News & Blogs

Big Four Firms Under Scrutiny for AI 'Hallucinations' in Client Reports

Global · · airiskdesk.beehiiv.com

Major consulting firms, including KPMG, Deloitte, and EY, are facing intense scrutiny after multiple reports generated with AI assistance contained fabricated citations and inaccurate information. This pattern highlights critical governance failures in AI-assisted work, underscoring the urgent need for robust internal controls and verification processes for audit and assurance professionals. The incidents demonstrate that relying on AI without stringent human oversight poses significant reputational and professional risks, impacting client trust and regulatory compliance.


The Alarming Pattern of AI-Generated Fabrications

Over an eight-month period, several Big Four-tier firms—KPMG, Deloitte (twice), and EY—have been caught publishing client reports containing significant AI-generated fabrications. These incidents include fabricated citations, non-existent academic papers, and invented case studies, leading to report retractions, refunds, and formal investigations. For instance, KPMG's flagship report on agentic AI had 40 out of 45 citations fabricated or unverifiable, with named organizations disputing claims made about them. Similarly, Deloitte Australia refunded a portion of a government contract after its report cited a non-existent book and fabricated a court judgment quote, while Deloitte Canada faced a professional licensing inquiry for similar issues in a health workforce plan. EY Canada also withdrew a cybersecurity report after an AI detection firm found widespread fabrications and internal contradictions.

Governance Gaps and the Illusion of Controls

The recurring nature of these failures points to a systemic governance problem rather than isolated incidents. Despite all firms reportedly having written policies for human verification of AI-assisted work, the fabrications were consistently caught by external parties—researchers, named third parties, or AI detection firms—never by the firms' internal review processes. This suggests a critical disconnect between documented policies and their practical implementation. The firms' responses, often downplaying the errors as minor or asserting that the 'substance is unchanged,' further highlight a lack of accountability and a failure to address the root cause of these control deficiencies. This pattern reveals that a policy without a named owner and documented sign-off for each engagement is not an effective control.

Implications for Internal Audit and Assurance

These incidents have significant implications for internal audit and assurance professionals. The article emphasizes that AI 'hallucination' is a known technological characteristic, making the failures a governance and controls problem. Standards like ISO 42001:2023 and the Global Internal Audit Standards (GIAS), effective since January 2025, mandate documented evidence of effective operational controls for AI-assisted work. The fact that a professional regulator has initiated a licensing investigation into Deloitte underscores that these are not merely 'writing quality' issues but matters of professional conduct and accountability. Internal audit functions, under GIAS Standard 9.4, are now explicitly required to maintain visibility into AI-assisted work products, especially those that are external-facing. This necessitates a robust verification checklist:

  • Confirming external claims with named third parties.
  • Cross-checking internal figures against the organization's other published research.
  • Ensuring documented sign-off by a named individual for AI-assisted content.

Furthermore, organizations must have clear protocols for retraction and correction, internal audit visibility into AI-assisted external content, and a formal review process for repeat incidents. Relying on external detection tools post-publication is a reactive backstop, not a proactive governance strategy. The core takeaway for audit and assurance professionals is that robust, documented, and enforced verification steps are essential to mitigate the risks associated with AI-generated content and maintain professional integrity.


Read more
Comments

No comments yet. Be the first.


Sign in to join the discussion.

Sign in or Create account
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →