Next generation auditing can be just for you.
Every organisation is ultimately a manifestation of people.
By nature the performance drivers and the forces influencing an organisation are unique.
If you would like to understand how to understand any aspect of your management system let us know and we can help you accelerate your progress.
FAQs: AI in Next-Gen Auditing
DeepFathom uses trained AI models to analyse your evidence against all clauses using a risk-based approach. This means a single piece of evidence can demonstrate compliance with multiple clauses, providing a comprehensive and accurate assessment of your management system.
ISO 17021 does not prescribe specific audit methods but emphasises delivering robust certification processes. Clause 4.5 of IAF MD 5:2023 reiterates this:
"Certification audits may include remote auditing techniques such as interactive web-based collaboration, web meetings, teleconferences, and/or electronic verification of the client’s processes. If the CAB plans an audit for which remote auditing activities are utilised, it shall apply the requirements defined in IAF MD 4. These activities shall be identified in the audit plan, and the time spent on these activities may be considered as contributing to the total duration of management systems audits."
This confirms remote auditing techniques are valid audit time. IAF MD 4:2023 explicitly mentions AI under ICT in section 0.2:
"ICT is the use of technology for gathering, storing, retrieving, processing, analysing, and transmitting information. It includes software and hardware such as smartphones, handheld devices, laptop computers, desktop computers, drones, video cameras, wearable technology, artificial intelligence, and others. The use of ICT may be appropriate for auditing/assessment both locally and remotely."
This recognition validates AI for both local and remote auditing, complementing ISO 17021's emphasis on onsite auditing.
DeepFathom's platform uses trained AI models to analyse your evidence against all clauses using a risk-based approach. This means a single piece of evidence can demonstrate compliance with multiple clauses, providing a comprehensive and accurate assessment of your management system.
Yes, The High Performance Assessment Ltd (trading as HPA) and Certification International have both used this approach whilst meeting UKAS requirements.
DeepFathom is committed to helping ISO Certification Bodies and their client benefit from Next-Gen auditing services.
The system generates risk-assessed and scored reports for each clause and sub-clause of the standard (depending on the product purchased). It highlights areas of compliance and non-compliance, includes your recorded evidence, and outlines action plans for improvement. This format makes the reports highly suitable for management review.
Yes, the product allows you to efficiently review compliance with each clause. It enables you to record objective evidence and identify areas for improvement where needed.
Absolutely. It’s a simple, click-and-play platform accessed via a URL. There’s no need to download software or apps. The system automatically analyses your responses and shows how they demonstrate compliance with each clause.
Yes, the process is straightforward. We provide a URL for accessing the assessment, and you can pause and resume at any time without losing your data.
Yes, while we offer generic solutions such as gap analysis, internal audits using cultural analytics, and third-party reviews, we can customise these to meet your unique requirements. Simply reach out to us, and we’ll assist.
Yes, our team is readily available. You can email us anytime or call us during our business hours. Contact details are provided on our website.
Yes, we continuously update the gap analysis content to align with any changes in standards. This includes adjustments to reflect new requirements for documents and records, ensuring your compliance remains current.
Yes, our website features examples of how our AI solutions have positively impacted organisations. If you need further information or have specific questions, don’t hesitate to contact us.
Click here to view case studiesAI provides transformative tools that auditors can use for auditing requirements with its data analytics capabilities and decision-support functions:
- Automating Data Analysis: AI rapidly processes large compliance datasets, identifying trends, patterns, and deviations.
- Enhancing Auditor Decision-Making: Machine learning algorithms pinpoint high-risk areas, reducing human oversight errors.
- Providing Scoring Profiles: These metrics quantify compliance, offering actionable insights beyond traditional pass/fail evaluations.
For effective implementation, AI must maintain certification integrity by addressing:
Risk-Based Thinking: AI identifies risk concentrations, measures cultural impacts, and uses predictive analytics—areas where traditional auditing struggles with its retrospective view.
Impartiality: Algorithms must be unbiased, with transparent programming and validation ensuring objective results.
Competence: Auditors must understand AI tools, their strengths, weaknesses, and appropriate usage based on scope and context. Just as they would understand the strengths and weaknesses of other audit techniques.
Consistency: AI standardises processes, reducing variability across audits.
AI-powered scoring profiles enhance compliance audits by quantifying management system performance across areas like policy implementation, risk management, and operational effectiveness.
Advantages of Scoring Profiles:
- Objective Metrics: Reduces subjectivity through data-driven evaluations.
- Trend Analysis: Identifies compliance progress or decline over time.
- Actionable Insights: Helps prioritise corrective actions, driving continuous improvement.
- Added Value to Reports: Provides strategic insights aligning compliance with business objectives.
For instance, in an ISO 9001 audit, AI-generated scores can highlight low-performing clauses, guiding targeted improvements.
AI’s ability to analyse cultural dynamics, predict risks, and adapt to audit environments offers insights unattainable through traditional audits. This capability, aligned with MD 4 section 0.2, enhances certification audits and builds trust in findings and recommendations.
Generative AI, a subset of AI, learns patterns from existing data to create content like reports and findings through advanced models. Its key components include:
- Neural Networks: Mimicking the human brain, these systems recognise patterns and relationships in data. They can identify anomalies, compliance risks, and inefficiencies, providing immediate insights into operational practices and complementing other audit methods.
- Regression Testing: Evaluates variable relationships to predict compliance risks. By analysing historical data, it forecasts potential non-conformities, enabling proactive responses.
Cultural Complexity Analysis: AI tools assess organisational culture by analysing employee experiences, communication patterns, and workflows. Unlike human auditors’ observations, AI quantifies cultural factors, delivering insights into leadership, engagement, and ethical practices.
While AI significantly enhances certification audits, its integration presents challenges. To ensure AI effectively supports audit processes, its implementation must include the use of pre-trained networks (static models) to reduce risks of bias and false information. AI does not always need to learn continuously; whether continuous learning is necessary depends on the system's purpose and the dynamics of the environment it operates in. For some systems, static models are more suitable, while others may require continuous learning for adaptability. Parallel deployment with traditional auditing can validate AI results and refine its application.
- Bias and Transparency Risks
Challenge: AI may produce biased results due to flawed training data, and complex algorithms can lack transparency.
Solution: Use pre-trained neural networks (static models) vetted for quality and diversity to reduce bias and false outputs. Where static models suffice, avoid unnecessary continuous learning that might introduce new biases. Incorporate academic rigor by applying systems thinking, social systems, anthropology, and other interdisciplinary insights. Run AI audits alongside traditional methods to validate and refine outputs, ensuring transparency and reliability.
- Over-Reliance on Technology
Challenge: Overdependence on AI can overshadow the human judgment critical for nuanced assessments.
Solution: Integrate AI as a decision-support tool that complements human auditors. Use pre-trained networks (static models) where the audit environment is stable and predictable. Parallel auditing with traditional methods ensures AI results align with human insights, maintaining balanced decision-making.
- Ethical and Security Concerns
Challenge: Handling large datasets with AI raises privacy, security, and ethical issues.
Solution: Leverage static models when dynamic learning is unnecessary to limit data exposure and reduce risks. Employ robust data protection protocols and pre-trained networks designed with ethical principles. Test systems against traditional audits to ensure they respect cultural and social dynamics while upholding privacy and security standards.
- High Implementation Costs
Challenge: The costs of integrating AI, including software, hardware, and training, can be prohibitive.
Solution: Use pre-trained networks (static models) to reduce computational requirements and initial investment. Begin with parallel implementation alongside traditional audits to minimise disruption, allowing gradual scaling and ensuring AI-driven efficiencies are validated and cost-effective.
- Potential for Overstandardisation
Challenge: AI-driven consistency may lead to overly rigid audit processes that overlook organisational uniqueness.
Solution: Develop customisable AI systems based on pre-trained networks (static models) for predictable audit environments and introduce dynamic learning only when adaptability is essential. Use parallel auditing to identify and address rigidity, ensuring AI systems remain flexible and context-sensitive.
The platform can use languages written and read from left to right.
Languages which use the following scripts are written left to right: Latin, Modern Greek, Cyrillic, Indic and Southeast Asian. Therefore, most of the modern languages of Europe, North and South America, India and Southeast Asia are written left to right.
There are however 12 languages that we do not currently support namely; Arabic, Aramaic, Azeri, Divehi, Fula, Hebrew, Kurdish, N'ko, Persian, Rohingya, Syriac, and Urdu. Part of our vision is to provide access to all. This will include all languages, but also access to what we call the 'last mile'. The last mile is to provide access for participants who may not have access to the internet, tablets, computers, or literate skills.
This work is under way as we look to develop value chains that provide omnichannel access, but also innovative ways to provide people in remote locations with a voice in our auditing services.