ЕВОЛЮЦІЯ ВНУТРІШНЬОГО АУДИТУ ДЛЯ ПІДВИЩЕННЯ ЕФЕКТИВНОСТІ ДІЯЛЬНОСТІ ІТ-КОМПАНІЙ В УМОВАХ ЦИФРОВОЇ ТРАНСФОРМАЦІЇ

Main Article Content

Артем Басін
https://orcid.org/0009-0003-4579-3315
Олена Петрик
https://orcid.org/0000-0003-1881-9412
Ірина Матієнко-Зубенко
https://orcid.org/0000-0003-0266-1489
Наталія Кузик
https://orcid.org/0000-0001-5042-8759
Людмила Мельник
https://orcid.org/0000-0003-2498-5556

Анотація

Об’єктом дослідження є система внутрішнього аудиту ІТ-компаній в умовах цифрової трансформації та європейської інтеграції. Головною проблемою аудиту ІТ-компаній є критична неефективність традиційних і ретроспективних підходів у випадку швидких автоматизованих операцій, складних багатокомпонентних механізмів визнання доходів і хмарних ERP-систем.
Метою дослідження є узагальнення існуючих моделей зрілості та узгодження процесів внутрішнього аудиту з вимогами європейських нормативних актів, а саме: Директиви про корпоративну звітність щодо сталого розвитку (CSRD), Закону ЄС про штучний інтелект (EU AI Act) і МСФЗ 15. Також ураховане внутрішнє регулювання правового режиму «Дія Сіті» в Україні. З методологічного погляду в дослідженні застосовані історико-логічний, порівняльний і систематичний аналізи для оцінки існуючих парадигм і створення структурної аналітичної рамки.
Основними результатами дослідження є п’ятиступенева еволюційна модель зрілості внутрішнього аудиту, яка розвивається від реактивної базової парадигми до прогностичної парадигми з використанням штучного інтелекту. Моделювання етапів призвело до створення архітектури «Audit Layer» і «Compliance as Code». Вимоги фінансового контролю реалізовано у вигляді автоматизованих перевірок у конвеєрах DevOps і CI/CD відповідно до запропонованої архітектури. У результаті парадигма аудиту перейшла від виявлення помилок ex-post до прогнозування помилок ex-ante з автономним блокуванням некоректних фінансових операцій, зокрема неправильного розподілу ціни операції. Також для оцінки ефективності аудиту розроблено матрицю RACI та скориговану систему KPI.
Основні висновки показують, що поєднання алгоритмічного блокування та моніторингу поведінки з використанням штучного інтелекту (ШІ) усуває розрив між ІТ- та фінансовими підрозділами компанії. Це має важливе значення для масштабування діяльності ІТ-компаній на європейському цифровому ринку. Крім того, економічна доцільність переходу до просунутих аналітичних етапів доведена розрахунком рентабельності інвестицій (ROI) ≥ 1,5, що враховує фінансові ризики, пов’язані з недотриманням нормативних вимог.

Article Details

Посилання

Aguiar, J., Pereira, R., Vasconcelos, J. B., & Bianchi, I. (2018). An overlapless incident management maturity model for multi-framework assessment (ITIL, COBIT, CMMI-SVC). Interdisciplinary Journal of Information, Knowledge, and Management, 13, 137–163. https://doi.org/10.28945/4083 DOI: https://doi.org/10.28945/4083

Baharom, Z. (2025). Theoretical and practical insights into digital technologies in internal auditing: A bibliometric analysis of trends and future directions (1980–2024). Discover Data, 3, Article 41. https://doi.org/10.1007/s44248-025-00081-z DOI: https://doi.org/10.1007/s44248-025-00081-z

Chambers, R. (2025, December 9). Five barriers slowing AI adoption in internal audit. Audit Beacon. https://www.richardchambers.com/five-barriers-slowing-ai-adoption-in-internal-audit/

Chernetska, O. V., & Karnaukh, S. D. (2023). Oblikove zabezpechennia protsesu nadannia IT-posluh na pidpryiemstvi. Biznes Inform, 10, 259–264. https://doi.org/10.32983/2222-4459-2023-10-259-264 DOI: https://doi.org/10.32983/2222-4459-2023-10-259-264

Clearsulting. (2024). 5 levels of internal audit automation maturity. https://www.clearsulting.com/insights/blog/5-levels-internal-audit-maturity/

Damen, V., Wiersma, M., Aydin, G., & van Haasteren, R. (2025). Explainable AI for EU AI Act compliance audits. Maandblad voor Accountancy en Bedrijfseconomie, 99(4), 231–242. https://doi.org/10.5117/mab.99.150303 DOI: https://doi.org/10.5117/mab.99.150303

De Leeuw, R., & de Draaijer, A. (2025). Internal audit's strategic role in sustainability and ESG transformation. Maandblad voor Accountancy en Bedrijfseconomie, 99(4), 243–250. https://mab-online.nl/article/167721/ DOI: https://doi.org/10.5117/mab.99.167721

Deloitte. (2025). AI and tech investment ROI. Deloitte Insights. https://www.deloitte.com/us/en/insights/topics/digital-transformation/ai-tech-investment-roi.html

DOU.ua. (2025). Minus 20 tysiach fakhivtsiv v Ukraini: Yak povnomasshtabna viina vplynula na top-50 IT-kompanii. https://dou.ua/lenta/articles/top-50-three-years-of-war/

European Confederation of Institutes of Internal Auditing. (2024). Risk in focus 2025: Hot topics for internal auditors. https://www.eciia.eu/wp-content/uploads/2024/09/Risk-in-Focus-2025-FINAL.pdf

European Confederation of Institutes of Internal Auditing. (2025). The AI Act: Road to compliance. https://www.eciia.eu/wp-content/uploads/2025/01/The-AI-Act-Road-to-Compliance-Final.pdf

European Financial Reporting Advisory Group. (2024). Post-implementation review of IFRS 15 – Issues paper. EFRAG Financial Reporting Technical Expert Group and Consultative Forum of Standard Setters meeting. https://www.efrag.org/system/files/sites/webpublishing/Meeting%20Documents/2312131548185581/08-01%20PIR%20IFRS%2015%20-%20Issues%20paper%20-%20EFRAG%20FR%20TEG-CFSS%202024-03-13.pdf

Eulerich, M., Bamberg, A., Bonrath, A., Kordes, J., & Wagener, M. (2025). How Deutsche Telekom uses emerging technologies to enhance the internal control system. Journal of Emerging Technologies in Accounting, 22(2), 79–96. https://doi.org/10.2308/JETA-2023-054 DOI: https://doi.org/10.2308/JETA-2023-054

Eulerich, M., Fligge, B., López Kasper, V. I., & Wood, D. A. (2025). Patience is key: The time it takes to see benefits from continuous auditing. Accounting Horizons, 39(1), 69–86. https://doi.org/10.2308/HORIZONS-2023-060 DOI: https://doi.org/10.2308/HORIZONS-2023-060

Fırat, Z. (2025). Yapay zekânın muhasebe denetiminde kullanımı: Fırsatlar, zorluklar ve gelecek yönelimleri. Muhasebe Bilim Dünyası Dergisi, 27(2), 77–95. https://doi.org/10.31460/mbdd.1577715 DOI: https://doi.org/10.31460/mbdd.1577715

Hecimovic, A., & Canestrari-Soh, D. (2025). Strategies for internal auditors to expand their role in ESG assurance. The British Accounting Review. Advance online publication. https://doi.org/10.1016/j.bar.2025.101805 DOI: https://doi.org/10.1016/j.bar.2025.101805

IFRS Foundation. (2014). IFRS 15: Revenue from contracts with customers. https://www.ifrs.org/issued-standards/list-of-standards/ifrs-15-revenue-from-contracts-with-customers/

IFRS Foundation. (2024). Academic literature review: Post-implementation review of IFRS 15. https://www.ifrs.org/content/dam/ifrs/resources-for/academics/research-citations/pir-ifrs-15-literature-review-may-2024.pdf

Instytut vnutrishnikh audytoriv Ukrainy. (2024). Hlobalni standarty vnutrishnoho audytu. https://www.iia.org.ua

ISACA. (2011). COBIT mapping: Mapping of CMMI for development V1.2 with COBIT 4.1. https://www.isaca.org

Jupić, N., & Gadžo, A. (2025). Enhancing small and medium enterprise performance through artificial intelligence integration in accounting. In SMEPP 2025: Zbornik radova (pp. 33–46). Univerzitet u Novom Pazaru. https://www.econstor.eu/bitstream/10419/324135/1/CLANAK-SMEPP-ENG.pdf

Kononenko, L. V. (2024). Vykorystannia suchasnykh tsyfrovykh tekhnolohii v audyti: Problemy ta perspektyvy. Ekonomichnyi Prostir, 192, 109–112. https://economic-prostir.com.ua/wp-content/uploads/2024/09/192-109-112-kononenko.pdf DOI: https://doi.org/10.30838/EP.192.109-112

KPMG. (2025). The new Global Internal Audit Standards. https://kpmg.com/be/en/insights/risk/new-global-internal-audit-standards.html

KPMG International. (2024). Implementing IFRS 15: Revenue from contracts with customers. https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/ifrg/2024/isg-kpmg-comment-letter-pir-of-ifrs15-revenue-from-contracts-with-customers.pdf

Lviv IT Cluster. (2026). IT research Ukraine 2025. https://itcluster.lviv.ua

Ministerstvo finansiv Ukrainy. (1999). Natsionalne polozhennia (standart) bukhhalterskoho obliku 15 “Dokhid” (Nakaz No. 290 vid 29.11.1999). Zakonodavstvo Ukrainy. https://zakon.rada.gov.ua/laws/show/z0860-99#Text

Myerson, J. (2016). How CMMI models compare and map to the COBIT framework. TechTarget. https://www.techtarget.com/searchsecurity/tip/How-CMMI-models-compare-and-map-to-the-COBIT-framework

Napier, C. J., & Stadler, C. (2020). The real effects of a new accounting standard: The case of IFRS 15 revenue from contracts with customers. Accounting and Business Research, 50(5), 474–503. https://doi.org/10.1080/00014788.2020.1770933 DOI: https://doi.org/10.1080/00014788.2020.1770933

Opendatabot. (2026). Diia.City: Pidsumky 2025 roku. https://opendatabot.ua/analytics/diia-city-2025

Orbus Software. (2023). A look at the Innovation Value Institute. Orbus Software Blog. https://www.orbussoftware.com/resources/blog/post/a-look-at-the-innovation-value-institute

Ostapets, A., Parasii-Verhunenko, I., Bezverkhyi, K., Matiukha, M., & Yurchenko, O. (2026). The development of analysis methodology of financial risks of projects in IT sphere. Technology Audit and Production Reserves, 1(4(87)), 6–20. https://doi.org/10.15587/2706-5448.2026.352430 DOI: https://doi.org/10.15587/2706-5448.2026.352430

Papinko, A. I. (2024). Upravlinskyi oblik biznes-protsesiv v IT-kompaniiakh [Doctoral dissertation, Zakhidnoukrainskyi natsionalnyi universytet]. https://dspace.wunu.edu.ua/bitstream/316497/50101/1/Dis%20Papinko%20%D0%90.pdf

Protiviti & The Institute of Internal Auditors. (2023). 11th annual global technology audit risks survey. https://www.protiviti.com/sites/default/files/2023-10/11th-annual-global-technology-audit-risks-survey-iia-protiviti-2023.pdf

PwC. (2024). Implementing the IIA's Global Internal Audit Standards. https://www.pwc.com/gx/en/services/audit-assurance/internal-audit/new-global-internal-audit-standards.html

SafePaaS. (2025). Continuous monitoring in IT audit. https://www.safepaas.com/articles/continuous-monitoring-in-it-audit/

Shukurova, N. M., & Plevako, N. O. (2020). Suchasnyi stan ta tendentsii rozvytku ukrainskykh pidpryiemstv IT-haluzi v umovakh tsyfrovykh transformatsii. Ekonomika: Realii Chasu, 4, 71–77. https://doi.org/10.15276/ETR.04.2020.10

Szeberényi, A. (2026). From compliance to accountability in digital globalization: The ethical friction threshold model for artificial intelligence-enabled business leadership. Business Ethics and Leadership, 10(2), 228–243. https://doi.org/10.61093/bel.10(2).228-243.2026 DOI: https://doi.org/10.61093/bel.10(2).228-243.2026

The Institute of Internal Auditors. (2024). Global internal audit standards. https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/

Tsyfrova transformatsiia bukhhalterskoho obliku ta audytu v Ukraini. (2025). Visnyk Lvivskoho natsionalnoho universytetu pryrodokorystuvannia. Seriia: Ekonomika, 16(3–4), 45–54. https://visnyk.lnau.edu.ua/index.php/economics/article/view/435

Wassie, F. A., & Lakatos, L. P. (2024). Artificial intelligence and the future of the internal audit function. Humanities and Social Sciences Communications, 11(1), 1–13. https://doi.org/10.1057/s41599-024-02905-w DOI: https://doi.org/10.1057/s41599-024-02905-w

Zanócz, A. (2025). Non-financial reporting and assurance trends in selected Central European countries. Public Finance Quarterly, 71(3), 94–115. https://doi.org/10.35551/PFQ_2025_3_4 DOI: https://doi.org/10.35551/PFQ_2025_3_4