India Audit Lens

Configure AI providers, models, and budgets

Enable firm AI features, store provider credentials, select the default provider/model, test the connection, and set generation parameters and cost/call limits. AI configuration does not remove professional review,…

By India Audit Lens product team · Updated 2026-07-17

Complete governance checks first

Confirm the firm has approved the provider, model, purpose, data region/retention terms, and client-data handling. Create a firm-owned restricted API key with the minimum required scope and provider-side budget. Decide which workflows may use AI and who reviews every output. Set a monthly cost ceiling and maximum calls per audit run. Prepare non-client synthetic text for the connection/functional test.

Configure and test a provider

Navigate to Settings → Integrations → AI. Review whether a provider is already marked configured; existing secrets are not displayed. Enable AI features only after approval. Choose Default provider. Under Anthropic, OpenAI, or Groq, enter the API key and select the approved Model. Click that provider's connection-test action. Confirm the success message identifies the expected provider/model. If the test fails, correct credentials, provider access, model name, network, or quota without exposing the key in a support screenshot.

Entering a blank/masked field must not be assumed to recover an old key. Follow the page behaviour and provider key-rotation process.

Configure parameters and limits

Set Max tokens appropriate for the supported output size. Set Temperature under the firm's consistency policy; higher values can increase variation. Set Monthly budget (USD) in addition to provider-side limits. Set Max LLM calls per audit run to prevent uncontrolled looping/cost. Click Save AI settings and wait for AI settings saved successfully. Reopen the page and verify provider/model/limit settings without expecting the secret to be revealed.

Validate a real workflow safely

Use a synthetic/test engagement and non-confidential data. Run one supported AI action. Confirm provider/model, output provenance/status, cost/call behaviour, and failure handling. Review the result for unsupported legal/accounting claims, hallucinations, missing evidence, and privacy leakage. Confirm the product still requires the appropriate user review/approval before downstream use.

Rotate or disable

Create the replacement key at the provider before revoking the old one when continuity matters. Enter and test the replacement in AuditLens. Save, run a synthetic check, then revoke the old provider key. To suspend use, disable AI features and save; also revoke the provider key when compromise is suspected. Review provider usage logs and AuditLens activity under the incident procedure.

Expected result

Only approved providers/models are configured, secrets remain concealed, connection tests pass, budgets/call limits are set, and every AI output remains a reviewable draft rather than evidence or a professional conclusion by itself.

Related pages

Book a demo or run one engagement free.