The Real Barrier to Audit Analytics Isn’t Adoption. It’s Trust. 

data analytics in external audit

ICAEW’s new report on data analytics in external audit, Analytics in External Audit: A Survey of Current Practice and Trends, has a finding buried in its middle chapters that says more than anything in its executive summary: a lot of audit firms have analytics tools sitting on the shelf that they don’t actually rely on. 

Some default to sampling and skip the analytics almost entirely, tools notwithstanding. Others run full substantive testing right alongside the analytics, just to be safe. ICAEW’s own language for this is blunt: firms end up doing the same work twice, for essentially no payoff. That’s not a rounding error in an otherwise upbeat progress report. That’s the real headline. 

MindBridge contributed to the research behind this report, through an interview with our Head of AI Governance, Wenzel Reyes, and we’re referenced a few times in its discussion of where audit analytics is heading. But the more useful thing we can do here isn’t recap the report. ICAEW already did that well. It’s to name the pattern running underneath three things the report categorizes separately. 

Three “barriers.” One root cause. 

ICAEW organizes the obstacles to analytics adoption into three categories: data quality, methodology alignment, and standards uncertainty. Looking at the specific examples inside each one, though, they read less like three different problems and more like one problem showing up in three places: audit teams don’t have a reliable way to know how much to trust what the analytics just told them. 

On data, the report is candid that quality often can’t be properly assessed until it’s already been fully ingested, that data extracted manually from client systems frequently lacks consistency, and that “batch” journals can obscure what’s actually happening at a transactional level. Every one of those issues undermines the same thing: confidence that what went into the analysis was complete and accurate in the first place. 

On methodology, the report describes two failure modes that appear opposite but stem from the same gap. Some teams swing one way, treating an analytics output as settled and final rather than as a prompt for further digging. Others swing the other way, running the traditional test anyway just in case. Neither is really about the tool. Both happen because nobody has told the team how much evidentiary weight a given output is supposed to carry. 

On standards, it’s the same gap at an institutional level. A single analytics-based test can blend risk assessment, analytical procedures, and tests of detail in ways that don’t map cleanly onto the categories current auditing standards describe, so firms aren’t always sure how to document what they did or whether a reviewer will accept it. Regulators say they rarely see analytics being used inappropriately. What they see instead is firms that can’t yet articulate, with confidence, why what they did was enough. 

Reframed that way, three sections of the report collapse into one finding: the barrier to audit analytics was never really about whether the tools work. It’s about whether audit teams, and eventually a partner, a reviewer, a regulator, can trust what the tools produced enough to act on it and stand behind it. 

Exhibit A: the journal-testing plateau 

This shows up most clearly in one detail ICAEW picked up directly from MindBridge. Most mid-tier and smaller firms get comfortable with analytics for one thing, journal entry testing, long before they extend it anywhere else. It’s often the entry point, with risk assessment and broader substantive analytics arriving much later, if at all. 

That’s not really about firm size or budget. Journal entry testing is the easiest way to trust a tool’s output because the data comes straight from the general ledger. It’s largely self-evidencing. Extend analytics into risk assessment or revenue testing, and a team suddenly has to trust a model’s judgment on data that’s harder to independently verify and a result that’s harder to sanity-check on sight. So firms stop where confidence is easiest to build, and stay there. 

That’s the practical, day-to-day version of what we at MindBridge call the Relevance Gap: the growing distance between how complex modern financial environments have become and a firm’s ability to confidently say where the real risk sits. Buying a tool doesn’t close that gap on its own. Being able to trust and defend what the tool tells you does. 

What actually moves firms past it 

The report’s own examples of firms that pushed past journal testing all did the same underlying thing, even though they’d describe it differently: 

  • KPMG built a central “clearing house.” Every new analytics technique goes through review before it’s rolled out, so teams know in advance it will hold up against the standards. That removes the guesswork about how much to trust it. 
  • Grant Thornton built methodology wrappers around specific tools, spelling out exactly how to interpret and document a given output. Once that was in place, the firm was able to scale back hands-on consultation over time and focus expert attention on the highest-risk areas. That’s a sign confidence had genuinely grown, not just that a tool had been installed. 
  • Firms with the least of this structure default to “wait and see.” ICAEW is candid that many smaller and mid-tier firms have tools they aren’t using to their full potential, largely because nobody has built the bridge between what a tool outputs and how confidently a team can rely on it. 

None of these are really adoption strategies. They’re trust-building strategies that happen to route through methodology. 

Why explainability is the actual unlock 

There’s a reason the report ties this directly to updates like ISA 315 (Revised 2019) and ISA 240 (Revised): both push firms toward more rigorous, better-evidenced risk assessment. A model that can’t show its reasoning gives a team exactly two options when it flags something: accept the score on faith, or ignore it and do the work manually anyway. Both behaviors show up throughout the report, and neither one moves a firm forward. 

This is the specific gap the MindBridge AI™ Platform is built to close, and it’s why the report describes our approach as a “glass box” model: every risk score comes with a rationale an auditor can actually investigate, not just a number to accept or discard. It’s the same principle behind KPMG Clara AI Transaction Scoring: MindBridge-powered analytics that score the full population of a client’s transactions, now running on roughly 20,000 audit engagements globally. The goal was never to replace a reviewer’s judgment. It was to give that judgment something concrete and defensible to work from. 

If you’re building your firm’s analytics roadmap 

A few things worth taking from this, regardless of which vendor a firm ends up using: 

  • Don’t measure success by how many licenses got deployed. Measure it by how far past journal testing your teams are actually willing to rely on the output. 
  • Before rolling out a tool broadly, decide and document how much evidentiary weight its output is supposed to carry. That decision is what turns a flagged anomaly into usable audit evidence rather than a number nobody trusts. 
  • When evaluating any analytics tool, ask it to show its reasoning, not just its score. If a vendor can’t answer “why did this get flagged” in language an auditor can put in a working paper, that tool will hit the same ceiling ICAEW just documented across the whole profession. 

The tools clearly aren’t the constraint anymore. ICAEW’s own data makes that plain: firms of every size now have real options. What separates the ones actually getting value from analytics from the ones still running everything twice isn’t the software they bought. It’s whether they’ve given their teams a reason to trust what that software tells them. That’s a solvable problem, but it takes a decision, not just a purchase. 

Read the report 

ICAEW’s full report is available directly from ICAEW: Analytics in External Audit: A Survey of Current Practice and Trends. 

FAQ 

What’s the biggest barrier to audit analytics adoption, according to ICAEW’s 2026 report?

Not the technology. It’s trust. Firms across every size band described analytics tools they had but didn’t fully rely on, often running traditional testing alongside the analytics anyway, which duplicates effort without adding assurance. 

Why do most audit firms stop at journal testing when it comes to analytics?

Because it’s the easiest place to trust the output. The data comes straight from the general ledger and is relatively easy to verify. Extending analytics into risk assessment or substantive testing means trusting a model’s judgment on harder-to-verify data, which is a bigger ask without an explainable rationale behind it. 

Is MindBridge mentioned in the report?

Yes. MindBridge contributed through an interview with our Head of AI Governance, Wenzel Reyes, and the report discusses our “glass box” approach to explainable risk scoring, as well as KPMG Clara AI Transaction Scoring, which runs on MindBridge technology. 

What does MindBridge mean by the “Relevance Gap”?

It’s our name for the growing distance between how fast and complex modern financial environments have become and a firm’s ability to confidently identify where the real risk sits. This report shows the gap in practice: firms have more data and more tools than ever, and many still can’t say with confidence how much to trust what those tools are telling them. 

Library item

The Real Barrier to Audit Analytics Isn’t Adoption. It’s Trust. 

Please enter your email to proceed