France Statutory Auditors Confidentiality and Use of Artificial Intelligence
H1 260910 France and the French Overseas Departments: Statutory Auditors, Confidentiality and the Use of Artificial Intelligence
Christophe Guyot-Sionnest, Chartered Accountant and Statutory Auditor since 1990
CEL +33667399676 BUR +33188245403 email contact@conseil-cac.com site web www.conseil-cac.com
France and the French Overseas Departments: Statutory Auditors, Confidentiality and the Use of Artificial Intelligence
Artificial intelligence is gradually transforming the working methods of statutory auditors. It can facilitate the analysis of accounting entries files, identify unusual transactions, compare several financial years, prepare audit questionnaires and summarise large volumes of documents. However, its use must remain compatible with professional secrecy, personal data protection requirements and the professional standards applicable to statutory audits.
These requirements apply throughout mainland France and in the French overseas departments: Guadeloupe, Martinique, French Guiana, Réunion and Mayotte.
The statutory auditor’s duty of professional secrecy
A statutory auditor has access to particularly sensitive information, including detailed accounting records, remuneration data, bank details, contracts, disputes, cash-flow forecasts, capital transactions and information relating to employees and customers.
Article L.821-35 of the French Commercial Code subjects statutory auditors, their staff and the experts they appoint to professional secrecy, subject to the exceptions provided for by law. This obligation does not disappear when an IT tool or an artificial intelligence system is used to process information.
Sending an accounting entries file, trial balance or audit working paper to an AI service technically and legally involves disclosing data to a service provider. Before doing so, the statutory auditor must therefore determine how the provider receives, processes, stores and potentially reuses the information.
Using a general-public AI service without prior assessment may expose the audit firm to several risks:
disclosure of information protected by professional secrecy;
uncontrolled storage of documents and conversations;
use of data to train or improve AI models;
access by unidentified subcontractors;
transfer of data outside the European Economic Area;
production of inaccurate or fabricated information;
loss of control over the audit trail.
Can artificial intelligence be used in an audit engagement?
The use of AI by statutory auditors is not prohibited in principle. It may be used as an assistance tool, provided that its use is controlled, documented and proportionate.
AI may notably help to:
check the structure and technical compliance of a French FEC accounting entries file;
identify duplicates, sequence gaps and unusual journal entries;
analyse suspense accounts, manual entries and closing transactions;
perform analytical reviews covering several financial years;
select transactions presenting particular risk factors;
summarise contracts, minutes and related-party agreements;
prepare questions for management or the entity’s accountant.
However, AI cannot replace the statutory auditor’s professional judgement or professional scepticism. It cannot independently determine whether sufficient appropriate audit evidence has been obtained, conclude that a material misstatement exists or decide which audit opinion should be issued.
The statutory auditor remains personally responsible for the procedures performed, the conclusions reached and the report issued.
Is pseudonymisation sufficient?
Pseudonymisation is a risk-reduction measure, but it must not be confused with anonymisation.
It may involve replacing the name of a company, employee or supplier with an identifier. If a correspondence table can be used to identify the relevant persons or entities, the information remains capable of re-identification. It may therefore remain subject to the GDPR and, more generally, to the statutory auditor’s duty of professional secrecy.
To be effective, pseudonymisation should cover all identifying information, including:
names and company names;
addresses, email addresses and telephone numbers;
company registration numbers, social security numbers and tax identifiers;
IBANs and other bank details;
accounting entry descriptions allowing indirect identification;
metadata embedded in files.
Excessive pseudonymisation may nevertheless reduce the relevance of certain audit procedures. In such circumstances, the safer solution is to use a professionally managed environment supported by contractual safeguards appropriate for confidential audit information.
Checks to perform before selecting an AI solution
The audit firm should obtain written, verifiable answers to the following questions:
Is the data used to train or improve the models?
How long is it retained?
In which countries is it hosted and processed?
Which subcontractors may access it?
Is a no-retention or “Zero Data Retention” option available?
Is data encrypted in transit and at rest?
Can the firm manage access rights and delete content?
Does the provider offer a GDPR-compliant data processing agreement?
Are security incidents subject to contractual notification requirements?
Can the firm obtain the logs required to document the processing performed?
A general marketing statement that data is “secure” or “confidential” is insufficient. The contract, terms of use, data processing agreement, retention policy and actual location of processing operations must be reviewed.
The French Data Protection Authority states that AI systems processing personal data must comply with the GDPR, particularly the principles of purpose limitation, data minimisation, security and accountability. The European Artificial Intelligence Act also establishes a risk-based framework and requires organisations to ensure an appropriate level of AI literacy among the people using these systems. Regulation (EU) 2024/1689 on artificial intelligence.
An internal procedure is essential
The audit firm should adopt an internal AI policy defining:
authorised and prohibited solutions;
categories of documents that may be processed;
applicable pseudonymisation rules;
authorised users;
mandatory human review procedures;
methods for retaining results;
the procedure to follow in the event of an incident.
Each material use of AI should be traceable in the audit file. The documentation should identify the objective pursued, data transmitted, tool used, checks performed and conclusions accepted or rejected by the statutory auditor.
AI as a means of improving audit quality
When properly governed, artificial intelligence can enable statutory auditors to devote more time to high-risk areas, discussions with management and the exercise of professional judgement.
Confidentiality does not necessarily require statutory auditors to avoid AI altogether. It requires them to select a secure architecture, minimise the data transmitted, obtain appropriate contractual safeguards and retain complete human oversight.
Looking for a statutory auditor experienced in digital audit techniques?
Are you looking for a statutory auditor in mainland France or the French overseas departments for a statutory audit, FEC analysis, the takeover of an existing audit appointment or a specific engagement?
Conseil et Audit assists companies, groups and non-profit organisations through an approach combining professional experience, data analysis and respect for confidentiality.
Request a confidential initial discussion or a personalised quotation at www.conseil-cac.com.
Frequently Asked Questions
Can a statutory auditor send an FEC accounting entries file to an AI system?
Yes, but only after assessing the solution’s confidentiality, security, retention arrangements and contractual terms. If the tool does not provide sufficient safeguards, the FEC should be properly pseudonymised or should not be transmitted.
Does a commitment not to train models on customer data guarantee confidentiality?
No. The statutory auditor must also examine data retention, technical logs, subcontractors, processing locations, internal access rights and deletion procedures.
Is the client’s authorisation required?
The client’s consent does not release the statutory auditor from their own professional obligations. Depending on the data, solution and intended purpose, providing information to the client or obtaining contractual authorisation may be appropriate. However, the client’s consent cannot make an inadequately secured system compliant.
Can AI draft a statutory auditor’s report?
AI may assist in preparing an initial draft, but the statutory auditor must verify every statement and remains solely responsible for the wording, audit opinion and signature of the report.
Do the same rules apply in the French overseas departments?
Yes. Professional secrecy, the French Commercial Code, the GDPR and the European Artificial Intelligence Act apply in the French overseas departments in the same way as in mainland France.
Article written or presented by Christophe Guyot-Sionnest
Registered Statutory Auditor – Services throughout mainland France and the French overseas departments
Statutory audit appointments and complex one-off engagements
Do you need a statutory auditor for a specific transaction?
Mobile: +33 6 67 39 96 76
Email: cgs.conseil@gmail.com
Request a quotation or ask us to call you back by using the blue buttons available on all our pages. All initial discussions are direct and confidential.
Christophe Guyot-Sionnest Mobile: +33 6 67 39 96 76 Office: +33 1 88 24 54 03 Email: cgs.conseil@gmail.com Website: www.conseil-cac.com
Below are links to the cornerstone pages presenting the one-off and recurring professional services we offer throughout mainland France and the French overseas departments: statutory audits, contributions in kind, company conversions and other specialist engagements.
Below is a useful link for mainland France and the French overseas departments: obtain your statutory audit quotation within 24 hours: https://www.conseil-cac.com/2605-france-et-dom-obtenez-votre-devis-commissaire-aux-comptes-audit-legal-cac-en-24h_ad44798.html
Below is a useful link to the index of the one-off and recurring statutory audit services we offer throughout mainland France and the French overseas departments: Index of our statutory audit and specialist services: https://www.conseil-cac.com/france-dom-christophe-guyot-sionnest-commissaire-aux-comptes-nos-services-index_ad44312.html
Below is a useful link to our cornerstone article, “2603 P1 – France and the French overseas departments: the role and responsibilities of statutory auditors and the obligations applicable to companies”: Statutory auditors in France: role, engagements and company obligations: https://www.conseil-cac.com/2603-p1-commissaire-aux-comptes-france-role-missions-obligations-des-entreprises_ad44174.html
Below is a useful link to “2603 P2 – France and the French overseas departments: the role of the contributions auditor and the procedure applicable to contributions in kind”: Contributions auditor: role and procedure for contributions in kind: https://www.conseil-cac.com/2603-p2-france-commissaire-aux-apports-role-et-procedure-pour-les-apports-en-nature_ad44180.html
Below is a useful link to the index of our contributions audit services in mainland France and the French overseas departments, covering contributions of vehicles, property, shares and other assets: Contributions auditor: index of services for contributions in kind: https://www.conseil-cac.com/commissaire-aux-apports-index-services-apports-en-nature-voiture-immeuble-titre---_ad44483.html
Below is a useful link to “2603 P3 – France and the French overseas departments: the conversion auditor’s role in securing a change of legal form”: Conversion auditor: securing a change in a company’s legal form: https://www.conseil-cac.com/f-2603-p3-commissaire-a-la-transformation-securiser-le-changement-de-forme-sociale_ad44183.html
Below is a useful link to “2603 P20 – France and the French overseas departments: bond issues and the prior verification performed by a statutory auditor”: Bond issues: prior verification by a statutory auditor: https://www.conseil-cac.com/2603-p20-france-emission-d---obligations-verification-prealable-par-1-commissaire_ad44243.html
Below is a useful link presenting the one-off and recurring statutory audit services we offer throughout mainland France and the French overseas departments: Christophe Guyot-Sionnest – Index of statutory audit and specialist services: https://www.conseil-cac.com/france-dom-christophe-guyot-sionnest-commissaire-aux-comptes-nos-services-index_ad44312.html
- septembre 2026
- Isère Meylan COMMISSAIRE AUX COMPTES COMMISSAIRE À LA TRANSFORMATION AUX APPORTS
- MAYOTTE COMMISSAIRE AUX COMPTES RESOLUTION NOMINATION CAC TITULAIRE, SUPPLEANT
- Fra & DOM COMMISSAIRE AUX COMPTES CONFIDENTIALITÉ ET INTELLIGENCE ARTIFICIELLE
- Certif situation comptable interim commissaire aux comptes rôle doc nécessaire
- PARIS 75020 CAC COMMISSAIRE A LA TRANSFORMATION EURL EN SASU Interprète Formation