Auditors Get AI-Suggested Risks as Caseware Rolls Out Verity Agent

Caseware’s Verity agent drafts engagement-specific risks from financials and documents, at no extra cost to existing Verity licence holders.

Auditors Get AI-Suggested Risks as Caseware Rolls Out Verity Agent

Caseware launched its Verity-powered Risk Suggestion Agent worldwide on October 6, giving audit teams an AI-drafted starting point for risk assessment at no extra cost to existing Verity licence holders.

The company announced the release at its CwX London 2026 conference at County Hall. The agent proposes engagement-specific risks from current and prior-year financial information, existing risks, controls and selected documents.

For audit firms, the release puts AI audit risk assessment into the planning stage, where partners and managers spend hours building a risk register from scratch. The agent produces a first draft. Auditors still decide what goes into the file.

The feature is the third agent Caseware has taken beyond testing since it introduced Verity in May. It arrives weeks after MindBridge unveiled its own agentic risk assessment tool, and the two now compete for the same step of the engagement.

What the AI audit risk assessment agent does

The Risk Suggestion Agent works inside the engagement, from the Risks and controls tab, according to Caseware’s product page. Auditors can select up to five prior years of data, which lets the agent separate recurring risks from new ones.

Where a suggestion matches an existing risk, it adopts the firm’s standard wording. New risks are flagged as new. Board minutes are one example of the qualitative documents the agent can read alongside the numbers.

Each suggestion appears under pending suggestions. The page tells reviewers to accept, edit or reject each one before it is added to the engagement. Caseware said in its release that none can be incorporated without an explicit decision by the practitioner.

“The result is a meaningful reduction in the time and effort required to produce a strong first draft,” the company said in its October 6 media release. It added that the judgment “remains squarely with the auditor throughout.”

At CwX in May, a preview showed the agent working through a trial balance, board minutes and a prior-year file. It surfaced five risks for review, including a $118,000 gap between the trial balance and the net profit figure in the minutes, which it labelled a potential high-impact issue.

Caseware Verity and how it is built

Caseware describes Verity as an intelligence and orchestration layer inside its engagement platform rather than a standalone product. It combines large language models, workflow orchestration, engagement context, firm methodology and agents built for individual tasks.

The company announced Verity on May 20, 2026, in Toronto, and said it followed more than $100 million of AI investment over several years. Agents are grouped into four suites: Prepare, Plan, Evaluate and Report. The risk agent sits in the Plan suite.

Caseware has not named the underlying models, referring only to frontier intelligence. It said outputs are citation-backed, reviewable and traceable before they enter the engagement file.

On data, the company said the agent operates entirely within a firm’s own Caseware environment and that engagement data is never used to train AI models. Caseware’s May release described engagement-level data isolation, firm-configured permissions and support for SOC 2 Type II and ISO 27001.

The announcement does not say which Caseware products or regions the agent covers beyond the word worldwide. The product page does not list products, regional availability or retention terms. Firms should put those questions to their account manager before switching it on.

How the agent fits Caseware’s earlier AI releases

The agent was in alpha when Caseware launched Verity in May. Its general release five months later shows how fast the company is moving agents out of testing.

The first Verity agent in the workflow was the Disclosure Checklist Agent, which reviews financial statements and gives citation-backed suggestions. Caseware reported it saves 2.7 review hours per workflow on average.

The Document Intelligence Agent, which pulls information from source documents into workpapers, was in closed beta at the May launch. It overlaps with what document capture and data extraction tools do. Firms weighing the platform against specialist tools can use Accountio’s Caseware and DataSnipper comparison.

In September, at CwX Germany, Caseware added Verity for Excel, which brings engagement-aware AI into the workpapers auditors already use. In testing, the company reported savings of about nine hours per engagement and 75% per task. It also released an AI-first version of its Client Requests process.

Andrew Smith, Caseware’s chief product officer, said in May that AI “is going to create a real separation in terms of efficiency between firms that embrace it and those that don’t.”

What auditors say about AI risk assessment

Tricia Katebini, a partner at GRF CPAs & Advisors, said the agent gives her teams a strong starting point. “Risk assessment is one of the most important parts of an engagement, and it can also be incredibly time-consuming,” she said.

She said the time saved lets the firm spend more effort on testing, follow-up and deeper analysis of the risks it identifies. Her comment describes how her teams use the tool, but Caseware did not say how many firms run it on live engagements.

David Marquis, Caseware’s chief executive, said Verity “sits inside the workflow our customers already trust, saves reviewers real time, and leaves the final judgement exactly where it belongs, with the auditor.”

The release makes no claim about ISA 315 (Revised 2019) or PCAOB AS 2110, and neither does the product page. Both standards require the auditor to identify and assess the risks of material misstatement and to document that process.

That leaves a documentation question for firms. An accepted suggestion enters the file as the engagement team’s own assessment, so reviewers will need to record why they accepted, edited or rejected each one. Caseware has not published guidance on how the review should be evidenced. Firms should settle that in their quality management procedures before the first engagement, not after an inspection.

The competition in AI audit risk assessment

MindBridge announced Agentic Risk Assessment on September 22, 2026. It extends the company’s analytics earlier into the audit and describes an evidence-linked risk assessment aligned to a firm’s methodology. Les Rechan, MindBridge’s chief executive, said customers want AI that reduces complexity and keeps people in control of decisions they are accountable for.

MindBridge is built on full-population analysis of ledger data, which differs from Caseware’s approach of reading engagement context and documents. Buyers weighing the two can start with Accountio’s MindBridge profile, and the underlying concept is covered in its guide to audit risk assessment.

Thomson Reuters launched its Audit Intelligence suite in September 2024. It has marketed an Audit Intelligence Plan tool that combines full data populations with analytics to support planning and risk assessment, and CoCounsel Audit supports risk assessment work as well. I found no 2026 Thomson Reuters release matching a risk-drafting agent. I also found no comparable announcement from CCH Axcess.

Caseware’s advantage is distribution. The agent costs nothing extra for firms already on Verity, and it sits inside the file where the risk register lives.

The test is whether firms use it on live engagements and whether regulators and inspectors accept the documentation that goes with it. Caseware’s next customer event, and any inspection findings from the PCAOB or the UK Financial Reporting Council on AI-assisted planning, will show how far AI audit risk assessment has moved from pilot to practice.