Skip to main content

Zade Associates

Category Archives

2 Articles
ARTIFICIAL INTELLIGENCE AND THE FUTURE OF AUDIT & ASSURANCE – A Kenyan and East African Perspective

ARTIFICIAL INTELLIGENCE AND THE FUTURE OF AUDIT & ASSURANCE – A Kenyan and East African Perspective

by Zade

Introduction

Audit and assurance are undergoing their most significant transformation since the move from paper working papers to digital audit files. Artificial Intelligence (AI), machine learning, and generative AI are moving rapidly from experimentation into everyday practice. For Kenya and the wider East African Community (EAC), this transition comes at a pivotal moment as sustainability reporting requirements emerge, digital adoption accelerates and a new generation of technology-enabled professionals enters the workforce.

Why This Matters Now for Kenya and East Africa

Two regulatory developments make this a live issue rather than a future one for the region:

  1. Mandatory sustainability disclosures – Kenya is preparing to introduce mandatory IFRS S1 and S2 sustainability disclosures starting in January 2027, under a phased roadmap led by the Institute of Certified Public Accountants of Kenya (ICPAK), while the global assurance standard ISSA 5000 is expected to take effect around December 2026. Assuring ESG and carbon data at scale is very difficult to do manually, which is why AI-enabled continuous monitoring tools are already being piloted in the Kenyan market.
  1. A live example – Grant Thornton Kenya and Newtral Technologies have partnered to deploy an AI platform called Noa, which continuously monitors organizational data, reconciles information, identifies reporting gaps and prepares audit-ready disclosures for carbon accounting and ESG reporting. A concrete illustration of how continuous, machine-assisted assurance is starting to replace the old model of periodic, sample-based review.

At the same time, the profession’s own institutions are actively discussing what this means for practice. KCA University and the Institute of Internal Auditors (IIA) Kenya jointly hosted a forum on the future of internal auditing in May 2026, focused explicitly on AI, governance reform, and strategic risk management across public and private sectors.

Where AI Is Already Showing Up in East African Audit Practice

Adoption in the region is uneven but real and it clusters around a few use cases:

  1. Document and data extraction – Tools that read invoices, receipts, and bank statements and pull the data straight into working papers are gaining traction locally. These are the most immediately useful forms of AI for East African practices because it attacks the single most labour-intensive part of a traditional audit, manual data capture and reconciliation.
  2. Public-sector audit management – Kenya’s Office of the Auditor-General relies on audit management platforms such as TeamMate+ to track the entire audit lifecycle in a secure environment, which is important for institutional transparency on large public projects. As these platforms add AI-assisted risk scoring and anomaly detection, public-sector audit stands to benefit significantly from earlier detection of irregular spending patterns.
  3. Locally built infrastructure – ICPAK itself has developed an online audit automation platform, commonly referred to as myAudit, built around IFRS for SMEs and the official ICPAK Audit Manual, allowing auditors to collaborate remotely, manage client access, and centralize working papers in the cloud. 
  4. Continuous assurance for ESG and compliance – Platforms like Noa point toward a model where assurance is not a once-a-year exercise but an ongoing check against live organizational data, such a meaningful departure from the traditional audit cycle.

The Opportunities

  1. Efficiency and cost – Manual vouching, reconciliation and sampling are time-consuming and expensive. AI-driven data extraction and continuous monitoring can shrink fieldwork time substantially, potentially making quality audits more affordable and accessible to a broader base of businesses including the large informal and semi-formal sector that currently receives little or no assurance coverage at all.
  2. Better risk detection – Instead of testing a sample of transactions, machine learning models can scan entire populations of data for anomalies, unusual relationships or patterns consistent with fraud. In markets where financial crime, mobile-money fraud and public procurement irregularities are recurring concerns, full-population testing is a genuine upgrade over sample-based methods.
  3. Freeing auditors for judgment work – If AI absorbs routine testing and drafting, auditors can spend more time on professional skepticism, client dialogue and complex judgment calls, the parts of the job regulators most want strengthened and the parts hardest to outsource to a machine.

The Risks and Constraints

  1. Data and connectivity gaps – AI tools are only as good as the data feeding them. Many East African businesses, particularly SMEs and informal enterprises keep incomplete, paper-based, or inconsistent records and rural connectivity remains patchy. An AI tool trained or tuned on data-rich, well-digitized environments may perform poorly, or produce misleading confidence, when applied to messier local datasets.
  2. Cost and the small-firm reality – Enterprise AI-audit platforms (of the kind used by large multinational networks) are often priced well beyond what a small Kenyan, Ugandan, Tanzanian or Rwandan practice can afford. Without deliberate low-cost alternatives the ICPAK myAudit approach is a useful model. AI adoption risks widening the gap between large and small firms rather than levelling the playing field.
  3. Skills and training – Auditors need to understand not just how to use AI tools but how to evaluate them: what data they were trained on, where they are likely to be wrong and how to document reliance on their output. This is a new competency area and East African accountancy curricula, and CPD programmes are only beginning to catch up. The KCA University/IIA Kenya forum on the future of internal audit is an early sign that institutions recognize this gap.
  1. Overreliance and the “black box” problem – Auditing standards require auditors to understand and be able to explain the basis for their conclusions. Many AI models, particularly deep learning ones, do not readily explain their outputs. Regulators globally are grappling with how auditors can rely on a tool whose reasoning cannot be fully inspected, without simply treating the AI’s output as ground truth.
  2. Data protection and confidentiality – Client financial data is highly sensitive. Kenya’s Data Protection Act, 2019, and equivalent frameworks in neighbouring countries impose obligations on how personal and financial data is processed, stored and transferred, obligations that become more complex when AI tools process data via cloud infrastructure that may sit outside the region. Firms need clear policies on what data can be fed into third-party AI systems, especially where models are hosted abroad.
  3. Talent and job-displacement concerns – Junior audit roles have traditionally been where vouching, ticking and reconciliation work is learned. If AI absorbs that work, the profession needs a deliberate plan for how junior staff still develop the foundational skills and judgment that senior auditors rely on, otherwise the pipeline of well-trained future partners and Audit staff could weaken over time.

What are Standard-Setters and Regulators Doing?

The global standard-setting response is directly relevant to Kenya and East Africa because ICPAK and its counterparts across the EAC adopt International Standards on Auditing.  The International Auditing and Assurance Standards Board (IAASB) held global roundtables in the second half of 2025 with more than 240 stakeholders across six continents to explore how AI and other emerging technologies affect audit engagements and the application of quality management standards, concluding that robust quality management of AI-enabled tools is the starting point for maintaining trust and consistency in their use. The IAASB has also been building out guidance on “Automated Tools and Techniques” – a deliberately broad term covering AI, robotic process automation and other evolving technologies. In December 2025 the Board approved development of non-authoritative material on this topic, meaning more detailed guidance is on its way rather than already finalized.

Domestically, ICPAK maintains direct responsibility for quality assurance review in Kenya and supports members through mandatory training on audit quality assurance, quality management, and inspection readiness, alongside implementation tools such as audit software and illustrative financial statements. As AI tools proliferate, this quality-assurance apparatus will need to explicitly extend to reviewing how firms select, validate and rely on AI in engagements not just whether the final opinion was correctly formed.

A Regional, Not Just Kenyan, Concern!

While Kenya has the most visible activity the same dynamics apply across Uganda, Tanzania, Rwanda and Burundi. All EAC member states’ professional bodies are IFAC members that base their standards on the same International Standards on Auditing, meaning:

  • Any AI-related guidance the IAASB eventually issues will apply, in principle, across the whole region.
  • Cross-border audit networks operating in multiple East African markets will face pressure to apply consistent AI tools and controls across offices of very different sizes and levels of digital maturity.
  • Regional bodies have an opportunity to coordinate, through the Pan African Federation of Accountants, for instance: on shared, affordable AI-audit tooling and joint training, rather than each country building parallel, under-resourced solutions.

Recommendations

  1. For audit firms, especially SMPs: start with narrow, well-understood use cases (data extraction, reconciliation) rather than end-to-end AI decision-making; document clearly where AI output was used and how it was reviewed and invest in staff training on AI literacy alongside traditional technical training.
  2. For regulators and professional bodies: issue interim local guidance on AI use in audits while global standards catch up; extend quality assurance inspections to cover AI tool governance; and keep licensing and technology costs) low enough that small firms are not locked out.
  3. For educators: integrate AI literacy, including its limitations into accountancy curricula now, so that the next generation of auditors enters practice already able to evaluate, not just operate, these tools.
  4. For businesses and audit clients: improve the quality and digitization of underlying financial records, since AI-enabled audit and assurance can only be as reliable as the data it is given.

Conclusion

AI is not going to replace professional judgement in audit and assurance, but it is already changing what auditors spend their time on. How much of a population can be tested and how quickly assurance can be delivered. East Africa is an active participant in this shift, the region’s challenge is to capture the efficiency and quality gains that AI offers without deepening the divide between large, well-capitalized firms and the small practices that make up most of the profession. Getting the balance right will depend on deliberate, affordable and locally grounded choices by ICPAK, its regional counterparts, the firms and universities that train the next generation of auditors.

Credits to Robert Maithia | Business Dev. Officer | Zade Associates LLP

Ransomware and the SACCO: Closing the Gap Between Assumed and Verified Security

Ransomware and the SACCO: Closing the Gap Between Assumed and Verified Security

by Zade

Credits: Ernest Hawi | System Auditor | Zade Associates LLP

Ransomware is no longer a distant or theoretical risk for Sacco’s and mid-sized financial institutions. It is an active, well-organised criminal industry that increasingly targets exactly this segment: organisations that hold significant amounts of sensitive financial and personal data, but that typically run on lean IT teams, legacy core banking platforms, and IT budgets sized for keeping the lights on rather than for dedicated security functions.

Ransomware and extortion groups do not select victims based on size, prestige, or public profile. They select victims based on opportunity an exposed login, an unpatched system, a poorly segmented network, or a backup that turns out to be reachable by the very attacker it was meant to protect against. A SACCO holding members’ deposits, loan books, and identity documents represents exactly this kind of opportunity, and the consequences of a successful attack extend well beyond a technical outage: operational disruption, member panic, regulatory scrutiny, and reputational damage that can outlast the incident itself by years.

Ransomware groups do not select victims by size or prestige. They select victims by opportunity, and an under-resourced SACCO can present exactly that opportunity.

The Anatomy of a Ransomware Attack

Ransomware incidents follow a consistent structure. Understanding each stage matters because every stage represents a point where a specific control often inexpensive relative to the cost of an incident can stop the attack before it escalates. 

  1. Initial access 

The overwhelming majority of ransomware intrusions begin one of four ways: a phishing email carrying a malicious attachment or link; an exposed Remote Desktop Protocol (RDP) or VPN endpoint secured with a weak or reused password; exploitation of an unpatched internet-facing system such as a mail server, VPN appliance, or file transfer tool; or a compromised connection through a third-party vendor. Public-facing assets a member portal, an online loan-application form, an SMS or USSD gateway are disproportionately common entry points precisely because they are, by design, reachable from anywhere on the internet.

  1. Establishing a foothold 

Once inside, attackers typically deploy a lightweight tool that grants interactive, hands-on access to the compromised environment. At this point the incident stops being an automated malware infection and becomes a human-operated intrusion an actor actively exploring the network, often over a period of days or weeks before taking further action.

  1. Privilege escalation and credential harvesting

Attackers extract credentials from system memory, exploit misconfigured directory service permissions, and search scripts, configuration files, and browser storage for saved passwords. Each credential recovered extends their reach further into the environment, and an IT account that doubles as a domain administrator account hands an attacker a master key far earlier than it should.

  1. Lateral movement 

This is frequently the stage that determines whether an incident remains contained or becomes catastrophic. Flat networks where teller terminals, administrative workstations, and core banking servers all sit on the same network segment without meaningful separation allow an attacker who compromises one ordinary workstation to reach the most critical systems with little additional effort. The absence of network segmentation is one of the most common and most consequential findings in technical security reviews of financial institutions.

  1. Data exfiltration 

Before deploying encryption, modern ransomware operators typically copy sensitive data member KYC records, loan histories, identification documents to infrastructure they control. This is the mechanism behind “double extortion”: even an institution with fully functional backups can still be blackmailed with the threat of a public data leak, because the attacker’s leverage no longer depends on the encryption succeeding at all.

  1. Encryption 

Attackers typically disable security tooling and destroy accessible backups before deploying the encryption payload, and often time detonation for a weekend or public holiday when response capacity is thinnest. A backup reachable using the same administrative credentials as the production environment is not a meaningful control it is simply a second target sitting adjacent to the first.

  1. Extortion 

A ransom note follows, generally including a payment deadline, a cryptocurrency wallet address, and instructions for further contact. Some groups now bypass encryption entirely and proceed straight to data-leak extortion, since the threat of exposure alone is often enough to force a payment.

Why These Incidents Recur

A recurring pattern across ransomware incidents generally, not tied to any single case, is that organisations frequently resolve the immediate symptom of an attack restoring an affected system, paying to have data decrypted, rebuilding a compromised server without a corresponding investigation into how the attacker gained access in the first place, and without independent verification that the same path has actually been closed. The visible problem is fixed. The underlying condition that produced it remains in place, and eventually produces a repeat incident, sometimes against the same organisation.

A related observation is that reputational damage from a ransomware or extortion incident is frequently independent of whether sensitive data is ultimately confirmed to have been stolen. The threat itself the possibility of a public leak, communicated to a nervous membership base produces real reputational and operational consequences regardless of the technical outcome. Institutions should not treat “no data loss confirmed” as equivalent to “no real incident occurred.”

Why This Is Difficult to Catch From the Inside

The conditions that produce ransomware incidents an unpatched service, a flat network, an over-privileged account, a backup with an overlooked access path, an incident response plan that has never been rehearsed rarely look dangerous during normal operations. They look like ordinary configuration. This is precisely why they tend to persist undetected for long periods: the people who built and maintain a system are accustomed to its structure and are not well positioned to independently identify its weaknesses. A system audit exists to provide exactly this independent perspective, examining evidence rather than accepting assurances.

A properly scoped system audit asks specific, testable questions: What is actually reachable from the internet, verified through scanning rather than assumed from documentation? Can the core banking database be reached directly from an ordinary staff workstation, tested rather than presumed impossible? Has the most recent backup actually been restored end-to-end, with a documented result, rather than merely logged as a completed job? Has the incident response plan been rehearsed by the people who would execute it, or does it exist only as an unread document? Does the current list of administrative access holders match the list of people who genuinely require that access today?

“A system audit converts an untested assumption of security into either verified assurance or a specific, prioritised, and fixable list of gaps.”

A Practical Defense Program

Once gaps are identified, addressing them is a matter of implementing a set of well-established and proportionate controls.

  1. Identity and access management

Mandatory MFA on all remote access and privileged accounts; least-privilege access with administrative and daily-use accounts kept separate; no RDP or admin panels exposed directly to the internet; unique, rotated service account credentials.

  1. Network architecture

The core banking environment segmented onto its own zone with explicit, tested firewall rules, isolated from teller networks, administrative networks, and guest access; workstation-to-workstation communication restricted where feasible.

  1. Patch and vulnerability management

A current, reconciled inventory of internet-facing assets; time-bound patching SLAs, tightest for internet-facing systems; regular vulnerability scanning tracked to closure.

  1. Endpoint and email security

Behavioural EDR rather than legacy antivirus; application allow-listing on core banking servers; email filtering with attachment sandboxing and macros disabled by default.

  1. Backup and recovery

The 3-2-1-1 principle — three copies, two media types, one offsite, one immutable or fully offline; backups isolated from production domain credentials; full restoration tested on a regular schedule with documented results.

  1. Monitoring and detection

Centralised logging across domain controllers, core banking, VPNs, and firewalls; alerting on high-signal indicators such as disabled security tooling, mass file renaming, or unusual login times and locations.

  1. Governance and third parties

A ransomware-specific incident response plan naming ransom decision authority rehearsed at least annually; vendor contracts with enforceable security and audit clauses; cyber risk as a standing board agenda item.

Conclusion

Ransomware and extortion operations succeed not through sophistication but through opportunism, targeting whichever organisation presents the weakest set of basic controls at the time of the attack. The gap between what an institution believes about its own defences and what an independent, evidence-based review would actually find is common, persistent, and rarely visible from the inside and closing that gap is precisely the purpose of a system audit.

The relevant question for any SACCO or financial institution is straightforward: ”If an attacker gained a foothold on an ordinary staff device today, how far could they reach into the institution’s systems before being detected  and has that question actually been tested, with evidence, or only assumed?

Credits: Ernest Hawi | System Auditor | Zade Associates LLP