Key insights
- The PCAOB has not issued a standard written for AI, and its June 2024 technology amendments excluded it.
- Under QC 1000, approving and monitoring AI tools is part of the firm's quality-control system rather than an IT decision.
- The PCAOB is already asking about AI use during inspections, and a traceable record of source material, output, and team review makes those conversations easier.
A senior associate drops a GenAI-drafted risk assessment memo into the workpapers on a Tuesday afternoon. The output reads well, the citations look right, and the reviewer has three other files waiting. Six months from now, will the engagement file show which prompts were used, which source documents the model read, and where the reviewer's own judgment entered the workpaper? If an inspector asked, could the team walk them through it?
The PCAOB has not issued a single rule written specifically for AI. But existing standards on evidence, documentation, review, and quality control still apply to any work an AI tool touches, and inspectors are already asking firms how they use these tools. This article covers where the PCAOB stands today, what its GenAI Spotlight and recent inspections signal about where the risk actually lives, and how firms should evaluate AI tools before an inspector asks.
What is the PCAOB's position on AI in audit?
The Board has been clear that AI does not change who is responsible for the audit. Generative AI may affect audit planning and performance, but auditor responsibility for due professional care and professional skepticism does not shift. No tool, however capable, moves the standard of care or the burden of judgment away from the humans on the engagement.
Board members have publicly discussed how AI can reimagine accounting and auditing, and whether the PCAOB should issue AI-specific guidance and a risk management framework, but the questions remain open. Any future rulemaking is expected to leave room for firms of all sizes to use AI responsibly rather than lock the profession into a narrow definition of acceptable tools. Until that happens, firms are operating under guardrails that predate the technology, with inspectors still calibrating what they expect to see.
Why the PCAOB's interest in AI is intensifying
The Board's historical preference has been for technology-neutral standards, so a firm's choice of tool did not usually shape what an inspector wanted to see. AI is testing that preference. Technology-neutral standard-setting can discourage AI adoption when firms need clearer boundaries and adoption is moving faster than firms can document and defend.
Several developments are compressing the timeline at once:
- A dedicated research effort. The PCAOB's Data and Technology project is assessing whether new guidance or changes to standards are needed as AI use grows.
- Calls from within the profession. The Technology Innovation Alliance working group has called for risk management guidance with AI-specific principles and frameworks.
- A shift from generative to agentic tools. Agentic AI can move beyond generative AI to handle multistep plans and file manipulation with less human input, changing what a firm has to supervise.
- Parallel movement at the SEC. Auditors evaluating a client's use of AI in internal control need to understand and document how AI models are designed to perform their tasks, and that fraud risk may evolve with threats such as data poisoning and prompt engineering.
Firm leaders need to know how much of their AI use can be explained before an inspection team asks. None of these four developments is waiting for a formal AI standard to arrive, which is exactly why the clearest written signal firms have, the staff Spotlight, is worth taking seriously.
What the PCAOB Spotlight says about GenAI in audits
The July 2024 GenAI Spotlight is the most concrete read available on how the PCAOB is thinking about GenAI right now. It is based on outreach to firms that audit the majority of issuers by market capitalization, and it reflects staff views rather than binding rules. Firms should treat it as a preview of what inspectors will look for.
A few consistent themes come through:
- Use is concentrated in low-risk areas. Most GenAI use sits in administrative and research tasks, while firms test where it can support planning and audit performance.
- Firms are calibrating carefully. According to the Spotlight, some outreach participants are keeping GenAI out of audit or attest procedures for now, citing data privacy and reliability concerns about tools that were not built for that context.
- Auditability cuts both ways. It matters for both the source data fed into a GenAI tool and the GenAI-generated content.
- The file has to reflect the work. AI-assisted procedures need to be documented like any other procedure: the information used, the output produced, and the reasoning that supports the team's conclusion.
AI does not create a separate compliance track. It routes back into the same evidence, documentation, and quality-control expectations that already apply to every audit.
What existing PCAOB expectations still require when AI is used
The standards already on the books apply to AI in a fairly mechanical way. A procedure performed with an AI tool must still produce sufficient and appropriate audit evidence, and the file must defend it in the same way. Consider a control testing procedure in which the team uses an AI tool to review 200 access-review sign-offs pulled from the client's portal: the workpaper must still show which population the tool covered, which items it flagged as exceptions, and how the team followed up on them. The June 2024 technology amendments did not carve out AI or lower that threshold, so electronic information still needs to be reliable, and a procedure used for more than one purpose must meet each objective.
AI changes how easily a team can meet those requirements, even when the requirements themselves stay the same. Two areas carry most of the inspection risk for AI-assisted work: quality control, which determines what a tool is allowed to do within the firm, and automation bias, which determines how carefully a team engages with the tool's output.
AI tool governance belongs in quality control
AI adoption is a quality-control decision as much as a technology one. QC 1000, the firm's quality control system, sets requirements for technology resources, and a related 2024 rulemaking on technology-assisted analysis placed the evaluation of tool appropriateness within the firm's quality control system.
In practice, that means the firm has to show it has thought through whether a given AI tool can hold up in an engagement: whether it produces a reliable evidence trail, whether it protects firm and client data, and whether the work remains defensible when teams depend on it. That evaluation belongs to the same governance body that approves other engagement technology, and the approval needs to sit in a file someone can point to.
Automation bias remains an evidence and documentation risk
Automation bias is the tendency to favor automated suggestions and miss contradictory information. A confident-sounding output from any tool can quietly stand in for the team's own evaluation, especially under deadline pressure, which is why review has to be built into the workflow rather than left as a manual afterthought. If a sample item flags a control deviation the AI summary skimmed past, the workpaper has to reflect that the reviewer caught it. That kind of visible judgment is what an inspector will look for first.
Unmanaged AI use creates inspection risk
The consequences of these expectations are already landing through inspections rather than through a new rulebook. The PCAOB has signaled that it will inquire about AI use during inspections, particularly where technology addresses identified risks of material misstatement. When no AI-specific standard applies, it creates regulatory-by-inspection pressure: the bar can feel higher than expected, even though no written rule tells firms in advance what inspectors will ask.
That pressure is already showing up in firm-specific inspection work. In the 2024 PwC inspection report, the PCAOB assessed the firm's use of AI technologies for recently IPO'd biotech issuers, as well as its cash flow and segment reporting procedures. An AI review appearing in an individual firm report is a signal worth paying attention to: it tells the market that AI usage is now something inspectors are willing to write about by name, on a firm-by-firm basis. Without proper governance, AI systems can produce misleading or fabricated output and can reflect existing biases.
A tool that produces a clear record of its inputs and reasoning makes an inspection conversation more straightforward, whereas a black-box tool leaves the team with less to work with. That difference is the practical filter that firms should apply when evaluating tools in the first place.
How firms should evaluate AI tools under PCAOB expectations
That filter turns into a short list of concrete questions, drawn directly from the Board's own open questions about AI. What a tool does in a demo matters less than what the engagement file can support afterward: if the workpaper cannot show the tool's work, the team's evaluation of the output, and where professional judgment entered the process, the time saved will not offset the documentation risk. Before adopting a tool, a firm needs to be able to answer:
- Can the tool itself be audited end-to-end?
- If the model is third-party-developed, can its behavior be explained?
- Have bias and auditability been considered in the context of the specific procedures the tool supports?
- Do the digitally native audit evidence and the underlying data hold up under scrutiny?
Inspectors will care about answers to those questions, well ahead of anything in the vendor pitch.
External frameworks can help organize the rest of the governance picture, and firms do not need to build it from scratch. The ISO 42001 standard offers a structured way to manage AI risks and opportunities, with independent bodies administering voluntary certification, providing firms with a reference point outside the audit profession. A useful governance lens is to separate what the firm is doing with AI in its own work from what its clients are doing with AI in theirs, since governance obligations look different in each direction.
Where Fieldguide fits in AI-powered engagement work
The PCAOB's concerns point in one direction: AI-powered engagement work has to be governed and traceable within practitioner-led workflows. Fieldguide's platform is built for that operating model: AI-assisted work runs within controlled workflows, and each agent run produces a Trace showing its inputs, outputs, and reasoning, which is kept with the engagement record. Fieldguide holds ISO 42001 certification, and practitioner review and approval remain part of any AI-assisted workflow, so the record an inspector would look for builds up as the team works through the Trace and the practitioner's own sign-off, rather than being rebuilt afterward. To see how the model handles governance in practice, request a demo.