FRC’s AI Warning Puts Audit Independence, Accountability and Algorithmic Risk Under the Microscope
The Financial Reporting Council of Nigeria has issued a warning that could become increasingly consequential as artificial intelligence moves from experimental technology into the machinery of...
The Financial Reporting Council of Nigeria has issued a warning that could become increasingly consequential as artificial intelligence moves from experimental technology into the machinery of financial reporting, audit and regulatory supervision.
Speaking at the 2026 Audit and Assurance Leadership Summit in Lagos, FRC Executive Secretary, Rabiu Olowo, urged auditors, regulators and corporate boards to ensure that AI strengthens audit integrity rather than weakening public confidence in financial reporting.
The message is straightforward, but the compliance implications are considerably more complicated.
AI can process enormous volumes of financial information, identify anomalies and improve fraud risk assessment. It can potentially allow auditors to examine virtually an entire transaction population instead of relying heavily on traditional sampling. Olowo said the technology can improve audit efficiency, analytical depth and coverage.
But there is an uncomfortable regulatory question beneath that promise.
Who is accountable when the machine gets it wrong?…..
The FRC’s position is that technology cannot displace professional responsibility. Olowo put the principle plainly: “The future of assurance will undoubtedly be shaped by AI, but trust in financial reporting will always depend on human integrity, ethical leadership, and sound judgment.”
That principle may become one of the most important rules for Nigeria’s emerging AI governance framework.
Consider a hypothetical audit of a major company. An AI system reviews millions of transactions and identifies a cluster of payments as high risk. The audit team follows the model’s recommendation, expands testing around those transactions and ultimately issues an audit opinion.
Months later, investigators discover that the system failed to identify a sophisticated revenue manipulation scheme because the fraudulent transactions resembled legitimate commercial activity.
Who carries the responsibility? The software developer? The audit firm? The individual audit partner? The company’s board? The regulator?
There is no room for accountability gaps in financial reporting.
The black box problem…..
One of the most immediate risks is explainability.
Traditional audit procedures can generally be traced through working papers, evidence and professional judgements. AI introduces another layer. An algorithm may generate a risk score without providing a sufficiently transparent explanation of how it arrived at that conclusion. That creates a serious audit trail problem.
If a regulator challenges an audit conclusion, can the audit firm demonstrate precisely how the AI system reached its recommendation? Can it reproduce the model’s output? Was the model trained on reliable data? Was the system independently validated? Had it been changed during the audit?
These questions become particularly important where generative or agentic AI is involved.
The global regulatory direction is already moving towards formal controls. The UK’s Financial Reporting Council, for example, issued guidance in March 2026 on the use of generative and agentic AI in audit engagements. Its position is that the use of AI does not transfer regulatory accountability away from auditors and audit firms. That provides an important benchmark for Nigeria.
Data becomes an audit risk….
AI is only as reliable as the data it receives.
If an audit model is trained or operated using incomplete, inaccurate or manipulated financial data, its apparent sophistication can become misleading. A system may process millions of records and still produce an unreliable conclusion because the underlying information is defective.
That creates a different kind of compliance risk.
Auditors will need to establish controls around data lineage, data quality, access rights, model configuration and system changes. They will also need to know whether sensitive client information is being transferred into third-party AI platforms.
For Nigerian companies, that introduces questions around confidentiality, cybersecurity and data protection.
What happens when an audit firm’s AI tool processes payroll information, customer records, bank statements, tax information or commercially sensitive contracts on an external platform?
Who owns the data? Where is it stored? Who can access it? Can the technology provider use it to train another model? How quickly can the auditor demonstrate that confidential information has been deleted or secured?
These are no longer purely technology questions. They are audit governance questions.
AI could improve fraud detection, but it can also amplify bad assumptions….
The FRC has identified bias, inaccurate reporting, manipulation and cybersecurity among the risks accompanying greater technological dependence.
Bias is particularly important. Suppose an AI system is trained on historical audit data in which certain industries, customer categories or transaction patterns were disproportionately associated with previous fraud cases. The model could begin treating similar characteristics as inherent indicators of risk.
The result may be a system that appears objective because it is mathematical, while quietly reproducing the biases embedded in its historical data.
Professional scepticism therefore remains essential.
An auditor cannot simply say that an algorithm classified a transaction as low risk. The auditor must still ask whether the conclusion makes sense.
That may become one of the defining skills of the AI-era auditor: knowing when not to trust the machine.
The boardroom responsibility…….
The FRC’s warning also places responsibility squarely on corporate boards.
Boards should know what AI systems their auditors and internal finance teams are using, what those systems are permitted to do and what controls exist around them.
An organisation that deploys AI to generate financial forecasts, detect fraud or support financial reporting cannot reasonably treat the technology as an ordinary software subscription.
There should be documented governance around approved tools, access, data usage, human review, model validation, incident reporting and accountability.
The board should also be able to answer a basic question: if the AI system fails, who has authority and responsibility to intervene?
The regulatory challenge is coming next….
For regulators, AI presents an equally difficult problem.
Supervisors themselves will increasingly use technology to monitor financial statements, identify unusual reporting patterns and prioritise inspections. That could make regulatory oversight faster and more sophisticated.
But regulators will face the same problems they are asking companies to solve.
Their algorithms must be auditable. Their data must be reliable. Their risk models must be tested for bias.Their decisions must be explainable.
And where an automated system triggers regulatory action against a company, there must be a clear route for human review.
The FRC’s summit brought together auditors, regulators, corporate leaders, investors, academics and technology specialists precisely because AI is changing not only how audits are conducted, but how financial information is generated, processed, analysed and ultimately trusted.
That last word, trusted, is the heart of the issue.
Financial reporting exists because investors, lenders, regulators, shareholders and the public need reliable information on which to make decisions. AI can make the process faster. It cannot make an unreliable number trustworthy simply because the number was generated by an advanced model.
Nigeria’s compliance framework is therefore entering a new phase.
The question is no longer whether auditors should use AI. They almost certainly will.
The more important question is whether Nigeria can build an audit environment in which AI becomes powerful enough to improve assurance, but controlled enough that responsibility never disappears behind the algorithm.
The machine may analyse the evidence. The professional still owns the judgement.
And when the regulator comes knocking, “the algorithm said so” cannot become an acceptable audit defence.



No Comment! Be the first one.