Data Governance and Auditor Readiness for Generative AI-Based Audits: A Survey Study of Indonesian External Auditors with AI Literacy as a Mediator
Abstract
The integration of generative artificial intelligence into financial statement auditing COPYRIGHT promises enhanced efficiency and analytical depth. This study addresses this gap © 2026 Harahap and Fahmi. This is by investigating the relationship between data governance and auditor readiness an open-access article distributed for generative AI-based audits, with AI literacy as a mediating variable. Using a under the terms of the Creative quantitative survey design, data were collected from 248 external auditors across Commons Attribution License (CC public accounting firms in Indonesia, including Big Four affiliates, large national BY). The use, distribution or reproduction in other forums is firms, and small and medium practices. The research model, grounded in the permitted, provided the original Technology-Organization-Environment framework and knowledge-based theory, author(s) and the copyright was tested through Partial Least Squares Structural Equation Modeling. Data owner(s) are credited and that the governance exerted a significant positive effect on both auditor readiness (β = original publication in this journal is 0.47, p < 0.001) and AI literacy (β = 0.67, p < 0.001). AI literacy partially mediated cited, in accordance with accepted this relationship (indirect effect = 0.26, p < 0.001; VAF = 35.6%), indicating that academic practice. No use, distribution or reproduction is robust data governance enhances readiness both directly and indirectly by permitted which elevating auditors' AI comprehension. The model explained 61.7% of the variance does not comply with these in auditor readiness. Among data governance dimensions, data quality terms. demonstrated the highest relative importance, while data architecture showed lower contribution. These findings extend the TOE framework by specifying data governance maturity as a critical organizational context factor for generative AI adoption in auditing, and they provide practical guidance for audit firm leaders, regulators, and professional bodies in emerging economies. Key recommendations include institutionalizing data quality standards, establishing clear stewardship roles, and integrating AI literacy development with data governance training.
Keywords: data governance; auditor readiness; generative AI; AI literacy; audit technology; Indonesian audit profession.
Introduction
The audit profession is undergoing a paradigmatic transformation driven by the proliferation of artificial intelligence technologies. While traditional computer-assisted audit tools have long supported analytical procedures, the emergence of generative AI— capable of creating draft audit reports, synthesizing vast unstructured datasets, and suggesting audit opinions based on pattern recognition—introduces new opportunities and complexities (Okogun et al., 2026). Generative AI models, including large language models and generative adversarial networks, can process and produce human-like text, simulate scenarios, and generate sophisticated analytical outputs. In financial statement audits, these capabilities may enhance anomaly detection, automate documentation, and reduce manual sampling work, potentially increasing audit efficiency and quality (Abduh et al., 2026). However, such systems also introduce significant risks, including output hallucination, limited explainability, data privacy concerns, and challenges to audit evidence reliability. These risks make data governance—the management of data availability, usability, integrity, and security—central to distinct organizational context factor for generative AI adoption effective AI adoption (Gomaa, 2026). in auditing, extending the TOE framework; (2) empirically The rapid digital transformation in Indonesia's financial testing AI literacy as a knowledge-based mediator between sector, accompanied by regulatory encouragement for governance and readiness; (3) distinguishing generative AI technology adoption, has pushed audit firms to explore AI- from general audit technology; and (4) providing evidence from based tools. The Financial Services Authority (OJK) has issued an emerging economy with heterogeneous firm-level digital the Indonesian Digital Finance Transformation Roadmap capabilities. 2024-2028, which emphasizes digital infrastructure In emerging economies like Indonesia, where data development and data management standards across infrastructure and digital maturity vary significantly across financial services (Madhavan, 2024). Similarly, the Institute firms, investigating the data governance-readiness nexus of Indonesia Chartered Accountants (IAI) has incorporated becomes particularly pertinent. Auditors in Big Four firms may technology competencies into its professional development have access to global data standards, while those in small and framework through IAI Regulation No. 1/2023 on Continuing medium practices (SMPs) face limited resources and Professional Education (Thota, 2025). Despite these fragmented data environments. With over 1,200 public developments, a critical gap remains between the availability accounting firms registered under the Ministry of Finance of AI technology and the readiness of auditors to deploy it (Minister of Finance Regulation No. 127/PMK.01/2023 effectively and ethically (Yulfani et al., 2025). Auditor concerning Public Accountant Licensing, citing 1,246 active readiness is a multidimensional construct encompassing firms as of December 2023) and IAI, the audit market ranges technological competence, ethical awareness, adaptive from large international affiliates to local SMPs. This mindset, and procedural familiarity with AI driven workflows. heterogeneity calls for an empirical examination of how data When governance structures fail to support data quality and governance dimensions influence auditor readiness in the security, auditors' confidence and readiness may be specific context of generative AI-based audits. undermined, inhibiting AI adoption (Rawat, 2026). The current study addresses these gaps by proposing and Prior literature on AI in auditing has primarily focused on testing a conceptual model that links data governance, AI the technical capabilities of AI, adoption intention using literacy, and auditor readiness. AI literacy, defined as an Technology Acceptance Model (TAM) or Unified Theory of individual’s ability to understand, use, and critically evaluate AI Acceptance and Use of Technology (UTAUT) frameworks, and applications (Fitriani et al., 2026), is positioned as a mediator. the implications for audit quality (Vu Thi Mai, 2026). However, The rationale is that robust data governance can enhance these studies largely treat AI as a monolithic tool and do not auditors’ exposure to well-structured data, facilitating learning distinguish generative AI from narrower analytical AI. and competence building, which in turn improves their Furthermore, they often neglect the foundational role of readiness to trust and effectively use generative AI tools organizational data governance as a prerequisite for (Petchprayoon et al., 2026). Without data governance, even a readiness. Studies that do address data governance in high level of AI literacy may be ineffective because the auditing tend to examine data analytics adoption without underlying data would be unreliable. Conversely, high data delving into the unique demands of generative AI, such as the governance alone cannot guarantee readiness if auditors lack need for extensive, high-quality training data, model the necessary skills and mindset. Therefore, a mediated explainability concerns, and real-time data pipelines (Cicin & pathway is hypothesized (Tikhonova & Sabirova, 2025). Çetin Gürkan, 2026). In emerging economies like Indonesia, The Technology-Organization-Environment (TOE) framework where data infrastructure and digital maturity vary provides a theoretical lens: data governance represents an significantly across firms, investigating the data governance– organizational context factor, AI literacy captures the human readiness nexus becomes even more pertinent. Auditors in capability dimension bridging organization and technology, and Big Four firms may have access to global data standards, auditor readiness reflects the technology adoption outcome while those in small and medium practices (SMPs) face (Gupta et al., 2026). In addition, the knowledge-based view of limited resources and fragmented data environments. This the firm posits that knowledge resources (here, AI literacy) are heterogeneity calls for an empirical examination of how data critical for leveraging technological assets. Combining these governance dimensions influence auditor readiness in the perspectives, the study formulates four hypotheses. A survey of specific context of generative AI- based audits (Mohammad & 248 Indonesian external auditors was conducted, and data Mohammed, 2026). were analyzed using PLS-SEM (Mpanza, 2025). By quantifying The research gap can be systematically articulated as the relationships, the research aims to answer the following follows. First, TAM and UTAUT studies in audit technology questions: (1) to what extent does data governance influence adoption have primarily examined individual-level perceptions auditor readiness for generative AI-based audits? (2) Does AI of usefulness and ease of use, but have not sufficiently literacy mediate the relationship between data governance and explored organizational-level data infrastructure factors that auditor readiness? (3) Which dimensions of data governance enable or constrain AI effectiveness (Mohammad & are most impactful in fostering readiness? (Carandang et al., Mohammed, 2026; Vu Thi Mai, 2026). Second, TOE-based 2026). studies have examined organizational readiness broadly, but The Indonesian setting offers a compelling context. With have not specified data governance maturity as a distinct over 1,200 public accounting firms registered under the organizational context variable for generative AI adoption in Ministry of Finance and IAI, the audit market ranges from large auditing (Gupta et al., 2026; Mpanza, 2025). Third, prior international affiliates to local SMPs. OJK’s roadmap for digital research has not investigated AI literacy as a mechanism finance and Bank Indonesia’s push for open banking have through which governance practices translate into readiness, accelerated data digitization, making generative AI an despite theoretical arguments from knowledge-based theory increasingly feasible tool. Nevertheless, high-profile data that knowledge resources mediate the relationship between breaches and concerns over data sovereignty underscore the organizational infrastructure and individual capability fragility of data governance. Auditor readiness thus becomes a (Tikhonova & Sabirova, 2025). Fourth, most studies have strategic priority. The findings of this study are expected to been conducted in developed economy contexts, limiting provide theoretical contributions by extending TOE and applicability to emerging economies like Indonesia where knowledge-based frameworks into the generative AI auditing data infrastructure and digital maturity vary significantly domain, as well as practical guidance for audit firm leaders, across firms (Thota, 2025) . This study contributes to the policymakers, and educators designing upskilling programs literature by: (1) positioning data governance maturity as a and governance protocols (Paisey & Paisey, 2006) The remainder of the article is organized as follows. interacting with AI tools, and awareness of AI limitations and Section 2 reviews the literature on generative AI in auditing, ethical implications. AI literacy is not merely technical data governance, auditor readiness, and AI literacy, leading to knowledge but includes professional judgment about when and hypothesis development. Section 3 describes the research how to rely on AI-generated evidence. method, including sample, measurement, and analytical Data governance enhances AI literacy through several approach. Section 4 presents the results, complete with pathways. Access to well-structured, annotated datasets tables and a structural model figure. Section 5 discusses the provides experiential learning opportunities for auditors to findings in light of theory and practice. Section 6 concludes observe how data preprocessing affects AI outputs, understand with implications, limitations, and future research directions. data biases, and develop critical evaluation skills Generative AI refers to artificial intelligence systems (Petchprayoon et al., 2026). Cross-functional collaboration in capable of generating novel content—including text, images, data governance (involving IT, data specialists, and auditors) and data patterns—based on training data. In auditing, naturally exposes auditors to AI vocabulary and concepts. generative AI applications include automated drafting of audit Furthermore, governance frameworks that document data reports, synthesis of unstructured financial and non-financial provenance and transformations help auditors understand the data, anomaly detection through pattern recognition, and data pipelines underlying AI systems, building mental models simulation of alternative accounting scenarios (Okogun et al., that enhance literacy (Joshi et al., 2026). Therefore: 2026). These capabilities promise increased efficiency and H2: Data governance has a positive effect on AI literacy. depth of analysis, yet they also introduce risks such as output AI literacy, in turn, equips auditors with the skills and hallucination, reduced transparency of decision-making, and mindset necessary for readiness. Auditors with higher AI potential for bias amplification. The quality and reliability of literacy are better positioned to maintain professional generative AI outputs depend fundamentally on the quality skepticism, as they understand that generative AI may and governance of input data, making data governance a "hallucinate" and thus do not blindly accept outputs (Khanal, prerequisite rather than an adjunct to AI adoption (Madhavan, 2025). They feel more competent in interacting with AI systems, 2024). customizing prompts, and interpreting results within the audit Auditor readiness for generative AI is defined as the extent context. Literacy enhances not only confidence but also to which auditors possess the technological competence, practical capability, as auditors who understand AI principles ethical awareness, adaptive mindset, and procedural can better assess when AI outputs are reliable and when familiarity necessary to effectively and responsibly employ human judgment should override algorithmic suggestions generative AI tools in financial statement audits (Yulfani et al., (Lindkvist et al., 2026). Thus: 2025). Readiness extends beyond basic technology H3: AI literacy has a positive effect on auditor readiness for acceptance to include professional skepticism in evaluating generative AI-based audits. AI-generated outputs, understanding of AI limitations, and Combining H2 and H3, AI literacy is expected to mediate the ability to integrate AI-driven insights with traditional audit relationship between data governance and auditor readiness. evidence. Previous studies have examined readiness through Data governance creates a supportive data environment and technology acceptance models, but have not adequately learning ecosystem that enhances AI literacy, and this addressed the role of organizational data infrastructure in enhanced literacy then translates into readiness. The enabling readiness (Almashekhi et al., 2026; Carandang et mediation is partial because data governance also exerts direct al., 2026). effects on readiness through infrastructure and confidence-Data governance encompasses the overall management building mechanisms. Therefore: of data availability, usability, integrity, and security, including H4: AI literacy mediates the relationship between data policies, procedures, and standards (Madhavan, 2024). In the governance and auditor readiness. audit environment, data governance ensures that financial and non-financial data fed into AI models are accurate, Methods complete, and appropriately authorized. Key dimensions include data quality (accuracy, completeness, timeliness, consistency), data security and privacy (protection against
Research Design and Sampling
unauthorized access and breaches), data architecture and A quantitative, cross-sectional survey design was employed integration (structure, interoperability, and accessibility), and to test the hypotheses. The target population comprised data stewardship (accountability, lineage, and lifecycle external auditors working in public accounting firms registered management) (Pal & Islam, 2025). with the Indonesian Institute of Chartered Accountants and the Data governance affects auditor readiness through Ministry of Finance. A stratified purposive sampling technique multiple mechanisms. First, high-quality, well-documented was applied, dividing the population into strata based on firm data reduces uncertainty and increases auditors' confidence size: Big Four affiliates, large national firms, and small and in AI-generated outputs, enabling them to focus on higher- medium practices. This stratification was intended to ensure level analysis rather than data validation (Kim & Park, 2025). representation across different levels of organizational Second, clear data lineage and stewardship facilitate resources and data governance maturity. traceability and accountability, essential for audit evidence All constructs were measured using multi-item scales and professional liability. Third, data security protocols build adapted from previously validated instruments and refined trust in the AI environment, reducing resistance to adoption. through a pilot test with 35 auditors.
Data Governance
was Fourth, governance structures expose auditors to organized, conceptualized as a formative higher-order construct annotated datasets, which serve as learning resources that consisting of four dimensions: Data Quality, Data Security and enhance their understanding of AI systems and data Privacy, Data Architecture and Integration, and Data preprocessing. Thus: Stewardship, with each lower-order construct measured H1: Data governance has a positive direct effect on auditor reflectively by three indicators.
AI Literacy
and Auditor readiness for generative AI-based audits. Readiness were modeled as reflective constructs, and all AI literacy is defined as an individual's ability to questionnaire items used a five-point Likert scale ranging from understand, use, and critically evaluate AI applications strongly disagree to strongly agree. (Fitriani et al., 2026; Tikhonova & Sabirova, 2025). In the audit context, AI literacy encompasses understanding of basic
Hierarchical Component Model Specification
AI principles, ability to evaluate AI outputs, competence in
Data Governance
was specified as a formative higher-order construct comprising four reflective lower-order constructs: describing the study purpose, voluntary nature of participation, Data Quality, Data Security and Privacy, Data Architecture and expected completion time, confidentiality protections, eligibility Integration, and Data Stewardship. The formative requirements, and the right to discontinue without penalty. specification was retained because the four dimensions Consent was documented electronically: respondents had to represent conceptually distinct facets that jointly form the select an “I agree to participate” option before the survey broader domain of data governance rather than questions became accessible. No names, email addresses, interchangeable manifestations of a single latent trait. employee numbers, IP addresses, or other directly identifying The higher-order construct was estimated in SmartPLS 4 information were collected. using the embedded two-stage approach. In Stage 1, the four lower-order constructs were estimated using their respective
Common Method Bias Procedures
reflective indicators. In Stage 2, the latent variable scores of Procedural remedies to reduce common method bias these lower-order constructs were used as formative included: (1) ensuring respondent anonymity and indicators of the higher-order
Data Governance
construct. confidentiality to reduce social desirability bias; (2) using Accordingly, the term repeated-indicator approach should not different scale anchors and reverse-coded items to reduce be used elsewhere in the manuscript to describe the final acquiescence; (3) separating independent and dependent estimation procedure, because the Method section currently variables in the questionnaire layout; (4) including an attention-mixes repeated-indicator terminology with a two-stage check item. Statistical assessments of common method bias estimation description. included: (1) Harman's single-factor test, which showed that a The assessment of the higher-order formative construct single factor accounted for 28.7% of total variance, below the focused on collinearity among the lower-order dimensions 50% threshold; (2) full collinearity assessment with all VIF and on the significance and relevance of the outer weights. values below 3.3 (VIF range: 1.47 to 2.86), indicating no Because
Data Governance
is formative at the higher-order substantial common method bias based on Kock's (2015) level, internal consistency reliability, AVE, and HTMT were not criterion. used as validity criteria for the higher-order construct. HTMT remained relevant only for the reflective constructs and, Result and Discussion where applicable, the reflective lower-order constructs.
Control Variable Specification
Respondent Profile
Firm size should be treated as a nominal categorical Table 1 presents the demographic profile of the 248 control variable rather than as an ordinal numerical score. The respondents. Males constituted 57.3%, females 42.7%, current manuscript classifies firm size into Big Four affiliates, reflecting the gender distribution in Indonesian public large national firms, and SMPs, but the Results table indicates accounting. The largest age group was 26-35 years (45.2%), coding as 1, 2, and 3, which imposes an equal-distance followed by 36-45 (30.6%). Experience varied: 34.7% had 2-5 assumption that is not justified for these categories. years, 39.1% had 6-10 years, and 26.2% had over 10 years. For re-estimation, Big Four affiliates should be used as the Regarding firm size, 28.6% were from Big Four, 33.5% from reference category and two dummy variables should be large national firms, and 37.9% from SMPs. created: Large National Firm and SMP. The statistical Educationally, 82.7% held a bachelor’s degree, 17.3% a conclusion regarding firm size should then be based on the master’s or professional degree. Notably, 48.4% had received coefficients of these two dummy variables, or alternatively on some formal AI-related training, indicating growing awareness an appropriate multigroup analysis if the authors wish to but still less than half. compare structural relationships across firm categories.
Descriptive Statistics and Measurement Model Assessment
Analytical Technique
The descriptive statistics indicate that the mean scores for Partial Least Squares Structural Equation Modeling was the four data governance dimensions ranged from 3.42 for used because the model includes a formative higher-order Data Architecture to 3.78 for Data Security, while
AI Literacy
construct and examines both direct and indirect relationships and
Auditor Readiness
had mean scores of 3.61 and 3.55, among latent variables. The measurement model assessment respectively (Table 2). These values suggest moderate levels distinguished between formative and reflective specifications. across the focal constructs. For the higher-order formative
Data Governance
construct, For the higher-order formative
Data Governance
construct, evaluation focused on collinearity and the significance and the manuscript reports that all VIF values were below 3.0, relevance of outer weights. For reflective constructs, internal indicating no serious collinearity problem among the four lower-consistency reliability, convergent validity, and discriminant order dimensions. The outer weights were also reported as validity were assessed using Cronbach’s alpha, rho_A, significant, with Data Quality contributing the largest weight at composite reliability, AVE, and HTMT where appropriate. 0.38, followed by Data Security and Privacy at 0.29, Data The structural model was evaluated using bootstrapping Stewardship at 0.25, and Data Architecture and Integration at with 5,000 subsamples to obtain path coefficients, t-values, 0.18. These results are appropriate as evidence for the p-values, and confidence intervals. Mediation was assessed formative higher-order construct and should remain central in using the indirect effect and variance accounted for. However, the revised Results section. because the Results section does not clearly report a By contrast, HTMT values involving
Data Governance
separate empirical assessment of nomological validity, the should not be interpreted as evidence of validity, because claim in the Method that nomological validity was assessed HTMT is intended for reflective constructs rather than formative should either be supported by explicit empirical evidence or higher-order constructs. The manuscript may retain the HTMT removed for consistency coefficient between
AI Literacy
and
Auditor Readiness
, reported as 0.78 and below the 0.85 threshold, as evidence of
Data Collection and Ethics
discriminant validity between those reflective constructs. The questionnaire was administered online through a However, HTMT coefficients reported between Data secure survey platform and distributed through IAI regional Governance and the reflective constructs should be removed chapters’ mailing lists and professional networks from from the validity argumentThe descriptive statistic sindicate November 2025 to January 2026. Before accessing the that the mean scores for the four data governance dimensions questionnaire, each respondent viewed an information sheet ranged from 3.42 for Data Architecture to 3.78 Table 1. Demographic Profiles constructs. However, HTMT coefficients reported between Data Governance and the reflective constructs should be removed Characteristic Category Frequency Percentage from the validity argument. Gender Male 142 57.3% Formative Measurement:
Data Governance
. Collinearity Female 106 42.7% diagnostics showed all VIF values below 3.0 (Table 3), Age Group < 26 35 14.1% indicating no multicollinearity issues. The outer weights of the years four dimensions were significant (p < 0.01), with Data Quality 26–35 (weight = 0.38), Data Security (0.29), Data Architecture (0.18), 112 45.2% years and Data Stewardship (0.25) contributing significantly to the 36–45 formative construct. Bootstrap confidence intervals confirmed 76 30.6% years their relevance. > 45 The formative construct was regressed on a global 25 10.1% years reflective measure of data governance (three items adapted 2–5 from Weber et al., 2009: "Overall, my firm has effective data 86 34.7% years governance practices," "Data governance is taken seriously in Audit 6–10 my firm," and "Our firm's data governance supports our audit 97 39.1% Experience years objectives"). The correlation between the formative construct > 10 and the global reflective measure was 0.72 (p < 0.001), 65 26.2% years exceeding the recommended threshold of 0.70, thereby Big Four establishing convergent validity. 71 28.6% affiliate Large
Nomological Validity Assessment
national 83 33.5% Nomological validity was assessed by examining whether (top 10)
Data Governance
related to theoretically expected constructs Firm Size Small in the nomological network. Specifically, we tested whether and
Data Governance
was positively associated with perceived data Medium 94 37.9% quality (a theoretically related construct) and negatively Practices associated with data-related audit difficulties. Results (SMPs) confirmed that
Data Governance
correlated positively with Bachelor’ perceived data quality (r = 0.68, p < 0.001) and negatively with s degree 205 82.7% data-related difficulties (r = -0.41, p < 0.001), supporting (S1) nomological validity. Internal consistency reliability and convergent validity for Master’s/ Education the reflective constructs (AI-Literacy and
Auditor Readiness
) Professio were assessed using Cronbach's Alpha, Composite Reliability, nal 43 17.3% and AVE. Both constructs exceeded the recommended (S2/Prof. thresholds (Table 4). Discriminant validity, assessed using ) HTMT, showed a ratio of 0.78 between AI-Literacy and Auditor AI Training Yes 120 48.4% Readiness, below the 0.85 threshold, confirming discriminant Received validity (Table 5) No 128 51.6% Note: The firm size categories presented in this table serve
Structural Model and Hypothesis Testing
purely descriptive purposes to illustrate the sample The structural model results indicate that
Data Governance
composition. For the structural equation modeling (PLS-SEM) had a positive and significant direct effect on Auditor analysis, these three categorical groups were converted into Readiness, with a reported coefficient of 0.47. Data dummy variables, with the Big Four affiliates designated as Governance also had a significant positive effect on
AI Literacy
, the reference category. This approach ensures that the with a coefficient of 0.67, while
AI Literacy
significantly categorical nature of firm size is properly accounted for predicted
Auditor Readiness
with a coefficient of 0.39. The without imposing an arbitrary equal-interval scale (i.e., 1, 2, 3) indirect effect of
Data Governance
on
Auditor Readiness
on the non-numeric ordinal groups. through
AI Literacy
was reported as 0.26, supporting partial mediation with a VAF of 35.6 percent. for Data Security, while
AI Literacy
and
Auditor Readiness
had The model explained 45.2 percent of the variance in AI mean scores of 3.61 and 3.55, respectively. These values Literacy and 61.7 percent of the variance in
Auditor Readiness
. suggest moderate levels across the focal constructs. These values should be described more cautiously as indicating For the higher-order formative
Data Governance
moderate-to-substantial explanatory power for the endogenous construct, the manuscript reports that all VIF values were constructs rather than “substantial predictive power,” because below 3.0, indicating no serious collinearity problem among the manuscript does not report a dedicated predictive the four lower-order dimensions. The outer weights were also assessment such as PLSpredict. reported as significant, with Data Quality contributing the H1 posited a positive effect of
Data Governance
on Auditor largest weight at 0.38, followed by Data Security and Privacy Readiness. The direct path coefficient was 0.47 (t = 7.34, p < at 0.29, Data Stewardship at 0.25, and Data Architecture and 0.001, 95% CI [0.34, 0.58]), supporting H1. H2 predicted Data Integration at 0.18. These results are appropriate as evidence Governance positively affects
AI Literacy
, and the result was for the formative higher-order construct and should remain significant (β = 0.67, t = 12.19, p < 0.001, CI [0.56, 0.77]), central in the revised Results section. supporting H2. H3,
AI Literacy
→
Auditor Readiness
, was also By contrast, HTMT values involving
Data Governance
significant (β = 0.39, t = 5.82, p < 0.001, CI [0.26, 0.52]), should not be interpreted as evidence of validity, because supporting H3. The indirect effect of
Data Governance
on HTMT is intended for reflective constructs rather than
Auditor Readiness
through
AI Literacy
(H4) was 0.26 (t = 5.14, formative higher-order constructs. The manuscript may retain p < 0.001, CI [0.16, 0.36]). Because both direct and indirect the HTMT coefficient between
AI Literacy
and Auditor effects were significant, partial mediation was established. The Readiness, reported as 0.78 and below the 0.85 threshold, VAF was 35.6%, indicating that AI literacy accounts for about as evidence of discriminant validity between those reflective Table 2. Descriptive Statistics and Indicator Loadings Construct / Dimension Indicator Code Mean Std. Dev. Loading t-value*
Data Governance
(Formative) DQ1 3.64 0.88 0.84 22.31 Data Quality DQ2 3.70 0.82 0.87 28.15 DQ3 3.55 0.91 0.81 19.72 DS1 3.80 0.85 0.89 31.44 Data Security & Privacy DS2 3.75 0.89 0.85 24.10 DS3 3.78 0.79 0.86 27.83 DA1 3.40 1.02 0.78 14.25 Data Architecture & Integration DA2 3.45 0.96 0.80 16.70 DA3 3.41 0.98 0.76 13.88 DST1 3.52 0.94 0.82 18.43 Data Stewardship DST2 3.48 0.91 0.79 16.01 DST3 3.56 0.86 0.83 20.35 AIL1 3.65 0.78 0.84 25.10 AIL2 3.58 0.82 0.86 28.92 AIL3 3.60 0.80 0.81 20.67 AIL4 3.62 0.85 0.83 22.54
AI Literacy
(Reflective) AIL5 3.55 0.90 0.79 17.81 AIL6 3.67 0.77 0.85 26.90 AIL7 3.61 0.83 0.82 21.30 AIL8 3.59 0.81 0.80 19.78 AIL9 3.63 0.79 0.84 24.56 AR1 3.50 0.87 0.78 16.45 AR2 3.55 0.84 0.81 20.10 AR3 3.52 0.88 0.80 18.90 AR4 3.57 0.86 0.82 22.15 AR5 3.48 0.92 0.77 15.77 AR6 3.60 0.81 0.84 25.40
Auditor Readiness
(Reflective) AR7 3.53 0.89 0.79 18.03 AR8 3.56 0.83 0.83 23.62 AR9 3.54 0.90 0.80 19.84 AR10 3.58 0.85 0.81 21.22 AR11 3.51 0.88 0.78 17.51 AR12 3.59 0.82 0.83 24.09 Note: For reflective constructs (
AI Literacy
,
Auditor Readiness
, and dimension items), loadings are shown. For the formative Data Governance construct, these are outer loadings of the reflective indicators of each dimension; formative measurement is presented separately in Table 3. All loadings significant at p < 0.001 Table 3. Formative Measurement Assessment -
Data Governance
Dimensions Dimension VIF Weight t-value p-value 95% CI (BC) Interpretation Data Quality 1.8 0.38 4.65 <0.001 [0.22, 0.54] Highest relative contribution Data Security 1.73 0.29 3.82 <0.001 [0.14, 0.44] Moderate-high contribution Data Architecture 1.62 0.18 2.31 0.021 [0.03, 0.33] Lower but significant contribution Data Stewardship 1.79 0.25 3.14 0.002 [0.09, 0.41] Moderate contribution Table 4. Construct Reliability and Validity Average Variance Construct Cronbach's Alpha rho_A Composite Reliability (rho_c) Extracted (AVE)
AI Literacy
0.918 0.920 0.933 0.636
Auditor Readiness
0.932 0.934 0.942 0.619 Note:
Data Governance
is a formative higher-order construct; therefore, internal consistency reliability, AVE, and HTMT are not applicable as validity criteria for the higher-order construct. Table 5. Discriminant validity for reflective constructs (HTMT) Construct Pair HTMT Ratio 95% CI Threshold
AI Literacy
↔
Auditor Readiness
0.78 [0.71, 0.84] < 0.85 Note: HTMT is reported only for the reflective constructs (
AI Literacy
and
Auditor Readiness
). For the formative
Data Governance
construct, discriminant validity is not assessed via HTMT; instead, collinearity assessment, significance of outer weights, and convergent validity (redundancy analysis) were used. one-third of the total effect. small positive effect on readiness (β = 0.11, p < 0.05), but firm Control Variables. Table 6 presents the control variable size and experience were non-significant. Gender, age, and results. Among control variables, AI training history showed a education were also non-significant. Table 6. Hypothesis Testing Results (Direct, Indirect, and Total Effects) Path Std. Hyp. Path t-value p-value 95% CI (BC) f² Result Coeff. (β) Error
Data Governance
→ H1 0.47 0.064 7.34 <0.001 [0.34, 0.58] 0.24 Supported
Auditor Readiness
Data Governance
→ AI H2 0.67 0.055 12.19 <0.001 [0.56, 0.77] 0.82 Supported Literacy
AI Literacy
→ Auditor H3 0.39 0.067 5.82 <0.001 [0.26, 0.52] 0.16 Supported Readiness
Data Governance
→ AI Supported (Partial H4 Literacy → Auditor 0.26 0.051 5.14 <0.001 [0.16, 0.36] – Mediation) Readiness (Indirect) Total
Data Governance
→ 0.73 – – – – – – Effect
Auditor Readiness
R²
AI Literacy
= 0.452; R²
Auditor Readiness
= 0.617. VAF = 0.26 / 0.73 = 35.6% (partial mediation) in Figure 1. BC: Bias-corrected bootstrap confidence interval (two-tailed, 5,000 subsamples). Effect sizes: f²(H1) = 0.24 (medium-large), f²(H2) = 0.82 (very large), f²(H3) = 0.16 (medium). Figure 1. The structural model with path coefficients and R² values Figure 2. Mean
Auditor Readiness
Score by Firm Size
Additional Analysis: Importance-Performance Map
An importance-performance map analysis was conducted to identify governance dimensions that may warrant managerial attention. Importance was defined as the total effect of each The threshold of 52.75, rather than 3.59, was used to data governance dimension on
Auditor Readiness
. classify performance. A dimension was classified as high Performance was calculated from the mean latent variable importance when its importance exceeded 0.3075 and as high scores and linearly rescaled from the original five-point scale performance when its rescaled performance exceeded 52.75. to a 0–100 scale using: Dimensions above the importance threshold and below the performance threshold were classified as priority areas. These results in Table 7 indicate that audit firms should prioritize improving data quality standards and stewardship Table 7. Control Variable Effects on
Auditor Readiness
Control Variable Coding β Std. Error t-value p-value 95% CI AI Training Received 1=Yes, 0=No 0.11 0.052 2.12 0.034 [0.01, 0.21] Firm Size 1=Big Four, 2=Large National, 3=SMP 0.06 0.058 1.03 0.303 [-0.05, 0.17] Audit Experience 1=2-5 yrs, 2=6-10 yrs, 3=>10 yrs 0.04 0.061 0.66 0.509 [-0.08, 0.16] Gender 1=Male, 2=Female -0.03 0.059 -0.51 0.610 [-0.15, 0.09] Age Group 1=<26, 2=26-35, 3=36-45, 4=>45 0.07 0.063 1.11 0.267 [-0.05, 0.19] Education 1=Bachelor, 2=Master/Professional 0.02 0.057 0.35 0.726 [-0.09, 0.13] Note: Big Four affiliates were used as the reference category. The structural model included two separate firm-size dummy variables: Large National Firm and SMP. The coefficients for these variables represent differences in auditor readiness relative to Big Four affiliates. All estimates were obtained using the same embedded two-stage PLS-SEM model and 5,000 bootstrap subsamples. Table 8. Importance-Performance Analysis for
Data Governance
Dimensions Importance (Total Performance (Rescaled Dimension Priority Effect on Readiness) 0-100) High importance, lower performance → Data Quality 0.42 53.2 Priority 1 High importance, lower performance → Data Stewardship 0.31 48.7 Priority 2 High performance, moderate importance → Data Security 0.28 63.8 Maintain Lower importance and performance → Data Architecture 0.22 45.3 Longer-term improvement practices to maximize readiness gains. Data architecture learning ecosystem. When auditors have access to clean, well-improvements, while important, may be addressed over a documented datasets, they can experiment with AI tools in longer timeframe given their lower performance and sandbox environments, understand how data preprocessing importance scores. affects AI outputs, and develop critical evaluation skills. Data This study set out to examine the interplay between data stewardship programs often involve cross-functional teams governance, AI literacy, and auditor readiness in the context including IT and data specialists; auditors collaborating with of generative AI-based financial statement audits among these teams naturally enhance their AI vocabulary and Indonesian auditors. The results provide robust evidence comprehension. This confirms the knowledge-based view: data supporting all four hypotheses and offer nuanced insights into governance creates a fertile ground for knowledge creation and how data governance acts both directly and indirectly through transfer. In practical terms, firms should integrate data AI literacy to foster readiness. governance training with AI upskilling programs, ensuring that The direct effect of data governance on auditor readiness auditors not only learn about AI algorithms but also about the in Table 8 (H1, β = 0.47, f² = 0.24) underscores the data pipelines feeding those algorithms. foundational importance of institutional data management AI literacy significantly predicted auditor readiness (H3, β = policies. When audit firms implement comprehensive data 0.39). This finding extends the technology readiness literature quality protocols, security measures, architecture standards, by showing that beyond generic technology optimism or and stewardship roles, auditors report greater confidence and innovativeness, domain-specific AI preparedness to engage with generative AI tools. This finding literacy is crucial. Auditors with higher AI literacy are better aligns with organizational readiness theories that highlight the equipped to maintain professional skepticism; they understand role of supportive structural conditions (Kurniadhi & that generative AI might “hallucinate” and thus do not blindly Hindiarto, 2025) and resonates with the TOE framework, accept its outputs (Joshi et al., 2026). They also feel more where organizational readiness, proxied by data governance competent in interacting with AI systems, customizing prompts, maturity, directly influences technology adoption readiness and interpreting results within the audit context (Khanal, (Almashekhi et al., 2026). Notably, the dimension of data 2025). As generative AI becomes more conversational and quality had the highest outer weight (0.38), echoing the autonomous, such literacy becomes a core competency. The principle that "garbage in, garbage out" remains the moderate effect size suggests that while AI literacy is important, paramount risk in AI applications (Kim & Park, 2025). Without it is not the sole determinant—data governance still holds reliable data, generative AI could produce plausible but substantial direct relevance, probably because no amount of materially incorrect narratives, eroding audit quality and individual skill can compensate for systematically poor data increasing litigation risk. For example, if a generative AI model (Lindkvist et al., 2026). trained on poorly governed data suggests an adjusting entry The partial mediation (H4) indicates that data governance based on erroneous source information, the auditor must influences readiness both by creating a trustworthy data trace back through data lineage to validate outputs. Robust infrastructure and by elevating auditors’ AI-related knowledge data governance ensures this traceability exists. Therefore, (Ravindran Pillai, 2026b). The VAF of 35.6% suggests that the audit firms, especially SMPs, should prioritize data quality majority of the total effect is direct, but the indirect path is non-improvement initiatives as a prerequisite before deploying trivial. This dual pathway provides a more complete picture generative AI. than a simple direct-effects model. It implies that audit firms The strong linkage between data governance and AI should not focus exclusively on either technical infrastructure literacy (H2, β = 0.67) is a novel contribution. Although prior or human capital; a synergistic approach is essential. The studies have treated training and organizational support as importance-performance analysis further highlighted that data drivers of digital literacy, few have empirically connected data quality and stewardship are both highly important for readiness governance practices to AI literacy development. The finding but currently performed sub-optimally, particularly in SMPs, suggests that a well-governed data environment acts as a echoing the descriptive readiness gap across firm sizes (Ravindran Pillai, 2026a). SMPs, due to resource constraints, adoption readiness. This addresses calls in the literature for often rely on ad hoc data management, which not only more attention to mediating mechanisms in increases AI-related risks but also hinders auditors’ learning technology acceptance studies. Third, it provides empirical opportunities. Tailored interventions, such as shared service evidence distinguishing generative AI from general audit centers or industry-level data governance utilities, could help technology adoption; the former raises unique data provenance bridge this gap (Chintakindhi, 2025). and model explainability concerns that amplify the role of The non-significance of firm size and experience as governance. Fourth, it contributes to the emerging literature on control variables warrants careful interpretation. This result AI-augmented auditing in emerging economies, where does not prove that firm size and experience are unimportant; institutional contexts differ from developed settings (Waseem rather, it suggests that data governance and AI literacy explain Haider et al., 2025). variance in readiness above and beyond these traditional For audit firm leaders, the findings advocate a roadmap: (1) hierarchical factors. It is plausible that larger firms have better conduct a data governance maturity assessment to identify data governance (indirectly influencing readiness through gaps in data quality, security, architecture, and stewardship; (2) governance), and that controlling for governance reduces the establish clear data quality KPIs and stewardship roles with direct effect of firm size to non-significance. The descriptive accountability for AI input data; (3) design AI literacy modules pattern (Figure 2) showing higher mean readiness in Big Four embedded in day-to-day data work rather than as standalone firms supports this interpretation. Similarly, experience may training; (4) implement secure data sandboxes for low-risk be less relevant than specific AI-related training, as reflected experimentation with generative AI; (5) invest in AI training in the significant effect of AI training history (β = 0.11, p = programs, as this was the only significant control variable. For 0.034). This suggests that targeted upskilling can the Indonesian Institute of Chartered Accountants and the compensate for general experience differences. However, the Ministry of Finance, the results can inform competency claim that "SMPs can achieve readiness comparable to Big frameworks and continuing professional education Four firms" should be qualified: the data indicate that SMPs requirements. Incorporating AI literacy and data governance can achieve similar readiness if they have equivalent data into the certification syllabus will prepare future auditors. The governance and AI literacy, but achieving such equivalence non-significance of firm size suggests that targeted requires deliberate investment and may face resource interventions, rather than firm-scale strategies, may be more constraints (K Ghani et al., 2025). effective in boosting readiness. Regulators like OJK, when Alternative explanations for the findings should be issuing guidelines on AI use in financial services, should considered. Self-selection bias may have influenced results, emphasize data governance standards specific to audit as auditors more interested in AI topics may have been more evidence reliability. The prioritization of data quality and likely to respond. AI training exposure (48.4% of respondents) stewardship in the IPMA provides clear direction for resource may reflect either genuine organizational investment or allocation. individual motivation. Organizational culture, leadership support, and peer influence—variables not measured in this Conclusion study—could also affect readiness and potentially confound the observed relationships. Additionally, self-reported This study provides evidence that data governance is readiness may not perfectly reflect actual capability to use positively associated with auditor readiness for generative AI-generative AI in real audit tasks. Auditors may overestimate based financial statement audits, with AI literacy serving as a their confidence or underestimate the challenges of meaningful partial mediator. Within the Indonesian audit integrating AI into complex audit procedures. Future research profession, the findings indicate that robust data quality, should complement self-report measures with objective security, architecture, and stewardship are related to higher assessments, such as performance in AI-augmented audit readiness, while also nurturing auditors' ability to understand simulations (Nabiha et al., 2025). and critically evaluate generative AI tools. The study contributes Comparison with prior studies reveals both alignment and to TOE and knowledge-based frameworks by: (1) specifying data divergence. Supporting earlier TAM-based research, our governance maturity as a distinct organizational context variable findings confirm that individual cognitive factors (here, AI that directly and indirectly affects technology adoption readiness; literacy) are important for technology adoption (Vu Thi Mai, (2) demonstrating AI literacy as a knowledge-based mechanism 2026). However, our study extends this literature by through which organizational infrastructure translates into demonstrating that organizational data governance is not individual capability; (3) identifying a partial mediation pathway merely a contextual background factor but a direct (35.6% of total effect) that integrates structural and cognitive antecedent that shapes individual capability. Diverging from perspectives; and (4) providing empirical evidence from an some TOE studies that found firm size significant (Gupta et al., emerging economy with heterogeneous firm capabilities, 2026), our non-significant firm size result suggests that in the revealing that firm size effects operate through governance specific context of generative AI auditing, governance and rather than directly. literacy may be more determinant than organizational scale. This may reflect the early stage of generative AI adoption in Indonesian auditing, where even small firms can leverage Author contributions cloud-based AI tools if they have sound data practices. R.U.H - Conceptualization, Methodology, Formal Analysis, This study offers several theoretical contributions. First, it Writing – Original Draft, Writing – Review & Editing, Supervision, extends the TOE framework by specifying data governance Project Administration. M.F - Data Collection, Investigation, maturity as a distinct organizational context factor for Resources, Validation, Writing – Original Draft (Methodology generative AI adoption in auditing, rather than treating section), Software, Visualization. Both authors contributed to organizational readiness broadly. The framework is enriched the research design, interpretation of results, and final by demonstrating that the "organization" dimension approval of the manuscript. encompasses specific data infrastructure elements (quality, security, architecture, stewardship) that directly enable technology adoption outcomes. Second, it integrates AI Acknowledgements literacy as a mediator grounded in knowledge-based theory, showing how organizational resources (governed data) Authors thank to all people and institution. In most cases translate into individual capabilities (literacy) and ultimately helped this research.
Methods
Result and Discussion
Table 1. Demographic Profiles
| Characteristic | Category | Frequency | Percentage |
|---|---|---|---|
| Gender | Male | 142 | 57.3% |
| Gender | Female | 106 | 42.7% |
| Age Group | < 26 years | 35 | 14.1% |
| Age Group | 26–35 years | 112 | 45.2% |
| Age Group | 36–45 years | 76 | 30.6% |
| Age Group | > 45 years | 25 | 10.1% |
| Audit Experience | 2–5 years | 86 | 34.7% |
| Audit Experience | 6–10 years | 97 | 39.1% |
| Audit Experience | > 10 years | 65 | 26.2% |
| Firm Size | Big Four affiliate | 71 | 28.6% |
| Firm Size | Large national (top 10) | 83 | 33.5% |
| Firm Size | Small and Medium Practices (SMPs) | 94 | 37.9% |
| Education | Bachelor’s degree (S1) | 205 | 82.7% |
| Education | Master’s/Professional (S2/Prof.) | 43 | 17.3% |
| AI Training Received | Yes | 120 | 48.4% |
| AI Training Received | No | 128 | 51.6% |
Note: Firm-size categories are descriptive. For PLS-SEM, Big Four affiliates were the reference category and the other firm-size groups were represented by dummy variables.
Table 2. Descriptive Statistics and Indicator Loadings
| Construct / Dimension | Indicator Code | Mean | Std. Dev. | Loading | t-value* |
|---|---|---|---|---|---|
| Data Quality | DQ1 | 3.64 | 0.88 | 0.84 | 22.31 |
| Data Quality | DQ2 | 3.70 | 0.82 | 0.87 | 28.15 |
| Data Quality | DQ3 | 3.55 | 0.91 | 0.81 | 19.72 |
| Data Security & Privacy | DS1 | 3.80 | 0.85 | 0.89 | 31.44 |
| Data Security & Privacy | DS2 | 3.75 | 0.89 | 0.85 | 24.10 |
| Data Security & Privacy | DS3 | 3.78 | 0.79 | 0.86 | 27.83 |
| Data Architecture & Integration | DA1 | 3.40 | 1.02 | 0.78 | 14.25 |
| Data Architecture & Integration | DA2 | 3.45 | 0.96 | 0.80 | 16.70 |
| Data Architecture & Integration | DA3 | 3.41 | 0.98 | 0.76 | 13.88 |
| Data Stewardship | DST1 | 3.52 | 0.94 | 0.82 | 18.43 |
| Data Stewardship | DST2 | 3.48 | 0.91 | 0.79 | 16.01 |
| Data Stewardship | DST3 | 3.56 | 0.86 | 0.83 | 20.35 |
| AI Literacy (Reflective) | AIL1 | 3.65 | 0.78 | 0.84 | 25.10 |
| AI Literacy (Reflective) | AIL2 | 3.58 | 0.82 | 0.86 | 28.92 |
| AI Literacy (Reflective) | AIL3 | 3.60 | 0.80 | 0.81 | 20.67 |
| AI Literacy (Reflective) | AIL4 | 3.62 | 0.85 | 0.83 | 22.54 |
| AI Literacy (Reflective) | AIL5 | 3.55 | 0.90 | 0.79 | 17.81 |
| AI Literacy (Reflective) | AIL6 | 3.67 | 0.77 | 0.85 | 26.90 |
| AI Literacy (Reflective) | AIL7 | 3.61 | 0.83 | 0.82 | 21.30 |
| AI Literacy (Reflective) | AIL8 | 3.59 | 0.81 | 0.80 | 19.78 |
| AI Literacy (Reflective) | AIL9 | 3.63 | 0.79 | 0.84 | 24.56 |
| Auditor Readiness (Reflective) | AR1 | 3.50 | 0.87 | 0.78 | 16.45 |
| Auditor Readiness (Reflective) | AR2 | 3.55 | 0.84 | 0.81 | 20.10 |
| Auditor Readiness (Reflective) | AR3 | 3.52 | 0.88 | 0.80 | 18.90 |
| Auditor Readiness (Reflective) | AR4 | 3.57 | 0.86 | 0.82 | 22.15 |
| Auditor Readiness (Reflective) | AR5 | 3.48 | 0.92 | 0.77 | 15.77 |
| Auditor Readiness (Reflective) | AR6 | 3.60 | 0.81 | 0.84 | 25.40 |
| Auditor Readiness (Reflective) | AR7 | 3.53 | 0.89 | 0.79 | 18.03 |
| Auditor Readiness (Reflective) | AR8 | 3.56 | 0.83 | 0.83 | 23.62 |
| Auditor Readiness (Reflective) | AR9 | 3.54 | 0.90 | 0.80 | 19.84 |
| Auditor Readiness (Reflective) | AR10 | 3.58 | 0.85 | 0.81 | 21.22 |
| Auditor Readiness (Reflective) | AR11 | 3.51 | 0.88 | 0.78 | 17.51 |
| Auditor Readiness (Reflective) | AR12 | 3.59 | 0.82 | 0.83 | 24.09 |
Note: For reflective constructs and dimension items, loadings are shown. All loadings were significant at p < 0.001.
Table 3. Formative Measurement Assessment – Data Governance Dimensions
| Dimension | VIF | Weight | t-value | p-value | 95% CI (BC) | Interpretation |
|---|---|---|---|---|---|---|
| Data Quality | 1.8 | 0.38 | 4.65 | <0.001 | [0.22, 0.54] | Highest relative contribution |
| Data Security | 1.73 | 0.29 | 3.82 | <0.001 | [0.14, 0.44] | Moderate-high contribution |
| Data Architecture | 1.62 | 0.18 | 2.31 | 0.021 | [0.03, 0.33] | Lower but significant contribution |
| Data Stewardship | 1.79 | 0.25 | 3.14 | 0.002 | [0.09, 0.41] | Moderate contribution |
Table 4. Construct Reliability and Validity
| Construct | Cronbach's Alpha | rho_A | Composite Reliability (rho_c) | Average Variance Extracted (AVE) |
|---|---|---|---|---|
| AI Literacy | 0.918 | 0.920 | 0.933 | 0.636 |
| Auditor Readiness | 0.932 | 0.934 | 0.942 | 0.619 |
Note: Data Governance is a formative higher-order construct; internal consistency reliability, AVE, and HTMT are not applicable as validity criteria for the higher-order construct.
Table 5. Discriminant Validity for Reflective Constructs (HTMT)
| Construct Pair | HTMT Ratio | 95% CI | Threshold |
|---|---|---|---|
| AI Literacy ↔ Auditor Readiness | 0.78 | [0.71, 0.84] | < 0.85 |
Note: HTMT is reported only for the reflective constructs.
Table 6. Hypothesis Testing Results (Direct, Indirect, and Total Effects)
| Hyp. | Path | Path Coeff. (β) | Std. Error | t-value | p-value | 95% CI (BC) | f² | Result |
|---|---|---|---|---|---|---|---|---|
| H1 | Data Governance → Auditor Readiness | 0.47 | 0.064 | 7.34 | <0.001 | [0.34, 0.58] | 0.24 | Supported |
| H2 | Data Governance → AI Literacy | 0.67 | 0.055 | 12.19 | <0.001 | [0.56, 0.77] | 0.82 | Supported |
| H3 | AI Literacy → Auditor Readiness | 0.39 | 0.067 | 5.82 | <0.001 | [0.26, 0.52] | 0.16 | Supported |
| H4 | Data Governance → AI Literacy → Auditor Readiness (Indirect) | 0.26 | 0.051 | 5.14 | <0.001 | [0.16, 0.36] | – | Supported (Partial Mediation) |
| Total Effect | Data Governance → Auditor Readiness | 0.73 | – | – | – | – | – | – |
R² AI Literacy = 0.452; R² Auditor Readiness = 0.617. VAF = 35.6%. BC = bias-corrected bootstrap confidence interval (two-tailed, 5,000 subsamples).
Table 7. Control Variable Effects on Auditor Readiness
| Control Variable | Coding | β | Std. Error | t-value | p-value | 95% CI |
|---|---|---|---|---|---|---|
| AI Training Received | 1=Yes, 0=No | 0.11 | 0.052 | 2.12 | 0.034 | [0.01, 0.21] |
| Firm Size | 1=Big Four, 2=Large National, 3=SMP | 0.06 | 0.058 | 1.03 | 0.303 | [-0.05, 0.17] |
| Audit Experience | 1=2–5 yrs, 2=6–10 yrs, 3=>10 yrs | 0.04 | 0.061 | 0.66 | 0.509 | [-0.08, 0.16] |
| Gender | 1=Male, 2=Female | -0.03 | 0.059 | -0.51 | 0.610 | [-0.15, 0.09] |
| Age Group | 1=<26, 2=26–35, 3=36–45, 4=>45 | 0.07 | 0.063 | 1.11 | 0.267 | [-0.05, 0.19] |
| Education | 1=Bachelor, 2=Master/Professional | 0.02 | 0.057 | 0.35 | 0.726 | [-0.09, 0.13] |
Note: Big Four affiliates were used as the reference category. Estimates used the embedded two-stage PLS-SEM model and 5,000 bootstrap subsamples.
Table 8. Importance-Performance Analysis for Data Governance Dimensions
| Dimension | Importance (Total Effect on Readiness) | Performance (Rescaled 0–100) | Priority |
|---|---|---|---|
| Data Quality | 0.42 | 53.2 | High importance, lower performance → Priority 1 |
| Data Stewardship | 0.31 | 48.7 | High importance, lower performance → Priority 2 |
| Data Security | 0.28 | 63.8 | High performance, moderate importance → Maintain |
| Data Architecture | 0.22 | 45.3 | Lower importance and performance → Longer-term improvement |
Conclusion
This study provides evidence that data governance is positively associated with auditor readiness for generative AI-based financial statement audits, with AI literacy serving as a meaningful partial mediator. Within the Indonesian audit profession, the findings indicate that robust data quality, security, architecture, and stewardship are related to higher readiness, while also nurturing auditors' ability to understand and critically evaluate generative AI tools. The study contributes to TOE and knowledge-based frameworks by: (1) specifying data governance maturity as a distinct organizational context variable that directly and indirectly affects technology adoption readiness; (2) demonstrating AI literacy as a knowledge-based mechanism through which organizational infrastructure translates into individual capability; (3) identifying a partial mediation pathway (35.6% of total effect) that integrates structural and cognitive perspectives; and (4) providing empirical evidence from an emerging economy with heterogeneous firm capabilities, revealing that firm size effects operate through governance rather than directly.
Author Contributions
R.U.H - Conceptualization, Methodology, Formal Analysis, Writing – Original Draft, Writing – Review & Editing, Supervision, Project Administration. M.F - Data Collection, Investigation, Resources, Validation, Writing – Original Draft (Methodology section), Software, Visualization. Both authors contributed to the research design, interpretation of results, and final approval of the manuscript.
Acknowledgements
Authors thank to all people and institution. In most cases helped this research.
References
Abduh, M., Pramukti, A., Aliyah, N., & Ananda, R. (2026). Challenges of Implementing Artificial Intelligence in the Audit Profession and Its Impact on Audit Quality. Mustard Journal De Ecobusin, 3(1), 49–62. https://doi.org/10.37899/mjde.v3i1.338
Almashekhi, A. S. S., Mohamad, A. D., & Khafidz, H. A. (2026). Analyzing the Mediating Role of Organizational Readiness on Industry 4.0 Capabilities and Digital Transformation Strategy. International Review of Management and Marketing, 16(4), 779–786. https://doi.org/10.32479/irmm.23914
Carandang, D., Baran, B., Atento, R. G. O., Espelita, C. A. M., & Atento, A. G. (2026). Perceptions of Accounting Software among SMEs in Calamba City, Philippines: A Technology-Organization-Environment (TOE) Framework. Journal of Enterprise Strategy and Management Innovation, 1(1). https://doi.org/10.65166/dxqbny15
Chintakindhi, S. (2025). Trustworthy AI for Data Governance: Explaining Compliance Decisions Using SHAP and Causal Inference. International Journal for Multidisciplinary Research, 7(4). https://doi.org/10.36948/ijfmr.2025.v07i04.51762
Cicin, F. N., & Çetin Gürkan, G. (2026). How Physicians Embrace AI: Insights from Technology Acceptance and Trust Theories. Frontiers in Digital Health, 8. https://doi.org/10.3389/fdgth.2026.1722087
Fitriani, A. N., Risaldy, R., Rauf, A., & Afidatunisa, S. (2026). Academic Dependency, AI Literacy, and Cognitive Offloading Predict Students’ Cognitive Ability in Generative AI Learning. Artificial Intelligence in Lifelong and Life-Course Education, 1(2), 53–66. https://doi.org/10.66053/aillce.v1i2.18
Gomaa, A. H. M. (2026). Artificial Intelligence and the Auditing Profession: The Role of the International Federation of Accountants. International Journal of Accounting and Management Sciences, 5(1). https://doi.org/10.56830/IJAMS01202603
Gupta, D., Bhattacharyya, S. S., & Krishnamoorthy, B. (2026). Study of Artificial Intelligence Based Digital Transformation Initiatives, Explication from the Theoretical Perspectives of Technology Organization Environmental Framework. Journal of Science and Technology Policy Management, 1– 18. https://doi.org/10.1108/JSTPM-11-2024-0433
Joshi, S., Zulfiqa, N., Usman Asif, M., & Kazi, S. (2026). Designing and Implementing Agentic Generative AI Professional Learning for the U.S. Federal Workforce: An Education-Focused Framework for AI Literacy, Ethical Practice, and Transfer to Work. The Educational Review, USA, 10(2), 103–110. https://doi.org/10.26855/er.2026.02.007
K Ghani, E., Ilias, A., Muhammad, K., & Ab Samad, N. H. (2025). Exploring Professional Competency Criteria for Succession Planning Framework for Public Sector Accountants in Malaysia: A Proposal. IPN Journal of Research and Practice in Public Sector Accounting and Management, 15(1), 57–82. https://doi.org/10.58458/ipnj.v15.01.03.0112
Khanal, N. (2025). Generative AI Literacy and Students’ Academic Performance: The Mediating Role of Student Engagement in Higher Education. Patan Pragya, 14(2), 54–78. https://doi.org/10.3126/pragya.v14i2.90772
Kim, J., & Park, Y. (2025). Influence of Organizational Digital Transformation Competencies on Individual Job Performance: The Mediating Effects of Organizational Supportive Learning Environment and Individual Readiness for Change. Industrial and Commercial Training, 57(1), 53– 68. https://doi.org/10.1108/ICT-07-2024-0062
Kurniadhi, F., & Hindiarto, F. (2025). Organizational Justice dan Organizational Readiness to Change: Peran Mediasi Psychological Empowerment. Persona: Jurnal Psikologi Indonesia, 14(1), 70–88. https://doi.org/10.30996/persona.v14i1.132296
Lindkvist, A., Curbo, S., & Hultgren, C. (2026). Choosing Not to Use Generative AI in Higher Education: A Mixed Methods Study of Student Reasoning, Assessment Design, and AI Literacy. Frontiers in Education, 11. https://doi.org/10.3389/feduc.2026.1813306
Madhavan, D. (2024). Enterprise Data Governance: A Comprehensive Framework for Ensuring Data Integrity, Security, and Compliance in Modern Organizations. International Journal of Scientific Research in Computer Science, Engineering and Information Technology, 10(5), 731–743. https://doi.org/10.32628/CSEIT241051062
Mohammad, M., & Mohammed, A. (2026). Explaining Faculty Adoption of AI Tools: An Extended Technology Acceptance Framework for Higher Education. Communications of International Proceedings. https://doi.org/10.5171/2025.4624325
Mpanza, S. S. (2025). Revisiting the Technological-Organizational-Environmental (TOE) Framework and Diffusion of Innovation (DOI): A Theoretical Review for Artificial Intelligence (AI) Adoption. International Journal of Applied Research in Business and Management, 6(5). https://doi.org/10.51137/wrp.ijarbm.441
Nabiha, A. K. S.-, Hashim, F., & Mahadi, R. (2025). Strategic Competency Framework for Public Sector Accountants: Integrating International and National Insights. IPN Journal of Research and Practice in Public Sector Accounting and Management, 15(2), 1–24. https://doi.org/10.58458/ipnj.v15.02.01.0117
Okogun, I. O., Apatu, V., Mwanandimayi, N., Talent Sithole, R., & Mufandaidza, C. (2026). Audit 5.0 and the Digital Transformation of Auditing: The Role of Big Data Analytics and Artificial Intelligence in Enhancing Audit Quality and Decision-Making. Asian Journal of Economics, Business and Accounting, 26(2), 59–71. https://doi.org/10.9734/ajeba/2026/v26i22162
Paisey, C., & Paisey, N. J. (2006). Cutting to the core? A reflection upon recent education policy debates within the Institute of Chartered Accountants in England and Wales. The British Accounting Review, 38(1), 31–61. https://doi.org/10.1016/j.bar.2005.08.002
Pal, T., & Islam, M. M. (2025). ASSESSING ORGANIZATIONAL AI READINESS IN CRITICAL INFRASTRUCTURE: AN INTEGRATED MATURITY FRAMEWORK FOR HEALTHCARE SYSTEMS AND SUPPLY CHAIN MANAGEMENT. American Journal of Scholarly Research and Innovation, 04(01), 613– 621. https://doi.org/10.63125/vh7x5h50
Petchprayoon, C., Maneengam, R., Maneengam, A., & Chantarakamol, P. (2026). Social Media’s AI Ethics, Digital Literacy, and AI Trust: Could These Lead to Positive Health Behavior? Human Behavior, Development and Society, 27(2), 283345. https://doi.org/10.62370/hbds.v27i2.283345
Ravindran Pillai, P. (2026a). The GCC Sovereignty Paradox: Measuring the Geopolitical Friction Gap Between AI Infrastructure Investment and Governance Readiness Across the Gulf Cooperation Council. https://doi.org/10.2139/ssrn.6741941
Ravindran Pillai, P. (2026b). The National Sovereign AI Readiness Index (NSARI): A Replicable Framework for Measuring Infrastructure-Governance Alignment in Non-Western AI Ecosystems. https://doi.org/10.2139/ssrn.6742058
Rawat, S. K. (2026). Identity Governance and Security Automation: A Technical Framework for Enterprise Access Management. Computer Fraud and Security, 703–710. https://doi.org/10.52710/cfs.962
Thota, S. (2025). Secure and Scalable AI-Powered Data Governance Models for Salesforce Cloud-Based Enterprises. International Journal of Artificial Intelligence, Data Science and Machine Learning, 6, 180–189. https://doi.org/10.63282/3050-9262.IJAIDSML-V6I2P120
Tikhonova, N. V, & Sabirova, D. R. (2025). Teacher AI Literacy: A Theoretical Conceptualisation. The Education and Science Journal, 27(6), 180–206. https://doi.org/10.17853/1994-5639-2025-6-180-206
Vu Thi Mai, C. (2026). Determinants of Intention to Use Artificial Intelligence in Online Cosmetic Shopping: An Integrated Technology Acceptance — Unified Theory of Acceptance and Use of Technology Model. PaperASIA, 42(2b). https://doi.org/10.59953/paperasia.v42i2b.1015
Waseem Haider, Naseebullah, Dr. Noor Ahmed, & Salman Ali Khan. (2025). Unlocking Project Success: The Synergistic Effects of Project Management Maturity Matrix, Governance, and Top Management Support. Social Science Review Archives, 3(1), 1154–1165. https://doi.org/10.70670/sra.v3i1.415
Yulfani, Ansar, M., Yamin, N. Y., Paranoan, S., & Gunarsa, A. (2025). Fraud Prevention: The Contribution of Internal Control, Internal Audit, and Organizational Culture. Quantitative Economics and Management Studies, 6(4), 612–622. https://doi.org/10.35877/454RI.qems4118