CAG’s AI Audit Reform: The Real Test Is Whether It Can Audit Policy, Not Just Transactions
CADS and other digital tools can transform public auditing, but their success will depend on time-bound implementation (Image CAG on X)
By P. SESH KUMAR
CADS and other digital tools can transform public auditing, but their success will depend on time-bound implementation, all-India performance audits and greater transparency.
New Delhi, October 8, 2026 — India’s audit architecture is entering a new phase with AI-enabled tools, but the real test will be whether technology strengthens accountability rather than simply increasing the volume of transactions examined. The CAG’s digital reform will matter only if it produces more all-India performance audits, examines policy design and ministerial decisions, and makes its own audit roadmap measurable and transparent.
On the public record, the Foundation level opened on 27 August and its first batch began on 7 September; a four-month programme means the first certificates issued to outside learners cannot arrive before January 2027. The Proficient and Expert tiers, where the sandbox auditing that gives the programme its teeth actually begins, carry no dates. The mandatory requirement is promised “in time”. The CAG-LLM was announced in September 2025, showcased in November, and in February 2026 field offices were still being asked to nominate teams to supply feedback; there is no published evaluation of its accuracy, coverage or error rates.
The case against deadlines deserves its hearing. Skills cannot be hurried; tools need iteration; hard targets invite box-ticking, and a department forced to certify a quota of officers by March may certify the wrong ones. All true– and none of it argues against publishing milestones, only against making them brittle. Peer institutions manage the balance. The Australian National Audit Office publishes a corporate plan each July setting out the measures by which it will be held to account, alongside an explicit target for the number of performance audits to be tabled in the year. A credible CADS roadmap would do no less: a date for opening the Proficient and Expert tiers, a date from which certification becomes a precondition for leading an IT or digital-systems audit, a target number of officers certified at each tier, and a published evaluation of the CAG-LLM before its outputs are allowed anywhere near a report. A reform without dates is an aspiration; with dates, it becomes something Parliament can evaluate.
The Real Test: Whose Policy Gets Audited?
Here we reach the question that matters most, and on which the launch is silent. The proof of AI-enabled audit will not be measured in certificates issued or models trained, but in the reports it produces– and specifically in whether those reports reach the decisions that shape national programmes. Will the new tools power all-India performance audits that examine the soundness of the assumptions behind a Union scheme and the nodal Ministry’s conduct in releasing funds and monitoring their use? Or will they be poured into scattered State-level examinations of inputs and outputs that never climb the stairs to Delhi?
The backdrop is not reassuring. The Hindu’s data team found that only 18 audit reports on the Union government were tabled in Parliament in calendar 2023, against an annual average of about 40 between 2014 and 2018 and a peak of 53 in 2015. An open letter from former civil servants put the 2015 and 2023 figures at 54 and 16–a difference of counting method, not of direction. An earlier RTI-based report had put the fall in reports relating to Union ministries at nearly three-quarters between 2015 and 2020; the CAG, for its part, rejected allegations that it had stopped field work and pointed to the reports approved and tabled in 2022-23. Whatever the precise count, the Union-level output has thinned.
Meanwhile the pattern of State-level slicing is visible in the department’s own published planning. The 2022-23 “Focus Areas for Audit” lists show the same centrally sponsored themes recurring State after State– pre- and post-matric scholarships with the National Social Assistance Programme, public health infrastructure and the management of health services, solid waste management, labour cess, PMAY–across Tamil Nadu, Telangana, West Bengal, Haryana and others. The public-health audit then surfaced as a series of separate State reports, Delhi’s placed in February 2025 and Jammu and Kashmir’s numbered Report No. 2 of 2025.
The steel-man for this approach is respectable. Health is a State subject; legislators in Chennai and Kolkata need findings about their own hospitals; State Public Accounts Committees can act only on State reports; and federal design means the implementing failure usually occurs where the money is spent. But the structural limitation is fatal to the larger purpose. For centrally sponsored schemes, the design, the unit costs, the release norms, the acceptance of utilisation certificates and the monitoring framework all live in the nodal Ministry. A State-by-State audit examines the implementing end. It can find that a State spent late or badly; it structurally cannot ask why the Ministry released the next tranche against unverified utilisation certificates, why the unit cost sat frozen for a decade, or whether the scheme’s founding assumption was ever tested. Thirty State reports do not add up to one national verdict. They add up to thirty footnotes the Ministry can disown.
The danger is that AI deepens rather than cures this tendency. The data-led audit cascaded to field offices targets works, establishment, social-sector schemes and receipts–the transaction layer. Beneficiary-fraud detection is real value, but it is also the politically safest kind of finding: it indicts the dead pensioner and the district clerk, never the Secretary. Point the new tools only downward and the result will be more findings and less accountability.
Yet the same technology removes the oldest alibi for fragmentation. The Union’s own PFMS carries release and expenditure data for every State; an AI-enabled central team can now assemble an all-India view of a scheme– release timing, unspent balances parked in single-nodal-agency accounts, outcome indicators set against the assumptions on which the Cabinet approved the scheme–without dispatching thirty field parties. The logistical argument for State-wise slicing evaporates. And the CAG has shown it can do the national thing when it chooses: the 2023 performance audits of Bharatmala Pariyojana Phase-I and of Ayushman Bharat-PMJAY were all-India reports that reached planning, approval and design questions, and the Bharatmala report went on to a Public Accounts Committee report. That officers associated with those audits were later reported to have been moved –a characterisation the CAG contested–shows only that the national audit carries a price the State-level audit never does.
There remains the mandate objection: SAIs may not question policy, which belongs to the legislature and the executive. Rightly understood, that is a boundary on questioning policy objectives, not on examining whether the evidence, cost estimates and assumptions on which a policy was approved were sound, or whether the Ministry’s monitoring could detect failure. The Bharatmala audit did precisely that when it tested the programme’s stated objective of improving India’s logistics performance and found the geo-mapping basis of its gap analysis unverifiable. Unless the CAG deliberately designs all-India performance audits with the nodal Ministry as principal auditee and with design-assumption questions written into the audit matrix, its new tools will default, by gravity, to the transaction layer.
Should the CAG Publish Its Audit Plan?
If the dividend is to be judged by reports, the public must know which reports are coming. The CAG already does part of this: its website hosts State-wise “Focus Areas for Audit”, a public-consultation page and the Strategic Plan of SAI India 2023-2030. So the question is not whether to disclose but how much. What is missing is a consolidated, Union-level programme naming the all-India performance audits planned for the year, the nodal Ministry in each case, the audit objectives, the data and AI methods to be used, and an expected tabling window–together with an annual account of what was planned against what was delivered. One cannot not verify whether the published focus-area lists have been refreshed beyond 2022-23, since the department’s website restricts automated access, and the point should be checked before it is pressed.
The case against publication is not frivolous. Independence includes the freedom to choose subjects without lobbying; advance notice may tip off an auditee to tidy its data; and the CAG has historically treated work-in-progress as covered by parliamentary privilege and fiduciary confidentiality, as its RTI reply on the Rafale audit illustrated. But each objection is answerable by design rather than by secrecy. The Australian National Audit Office publishes an annual audit work program each July after consulting Parliament’s Joint Committee of Public Accounts and Audit, lists around a hundred potential performance-audit topics, and expressly retains the discretion to audit beyond the list. In 2025-26 it listed about 80 potential topics against a target of 38 to 42 tabled performance audits, so roughly half of what it publishes actually proceeds–the list signals intent without binding the auditor. The UK National Audit Office publishes a schedule of value-for-money work in progress with expected publication dates. The Austrian Court of Audit invites citizens to propose topics, and about a quarter of its planned 2019 audits drew on those suggestions; Argentina’s AGN runs participatory planning meetings with civil society before drafting its annual plan. INTOSAI-P 20– which the CAG itself hosts on its website– asks SAIs to make public their mandate, responsibilities and strategy, and to report publicly on their results.
Publishing topics is not publishing findings; a list is not a leak. A confidential reserve for fraud-sensitive or security-sensitive audits can remain. For the AI agenda specifically, the argument is stronger still: if the department announces which audits will deploy which tools, the dividend becomes traceable, and the institution that asks every Ministry for outcome indicators will at last have published its own.
Measuring the Digital Audit Dividend
Since the proof of the pudding is in the reports, the CAG could commit to an annual “digital audit dividend” statement in its Annual Report. It would record the number of all-India performance audits of Union schemes tabled in the year with the nodal Ministry as principal auditee; the share of those reports carrying findings on scheme design, fund release and monitoring rather than implementation alone; the elapsed time from audit commencement to tabling, before and after the new tools; the findings attributable to analytics that sampling would have missed; the amounts recovered or savings accepted by Ministries; the take-up of those reports by the Public Accounts Committee; and CADS throughput, tier by tier. The department already publishes impact material–its compendium on the impact of audit on tax administration is one example –so this would extend an existing practice rather than invent a new one. What gets measured gets managed; what gets published gets defended.
CADS deserves credit. It is overdue, well designed, honest about the half-life of AI and cybersecurity skills, and anchored in a partner with genuine capability. The surrounding architecture– analytics centre, workflow platform, Connect portal, CAG-LLM–is the most coherent digital programme the department has assembled. But a certificate is an input, a model is an instrument, and neither is accountability. There are two futures on offer. In one, the CAG audits a hundred times more transactions and noticeably fewer decisions, and the tables in Parliament fill with ghost beneficiaries while scheme design goes unexamined. In the other, the new tools make an all-India audit of a Union scheme as cheap as a district audit once was, and the nodal Ministry finds the auditor waiting at its own door.
Which future India gets will be decided not in the classrooms of Chennai but in the annual audit plan in Delhi. That is why the plan should be published, the reform time-bound, and the dividend measured. The algorithm can find the ghost beneficiary. Only the auditor can name the Ministry that kept paying him.
CAG’s AI Audit Push: Can Technology Transform India’s Public Audit System?
(This is second of the two-part series. Views expressed in the article are author’s own.)
Follow The Raisina Hills on WhatsApp, Instagram, YouTube, Facebook, and LinkedIn