operations, and manual re-keying. A change in one spreadsheet can cascade through dozens of others in ways that are difficult to predict and impossible to trace systematically. These interconnections are typically undocumented and exist only in the tacit knowledge of the people who maintain them.
- Audit difficulty: When an auditor examines the closing book, they are essentially reverse-engineering the logic of 800 interconnected electronic spreadsheets to determine whether the numbers in the compliance report are reliable. This is enormously time-consuming, requires the auditor to trust that the spreadsheet logic correctly represents the entity's accounting policies and transactions, and provides limited assurance that the interconnected system as a whole is coherent.
The Deeper Problem: Knowledge Without Structure
Replace Documents with Graphs
- Tagged with its identity and meaning (what concept it represents)
- Linked to its source (where the number came from; the general ledger, a sub-ledger, a calculation, a manual estimate)
- Connected to its dependencies (what other data points feed into it or flow from it)
- Constrained by the rules of the financial reporting scheme (what must be true for the graph to be internally consistent)
- Verified using reliable automated processes which leverage the deterministic nature of accounting and the rich set of standardized accounting terminology
- Versioned with complete traceability/trackability (who changed what, when, and why)
How All this Connects to the Seattle Method
- What nodes a complete closing book must contain
- What edges (relationships) must exist between those nodes
- What constraints must be satisfied for the closing book to be internally consistent
- What the hierarchical structure of the financial reporting framework looks like, so that the closing book is organized according to the actual logic of accounting rather than the arbitrary structure of 800 spreadsheets
The Transformation this Enables
- Real-time validation during the close: Rather than completing the close and then discovering errors during the subsequent audit, a graph-based closing book can be validated against the financial reporting framework continuously as data is entered. If a calculation relationship is violated, if a required node is missing, or if an inconsistency is detected between interdependent elements, the system can flag it immediately; when it is cheap and easy to correct, rather than weeks or months later.
- Effective control: Electronic spreadsheets are too flexible to control, so it is hard to create scalable processes using electronic spreadsheets. But ERP systems tend to be too inflexible; that is why we use electronic spreadsheets. But graph-based structures are controllable at scale.
- Enforceable canonical artifacts and templates: Because of the control and because graph-based nodes and edges can be worked with directly good practices and best practices can be reliably specified and enforced.
- Leverage Lean Six Sigma philosophies, techniques, practices: Because software can work with and interpret objects of a digital closing book, digital audit bundle, digital reporting framework, or digital report; work can be reliably and effectively automated. (e.g. Poka Yoke mistake proofing) Processes can be fixed rather than errors remediated of failures dealt with.
- Automated completeness assessment: The financial reporting scheme defines what a complete set of financial statements looks like. A graph-based closing book can be automatically checked against this template to determine whether all required elements are present. This is not a syntactic check (are all tags present?) but a structural check (does the graph contain all the nodes and edges that the financial reporting framework requires?).
- Traceable interconnections: When a number in the income statement changes, the graph immediately reveals every other node that is affected (e.g. fails loudly); the tax provision, the earnings per share calculation, the segment disclosures, the statement of cash flows. This traceability eliminates the hidden dependencies that plague spreadsheet-based processes, where a change in one spreadsheet silently corrupts calculations in others.
- AI-readiness: A graph-based closing book, audit bundle, reporting framework, and financial statement are all natively consumable by both rules-based and generative AI:
- Rules-based systems can traverse the graph, validate its structure, and check its consistency
- LLMs can reason about the graph's contents, identify anomalies, and generate analyses with full knowledge of the underlying structure
- Machine learning models can be trained on historical closing book graphs to identify patterns, predict issues, and optimize the close process
- Industrial strength processes: Process improvement, improved quality, reduction in costs, increases in value to your organization.
The XBRL-Based Digital Audit Bundle
- The data being tested
- The procedure(s) performed
- The evidence obtained
- The conclusion(s) reached
- Every piece of evidence is tagged to specific financial statement elements. Rather than organizing evidence by audit area, the evidence graph links each piece of evidence directly to the specific XBRL-tagged financial statement element(s) it supports. The receivables confirmation evidence is linked to the Accounts Receivable node; the depreciation calculation workpaper is linked to the Depreciation and Amortization node; the management representation letter is linked to every node it covers.
- Every audit procedure is linked to specific assertions. Each procedure is tagged with the assertion(s) it addresses (existence, completeness, valuation, etc.), creating a matrix of evidence coverage that can be traversed in either direction, from financial statement element to supporting evidence, or from assertion type to the evidence that addresses it across all elements.
- The evidence graph mirrors the financial reporting scheme. By aligning the structure of the audit bundle with the structure of the financial reporting scheme (as defined by the Seattle Method's knowledge graphs), the audit documentation becomes a parallel structure to the closing book itself. Every node in the closing book has a corresponding cluster of evidence in the audit bundle, and the completeness of audit coverage can be assessed by checking whether every node in the closing book has adequate supporting evidence in the audit bundle.
- Traceability is bidirectional. An auditor, regulator, or AI system can start from any financial statement number and trace backward through the audit bundle to find every piece of evidence that supports it and can start from any piece of evidence and trace forward to see which financial statement elements it supports. This bidirectional traceability is impossible in a document-based audit bundle.
The Transformation this Enables
- Automated completeness assessment. The most labor-intensive aspect of audit quality management is ensuring that all required procedures have been performed and all required evidence has been obtained. An XBRL-based audit bundle can be automatically checked against a template derived from the audit methodology and the financial reporting scheme to identify gaps in evidence coverage. This transforms completeness assessment from a manual review exercise into a computational check.
- Regulatory inspection readiness. When a PCAOB inspector or other regulator reviews audit documentation, they are essentially trying to determine whether the audit evidence supports the auditor's opinion. An audit evidence graph that is explicitly linked to the financial reporting scheme makes this assessment dramatically more efficient. The inspector can navigate directly to the area of concern, see all the evidence that supports the relevant financial statement elements, and assess its sufficiency without having to reverse-engineer the auditor's documentation structure.
- AI-assisted evidence evaluation. With an audit evidence graph, AI systems can:
- Assess whether the evidence obtained is consistent with the financial statement assertions being made
- Identify areas where evidence coverage appears thin relative to the risk profile
- Cross-reference evidence across entities and periods to identify patterns that may indicate audit quality concerns
- Generate summaries of evidence coverage for audit committees and regulators
- Institutional memory. One of the most underappreciated problems in auditing is the loss of institutional memory between periods. When audit team members change, the tacit knowledge of why specific procedures were performed, why certain judgments were made, and what issues arose in prior periods is often lost. An evidence graph preserves this knowledge in structured form; every procedure is linked to its rationale, every judgment is documented in context, and the historical evolution of the audit is navigable.
Audit Evidence Graph
- The Financial Reporting Framework (enhanced using the Seattle Method framework) defines the structural template; what a complete, coherent financial report looks like, what elements it contains, and how those elements relate to each other.
- The Digital Closing Book is an instantiation of that template; a specific entity's financial data mapped onto the framework, with every node populated, every edge verified, and every constraint satisfied.
- The Audit Bundle is a parallel graph; the same nodes as the closing book, but with each node linked to the evidence, procedures, and conclusions that support it.
The Implications for AI
- Current state: An AI system must independently parse 800 spreadsheets (closing book), a separate document management system (audit bundle), and the accounting standards (reporting framework); three disconnected information sources with no shared structure. The AI must infer the connections between them, which is error-prone and often impossible.
- Future state: An AI system operates on a single, integrated graph in which financial data (closing book), supporting evidence (audit bundle), and structural logic (financial reporting framework) are all connected through explicit, machine-readable relationships. The AI can traverse the graph in any direction, checking consistency, identifying gaps, and generating insights with full knowledge of the underlying structure.
- New Approach to Creating a Closing Book or Audit Bundle
- Digital Information Organism (information Legos)
- Business Events Ledger
- Modern Version of Ricordanze
- Accounting & Audit by Design (A&AD) Framework
- Defensible Knowledge and Experience Moats
- Compliance Reporting as a "Skeleton" of the Enterprise Knowledge Graph
- AI-First, Digital-First, Graph-First
- From Janitor to Curator: Refactoring Accounting for the Age of Artificial Intelligence
- Reconfiguring the Economics of Human Memory
- Artificial Intelligence Explained for the Small Business Owner
- Productivity Boost for Accounting and Audit
- Next Generation XBRL – The First Public Working Draft
Comments
Post a Comment