When one skilled auditor finds a way to automate audit planning, or sampling, or a faster way to detect anomalies, it saves days of manual work. But more often than not, this knowledge stays on that auditor's laptop or in a spreadsheet macro they can’t easily share with the team.
Multiply that by hundreds of auditors, thousands of audits, and years of institutional memory, and you get an organization that is full of insight but unable to use that knowledge at scale.
This is the state of a lot of enterprise data and AI work. But not at ING, one of Europe’s largest banks where analytics is core to its business model.
One of the areas where they have scaled analytics is its internal audit function, Corporate Audit Services (CAS), an organization with over 400 individuals across 35 teams in over 20 countries.
The scale of the problem
ING's internal audit function covers 1,288 auditable entities and runs roughly 400 audits a year, each with a lead time of six to ten weeks. Their audit landscape spans their global bank's processes, systems, and controls.
As Tjasse Biewenga, Head of Data Analytics at ING's Corporate Audit Services, put it, the frameworks describing what a business should look like rarely match the reality auditors actually encounter, which is "a very complex data structure, data environment, and process flows which look like spaghetti."
Manual processes, fragmented data sources, and only limited access to specialized tools made it difficult to work efficiently at scale. ING focused on scaling audit analytics by replacing specialist tools with Knime to give 400+ auditors the ability to apply analytics independently without needing specialist support. Watch Tjasse Biewenga's presentation about how his team uses Knime for control testing, process mining, image analysis, and more, across multiple data sources and systems.
Why this is a governed virality story, not just an automation story
The numbers are striking.
- Individual auditor workload on certain tasks dropped from three days to fifteen minutes.
- Audit planning automation is estimated to save 400 hours a year.
- Analytics is now used in 65–70% of audits, with a goal of 85%.
But what matters is that analytics at ING didn’t stay with one specialist, but became solutions entire teams can use and stand behind.
ING scaled their data and AI work to enable more than 400 auditors the ability to run process mining, anomaly detection, and automated testing themselves. They don’t have to on a data science team, and they can build reusable solutions independently. That's the difference between an efficiency gain and governed virality. At ING, insight and capability didn't stay locked with the person who built them. They spread, in a form every other auditor could trust and reuse, because the process behind them was explainable, inspectable, and verifiable by design.
Process mining is the clearest example. Specialist process mining tools are typically licensed for one or a handful of expert users — which means everyone else in the audit team either waits for that specialist or does without. ING instead built its own process mining approach on Knime as a data app, so any auditor could upload event logs and see the real process flow instantly.
As Audit Manager Matheus Toscano described it, the team built something tailored to their needs and "made it available to four hundred auditors." The insight of the few became the working capability of the many.
Governance built into the infrastructure itself
Here's the detail that matters most for anyone responsible for governance, risk, or compliance sign-off: ING enabled to scale fast by building governance into the infrastructure itself, so it didn't need to be re-argued every time a new auditor picked up the tool.
- Outlier detection replaced random sampling with a documented, repeatable method for flagging unusual transactions, so a finding isn't just "this auditor's judgment call," but a traceable, defensible process any reviewer can inspect.
- Document and sanctions screening automated OCR-based review of trade finance documents against sanctions lists, with low-confidence matches automatically flagged rather than silently passed through, replacing manual review that was both slow and error-prone.
- Integrated data acquisition and testing replaced audit data collection that had taken up to eight weeks in some cases with near-instant, standardized access, while keeping sensitive data off individual laptops, reducing GDPR exposure in the process.
Data and AI work at ING is successful because the logic is standardized, the data lineage is visible, and the output can be inspected by anyone who needs to sign off on it, be that a QA reviewer, a regulator, an audit committee. This is how ING scaled from a handful of power users to hundreds of auditors without scaling risk alongside them.
ING's own lessons learned scaling analytics in audit
After several years of scaling audit analytics, ING shared these key lessons:
- Build modular, reusable solutions rather than one-off scripts — so what one auditor builds becomes usable by the next one, not just admirable to look at.
- Automate what solves a real problem, not everything that could theoretically be automated — governed virality spreads because it's valuable, not because it's mandated.
- Build for change — audit needs evolve, and tools that can't adapt quietly stop being used, no matter how well they worked on day one.
- "Use it or lose it" — as Biewenga put it, skills fade if auditors don't apply new tools soon after learning them. Adoption isn't a one-time rollout; it's a habit an organization has to keep reinforcing.
That’s the strategy. It’s about flexibility, scalability and reusability.
Tjasse Biewenga, Head of Data Analytics, CAS ING
The takeaway for executives outside of audit
Audit is a good stress test for governed virality, precisely because it's a function where "I found something interesting" is never good enough on its own.
Every insight an auditor produces has to survive scrutiny from a reviewer, a regulator, or a board member defending a conclusion months later. If governed virality can work here — at 400-plus users, across 1,288 auditable entities, inside one of the most heavily regulated functions in a bank — it's a strong signal for what's possible in other functions.
The lesson isn't "automate faster." It's that speed and trust stop being a trade-off the moment explainability, inspectability, and verifiability are built into the process itself, rather than bolted on as a review step after the fact.
Source: How ING Uses KNIME to Speed up Audit Planning, Testing, and Reporting
