At a time when the business world is undergoing rapid transformation driven by artificial intelligence, these technologies are no longer merely modern tools added to the workplace. They have become a significant factor in how organizations are managed, data is analyzed, decisions are made, and risks are monitored. In accounting, auditing and finance in particular, artificial intelligence is opening new horizons for professionals, from analyzing vast amounts of data and identifying patterns and anomalies to automating certain tasks and developing new approaches to auditing and consulting.
Against this backdrop, the experience of Cynthia Merhej stands out. She specializes in applying artificial intelligence to accounting, auditing and finance, combining her professional auditing experience with her understanding of emerging technologies. She helps organizations and professionals use artificial intelligence in a practical and thoughtful way, with strong emphasis on governance, data security and risk management. She founded AIKIT LB on a vision of connecting technology with the actual needs of the profession, away from random adoption or fascination with tools simply because they are new.
In this interview, Cynthia Merhej discusses the transformation artificial intelligence has brought to auditing and finance. She explains where the real opportunities lie, highlights the key risks, and explores how organizations can enter the world of AI with confidence and responsibility, avoiding rushed decisions and ill-considered implementation.
In light of the accelerating digital transformation, how can artificial intelligence contribute to the development of internal audit, and what are the main benefits it can bring to organizations?
Let me start with something I see every day in my work. Internal auditors have traditionally worked with samples. We would take 30 or 50 transactions out of 100,000 and build our opinion based on them. Data analytics tools broke that limitation years ago, making it possible to examine the entire population. What artificial intelligence adds on top of that are two new layers: machine learning, which can identify patterns and anomalies that we did not even program the system to look for, and large language models, which open the door to unstructured data — contracts, correspondence, meeting minutes, policies — an area that was previously almost inaccessible to automated analysis.
This is where the real benefits lie. The first is planning. Risk assessment is no longer based solely on an annual questionnaire and personal impressions, but on signals extracted directly from the data, allowing audit effort to focus where the actual risk lies. The second is continuous coverage rather than periodic testing. Continuous auditing is no longer merely a theoretical concept. Today, we can build indicators that capture exceptions as they occur, transforming auditing from simply looking backward into accompanying processes as they happen.
The third benefit, and one that is discussed less often, is time. A significant portion of an auditor’s working hours is spent reading, summarizing, drafting observations and organizing working papers. Large language models can significantly reduce this workload and give auditors back their most valuable resource: their ability to think and exercise professional judgment. It is no coincidence that the new version of the Global Internal Audit Standards explicitly refers to technological resources as a responsibility of the Chief Audit Executive, rather than treating them as an option.
But I want to be very clear about one point, because it is something I emphasize in every training session I deliver: the tool identifies; the auditor decides. Artificial intelligence improves the quality of the questions we ask of the data and expands what we are able to see, but the signature on the audit report remains the auditor’s signature, along with full responsibility. Organizations that understand this balance are the ones that truly benefit.
What do we mean by “AI governance,” and why has it become essential to ensuring the safe, responsible and effective use of these technologies within organizations?
AI governance, in the simplest definition I use, is the documented answer to four questions: Who owns the decision to use this technology? Within what boundaries? Who monitors the results? And who is accountable when something goes wrong? If an organization cannot answer these four questions in writing, it does not have governance, regardless of how advanced its tools are.
In practice, the first thing I ask any organization to do is very simple: create a register of its AI use cases. Where is AI being used, for what purpose, with what data, and who is responsible? Most organizations discover, while preparing this register, that they are using AI in places they were not even aware of.
Why has governance become essential? Because AI entered organizations through the back door before it came through the front door. Employees use general-purpose tools on their phones and computers before management has even approved a policy. This is what we call shadow AI, and it can be more dangerous than any formal project because it is invisible. Customer data, financial figures, draft contracts — all of these may be copied into tools without the organization knowing where the information is stored or how it is being used.
There is a second reason, related to the nature of the technology itself. Traditional systems either work or fail. Generative AI models, however, can give you a confident answer that is simultaneously wrong. In most cases I have seen, the machine did not necessarily “make a mistake”; we asked it an incomplete question. Governance is what places the right human reviewer at the right point before an answer becomes a decision.
The third reason is regulatory. Frameworks such as ISO/IEC 42001, the NIST AI Risk Management Framework and the European Union AI Act have established a common language around what is expected of organizations. In Lebanon, even before specific AI legislation is introduced, Law No. 81 of 2018 on Electronic Transactions and Personal Data already applies to the data that passes through these tools. Companies dealing with international partners or funders will be asked about these issues sooner or later. Organizations that build their governance today can do so gradually; those that wait will have to build it under pressure.
Internal audit has a dual role here, and I always emphasize this. It should use AI in its own work while also providing independent assurance to the board that the organization’s AI governance framework exists and is functioning. The second role is what will distinguish internal audit functions in the coming years.
How does internal audit intersect with IT audit in the age of artificial intelligence, and what are the main digital risks auditors should pay attention to?
I moved from financial auditing to IT auditing in 2014, when the distinction between the two fields was clear: one team examined the numbers, while another examined the systems. Today, that separation is no longer possible. When a model is classifying transactions, assessing customer risk or suggesting an accounting entry, the financial question and the technology question have become one: Can we trust this output, and why?
The way I explain this intersection is simple. AI auditing consists of three layers. First are the general IT controls that an IT auditor already knows well, including access management, change management and business continuity. Then comes governance of the data feeding the model, followed by governance of the model itself.
The first layer is not new, but it takes on a new meaning. Change management, for example, is no longer about code alone; it also involves prompts, model settings and the data on which the model was trained. This means that an internal auditor needs to understand enough about how the model works to ask the right questions, while an IT auditor needs to understand the business impact in order to determine which technical error deserves attention. This is precisely why I obtained the AAIA (Advanced in AI Audit) certification from ISACA: the profession needs people who can operate in the space between the two fields.
As for the risks I place at the top of any audit program, the first is data leakage through AI tools. What is being sent to the model? Where is it stored? Is it being used to train other models?
The second is blind reliance on outputs — the absence of a genuine, rather than merely formal, human review point, particularly given the tendency of generative AI models to confidently generate fabricated information.
The third is model bias, which can be difficult to detect because it does not necessarily appear in a single transaction, but rather as a pattern across thousands of transactions.
The fourth is deterioration in model performance over time, known as model drift, when real-world data moves away from what the model was trained on and no one notices.
The fifth is attacks targeting the model itself, such as prompt injection, where text embedded in a document or email can alter the behavior of the tool without the user’s knowledge.
The sixth is reliance on a single external provider that may change its terms or model without sufficient notice.
I would add one final risk that is often overlooked: traceability. If an audit committee asks you a year later why a particular decision was made with the assistance of a specific model, can you reconstruct the process? If the answer is no, that is an audit finding before it is even a technical issue.
How is artificial intelligence changing the field of consultancy, and what role can specialized consulting firms play in helping companies adopt AI solutions in a thoughtful and effective way?
I believe the biggest change is the shift in value from “knowledge of the technology” to “knowledge of the business.” Years ago, consultants were paid because they knew the tool. Today, the tools are available to everyone, and what clients need is someone who deeply understands their financial and control processes and knows where AI can add value — and where it should stay out of the process.
I founded AIKIT LB around precisely this idea. I am not a technology salesperson; I am an auditor working within the profession, bringing accountants and auditors what I have personally tested on real files. That distinction matters, because companies in Lebanon and the region have grown tired of flashy presentations that do not know how to apply AI to a real general ledger or an actual audit file.
I see the role of specialized consulting in three areas. The first is identifying priorities. Most organizations begin with the wrong question: “Which tool should we buy?” The right question is: “Which process consumes our time, is repetitive, and involves errors that can be identified and corrected at the lowest possible cost?” That is where we should start.
The second is building the governance framework alongside the first use case, rather than afterward. This means policies, permissions and review points — elements that are often overlooked in the excitement of the beginning and whose absence is paid for later.
The third, and I consider it the most important, is empowering the team itself. Successful consulting is what makes the client less dependent on you over time, because their team has learned how to ask questions, evaluate results and make decisions.
And I would add one candid observation: thoughtful adoption is slower at the beginning and faster in the end. Organizations that rush into full automation in the first month often find themselves, six months later, repairing what was broken.
With the growing number of AI tools and platforms on the market, what criteria should organizations use to select the most suitable tool for their needs, and how can they ensure that it is secure and capable of delivering real value?
I use a simple sequence with my clients, and I start where most people do not. The first criterion is data before features.
Before looking at what the tool can do, I ask: Where is my data stored? Is it used to train the model? Can I delete it? Which legal jurisdiction applies to it? If the answer is not clearly and explicitly stated in the terms of service and the data processing agreement, the tool is excluded, regardless of its capabilities.
Given my auditing background, I also request independent third-party reports or certifications from the provider, such as a SOC 2 report or ISO/IEC 27001 certification, because promises on a security webpage are not enough.
The second criterion is suitability for the actual need, rather than an imagined one. I always ask for the tool to be tested on a real task from the organization, using a real file with any sensitive information removed, rather than relying on a demonstration prepared by the vendor. The difference between the two can sometimes be striking.
The third criterion is transparency and auditability. Does the tool keep a record of what happened? Can you trace who requested what, when, and what the output was? For an auditor like me, a tool that does not produce a reviewable audit trail is not suitable for any process with financial impact.
The fourth criterion is enterprise-level controls: access management, integration with existing identity systems, and the ability to control what is and is not permitted. An individual account on a general-purpose AI tool is fundamentally different from an enterprise version of the same tool, and many people fail to recognize this distinction.
The fifth criterion is total cost, not simply the subscription price: training time, integration, the human review required, and the cost of switching providers if the organization decides to move elsewhere later.
As for determining whether the tool is actually creating value, my approach is simple: define one measurable indicator before starting — hours saved, errors detected or processing time — and measure it before and after implementation over the same period.
If the number has not changed after three months, then the issue is either with the tool or with the way it is being used, and both deserve to be reviewed before the subscription is renewed.
Ultimately, the most suitable tool is not necessarily the most powerful or the most popular. It is the one your team can understand, trust within its limitations, and take responsibility for the results it produces.
Alternative headlines
– Cynthia Merhej Reveals the Future of Artificial Intelligence in Finance and Auditing
– Cynthia Merhej: From Auditing Numbers to Auditing AI… The Profession Is Facing a Major Transformation
– Cynthia Merhej Reveals the Other Side of Artificial Intelligence: Opportunities, Risks and the Governance of the Future
– Cynthia Merhej: AI Governance Is No Longer an Option… Here Are Its Most Serious Risks
