Inspection staff at the Public Company Accounting Oversight Board, the PCAOB, have been recording the same gap for years: in each of the 2021 and 2022 inspection cycles, roughly 17% of the comment forms issued to audit firms carried a deficiency about testing the accuracy and completeness of the data and reports the audit was relying on.
AI in auditing runs on exactly that information, faster, and often across a whole population instead of a sample. What it does not change is who has to establish that the population was complete, or whose name sits above the conclusion. The evidence standards were written around information rather than around the tool that processed it, which is why they answer most of a firm's AI questions before the demo starts.
What AI in Auditing Changes, and What It Does Not
Start from where the standard puts the tool. Audit evidence rules are written around information and the procedures applied to it, so a model is a way of obtaining and processing information rather than a source that speaks with authority of its own.
The technology is named in the text. SAS No. 142, Audit Evidence, which supersedes AU-C section 500 and is effective for audits of financial statements for periods ending on or after December 15, 2022, gives artificial intelligence, machine learning, remote observation tools and robotic process automation as examples of automated tools and techniques, at paragraph A4 (AICPA, SAS No. 142, Audit Evidence). Automated tools and techniques is the standard's own umbrella term for software that performs or supports an audit procedure.
Then it says what you owe that information. At paragraph 7 the auditor should evaluate information to be used as audit evidence by taking into account its relevance and reliability, including its source, and whether the information corroborates or contradicts assertions in the financial statements. Paragraph 8 adds two evaluations on top: whether the information is sufficiently precise and detailed for the auditor's purposes, and obtaining audit evidence about its accuracy and completeness, as necessary (SAS No. 142).
Public company work reaches the same place in its own words. AS 1105 states at .04 that the auditor must plan and perform audit procedures to obtain sufficient appropriate audit evidence to provide a reasonable basis for his or her opinion. Sufficiency, at .05, is the measure of the quantity of audit evidence. Appropriateness, at .06, is the measure of its quality, meaning its relevance and reliability (PCAOB, AS 1105, Audit Evidence).
Sufficient appropriate audit evidence is the phrase both rulebooks turn on, and it is two tests rather than one. Most of what a tool improves lands on the first.
Reliability Turns on Four Attributes, and a Tool Does Not Change Them
The reliability of information to be used as audit evidence is affected to varying degrees, individually or in combination, by its accuracy, its completeness, its authenticity, and its susceptibility to management bias. Those four attributes "are also relevant when automated tools and techniques are used to obtain audit evidence," at paragraph A27 (SAS No. 142).
That sentence answers the strongest claim a demo will make. A tool can raise the quantity of information you have looked at without touching any of the four, because all four are properties of the information itself, not of the procedure that read it. Coverage is a sufficiency argument. Reliability still has to be established separately, and it is usually established somewhere upstream of the tool.
The Population Came Out of a Client System
Here is where an AI-assisted procedure inherits an old problem rather than solving one.
Information produced by the company, which inspection staff shorten to IPC, covers company-produced material such as invoices the company issued, shipping documents it created, and other data and reports from company information technology systems. Approximately 17% of the total comment forms for each of the 2021 and 2022 inspection cycles contained deficiencies where the auditor did not perform sufficient procedures to test, or sufficiently test controls over, the accuracy and completeness of IPC or other data and reports, including information produced by service organizations (PCAOB staff, Inspection Observations Related to Auditor Use of Data and Reports, April 2024). A comment form is the initial communication to an audit firm of deficiencies observed during an inspection, so this is the early record rather than the published one.
The requirement behind those findings is short. When using information produced by the company as audit evidence, AS 1105 requires at .10 that the auditor evaluate whether the information is sufficient and appropriate for purposes of the audit by testing the accuracy and completeness of the information, or testing the controls over that accuracy and completeness, including where applicable information technology general controls and automated application controls, and by evaluating whether the information is sufficiently precise and detailed for purposes of the audit (AS 1105). General IT controls are the controls over a company's IT processes that keep its IT environment working properly, and the risk assessment chain that identifies and evaluates them sits upstream of everything here.
Private company work lands in the same place through paragraph 8 of SAS No. 142, and the application material gives the example that matters most for a full-population procedure. A population being tested for a certain characteristic, such as payment authorization, is affected by the completeness of the population from which items are selected, at paragraph A40 (SAS No. 142).
So the first question about an AI-assisted test is never about the model. It is which report produced the population, which system produced the report, and what your file says about the completeness of that report. PCAOB staff put the same point on their reminder list: it is important for the auditor to identify the sources of the underlying data in reports, as well as how the reports are generated, when testing data and reports that may be used as audit evidence (PCAOB staff, April 2024).
Electronic Information the Client Hands You Has a Rule of Its Own
A newer requirement sits directly on this ground. Amendments updating AS 1105, Audit Evidence, and AS 2301, The Auditor's Responses to the Risks of Material Misstatement, address aspects of designing and performing audit procedures that involve analyzing information in electronic form with technology-based tools, and they are effective for audits of financial statements for fiscal years beginning on or after December 15, 2025 (PCAOB, Amendments Related to Aspects of Designing and Performing Audit Procedures That Involve Technology-Assisted Analysis of Information in Electronic Form).
The new paragraph .10A covers information the company received from an external source and then passed to you in electronic form. Using such information as audit evidence, the auditor should evaluate whether it is reliable by obtaining an understanding of the source the company received it from and of the company's process for receiving, maintaining and, where applicable, processing it, including the nature of any modifications made before it reached you. The auditor should then either test the information to determine whether the company modified it and evaluate the effect of any modifications, or test controls over receiving, maintaining and processing it (AS 1105).
Read that beside a tool that ingests a client-supplied export. The export is the thing under suspicion, and a model has no way to tell you whether the file it read is the file the bank sent.
A Full Population Scan Ends With a List, and the List Is Yours
The capability is genuine, and the standard describes it without hype. By using automated tools and techniques, auditors may be able to perform recalculation procedures on 100 percent of a population, and may scan an entire population of transactions to identify those meeting the auditor's criteria for a transaction being unusual, at paragraphs A57 and A61 (SAS No. 142).
The judgment does not travel with the coverage. The same application material says analytical procedures also provide audit evidence about the items not exhibiting characteristics of risks of material misstatement, because the auditor has determined, exercising professional judgment, that the items not selected for further audit procedures are less likely to be materially misstated (SAS No. 142). Somebody has to reach that determination and be able to explain it.
On the public company side the follow-through is written as a requirement rather than as guidance, and it arrives on the same clock as AS 1105 .10A. Paragraphs .48, .49 and .50 of AS 2301 are new paragraphs added by the same technology-assisted-analysis amendments, effective for audits of financial statements for fiscal years beginning on or after December 15, 2025 (PCAOB Release No. 2024-007).
When performing a test of details, the auditor may identify items that require further investigation, and AS 2301 says at .49 that the investigation of those items should include determining whether they, individually or in the aggregate, indicate misstatements to be evaluated in accordance with AS 2810, Evaluating Audit Results, or deficiencies in the company's internal control over financial reporting (PCAOB, AS 2301).
The items the tool did not flag are covered as well. Where the auditor selects specific items for testing, .50 requires the auditor to determine whether there is a reasonable possibility that the remaining items include a misstatement that, individually or aggregated with others, would have a material effect on the financial statements. Where that possibility exists, the auditor should perform substantive procedures that address the assessed risk (AS 2301).
A tool that returns a queue of flagged entries has not finished a procedure. It has produced work, and the reviewer hours that queue will cost are the number worth estimating before a license is signed. Sampling and the confirmation process have answers of their own, and which audit acts can move to another pair of hands at all is settled there rather than here.
Who Is Answerable Once the Tool Has Run
The regulator's own outreach records how firms have answered this. PCAOB staff reported that firms investing in generative AI tools, or GenAI, expect the technology to augment rather than replace humans in auditing. The same update records two firm positions that matter more than the forecast does: an engagement team member who uses a GenAI-enabled tool is still responsible for the results and documentation of the work, and supervisors who review work performed with the assistance of GenAI are expected to apply the same level of diligence as when reviewing work where GenAI was not involved (PCAOB staff, Staff Update on Outreach Activities Related to the Integration of Generative Artificial Intelligence in Audits and Financial Reporting, July 2024).
Staff also recorded the limits firms had set for themselves, which is the part a vendor will not read to you. Some firms said GenAI output may not always be reliable, because it can generate content that is false or misleading, so-called hallucinations, or content that is skewed or biased. Some firms did not allow GenAI to be used at all when performing audit or attest procedures, citing data privacy concerns and reliability concerns about the output (PCAOB staff, July 2024).
Where a tool's output and your other evidence disagree, the standard gives you a duty rather than a preference. The auditor should determine whether modifications or additions to audit procedures are necessary to resolve inconsistencies in, or doubts about the reliability of, audit evidence, including when evidence obtained from one source is inconsistent with evidence obtained from another, and when the results of one audit procedure are inconsistent with the results of another, at paragraph 10 (SAS No. 142).
Two adjacent questions have their own answers: what a finished file has to contain and when it has to be assembled, and whose identity software acts under once it stops drafting and starts doing.
When the Client Is the One Using AI
The harder version of this question is not about your tools at all. It is about a client running AI inside the system that produces the numbers you are auditing.
SAS No. 145, which supersedes AU-C section 315 and is effective for audits of financial statements for periods ending on or after December 15, 2023, handles it in its appendix on understanding IT. Entities may use emerging technologies, for example blockchain, robotics or artificial intelligence, and when such technologies are used in the entity's information system relevant to the preparation of the financial statements, the auditor may include them in the identification of IT applications and other aspects of the IT environment that are subject to risks arising from the use of IT (AICPA, SAS No. 145).
Then it closes the door on the obvious follow-up. Although emerging technologies may be seen as more sophisticated or more complex than existing ones, the auditor's responsibilities in relation to IT applications and identified general IT controls under paragraphs 28 and 29 remain unchanged (SAS No. 145).
That closing clause is the practical one. A client's new AI-driven billing or revenue tool is not a new category of audit work. It joins the same list of IT applications, and the identification and evaluation chain your risk assessment already runs is the one that applies to it. What it does cost is scoping time. A tool bought by a department rather than by IT may not appear on the system inventory the client handed you last year, so ask what has been added since that inventory was written.
Questions Firms Ask
Is AI Being Used in Auditing Yet?
Partly, and mostly not where the marketing points. In limited PCAOB staff outreach with the US global network firms and several US non-affiliated firms that audit more than 100 issuers, the integration of generative AI appeared to be focused primarily on administrative and research activities, such as preparing certain administrative documents or initial drafts of memos, and researching internal accounting and auditing guidance, though most of those firms saw potential for using it in aspects of planning and performing the audit (PCAOB staff, July 2024).
Is AI a Threat to Audit Quality?
The honest answer is that no AI-specific PCAOB standard or guidance exists yet, so a tool gets measured against the ordinary evidence requirements rather than against a rule of its own. A PCAOB board member, speaking for herself rather than for the Board, described a hypothetical in which an audit firm uses an AI tool to test 100% of journal entries rather than taking the traditional manual sampling approach. Her concern was that unclear standards and guidance on what constitutes an acceptable AI-based audit could push that firm back to manual sampling, because sampling is the safer compliance position. The remedy she pointed to came from the PCAOB's Technology Innovation Alliance Working Group, a panel of external technology specialists the Board convened in 2022, whose deliverable recommends that the PCAOB consider developing risk management guidance containing principles and frameworks to help audit firms responsibly use AI in auditing (Christina Ho, AI and the Pursuit of Audit Quality: A Regulatory Perspective, September 16, 2025).
Until such guidance exists, your file is where the answer gets written. Record why the tool's output was appropriate for the assertion you used it on, and what you did with the items it flagged.
Will AI Replace Accountants and Auditors?
Not in the shape the question is usually asked. The firms PCAOB staff spoke to said they expect these tools to augment, but not replace, humans in auditing or in financial reporting (PCAOB staff, July 2024), and the evidence standards keep the conclusion, and the responsibility for it, with a person either way. The useful version of the question is a sorting exercise rather than a forecast, and the task-by-task sort is worked through elsewhere.
Start With the Reports Your File Already Depends On
Pull the last audit file your firm released and list every report that came out of a client system: the transaction listing behind a test of details, the subledger behind a lead schedule, the export behind an analytic. Against each one, write which system produced it, who ran it, and what the file says about its completeness. That list is exactly what an AI tool inherits on its first day, and it is what the standards ask about first.
None of that work disappears when software runs the first pass. Someone still has to build and reconcile the population, tie a report back to the system of record, chase the client for what is missing, prepare the workpaper that records the linkage, and hand a reviewer something gradeable. That is preparation work, and every hour of it lands on the same people who have to reach the conclusion it supports.
If what actually limits your firm is that the people who review audit files are the same people carrying the year-round accounting underneath them, don't trust us, test us. Accountably places trained offshore accountants and tax preparers inside US CPA, EA and accounting firms, working on the firm's own software and SOPs, with the signature and the final judgment staying with the firm. The scope is accounting and tax work rather than audit fieldwork. Since 2022 that has meant 20+ US firms and 30+ placements.
The entry point is deliberately small. A Free 40-Hour Proof Pilot puts a fixed block of your own representative work through the offshore team and your review chain, so your reviewer grades real output before a client file depends on it. If a placement is not the right fit inside the first 30 days, the 30-Day Fit Guarantee replaces them free.
