Pattern Chaser: Audit Analytics for Internal Audit
Corrected, agreed and signed off before the stakeholder leaves the call.
|
The Pattern Chaser
Audit Analytics for Internal Audit in Financial Services
|
No. 017
|
|
|
|
|
Deep Dive · The Walkthrough
5 AI Techniques for Turning Walkthrough Transcripts into Signed-Off Process Maps While the Stakeholder Is Still on the Call
Five techniques that collapse the gap between hearing a process described and having it documented, corrected and agreed, so you cut the rework loop, bank instant sign-offs and walk into fieldwork already understanding the process.
|
|
By Tony Abraham · Data Science & AI for Internal Audit
|
|
|
Dear Reader,
This week is about the most expensive ritual in internal audit: the process walkthrough. Not the hour on the call. The weeks of rework after it.
If you have ever circulated a flowchart and received the reply “this isn’t quite how it works anymore”, you already know why this matters. That reply costs you a re-interview, a redraw, another review cycle and a slice of your credibility with the business. Multiply it across every audit in the plan and it is the single biggest drag on fieldwork that never makes it onto a timesheet.
And the walkthrough is not a side task. It is the front door to internal audit analytics. You cannot point full-population testing at the right risk, or pull the right data, until you understand how the process actually runs.
|
|
A process you understand is a process you can test. A process you half-understand is where audit analytics goes to guess.
|
|
|
So here is the question this issue answers: what would change if the process map existed, was corrected live and was verbally signed off before the stakeholder left the call?
By the end of this email you will have five techniques, in the order you would use them on a real walkthrough, to make that your normal. Each one leans on AI you very likely already have approved.
|
|
In this edition
| → |
Why the walkthrough rework loop is a distance problem, not a diligence problem |
|
| → |
Five AI techniques that get a process map corrected and signed off inside the call |
|
| → |
Why early understanding, not faster drawing, is what aims your audit analytics |
|
|
|
|
|
|
The Problem
The two-week loop nobody bills for
I spent nearly a decade running the audit analytics function at a FTSE 100 investment and wealth management firm and the walkthrough loop looked the same at the end as it did on day one.
You book the interview. You take notes at typing speed while someone describes a process at talking speed, so you capture maybe 60 per cent.
Three days later you reconstruct the rest from memory into Visio. You circulate the flowchart. The stakeholder sits on it for two weeks, because reviewing your homework is nobody’s day job.
Then the corrections arrive: a system you never heard mentioned, a handoff you missed, a step that was decommissioned last quarter. You re-interview. You redraw. Version 4 gets signed off five weeks after the conversation, and fieldwork has already started against version 2.
Notice what actually failed there. Not your diligence. Not the stakeholder’s goodwill. What failed is the gap between the conversation and the confirmation. Every day inside that gap, memories fade, details drift and your understanding of the process falls further behind the person who runs it.
|
|
|
|
The Reframe
You’re probably thinking the notes aren’t the problem
You might be thinking: my notes are fine, the real issue is that stakeholders are vague, or the process is genuinely complicated, or the business never reviews anything on time.
All of it is true. And none of it is the constraint. Stakeholders are vague because they are describing from memory with no picture in front of them. The review takes two weeks because it happens cold, long after the context has evaporated. Complexity hurts because you are absorbing it in one pass with no way to check your understanding in the moment.
Every one of those failure modes is a symptom of the same disease: the distance between saying and seeing. Close that distance to zero and they mostly stop happening. The stakeholder corrects a picture, not a memory. The review takes ninety seconds because the context is still warm. Complexity gets unpacked live, branch by branch.
That is what these five techniques do. None of them requires a platform purchase or an innovation lab. A meeting tool that transcribes, an approved enterprise AI assistant (Microsoft 365 Copilot for most audit teams, or your organisation’s equivalent) and a diagram format that renders from plain text. In the order you would use them:
|
|
|
|
The Playbook
The five techniques
|
|
1 · Brief the machine before it briefs you
The walkthrough starts before the call. Load your AI workspace with what the organisation already knows: the audit scope, the org chart, the process narrative from the last audit, the relevant policy, the systems inventory if you have one. Then ask it for a draft process flow, the likely actors and a candidate RACI based on those documents alone.
You will get something 60 per cent right. That is the point. You now walk into the interview testing a hypothesis instead of starting from a blank page. Your questions sharpen from “talk me through the process” to “the policy says approvals sit with the team leader, is that still true?” Stakeholders notice the difference immediately.
One caveat that is not optional: this happens inside your organisation’s approved enterprise AI environment, never a personal account and never a public chatbot. You are handling audit information about live controls and named people. Audit, of all functions, does not get to freelance on data handling.

“The tool” here is whatever AI your organisation has approved. For most audit teams that is Microsoft 365 Copilot or an internal wrapper, though ChatGPT Enterprise, Claude or Gemini behave the same.
|
|
|
|
2 · Transcribe live, extract structure, not summaries
Record the call with consent and in line with your firm’s recording policy. The platform handles the recording. The lawful basis is yours to get right. The transcript is the raw material, but the technique is in what you ask for. Do not ask the model to summarise. Ask it to extract structure. My working prompt is a table: actor, action, system used, input, output, decision points, exceptions mentioned. Run it every ten or fifteen minutes on the transcript so far.
A summary gives you prose you must re-read. Structure gives you the skeleton of a process map plus something more valuable: a list of what is missing, and the actors, systems and data each step touches. Blank cells in that table are your next questions, generated while the person who can answer them is still on the call. The systems-and-data column is where your analytics will start.

The same assistant turns the live transcript into a structured table and lists what is still missing, so the gaps become questions you ask on the call.
|
|
|
|
3 · Speak Mermaid, not Visio
Mermaid is a text format that renders into flowcharts instantly, and every major AI model writes it fluently. Ask for the structured table from technique 2 as a Mermaid flowchart and you have a rendered process map seconds later. No dragging boxes, no aligning arrows, no Visio licence.
Because it renders from text, regeneration is free. The stakeholder mentions a step you missed, you regenerate, thirty seconds. This is the property the old workflow never had. A Visio diagram is expensive to change, so you batch corrections into review cycles measured in weeks. A Mermaid diagram is free to change, so corrections happen mid-sentence.

A few lines of Mermaid text render into a shareable process map. No dragging boxes, no aligning arrows, no Visio.
|
|
|
|
4 · Make the model your co-interviewer
While you focus on the conversation, give the model the adversarial job. Ask it: looking at this process so far, where are the gaps? Which handoffs have no owner? What happens when the input arrives late or wrong? Which steps look like key controls, and which key controls would you expect in a process like this that nobody has mentioned?
That last question is the one that earns its keep. The model has seen a thousand payment processes, onboarding flows and reconciliation cycles. It has a strong sense of what usually exists. When it flags that no one has mentioned a segregation check between initiation and approval, you get to ask about it now, on the call, instead of discovering the gap in week three of fieldwork. That is also the control you will later point your testing at.
You are still the auditor. It is a prompt with pattern recognition. Everything it surfaces gets verified by you. But as a second brain that never zones out during minute 47, it has no equal. The map is only ever as good as the person describing it. They give you the official path. You are still there to chase the workaround, the shadow spreadsheet and the override they never mentioned.

Point the model at the process so far and it flags orphan handoffs, missing failure paths and the controls nobody has mentioned yet.
|
|
|
|
5 · Close with the read-back
Reserve the last ten minutes. Share your screen, put the rendered map up and walk it end to end: “you initiate here, it flows to the team leader for approval, exceptions route to operations, have I got this right?” Corrections happen live and regeneration is instant, so you fix the map while they watch. Then ask the sign-off question out loud: “are you happy this reflects the process as it runs today?”
Their yes is on the recording, attached to the exact version of the map they were looking at. Export the map and transcript to your workpapers and the walkthrough is documented, corrected and evidenced before the meeting ends. The two-week review cycle did not get faster. It got deleted because there is nothing left to review cold. That kills the cold re-draft loop, not your supervisory review. The map still goes up the normal chain. What changed is that it starts complete.

Share the map on the call, walk it end to end and capture the verbal sign-off live, attached to the exact version they saw.
|
|
|
|
The Point
The map was never the point
Here is what took me longest to understand, so I will save you the years.
The forty minutes versus two weeks makes a satisfying demo. What actually matters is what the early timing buys you. Audit’s oldest handicap is information asymmetry: the business knows how the process actually runs, and we spend the engagement expensively paying down our ignorance, usually finishing right about when the audit ends. These five techniques collapse that asymmetry at the start instead of the end, and early understanding is a different asset entirely.
Early understanding is what lets your analytics aim. A process map that exists during planning tells you the key controls before you design your testing, the systems that hold the data and where full-population testing will earn its keep. It can tell you the process is being decommissioned in Q3 and your audit is aimed at a corpse. It can hand your audit lead the evidence to walk into the next planning conversation and say “this area is cleaner than we thought, the hours belong on the platform migration instead”. The same map produced at the end of fieldwork changes nothing.
|
|
A map produced during planning aims your testing. A map that arrives after fieldwork is wallpaper.
Timing, not tempo.
|
|
|
And there is a second payoff hiding inside the first. Every one of these techniques is you getting reps with AI on real audit work: transcripts, structured extraction, adversarial prompting, evidence you can stand behind. The auditor who does this weekly is building exactly the data and AI fluency the profession is about to demand, right about when the audit committee starts asking who can give assurance over the models. Same forty minutes, two dividends.
|
|
|
|
The Recap
What we covered
The walkthrough rework loop has nothing to do with diligence and everything to do with distance. AI closes the distance between saying and seeing to zero. Do that and you do not just document the process faster, you walk into fieldwork with your audit analytics already aimed.
| → |
Brief the machine first. Pre-load scope, org charts and prior narratives so you interview with a hypothesis, not a blank page. Enterprise AI environment only. |
|
| → |
Extract structure, not summaries. Actor, action, system, input, output, decision points. Blank cells are your next questions, and the systems column is where the analytics starts. |
|
| → |
Render in Mermaid. Free regeneration means corrections happen mid-sentence instead of in review cycles. |
|
| → |
Run a co-interviewer. Ask the model for gaps, orphan handoffs and the key controls it expected but did not hear. Verify everything yourself. |
|
| → |
Do the read-back. Walk the live map, fix it on screen, capture the verbal sign-off on the recording. The review cycle is not shortened. It disappears. |
|
| → |
Remember why it matters. Early understanding, not faster drawing. A map that exists during planning aims your testing. A map that arrives after fieldwork is wallpaper. |
|
Try it once this week. One live audit, one call, one map. Show it to your audit lead on Friday and watch their face.
|
|
The Companion
Five prompts, one per technique
I have put the exact copy-paste prompts behind all five techniques into a Walkthrough Prompt Pack, with the STATED-versus-INFERRED guardrails baked in so nothing invented slides into your evidence. Reply and I will make sure you get it.
|
|
|
|
|
Pass it on
Know an auditor still redrawing Visio maps three weeks after the call? Send it on.
|
|
That’s it for this week.
Tony Abraham
Data Science & AI for Internal Audit
|
PS. If you run the forty-minute version this week, reply and tell me how it went, including where it fell over. I am collecting real attempts, the good and the ugly, for a future issue on what actually breaks when auditors try this, and I would rather publish your war stories than my theory.
|
|
How did you like today’s issue?
|
|
|
|
|