From Mystery to Practice: How the Swedish National Audit Office Approaches AI in Its Performance Auditing

Christina Gellerbrant Hagberg, Auditor General, Swedish National Audit Office. Source: Swedish National Audit Office (Riksrevisionen)

Author: Christina Gellerbrant Hagberg, Auditor General, Swedish National Audit Office (Riksrevisionen)

Introduction: Demystifying AI

Across Supreme Audit Institutions, conversations about artificial intelligence (AI) often focus on technology. Discussions highlight models, data infrastructure, governance frameworks and future potential. Talk about AI is often shrouded in a certain air of mystery; practical applications tend to be conflated with more visionary ideas such as autonomous agents or even quantum computing. For many auditors, this can make AI seem complex − sometimes even intimidating.

Last year at the Swedish National Audit Office (Swedish NAO), we deliberately took a different starting point. Rather than engaging with AI at an abstract level, our ambition was to demystify it − by bringing the focus back to how it can be used in auditing.

After six months of operational use of Microsoft Copilot throughout the organisation − both on a broad and more extensive scale in performance audit − we have begun to form a clearer view. Our experience indicates that the real transformation is not primarily technological, but is rather a matter of employees’ mindset.

A Strategic Choice: Practice Before Theory

Early in our adoption of Copilot, the Swedish NAO made a clear organisational choice. We did not position AI as a large-scale transformation programme or a technical development project. Instead, we chose a direction based on three simple principles:

  • Use existing, secure tools − primarily Copilot.
  • Emphasise practical rather than theoretical learning.
  • Encourage experimentation in daily work.

This approach embodies a basic insight about professional development: auditors do not learn professional judgement by reading policies − they learn it through practice.

No Need to Understand the Underlying Code

There is a useful distinction to be made between auditing AI models as such, and examining how organisations apply AI to improve their operations.

In some rare cases, the AI model itself may be the object of audit − for example, when a public authority relies on an algorithm in its decision-making. In such cases, a certain level of technical understanding may be needed to assess how the model functions and the risks it poses. However, this type of audit is relatively uncommon in performance auditing.

More often, the focus is on how organisations use AI as part of broader efforts to improve efficiency and effectiveness. Here, AI is not radically different from other forms of digitalisation. Relevant audit questions concern governance, risk management, internal controls, learning and follow-up: do organisations test and validate their use of AI, assess risks, manage unintended consequences, and ensure that the technology contributes to intended outcomes?

Auditing AI does not require entirely new audit tools – it necessitates the application of established audit approaches to a new type of instrument. As in other areas of digitalisation, the focus is on how the organisation operates, rather than on the internal workings of the technology itself.

The key implication is that most auditors do not need to have a deep technical understanding of AI. What they need is the ability to assess how organisations govern and how they use AI in practice, using the same core principles that underpin performance audit more generally.

AI − a Matter of Leadership

One of our most important lessons has been that AI adoption is less about technology and more about leadership. At the Swedish NAO, this means that leadership has focused on creating conditions for learning, lowering barriers to experimentation, clarifying expectations and responsibilities, and reducing unnecessary fear and uncertainty.

Encouraging experimentation does not mean removing control. Our approach has relied on a combination of freedom and clear boundaries. Auditors are encouraged to experiment in their daily work, while human judgement remains fully in control of all conclusions. AI tools must not be used to process sensitive or classified data.

This approach of ‘responsible freedom’ has proven essential. It enables learning while maintaining trust, accountability and compliance.

What AI Actually Supports

In practical terms, AI has proved to be most useful as a support tool. Our performance auditors use AI to:

  • structure and refine ideas;
  • analyse large volumes of text;
  • summarise documents and interviews;
  • improve clarity and language in reports;
  • challenge initial assumptions.

This often leads to a secondary effect involving higher expectations in terms of clarity and reasoning. When arguments can be tested more rapidly and alternative explanations are easier to generate, it raises the analytical standard. Our next step will be to explore how AI can support financial audit.

Quality, Risk and Responsibility

A common question is how the question of responsibility is affected by AI. At the Swedish NAO, we have taken the clear position that AI does not lead to a change in the fundamental principles of audit responsibility.

The auditor remains fully accountable for all conclusions. AI outputs are simply treated as suggestions by a very helpful ‘intern’ or ‘co-pilot’. AI output must always be critically reviewed and validated.

While risks such as error or bias are real, they should be managed in the same way as any other risks − with professional skepticism and through review.

One of the most significant practical challenges relates to data. Many datasets used in auditing are confidential or classified, while many advanced AI tools operate in cloud environments. This leads to limitations in terms of use. Our approach has been pragmatic; rather than waiting for perfect solutions, we focus on what is feasible within current limitations.

Six Months In: Early Observations

After six months of operational use, several patterns are emerging. Auditors increasingly find their own relevant use cases. AI is most useful in everyday tasks rather than in isolated pilot projects. Learning spreads through practice and dialogue rather than through formal training. The perceived mystery of AI is dispelled once auditors start using it.

The main lesson at the Swedish NAO is simple: do not begin with a technical approach − begin, instead, with a practical approach. To be useful, the technical underpinning of AI does not need to be fully understood. What matters is how it is integrated into everyday tasks, whether learning is supported, and that audit responsibility is maintained.

AI does not replace professional judgement. It reshapes how that judgement is developed and applied, which is, first and foremost, a matter of leadership.

Back To Top