A senior associate drops a GenAI-drafted risk assessment memo into the workpapers on a Tuesday afternoon. The output reads well, the citations look right, and the reviewer has three other files waiting. Six months from now, will the engagement file show which prompts were used, which source documents the model read, and where the reviewer's own judgment entered the workpaper? If an inspector asked, could the team walk them through it?
The PCAOB has not issued a single rule written specifically for AI. But existing standards on evidence, documentation, review, and quality control still apply to any work an AI tool touches, and inspectors are already asking firms how they use these tools. This article covers where the PCAOB stands today, what its GenAI Spotlight and recent inspections signal about where the risk actually lives, and how firms should evaluate AI tools before an inspector asks.
The Board has been clear that AI does not change who is responsible for the audit. Generative AI may affect audit planning and performance, but auditor responsibility for due professional care and professional skepticism does not shift. No tool, however capable, moves the standard of care or the burden of judgment away from the humans on the engagement.
Board members have publicly discussed how AI can reimagine accounting and auditing, and whether the PCAOB should issue AI-specific guidance and a risk management framework, but the questions remain open. Any future rulemaking is expected to leave room for firms of all sizes to use AI responsibly rather than lock the profession into a narrow definition of acceptable tools. Until that happens, firms are operating under guardrails that predate the technology, with inspectors still calibrating what they expect to see.
The Board's historical preference has been for technology-neutral standards, so a firm's choice of tool did not usually shape what an inspector wanted to see. AI is testing that preference. Technology-neutral standard-setting can discourage AI adoption when firms need clearer boundaries and adoption is moving faster than firms can document and defend.
Several developments are compressing the timeline at once:
Firm leaders need to know how much of their AI use can be explained before an inspection team asks. None of these four developments is waiting for a formal AI standard to arrive, which is exactly why the clearest written signal firms have, the staff Spotlight, is worth taking seriously.
The July 2024 GenAI Spotlight is the most concrete read available on how the PCAOB is thinking about GenAI right now. It is based on outreach to firms that audit the majority of issuers by market capitalization, and it reflects staff views rather than binding rules. Firms should treat it as a preview of what inspectors will look for.
A few consistent themes come through:
AI does not create a separate compliance track. It routes back into the same evidence, documentation, and quality-control expectations that already apply to every audit.
The standards already on the books apply to AI in a fairly mechanical way. A procedure performed with an AI tool must still produce sufficient and appropriate audit evidence, and the file must defend it in the same way. Consider a control testing procedure in which the team uses an AI tool to review 200 access-review sign-offs pulled from the client's portal: the workpaper must still show which population the tool covered, which items it flagged as exceptions, and how the team followed up on them. The June 2024 technology amendments did not carve out AI or lower that threshold, so electronic information still needs to be reliable, and a procedure used for more than one purpose must meet each objective.
AI changes how easily a team can meet those requirements, even when the requirements themselves stay the same. Two areas carry most of the inspection risk for AI-assisted work: quality control, which determines what a tool is allowed to do within the firm, and automation bias, which determines how carefully a team engages with the tool's output.
AI adoption is a quality-control decision as much as a technology one. QC 1000, the firm's quality control system, sets requirements for technology resources, and a related 2024 rulemaking on technology-assisted analysis placed the evaluation of tool appropriateness within the firm's quality control system.
In practice, that means the firm has to show it has thought through whether a given AI tool can hold up in an engagement: whether it produces a reliable evidence trail, whether it protects firm and client data, and whether the work remains defensible when teams depend on it. That evaluation belongs to the same governance body that approves other engagement technology, and the approval needs to sit in a file someone can point to.
Automation bias is the tendency to favor automated suggestions and miss contradictory information. A confident-sounding output from any tool can quietly stand in for the team's own evaluation, especially under deadline pressure, which is why review has to be built into the workflow rather than left as a manual afterthought. If a sample item flags a control deviation the AI summary skimmed past, the workpaper has to reflect that the reviewer caught it. That kind of visible judgment is what an inspector will look for first.
The consequences of these expectations are already landing through inspections rather than through a new rulebook. The PCAOB has signaled that it will inquire about AI use during inspections, particularly where technology addresses identified risks of material misstatement. When no AI-specific standard applies, it creates regulatory-by-inspection pressure: the bar can feel higher than expected, even though no written rule tells firms in advance what inspectors will ask.
That pressure is already showing up in firm-specific inspection work. In the 2024 PwC inspection report, the PCAOB assessed the firm's use of AI technologies for recently IPO'd biotech issuers, as well as its cash flow and segment reporting procedures. An AI review appearing in an individual firm report is a signal worth paying attention to: it tells the market that AI usage is now something inspectors are willing to write about by name, on a firm-by-firm basis. Without proper governance, AI systems can produce misleading or fabricated output and can reflect existing biases.
A tool that produces a clear record of its inputs and reasoning makes an inspection conversation more straightforward, whereas a black-box tool leaves the team with less to work with. That difference is the practical filter that firms should apply when evaluating tools in the first place.
That filter turns into a short list of concrete questions, drawn directly from the Board's own open questions about AI. What a tool does in a demo matters less than what the engagement file can support afterward: if the workpaper cannot show the tool's work, the team's evaluation of the output, and where professional judgment entered the process, the time saved will not offset the documentation risk. Before adopting a tool, a firm needs to be able to answer:
Inspectors will care about answers to those questions, well ahead of anything in the vendor pitch.
External frameworks can help organize the rest of the governance picture, and firms do not need to build it from scratch. The ISO 42001 standard offers a structured way to manage AI risks and opportunities, with independent bodies administering voluntary certification, providing firms with a reference point outside the audit profession. A useful governance lens is to separate what the firm is doing with AI in its own work from what its clients are doing with AI in theirs, since governance obligations look different in each direction.
The PCAOB's concerns point in one direction: AI-powered engagement work has to be governed and traceable within practitioner-led workflows. Fieldguide's platform is built for that operating model: AI-assisted work runs within controlled workflows, and each agent run produces a Trace showing its inputs, outputs, and reasoning, which is kept with the engagement record. Fieldguide holds ISO 42001 certification, and practitioner review and approval remain part of any AI-assisted workflow, so the record an inspector would look for builds up as the team works through the Trace and the practitioner's own sign-off, rather than being rebuilt afterward. To see how the model handles governance in practice, request a demo.