Our recent Insights posts have looked at how SAP AI and Joule are reshaping specific business areas, such as finance, compliance, quote-to-cash, supply chain and manufacturing, as well as industry-specific scenarios for software, telecom and utilities, and most recently the role of AI in clean core migrations to SAP Cloud ERP. In this post, we take on a topic that comes up in nearly every executive conversation we have: what happens to the audit when AI agents are doing the work?
In the past, audits have always operated on an assumption that is starting to look outdated: that assurance happens after the fact, such as using sampling based on evidence assembled by people who often stop their day jobs to go find it. That model made sense when transaction volumes were lower, systems were fragmented, and pulling a full transaction population was simply not feasible. These constraints no longer apply in a modern SAP environment.
What we call an "autonomous approach to audits" is the logical consequence. When AI agents operate natively inside governed SAP workflows, the same controls that govern human users can be applied continuously, across the full transaction population, in real time, and the audit trail becomes a byproduct of how the system runs rather than a deliverable someone has to assemble.
The Audit Function Is Already Changing, Just Unevenly
These types of changes are not a future-state conversation. Much of it is already underway in the audit profession itself, though with a notable gap between usage and discipline.
- Gartner found that 93% of audit leaders and auditors report some level of AI use, but only 15% say their department has deployed formal use cases and runs them routinely in audits, and 54% of chief audit executives polled had not started measuring the value of AI in audits at all.
- KPMG's April 2026 Future of SOX webcast, drawing on roughly 3,900 audit and risk leaders, found AI enablement in internal audit still at an early stage, with adoption at scale constrained by capability, resource and integration challenges.
- Meanwhile the external audit firms are moving fast: KPMG has built agents into its Clara platform, Deloitte launched its agentic Zora platform in 2025, and PwC says an end-to-end AI-integrated audit process will be in place for calendar 2026 audits, with EY describing the destination as "human-led, agent-operated".
Taken together, those three data points show that auditors are industrializing AI faster than most internal audit and controllership functions are changing. The companies that get ahead of this curve will be the ones whose ERP systems can produce clean, continuous, machine-readable evidence on demand.

What "Autonomous" Actually Means in an SAP Context
The word autonomous makes control-minded people nervous, and it should, right up until you look at how the governance is constructed. In SAP's model, agents do not run beside your controls; they run inside them.
SAP's own compliance guidance on Joule Agents sets out three principles that matter enormously for auditability:
-
Agents are not anonymous, since every agent operates under a uniquely provisioned identity logged in the same audit infrastructure that governs human users.
-
Agents cannot exceed human authorization, because their permissions are bound to a subset of what the delegating user holds.
-
Agents operate inside existing controls, subject to the same role-based authorizations, approval workflows and audit logging as people
That same guidance describes an audit trail designed to answer four questions consistently — who acted, what were they authorized to do, what did they actually do (both permitted and blocked actions), and on whose behalf did they act, including the full delegation chain.
SAP also positions three calibrated oversight models, human-in-the-loop, human-on-the-loop, and human-in-command, which make sure that review, override, rollback and non-AI alternative paths are always available.
For anyone who has ever spent excessive time unpacking a calendar quarter to determine who approved what and why, this is a meaningful architectural shift. It is also the difference between AI that creates audit risk and AI that reduces it.
Where the Practical Value Shows Up First
In our client work, the highest-value starting points for autonomous audit capability cluster in a few places:
- Continuous transaction monitoring instead of sampling. Every journal entry, posting and payment evaluated against policy at the moment it happens, with only exceptions routed to a controller, while the context is still fresh and the correction is still cheap.
- Segregation-of-duties and access monitoring on a continuous cadence. Rather than quarterly access reviews that surface conflicts months after they occurred, conflicts get detected and routed for remediation as role assignments change.
- Third-party and vendor risk screening at the point of creation. Sanctions and risk checks run when a vendor record is created, before any purchase order can be issued.
- Access certification distributed across the year. Low-risk certifications can be handled systematically, with only anomalous access escalated for human judgment, instead of overwhelming managers in a single annual review process.
- Evidence collection and control testing as a standing process. SAP's Governance Assistant for GRC is built to monitor risk, surface control exceptions and streamline compliance workflows with a human-in-the-loop design, and SAP's autonomous finance direction embeds compliance intelligence into the process itself so that audit readiness becomes a continuous state rather than a periodic effort.
The connective tissue across all of these is governance infrastructure. SAP AI Agent Hub is designed to serve as the enterprise system of record for agents, models and Model Context Protocol (MCP) servers, supporting discovery, ownership, lifecycle governance, evaluation, policy evidence and retirement controls. If you intend to scale beyond two or three agents, that inventory and ownership layer is not optional.
The Harder Question: What Will Your Auditor Accept?
This is where enthusiasm needs to meet reality, and it is the part of the conversation we find executives most want to have.
Auditors will expect organizations to provide evidence for what happened, when it happened, and what data was used to support the accuracy of outputs, with procedures ultimately focused on establishing that AI use is governed, controlled and evidenced well enough to support management's assertions about reliable financial reporting.
Professional standards reinforce the same discipline on the auditor's side, requiring competence and reliability of the AI system, supervision rather than blind reliance on outputs, and documented review and challenge of AI-generated conclusions.
Translated into design decisions, that means a handful of questions need answers before agents touch production:
- Which decisions warrant human-in-the-loop approval versus human-on-the-loop monitoring, and who made that call?
- Is the agent that detects an exception architecturally separate from the agent that remediates it?
- When an action initiated in SAP Cloud ERP cascades into adjacent systems, is that handoff observable and reconstructable end to end?
- Are agent permissions included in your normal access certification scope?
- Can you reconstruct the user, agent, prompt, tool calls, approvals, errors and business outcome for any given action, months later, for someone who was not there?
As noted in our post on finance and compliance scenarios, in areas like revenue recognition, lease accounting, treasury and statutory reporting, "almost right" is not good enough. The same standard applies to the AI agents operating in all auditable processes.
Bramasol's Perspective
Bramasol has spent years helping companies build compliance processes that hold up under scrutiny, including guiding the development of SAP Universal Revenue Recognition solutions and tailoring them to complex ASC 606 and IFRS 15 scenarios across a wide range of industries. That work taught us something directly relevant here: controls, traceability, auditability and governance by design are not features you add at the end. They should always be a fundamental part of the underlying architecture.
Our Finance-First S/4HANA Transformation methodology starts from process excellence and data readiness for exactly that reason. An autonomous approach to audits amplifies whatever foundation it sits on. Where the chart of accounts, master data, revenue events, billing data and control definitions are clean, continuous assurance becomes genuinely achievable. Where they are not, agents will simply generate exceptions faster than your team can clear them.
The practical sequence we recommend is unglamorous and it works: define ownership and risk tiers, get the data and control foundation right, pilot two or three governed scenarios with real evaluation criteria and documented human escalation paths, then scale only where quality, auditability and economics are proven, not just where the demo was impressive.
Summary
The shift from periodic, sample-based audits to continuous, population-level assurance is one of the most consequential changes SAP AI enables, and it is one of the least discussed. It does not remove the auditor, and it does not remove judgment. What it removes is the structural delay between a control failure happening and someone finding out about it.
For organizations in regulated industries and those with complex revenue, lease and compliance requirements, that delay has always been the expensive part.
Bramasol combines deep expertise in SAP Finance, Revenue Accounting, Treasury, Compliance and Quote-to-Cash with practical AI and S/4HANA implementation experience to help companies identify where continuous assurance will pay off first and build it on a foundation their auditors will accept.
.gif?width=320&height=80&name=7-logo-30years%20(1).gif)
