
South Africa Agentic AI: Boosts Continuous Audit Readiness
Summary
- South African organizations frequently struggle with maintaining continuous audit readiness between formal assessments, as evidenced by widespread non-compliance findings from the Auditor-General.
- The Auditor-General's 2024-25 report found only 151 of 417 national and provincial auditees achieved clean audits, citing persistent non-compliance and critical weaknesses in accountability.
- Agentic artificial intelligence offers a solution by continuously collecting and validating control evidence, addressing issues like outdated records and unclear responsibilities.
- New ISO standards now cover the auditing of Agentic AI, formally linking audit readiness with AI governance for the first time.
- Compliance officers and legal teams must assess Agentic AI solutions to achieve ongoing audit readiness and adhere to evolving global AI governance standards in South Africa.
The Persistent Challenge of Audit Readiness in South Africa
For compliance officers and legal teams in South Africa, this signifies an urgent need to evaluate Agentic AI solutions not only for their potential to foster continuous audit readiness but also to ensure alignment with these emerging international benchmarks.
South African organizations frequently excel at preparing for scheduled audits but struggle significantly with maintaining a state of continuous audit readiness between these formal assessments. This intermittent approach to compliance often leads to a scramble for documentation and evidence when auditors arrive, a process characterized by retrieving old files and reconstructing control operations from disparate sources. This pattern of reactive compliance is not sustainable and has significant implications for governance across both public and private sectors.
The national landscape of compliance issues is starkly illustrated by official reports. The Auditor-General's 2024-25 general report on national and provincial audit outcomes, released on March 26, 2026, revealed that only 151 out of 417 auditees achieved clean audits. This report specifically highlighted "persistent and pervasive non-compliance with legislation," identifying accountability and consequence management as a "critical weakness" within these entities. The situation in local government is equally concerning; the 2023-24 outcomes showed that a mere 41 of 257 municipalities secured clean audits.
The Auditor-General's assessment of local government was unequivocal, stating that fundamental financial management processes, including record keeping, independent reviews, and reporting, are "not functioning as they should." This indicates a "continued reliance on audit process" to uncover information that management should already possess. While the private sector reports through different mechanisms such as King IV disclosures, ISO surveillance audits, regulator returns, and client due diligence, the underlying issue remains consistent: evidence is typically compiled for the auditor's visit and then neglected until the next cycle.
Agentic AI: A Path to Continuous Compliance
The advent of Agentic artificial intelligence offers a transformative solution to these long-standing compliance challenges, enabling organizations to achieve continuous audit readiness. This advanced technology can autonomously collect and validate control evidence on an ongoing basis, eliminating the need for last-minute data gathering. JJ Milner, Managing Director of Global Micro Solutions, emphasizes that "Audit readiness should be continuous," asserting that an organization must be capable of demonstrating, at any given moment, that its controls are operational, evidence is current, responsibilities are clearly defined, and corrective actions are being diligently closed.
Many organizations possess policies outlining controls, such as enforced multifactor authentication or quarterly privileged access reviews. However, demonstrating the real-time status of these controls across complex IT environments—which might span a Microsoft tenant, a firewall console, and various ticketing systems—remains a significant hurdle. Global Micro Solutions, drawing from its experience with over 1,400 managed tenants, notes that critical control evidence often resides in fragmented locations like spreadsheets, shared folders, email threads, or even the personal records of past control owners. Such evidence quickly becomes outdated; a screenshot of a conditional access policy from February, for instance, offers no insight into its state in September.
Furthermore, the clarity of responsibility is a common pitfall. Claudia Correia de Araujo, Business Development Lead at Global Micro Solutions, points out that ownership is frequently assigned only after a finding is raised, which is the most costly moment for such an assignment. She describes the telling silence in a board or audit committee meeting when the chair inquires about ownership of a risk or control after a finding is tabled. Controls without named owners are often reconstructed under duress, leading to corrective actions that remain open until the subsequent audit. Similarly, leadership often relies on manually prepared reports for overdue actions, meaning the information's currency depends entirely on the last time someone had the capacity to update it.
Integrating AI Governance with Evolving Standards
The landscape for AI governance and auditing is rapidly evolving, with new ISO standards now specifically encompassing the auditing of Agentic AI. This development marks a pivotal moment, as it formally links audit readiness with robust AI governance for the first time. For compliance officers and legal teams in South Africa, this signifies an urgent need to evaluate Agentic AI solutions not only for their potential to foster continuous audit readiness but also to ensure alignment with these emerging international benchmarks.
These new ISO standards provide a framework for assessing the reliability and integrity of AI systems used in critical compliance functions. Organizations leveraging Agentic AI for continuous compliance must therefore ensure their deployments adhere to these global best practices, reinforcing the credibility of their automated evidence collection and validation processes. This proactive approach to AI governance in South Africa is crucial for addressing the pervasive non-compliance issues highlighted by the ZA Auditor-General and for preparing for a future where technology-driven auditing becomes the norm.
Practical Implications
Compliance officers and legal teams in South Africa should assess Agentic AI solutions for achieving continuous audit readiness, addressing pervasive non-compliance issues highlighted by the Auditor-General, and preparing for new ISO standards governing AI audits and governance.
Source
Source: Original reporting via ITWeb
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Wansom is AI and can make mistakes.
