Yes. In-app guidance counts as a control when it prevents or detects a defined error at the step where the error happens, and leaves a record that it did so. That is a narrower claim than "training helps", and it is the claim worth making.
It matters this month because Gartner told audit leaders that their own functions are finding it harder to spot risks in time, and that one of its three answers is to embed guidance into the workflows where the work is done. Fiducia is a certified WalkMe partner, so weigh what follows accordingly. The method applies whichever platform you use.
Because the work is changing faster than the checks around it. Gartner's survey of 108 audit leaders, run in April 2026 and published on 15 September, found 64 percent say it has become more difficult to spot potential issues before they have a material impact on the organisation. The three reasons Gartner gives are the race to adopt AI, rapidly changing regulation and geopolitics, and new strategies and operating models, all of which it says are overwhelming traditional governance, controls and risk practices.
The second number in the release matters more for an operations leader. Only 30 percent of business unit leaders say their ability to manage risk is heavily influenced by insights from audit, compliance and risk functions. Put the two together and the picture is clear: the second line cannot see the risk in time, and most of the first line does not say it leans on the second line's insight. Nancy Queally of Gartner's assurance practice said it plainly: audit, risk and compliance functions cannot realistically manage every risk themselves now. The control has to move to the moment of work.
It means the instruction, the check and the record all sit inside the application at the step where the person acts, rather than in a policy document they read once. Gartner's first recommendation to audit leaders is to design know-how as a service: embed guidance into workflows and deliver coaching at the point of need. Its second is to codify expertise so automated systems can scale it.
In practice that is four mechanisms. Field validation, so a value outside tolerance cannot be saved. Step gating, so a stage cannot be completed until a required action is recorded. Contextual help, so the rule appears at the field it applies to. And a usage log, so you can see how often each of the three fired, and for whom. A digital adoption platform delivers all four as a layer over the application, without changing the application itself, which is why it does not have to wait for the next platform release.
The ones where the wrong step is an audit finding rather than an inconvenience. A vulnerability flag that was disclosed on the call but never recorded. A fee waiver applied outside the agreed tolerance. A complaint logged under the wrong category, so the regulatory clock starts late. A payment reference keyed into the wrong field. Each of these is a single step in a single screen, and each can be a reportable event when it goes wrong.
Two filters pick the candidates. First, frequency: pull the support tickets and rework queue for the process and count how often the same step appears. Second, consequence: ask compliance which of those steps they would have to report. The steps that score on both are the shortlist. Where we have put guided processes live with WalkMe, support tickets on those processes have fallen by 60 percent, and tickets are the cheapest proxy for the errors that never reached audit at all.
With four artefacts, all of which the build should produce without anyone writing a report by hand. The design record: which step, which rule, what the control blocks or prompts, and who signed it off. The usage analytics: how many times the validation or gate fired in the period, on which steps, for which teams. The exceptions: every override, with who made it and why. And the change log: what changed in the guidance, when, and after which process or regulatory change.
That list is what audit will ask for, and it is increasingly what audit will query directly. Gartner's separate poll of 161 chief audit executives, published on 10 September, found 93 percent report some AI use in the function, but 60 percent have no formal AI strategy and 54 percent have not started measuring the return on it. An audit team already using AI on its own work, formally or not, is going to prefer evidence it can query to a policy PDF it has to read.
Pick one process where the wrong step is a reportable event, and build the guard on that step before anything else. Week one: agree the process with compliance and pull the ticket and rework history for it. Week two: identify the two or three steps that carry the consequence and write the design record for each. Weeks three and four: build the validation, gate and contextual help on those steps, switch on the analytics, and baseline the ticket count.
Then take the design record and the first month's analytics to internal audit and ask them one question: does this count? If it does the two things a control has to do, the answer should be yes. It stops the error at the point of work, and it proves it did. The system you already paid for should be paying back in fewer errors as well as faster work. This is how you show the finance director and the auditor the same number.
Both, but only the control use earns audit credit. Training content in the flow of work improves competence. Validation, step gating and a usage log on a defined step are a preventive control with evidence, and that is the part to design first.
No. The SOP still defines the process. In-app guidance enforces the steps in the SOP that carry regulatory or financial consequence, and records that it did, which is the part a written SOP cannot do.
The design record, the usage analytics for the period, the exception and override log, and the change history. All four should be available without anyone building a report by hand.
Not sure which steps in your own processes would fail an audit? Answer 9 questions and get a personalised Digital Adoption Score across three dimensions: not just whether you have a problem, but why, and what to do about it.
Tell us what you are rolling out and where adoption, automation or AI is sticking. We will come back with a clear plan for the first steps, what success looks like, and what it costs. No fifty-slide pitch.
Book a call