Abstract
Purpose: The study aims to design and validate a modular AI systems architecture for Continuous IT Audit (CITA), addressing increasing demands for real-time risk detection, regulatory compliance, and audit automation in complex IT environments. It explores how AI can support internal audit functions while aligning with standards like ISO 27001, COBIT 2019, and the IIA framework. Design/methodology/approach: The research adopts a design science methodology, integrating findings from prior works and practical insights from audit system implementations. It proposes a layered architecture composed of: (1) a data integration and quality assurance layer, (2) an AI-driven analytical and decision engine combining expert systems and machine learning, (3) a risk assessment and prioritization module, and (4) an Explainable AI (XAI) reporting interface. The system ingests heterogeneous data sources and employs ontologies to ensure interpretability, traceability, and standards compliance. Findings: The proposed architecture demonstrates how continuous audits can be enabled through AI technologies without compromising reliability or transparency. Key components such as data lineage tracking, anomaly detection, and threat prioritization were found critical to system performance. The model supports continuous monitoring of IT controls and enables the generation of real-time, stakeholder-specific audit insights, including SDG-linked sustainability metrics. Case evidence suggests that audit efficiency, coverage, and responsiveness improve markedly when such systems are adopted. Research limitations/implications: The framework has been validated conceptually and through implementation experiences in select organizations. Broader empirical testing across sectors is needed to assess generalizability. The dependence on high-quality, well-documented infrastructure data remains a key constraint for adoption. Practical implications: The architecture provides a blueprint for organizations aiming to implement AI-powered audit systems. It highlights how to balance technical feasibility with regulatory requirements and organizational readiness, including training and change management. Social implications: By enhancing audit reliability and reducing manual workloads, such systems may increase trust in digital governance. Additionally, the integration of sustainability indicators into audit reporting contributes to broader ESG accountability. Originality/value: This study offers one of the first comprehensive, standards-aligned frameworks for AI-based Continuous IT Audit, addressing both technical and organizational dimensions of implementation. Keywords: continuous IT audit, AI-driven audit architecture, data quality assurance, explainable AI (XAI), audit ontology, and threat prioritization. Category of the paper: Technical paper.
Cite
CITATION STYLE
Pycka, M., & Zastempowski, M. (2025). AI systems architecture for continuous IT audit: technical challenges and implementation frameworks. Scientific Papers of Silesian University of Technology. Organization and Management Series, 2025(234), 369–385. https://doi.org/10.29119/1641-3466.2025.234.21
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.