Why the falling cost of deception makes independently verified evidence the auditor's most valuable asset
Highlights
- AI is making financial fraud and fake audit evidence easier to create and harder to detect.
- Screenshots, PDFs, emails, and paper confirmations can no longer be assumed trustworthy.
- Authenticated electronic confirmations are becoming essential for reliable audit evidence.
For the past few years, almost every conversation about AI and audit has run in one direction: how can auditors use AI to work faster, cover more transactions, and catch what a human reviewer would miss. That’s AI in Audit — artificial intelligence as a tool inside the audit process.
There’s a second, much less discussed side to that equation: Audit in AI — what happens when auditors operate in an environment increasingly saturated with AI-generated content.
Auditors aren’t just gaining a new tool. They’re operating in an environment where documents, identities, and evidence can be generated, altered, or fabricated more easily than ever before.
The industry has spent considerable time asking how AI will change audits. It now needs to ask an equally important question: what happens to audit when AI changes the very environment that auditors are meant to verify?
Jump to ↓
The financial landscape is shifting under audit’s feet
Screenshots, PDFs, and paper: a question the audit industry can no longer defer
Why end-to-end validated electronic confirmation matters more than ever
The financial landscape is shifting under audit’s feet
Organizations are becoming more digital, AI agents are replacing humans in the loop, information is multiplying rapidly. At the same time, creating convincing fake evidence is becoming easier and cheaper. Forged bank statements, doctored invoices, or fake audit confirmations once required the fraudster’s time, technical expertise, and careful attention to detail. That barrier is gone. AI can now produce a passable fake letter, a synthetic identity document, or a realistic video of a company executive in minutes, at close to zero cost.
The scale of this shift is no longer theoretical. In January 2024, a finance employee at the Hong Kong office of a UK-based engineering firm joined what he believed was a routine video call with his CFO and several colleagues. Every participant except him was an AI-generated deepfake, built from publicly available footage of company meetings. Over the course of that call, he was persuaded to make 15 transfers totalling roughly $25.6 million to accounts controlled by the fraudsters. One can hope this was a rare circumstance, but Thomson Reuters Institute research shows that almost 43% of detected fraud attempts on financial institutions use AI, and of these, 29% are successful.
No system was breached; no login was stolen. The deception worked because it looked and sounded exactly right and regulators.
Screenshots, PDFs, and paper: a question the audit industry can no longer defer
Auditing standards have long treated external confirmation as strong evidence, precisely because it comes from an independent third party, outside the client’s control. But look closely at how much of that “external” evidence actually reaches the auditor today: a screenshot of an online banking portal, a PDF letter via email, a physical letter via mail or a scanned signature on a faxed reply.
A screenshot is not a confirmation
An internet banking screenshot is not evidence that a balance is real and all arrangements are captured. Cloning a bank’s online banking portal isn’t a particularly advanced feat, and it hasn’t been for years — it’s the backbone of a large share of ordinary phishing. A convincing lookalike domain, styling copied from the real site, and a functioning login page can be stood up in an afternoon.
What’s changed with AI is that producing the “evidence” no longer even requires that much effort: image-generation tools can now render a synthetic browser window showing an online banking dashboard, complete with a specific bank’s logo, layout, and whatever balance is convenient.
Appearance is not authentication
Paper confirmations carry a vulnerability that predates AI by decades: a letter can be intercepted anywhere along its physical route — in the mail, in a shared mailroom, sometimes by someone with access on either end then quietly swapped for a fabricated reply.
What AI adds isn’t the interception, it’s the forgery step that follows it. Replicating a specific institution’s letterhead, seal, and signature block used to take some artistry to get right. Now, a generative model can reproduce the exact visual design of a bank’s stationery from a single scanned example and create a bank statement with transactions reconciling to the fictitious balances/arrangements. The physical risk was always there. It’s now paired with a forgery step that takes minutes instead of genuine talent.
Credibility can be impersonated
Email confirmations rest on one assumption: that a reply from an address belongs to the person that address implies. That assumption has been shaky for years. Lookalike domains, display-name spoofing, and compromised mailboxes are standard tools in business email compromise, a fraud category that costs organizations billions of dollars a year without any help from AI at all.
What AI changes is fluency making it further difficult to differentiate.
Trust must be verified, not assumed
Increasingly, firms are responding to these risks by adopting electronic confirmation processes designed to authenticate both the source of a response and the path it takes to reach the auditor. The objective is not simply digitization but preserving the integrity of independently obtained evidence in an environment where fabrication and impersonation are becoming easier and less expensive.
To be clear, AI is also giving auditors new tools to detect anomalies, identify unusual patterns, and investigate potential fraud more efficiently. But as detection capabilities improve, so do deception capabilities. The issue is not whether AI helps auditors. It’s whether evidence itself remains trustworthy when the cost of fabrication approaches zero.
This is the practical meaning of audit in AI: the question is no longer only whether an auditor obtained a confirmation, but whether that confirmation can be traced and authenticated, back to the party it claims to come from.
Why end-to-end validated electronic confirmation matters more than ever
If one side of the audit equation — the client’s own records, documents, and representations (internal evidence) — is becoming harder to trust by default, the profession must hold the other side to a higher standard, not a lower one. That other side is independent, third-party confirmation: evidence that comes directly from the bank, counterparty, or institution itself, through a channel the client cannot shape and that is designed to help mitigate opportunities for manipulation or impersonation.
That’s why end-to-end validated electronic confirmation is no longer a “nice-to-have” workflow improvement. Increasingly, firms are treating confirmation not simply as an audit procedure, but as part of their broader risk infrastructure. As fraud grows more sophisticated and regulators place greater scrutiny on third-party evidence, the question is no longer how quickly a confirmation can be obtained, but how confidently its authenticity can be trusted
As AI makes it easier to create convincing but fraudulent documents, independently verified evidence becomes increasingly critical to audit quality. Thomson Reuters® Confirmation helps auditors obtain secure, authenticated responses directly from financial institutions and other third parties through a trusted electronic confirmation network. Confirmation can help strengthen audit evidence, reduce risk and support audit quality in an AI-driven world.
Be confident your response is coming from a validated financial institution with Confirmation The firms that build confirmation into the center of their audit design — not as a fieldwork checklist item, but as a planning-stage decision about where trust has to be airtight — are the ones whose opinions will still mean something. That is where the industry’s attention currently needs to belong.
Validated global network