Financial Audit Agent
Workday-built AI agent that identifies and retrieves audit samples and supporting documents within the accounts payable, procure-to-pay workflow and compiles them into an audit request package.
Recorded characteristics
- Function
- Workday documents the Financial Audit Agent as providing accountants an automated way to respond to high volumes of auditor sample requests within the procure-to-pay lifecycle. It includes two documented skills: Audit Samples and Supporting Documents, and Generate Compilation Package. Documentation states it can retrieve relevant documents such as supplier invoices, purchase orders, receipts, invoice operational journal entries, supplier payment support, supplier contracts, supplier invoice adjustments and prepaid spend amortization schedules, and compile the sourced documents into an organized package for review and delivery. A documented worked example runs through the Create Audit Request task, agent-selected document types confirmed by the user, review of sourced documents, and download of a compiled PDF package that the user then sends to the auditor. Workday states that agent skills use tools, which for Workday-interacting agents are Workday APIs.
- Data access
- Workday documents access limited to financial data in the accounts payable, procure-to-pay workflow, including supplier invoices and related supporting documents, plus audit requests and audit request results. Documentation states the agent operates on behalf of the initiator, retrieves objects the initiator has access to, and has read-only access to the financial dataset. Workday also documents that all applicable supporting documents requested are retrieved without evaluation of the initiator security, while the initiator security applies when viewing those supporting documents from the audit request results. Agent users can view all audit requests submitted by all users, while displayed results depend on the user security access. Workday states the agent does not have access to Human Capital Management data.
- Actions
- Read only
- External actions
- Unknown
- Human confirmation
- Conditional
- Permission basis
- Mixed
- Administrative control
- Administration is documented through the Agent System of Record and the Agent Management Hub: the agent appears under Unregistered Workday Agents, is registered with a confirmation step, is configured from its agent profile with skills enabled and Available To security groups per skill (which establish the agent interaction policy), and is then activated. Administrators can deactivate and reactivate it at any time. Setup requires the Agent Compliance, Agent Management Hub, Manage: Agents, Reports: Agent Reporting and Setup: Agents domains in the Agent System of Record functional area, plus Reports: AI Agent Security in the System functional area. Workday documents the View Security for Agent Skill report for checking which security policies a tool requires, an All AI Agent Accounts report for Agent System User accounts, and recommends regularly examining the audit log for agent actions.
- Default state
- Disabled
- Availability
- Workday reported on 27 August 2026 that the Financial Audit Agent became generally available. Setup documentation requires the Universal Main Service Agreement (UMSA) for Workday-built agents in both non-production and production tenants; Main Service Agreement (MSA) customers must opt in to UMSA. Agent System of Record must be set up, and registering Workday-built agents in production requires opting in to UMSA and the Workday Flex Credits and Platform Entitlement Policy. Organizations can only register agents in the SKUs they have obtained. Users also need view and modify permissions on the Audit: Audit Requests domain in Common Financial Management and supplier invoice data permissions through at least one documented domain.
- Licensing
- Workday documentation references the subscription service agreement model (UMSA/MSA) and states that Workday Flex Credits are impacted by agent usage, directing customers to the Workday Flex Credits Community page. No pricing for this agent is established in the reviewed documentation.
- External model or provider
- Not publicly established for this capability. Workday describes its agents generally as using large language models, and names Google Gemini for a different agent (Deployment Agent), but the reviewed documentation does not identify a model or provider for the Financial Audit Agent.
- Limitations and uncertainty
- Documented scope is limited to the accounts payable, procure-to-pay workflow; no Human Capital Management data access. Compilation packages only include invoice attachments of types PDF, CSV, JPEG, PNG, TXT, XLS and XLSX. Prompting guidance recommends time periods of 12 months or less for faster responses. Supporting documents are retrieved without evaluating the initiator security, with security applied at viewing time. Runtime confirmation behaviour is documented for the compilation package flow (confirming document types, completing review, completing the request) but is not established for every skill or tool execution. Whether the agent can act outside Workday is not established. The model or provider is not established. Availability depends on subscription agreement, tenant and SKU prerequisites and administrator registration, configuration and activation.
Evidence
- Example: Create a Compilation Package Using Financial Audit Agent
Supports: Limitations · Function · Human confirmation · Actions · Primary source
Compilation packages only include invoice attachments of types PDF, CSV, JPEG, PNG, TXT, XLS and XLSX.
Worked example shows creating an audit request, agent-selected document types, review of sourced documents and download of a compiled PDF package sent to the external auditor.
The documented flow includes Confirm Types, Complete Review and Complete Request steps by the user before the package is finalised.
Package delivery to the auditor is performed by the user after downloading the package.
- Set Up Financial Audit Agent
Supports: Function · Permission basis · Admin controls · Default state · Availability · Licensing · Primary source
Setup documentation states the agent is set up so that it can identify and retrieve audit samples for audit requests.
Security groups in the Available To prompt establish the agent interaction policy; Workday evaluates both user access to the agent and user access to the APIs the agent executes as tools at runtime.
Registration, confirmation, configuration of skills and Available To groups, activation, deactivation and reactivation in the Agent Management Hub, plus the listed Agent System of Record and AI Agent Security security domains.
The agent must be registered, configured and activated before use, and can be deactivated at any time.
UMSA is required for Workday-built agents in non-production and production tenants; MSA organizations must opt in to UMSA; Agent System of Record must be set up.
Documentation points to the Workday Flex Credits Community page for how agent usage impacts Flex Credits.
- Concept: Financial Audit Agent
Supports: Function · Data access · Actions · Permission basis · Limitations · Primary source
Overview describes providing accountants an automated way to supply auditors with high volumes of audit sample requests in the procure-to-pay lifecycle, using the Audit Samples and Supporting Documents and Generate Compilation Package skills.
Documents retrievable include supplier invoices, purchase orders, receipts, invoice operational journal entries, supplier payment support, supplier contracts, supplier invoice adjustments and prepaid spend amortization schedules; agent users can view all audit requests, with displayed results determined by user security.
States the agent has read-only access to the financial dataset and operates on behalf of the initiator, retrieving objects the initiator has access to and compiling documents into a package.
Requires view and modify permissions on the Audit: Audit Requests domain and supplier invoice permissions through at least one listed domain; agent acts on behalf of the initiator, though supporting documents are retrieved without evaluating initiator security.
Limitations section states support only for accounts payable, procure-to-pay financial data and no access to Human Capital Management data.
- Reference: Financial Audit Agent Sample Prompts
Supports: Function · Limitations · Primary source
Sample prompts show natural-language retrieval requests for supporting documentation filtered by invoice, supplier, company, amount and period.
Guidance recommends specifying a time period of 12 months or less for faster responses.
- Workday-Built Agents
Supports: Function · General · External model · Primary source
Registry of Workday-built agents describes the Financial Audit agent as providing accountants an efficient, automated and accurate way to provide auditors with high volumes of audit sample requests within the procure-to-pay lifecycle.
Lists Financial Audit Agent separately from Adoption, BP Optimize, Decision Intelligence, Deployment, Payroll, Planning and Self-Service agents.
Names Google Gemini LLMs for the Deployment Agent only; no model or provider is stated for the Financial Audit Agent.
- About Workday Agents
Supports: General · Permission basis · Admin controls · Availability · Primary source
Defines Workday agents, skills, tools as Workday APIs, resources, and ambient versus delegate execution modes.
States agent interaction security permissions are separate from tool execution permissions, and that successful tool execution requires the user to be in a security group on both the agent skill and the API security policies.
Describes Agent System of Record and the Agent Management Hub define, register, configure, activate and deactivate phases, agent security domains, Agent System User accounts and audit log review.
Registering Workday-built agents in production requires opting in to UMSA and the Workday Flex Credits and Platform Entitlement Policy.
- Setup Considerations: Agent Security
Supports: Permission basis · Admin controls · Primary source
Describes delegate mode security based on the intersection of user permissions and allowed agent skills, ambient mode where the agent acts as itself, and the Agent Interaction Policy defining which user security groups can invoke a skill.
Describes the agent security framework governing agent identity, authentication and authorization, with auditable activity logs and least-privilege controls.
- Register and Configure Workday-Built Agents
Supports: Admin controls · Availability · Primary source
Describes registering, configuring, activating and deactivating Workday agents in the Agent Management Hub, enabling skills and populating Available To security groups.
States organizations can only register agents in the SKUs they have obtained and details UMSA and MSA requirements.
- Workday Announces Fiscal 2027 Second Quarter Financial Results
Supports: Availability · Primary source
Workday states that its Financial Audit Agent, designed to cut the time to build audit evidence packages, became generally available.