Artificial intelligence in auditing sits within a uniquely complex regulatory space. While AI tools are widely deployed, they remain largely governed by existing legacy standards. However, the profession is experiencing the most significant reforms. This two-part article serves as a practical guide to help CPAs involved in external audits of public or private companies navigate the latest available guidance regarding AI in the audit process. Part 1 covers the PCAOB and AICPA landscape regarding AI standards and guidance; here in Part 2, we dive into AI risk areas in audits and professional liability implications.
AI-Specific Risk Areas in Audit Practice
Deploying AI in an audit environment introduces operational and behavioral risks that traditional legacy software never faced. Practitioners must actively manage five core risk areas:
Audit Evidence Quality: The baseline rules for verifying data under AS 1105—evaluating source independence, accuracy and completeness—apply directly to AI platforms.
Hallucination Risk: Large language model tools carry a risk with no analog in traditional audit: hallucination, the generation of plausible-sounding but factually incorrect information. PCAOB’s July 2024 GenAI Spotlight specifically noted this risk. An LLM asked to identify related-party transactions may fabricate references or miss actual transactions. Hallucination cannot be mitigated by prompt engineering alone; it requires explicit human verification of all AI outputs and documentation of that verification in the workpapers.
Automation Bias: Automation bias involves the cognitive tendency for practitioners to over-rely on or defer to software-generated outputs, potentially leading to a reduction in active information processing. Both the PCAOB and the AICPA have highlighted this behavioral risk in recent professional forums and staff updates, emphasizing that the use of advanced analytics or generative AI does not alter basic supervisory or professional skepticism requirements. To mitigate this risk, firms can focus on establishing clear internal review protocols that treat automated results as analytical inputs rather than definitive audit conclusions.
Algorithmic Bias: Algorithmic bias involves the risk that an AI model’s logic or underlying training data may skew its outputs, resulting in inconsistent risk scoring or flawed data classification. Practitioners can address this by reviewing available vendor documentation, system specifications, or independent third-party user reports to understand the model's design limitations, subsequently documenting how the tool’s parameters fit the specific engagement.
Vendor Supply-Chain Risk: Licensing AI platforms from third-party technology vendors introduces specific operational risks when software updates occur. If a vendor introduces an unannounced algorithmic update or baseline change to an underlying model between audit cycles, the tool’s logic and behavior may alter without the engagement team’s immediate awareness. To address this potential shift, practitioners can establish basic monitoring procedures, such as tracking vendor release notes, reviewing system version changes prior to starting a new audit cycle, and documenting how the software’s current state aligns with the prior year’s testing parameters.
Professional Liability Implications
Undisclosed AI Reliance and Workpaper Gaps: If an auditor relies substantially on an AI tool without documenting that reliance, the auditor faces dual exposure: an evidentiary gap under AU-C 230/AS 1215, and a potential argument in litigation that professional judgment was abandoned. AI-related securities litigation is rising: NERA’s 2025 Annual Review found 17 securities class action filings with AI-related claims in 2025 (8 percent of all new filings), and Stanford’s Securities Class Action Clearinghouse reported 12 AI-related filings in H1 2025 alone, which is on pace to exceed the 2024 total of 15. Most allege ‘AI washing’ (misrepresenting AI capabilities), but auditor liability theories based on inadequate evaluation of AI-generated evidence are an emerging risk in this litigation environment.
AI Tool Failure and the Vendor Defense: When an AI tool produces incorrect output and the auditor relies on it without independent verification, the auditor—not the vendor—bears professional responsibility. Vendor contracts universally disclaim liability for AI outputs used in professional services. This principle is now codified: the AS 1105 amendments require auditors to evaluate the reliability of technology-assisted outputs before treating them as audit evidence. The “I relied on the software” defense has been consistently rejected.
SEC Enforcement and AI Disclosures: The SEC Division of Examinations named AI a cross-cutting priority for the third consecutive year in its FY 2026 guidelines. Regulators are actively reviewing whether firms’ actual practices match their public AI disclosures, supervisory frameworks and security controls. Public company auditors must apply strict materiality standards to ensure client AI claims in annual reports are accurate and fully supported.
Data Privacy (CCPA/CPRA): AICPA Code of Professional Conduct Sec. 1.700.001 prohibits disclosure of client information without consent. Uploading client data to third-party AI platforms without client consent and appropriate data processing agreements may violate this obligation. Under the CCPA/CPRA, processing personal information via AI workflows can trigger strict data subject rights and processing limitations. California practitioners must exhaustively review vendor data-handling agreements against both AICPA and state privacy standards before letting any client data touch an AI workflow.
A Balanced AI Risk Approach
Managing AI risk within a CPA practice requires distinguishing between two separate operational environments: how the firm governs its own internal use of technology and how the firm designs procedures to audit clients who use AI in their financial reporting systems.
Internal Firm Governance
Firms must first establish clear internal protocols before deploying AI tools on live engagements. This begins with maintaining an updated inventory of all firm-used AI applications, classifying each by function and level of reliance to ensure workflows remain transparent for peer reviews.
Additionally, firms need a defined vetting process for both legacy software updates and new tools. This process must evaluate vendor data security, model limitations and compliance with confidentiality standards before ingesting client data. Once vetted, clear firm-wide policies must dictate exactly where these tools are permitted or restricted. Finally, continuous staff training is required to counter automation bias, paired with a structured internal process for teams to exchange practical deployment practices and documentation standards.
External Audit Procedures
The second layer focuses outward on how a client’s technology impacts their financial records. When a client implements AI within its accounting functions, the auditor's risk assessment must expand to evaluate those specific applications.
If a client relies on algorithms to generate estimates, automate journal entries or classify transactions, these systems directly affect the reliability of the information produced by the entity. The audit team may need to test the internal controls surrounding the client’s automated environment. The objective is to verify that client-generated AI data is accurate, complete and free of systemic error before it integrates into the general ledger.
Conclusion
The regulatory landscape indicates that the integration of AI into the audit workflow has transitioned from a theoretical concept into active practical application. At this stage, standard-setters are primarily leveraging modernized, existing baselines, such as the active AS 1105 amendments for public issuers and the core technology-validation requirements of AU-C Section 500 for private companies, to reinforce that final professional responsibility for the audit opinion remains strictly with the practitioner.
However, this framework represents only the starting point of a long-term, fluid transition. Because new software applications and automated tools are entering the market at a rapid pace, the regulatory guidelines and interpretations governing them are actively changing and will be subject to continuous modification in the future.
For practitioners, navigating this shift requires moving away from static compliance checklists in favor of continuous monitoring. To maintain a defensible audit methodology as technology matures, auditors must stay closely aligned with updates from primary authoritative channels and remain prepared to adapt their internal review procedures as official guidance evolves.
The opinions expressed are those of the author and should be taken as informational purposes only.
Svetlana Gadzhieva, CPA is a member of the CalCPA Accounting Principles and Assurance Services Committee. You can reach her at https://gadzhieva.com.

