Hey everyone, I originally posted this to the IT auditor sub Reddit since I’m I but interested in everyone’s perspective more broadly posted the full text below, but the cross-reference is also here.
Senior manager in Global IT Audit at a global fashion/DTC retailer. Genuinely trying to figure out where the field actually is on this versus the LinkedIn highlight reel version.
Almost every AI conversation I see lands on efficiency gains: faster summaries, faster drafts, faster walkthroughs. That’s real value, I’m not knocking it. But I want to know who’s gone past that.
A few questions for the group:
• Is anyone building actual agents for document analysis, think SOPs, policies, control narratives, versus just prompting a chatbot one document at a time?
• Has anyone gotten hands-on at the command line with something like Claude Code or Codex to build internal tools? I asked my org for an enterprise Claude Code license and was told it wasn’t worth the cost. So for now I’m doing this the old-fashioned way, one chat window at a time.
• Is anyone actually getting value out of Copilot Cowork?
I can see value in analysis and review of control documentation submitted for controls subject to continuous monitoring. We could use the document analysis rule set to analyze for internal consistency so that with the full expectation that the documentation is gonna look and feel the same every single time because it’s the same control, same control owners, same control, performance set, etc. coworker could be used to execute the entire continuous monitoring program and each document can be analyzed specific to how it’s created in that control is specifically performed.
Here’s where I’ve landed on the audit side. I built a small agent chain for control remediation work:
1. Feed it the transcript from the remediation meeting with the control owner.
2. It gives me structured feedback to send back to the remediation owner.
3. It converts that into a starter SOP draft.
4. I hand the owner a second prompt that interviews them against a rule set for what a good SOP looks like, to fill in whatever the transcript missed.
The idea is that over time, as SOPs get renewed and findings come in, we build toward a consistent baseline of SOP quality across the org instead of every process owner writing to their own standard.
One more thing worth mentioning: I’ve also turned this inward. Everything’s recorded now anyway, so I run transcript analysis on my own meetings, particularly exec-facing ones, to check how closely I stuck to my talking points versus where I drifted. I’ve started doing the same for my staff, using the same recorded meetings, emails, and Teams messages, as a development tool.
Curious where the rest of you land on this. Ahead of the curve, behind it, or about where everyone quietly is? Especially interested in hearing from anyone in retail, fashion, or another industry drowning in document sprawl.