Artificial intelligence (AI) is a supporting tool and does not replace professional responsibilities. Any product generated by AI is for reference purposes only. Therefore, auditors remain responsible for the accuracy and legal validity of the final product in accordance with the Law on State Audit and the State Audit Standards System.

Overview of the training class. Photo: N.LY
On the morning of September 15, the School of Audit Professional Training and Development organized a general introduction course on several popular AI tools for audit activities for nearly 40 participants who are auditors from units under the State Audit Office of Vietnam (SAV).
Using AI Within Permitted Scope and in Compliance with Regulations
The training program aims to equip officials and auditors with fundamental knowledge of AI and skills in utilizing generative AI tools for professional work. It also introduces principles for information security, protection of state secrets, and security of audit data throughout the entire process of AI application.
On this basis, participants gain a firm understanding of the concepts, capabilities, and limitations of generative AI systems; assess the suitability of different platforms for working conditions at the SAV; and master prompt engineering techniques for drafting, summarizing, and analytical tasks in audit activities.
Through the course, auditors can apply AI within permitted scope to various stages of the audit process, including audit preparation, audit implementation, preparation and issuance of audit reports, and monitoring the implementation of audit conclusions and recommendations.

Nguyen Ba Trung from the Department of Information Technology emphasizes that AI is a supporting tool and does not replace professional responsibilities. Photo: N.LY
In addition, auditors must strictly comply with regulations on the protection of state secrets, cybersecurity and information security, and personal data protection, while identifying and preventing risks associated with AI use. Accordingly, the use of AI at the SAV must be conducted within the framework of current laws and regulations, with a focus on the following:
Law on Protection of State Secrets and relevant guiding documents, as well as the list of state secrets in the field of State Audit: strictly prohibiting the provision or transfer of classified information to unauthorized organizations or individuals, including entering such information into external AI systems.
Laws and regulations on network information security and cybersecurity: requiring information systems to be protected according to their security levels and controlling data flows leaving the system.
Laws and regulations on personal data protection: personal data collected during audit activities, such as information on officials, taxpayers, and beneficiaries of state budget funds, may only be processed for the intended purposes. Transferring personal data to AI services whose servers are located overseas may potentially violate regulations on cross-border data transfers.
Law on State Audit and the State Audit Standards System: prescribing confidentiality obligations concerning information of audited entities and auditors’ professional responsibilities regarding audit evidence and audit conclusions.
Internal regulations and rules of the SAV on the management and use of information technology systems and audit files, as well as directives on AI application, updated in accordance with the agency’s applicable guidance at each point in time.
Compliance with the Principles
According to Nguyen Ba Trung from the Department of Information Technology, AI use must comply with mandatory principles: confidential and sensitive data must not be entered into public AI platforms. Audit files, data of audited entities, information classified as state secrets, and personal data must under no circumstances be entered into commercial AI services that have not been approved by the agency.
AI is a supporting tool and does not replace professional responsibilities. All products generated by AI, including draft documents, analytical results, code, and data queries, are for reference purposes only. Auditors and officials using AI bear full responsibility for the accuracy and legal validity of the final products in accordance with the Law on State Audit and the State Audit Standards System.

Participants attend the training class. Photo: N.LY
For SAV activities, generative AI is suitable for specific groups of tasks, including:
Language processing: drafting, editing, and standardizing administrative language; summarizing lengthy documents; and cross-checking and comparing content across different document versions.
Data-related technical support: generating and explaining SQL queries, Python code, and Excel formulas; debugging; and preparing documentation describing data processing procedures.
Information synthesis and structuring: developing outlines, tables, and checklists from unstructured documents.
Analytical support: suggesting approaches to data analysis, identifying anomalies in anonymized sample data, and explaining financial and budgetary indicators.
Learning and concept reference support: explaining standards, international auditing practices (ISSAIs), and emerging technology concepts.
The application of AI in audit activities must comply with the “10 DON’Ts - 5 MUSTs” rules.
10 DON’Ts
- DO NOT enter information classified as state secrets into any AI system that has not been specifically approved.
- DO NOT enter audit files, data of audited entities, or draft reports that have not yet been issued into public AI platforms.
- DO NOT enter personal data, such as names linked to identification numbers, accounts, income, health information, etc., into public AI platforms.
- DO NOT use personal or free AI accounts for official work.
- DO NOT enter passwords, connection strings, infrastructure diagrams, or internal server addresses into prompts.
- DO NOT incorporate AI-generated results directly into professional documents without verifying their sources, data, and legal grounds.
- DO NOT use AI to make audit conclusions or audit opinions, or determine violations in place of auditors’ professional judgment.
- DO NOT install AI applications or extensions from unknown sources on official devices; do not grant AI services that have not been approved access to official email accounts or organizational storage.
- DO NOT use AI to create falsified documents, signatures, seals, images, or voice content in any form or for any purpose.
- DO NOT conceal the use of AI when competent authorities require reporting on the process of creating a product.
5 MUSTs
- MUST anonymize and generalize data before interacting with AI, including Level 2 data.
- MUST independently verify all figures, legal citations, and calculation results provided by AI before using them.
- MUST use the correct platform and the account provided by the agency, and enable two-factor authentication.
- MUST immediately report to the unit’s information security focal point when detecting or suspecting data leakage through AI, including leakage caused by one’s own accidental actions, so that timely measures can be taken.
- MUST assume full personal responsibility for the final product in accordance with regulations on public service responsibilities and the professional ethics of State Auditors.
Auditors should note that AI may incorrectly cite the reference number, effective date, or provisions of legal normative documents. All legal citations must be cross-checked against the National Database on Legal Documents or the Official Gazette. AI must not be used to automatically provide audit opinions or assess and confirm the truthfulness of financial statements.
Data entered into AI services is transmitted to external servers beyond the agency’s control; therefore, the risk of data leakage is always present. In addition, AI-generated results may be biased or inappropriate to Vietnam’s administrative and legal context if prompts are not carefully designed.
During the training class, auditors discussed various topics, completed practical exercises on writing prompts, designed sequences of professional prompts, practiced extracting information fields, and checked accuracy rates.