Artificial intelligence in auditing sits within a uniquely complex regulatory space. While AI tools are widely deployed, they remain largely governed by existing legacy standards. However, the profession is experiencing the most significant reforms. This two-part article serves as a practical guide to help CPAs involved in external audits of public or private companies navigate the latest available guidance regarding AI in the audit process. Part 1 covers the PCAOB and AICPA landscape regarding AI standards and guidance, while Part 2 dives into AI risk areas in audits and professional liability implications.
PCAOB: The U.S. Issuer Landscape
Following the appointment of Chairman Demetrios (Jim) Logothetis in early 2026, the PCAOB issued a public request for comment (RFC No. 2026-001) to shape its 2026–30 strategic plan. A central focus of this reset is gathering stakeholder input on how to update auditing standards to reflect the rise of AI in financial reporting. The Office of the Chief Auditor is also establishing a formal consultation process to handle novel AI-related auditing questions.
Amendments targeting technology-assisted analysis of electronic information are now fully effective for calendar-year 2026 audits:
AS 1105 (Audit Evidence): Auditors must evaluate the relevance and reliability of information obtained or processed using technology-based tools. When auditors test a company’s controls over electronic information, testing must include, where applicable, IT general controls relevant to that information.
AS 2301 (Risk Responses): When performing tests of details using technology-assisted analysis, auditors must investigate identified items to determine whether they individually or in the aggregate indicate misstatements or control deficiencies. The amendments explicitly do not cover AI specifically or firm-level AI tool governance.
The PCAOB explicitly noted that these amendments target general technology-assisted analysis, not AI-specific applications or firm-level AI governance. Because a formal safe harbor does not exist, firms operate on the assumption that legacy standards permit AI use, provided proper validation is in place.
Staff Spotlight: Where GenAI Stands in Practice
According to the PCAOB’s Staff Spotlight, generative AI deployment in public audits remains concentrated in administrative and research tasks, such as drafting memos, summarizing accounting policies and researching internal guidance. While full deployment in substantive testing is nascent, audit firms largely believe existing standards aren’t an impediment to adoption. However, the PCAOB has not formally confirmed this interpretation, meaning firms are proceeding on an assumption rather than a guaranteed safe harbor. To help bridge the gap, the PCAOB issued follow-up Staff Guidance in late 2025 with specific examples on evaluating electronic information reliability under AS 1105.
Industry Calls for Clear AI Guidance
The Technology Innovation Alliance (TIA) Working Group’s ‘Future State Deliverable’ recommended four strategic pillars:
Standardized audit documentation taxonomy;
AI risk management framework;
PCAOB Innovation Lab; and
Push for technology literacy.
While none of these are binding standards yet, major firms heavily emphasized the need for action in their responses to the PCAOB's March 2026 strategic request. Stakeholders are actively calling for clear, principle-based guidance on emerging tech to reduce compliance uncertainty, making AI and private equity the top two themes in recent submissions.
Inspection Findings: The Documentation Gap
Recent PCAOB inspection reports contain AI-related deficiencies concentrated in journal-entry testing: firms using AI-assisted anomaly detection without documenting how the algorithm was calibrated, what data it used, or how false-positive results were evaluated. Under AS 1105, this is a standard deficiency regardless of whether the AI output was ultimately correct. A PCAOB Board member publicly warned of a second risk: that inspectors might demand firms “turn over every rock” on AI model documentation, potentially making AI-assisted procedures costlier to defend than manual sampling—the opposite of the intended benefit.
Other PCAOB guidance to be aware of includes AS 2110—Identifying and Assessing Risks of Material Misstatement, PCAOB Release No. 2024-007—Adopting Release for AS 1105/AS 2301 Amendments and PCAOB Data and Technology Research Project.
AICPA: Non-Issuer and Private Company Guidance
While major technology shifts can feel decentralized, the AICPA has established explicit guardrails for integrating AI into private company audits. Firms must evaluate their AI adoption through two distinct, but interconnected, prisms: tactical execution on the engagement level and macro-level firm governance.
AI and Technology Execution at the Engagement Level
Rather than waiting for a standalone AI auditing standard, practitioners must evaluate AI tools through the lens of existing authoritative literature. In practice, the AICPA’s collective standards and framework resources from the AICPA & CIMA AI Resource Center dictate six core areas for the engagement team:
Tool selection and due diligence: Before ingested data ever hits an algorithm, auditors must verify vendor security and model constraints to avoid unauthorized disclosures under the Confidential Client Information Rule: Refer to AICPA Code of Professional Conduct 1.700.001 and CPA.com “AI Solution Due Diligence Guide for Accounting Firms.”
Understanding AI methodology: Because practitioners cannot treat AI as an unvetted “black box,” they must understand whether the tool relies on deterministic logic (exact mathematical calculations) or probabilistic models (predictive patterns and generative assumptions) to evaluate the reliability of the output. Refer to the technology validation and source data reliability frameworks in AU-C Section 500 (Audit Evidence).
Data quality: Advanced algorithmic tools are entirely dependent on the integrity of the data being ingested. When using information produced by the entity (IPE) as an input for automated tools, the auditor must perform procedures to evaluate whether that source data is sufficiently reliable for the audit purposes, including obtaining audit evidence about its accuracy and completeness. Refer to Artificial Intelligence: The data-driven audit.
Output evaluation and professional skepticism: While clean inputs are critical, the output carries the ultimate audit risk. An AI-generated exception report, automated classification, or green-lit dashboard does not constitute sufficient appropriate audit evidence on its own. Auditors must guard against automation bias—the tendency to blindly trust automated results—and actively evaluate the relevance and reliability of the software's final output before using it to support an audit conclusion. Anomalies or low-confidence outputs require manual, independent investigation.
Documentation (meeting AU-C 230): AU-C 230 (Audit Documentation) applies in full to AI-assisted procedures. Working papers must enable an experienced auditor with no prior connection to the engagement to understand the nature of AI procedures performed, the basis for conclusions, and significant judgments made in evaluating outputs. A generic “AI tool was used” notation does not satisfy this requirement.
Firm-Wide Technology Guidance: Beyond individual engagement workflows, the macro-level vetting, firm-wide policy implementation, and ongoing risk monitoring of these applications must be officially integrated into the firm's broader technology oversight systems. Refer to AICPA AI/Gen AI Future of Finance Research.
Continuous Monitoring of Authoritative Guidance
Because authoritative auditing standards and regulatory interpretations are dynamically evolving to keep pace with technology, practitioners cannot treat AI risk management as a static exercise. To maintain a defensible audit methodology, the key is knowing where to find the most current updates. Firms should continuously monitor changing compliance baselines through centralized primary repositories, specifically the AICPA & CIMA AI Resource Center.
To maintain an up-to-date and defensible audit methodology, firms should routinely consult centralized, primary authoritative repositories, specifically the AICPA & CIMA AI Resource Center and the technical implementation updates managed by CPA.com.
Dive into Part 2, which covers AI risk areas in audits and professional liability implications.
The opinions expressed are those of the author and should be taken as informational purposes only.
Svetlana Gadzhieva, CPA is a member of the CalCPA Accounting Principles and Assurance Services Committee. You can reach her at https://gadzhieva.com.

