Scheduling converts an AI task into a recurring control execution
Workiva announced Agent Studio on September 15 and said organizations will be able to customize agents, enrich them with company knowledge, and schedule recurring automations. The same announcement names BEA surveys, US Census surveys, and Country-by-Country Reporting as examples of regulatory work moving into the platform. These are announced capabilities and directions, not evidence that a customer has reduced errors or that a control operated effectively.
The change still matters. A person running an assistant once can inspect the request, sources, and output in context. A scheduled agent may wake after a rule changed, an entity joined the group, a mapping was edited, a source extract arrived late, a credential expired, or a prior exception remained open. If the system simply repeats the last prompt, it can produce a polished report from the wrong population.
COSO's current GenAI internal-control roadmap calls out model drift, configuration changes, opaque reasoning, cyber exposure, and reporting integrity. PCAOB AS 2301 ties control reliance to design and operating effectiveness; AS 1215 emphasizes documentation that demonstrates procedures, evidence, and conclusions. These principles do not turn every management report into an audit workpaper. They make the operating point clear: repeatability means reproducing controlled inputs, logic, exceptions, review, and release - not reproducing text.
A September 21 r/InternalAudit discussion asked what teams accept as evidence of “human review” for AI-assisted decisions. That question is more important than the product label. A generic approval click proves that someone touched a workflow. It does not show what they checked, whether they had authority, which version they reviewed, what they re-performed, or how they resolved exceptions.