Skip to main content

Key insights

  • No PCAOB standard for generative AI exists. Workpapers get judged under the standards you already follow.
  • Deficiencies land on files that can't show what the tool did and how the output was evaluated.
  • AI use needs a workpaper trail: inputs, outputs, exception handling, and sign-off.
  • An undocumented check reads, on inspection, exactly like a check that never happened.

A senior on your team runs a firm-approved AI tool over a batch of revenue contracts on a Sunday night, flagging any where the recognized amount doesn't tie to the terms. Monday morning, the output lands in the workpaper. The tool's name is right there in the header. What isn't there: the population the agent actually read, how the flagged exceptions got cleared, who approved the conclusion. That's the workpaper the inspector pulls.

The PCAOB hasn't issued a standard for generative AI, and it doesn't plan to anytime soon. It doesn't have to. The Part I.A deficiency rate for all inspected firms was 39% in 2024, and the technology-neutral standards behind those findings judge AI-assisted work the same way they judge everything else in the file. What follows is a read on where that bar already sits, and what a defensible AI-assisted engagement file looks like when the inspector arrives.

What has the PCAOB said about generative AI?

The published record on generative AI is thin, but the direction of travel is already visible. A Spotlight, a set of inspection priorities, a conversation with audit committee chairs, board-member speeches, and an ongoing research project all point the same way.

Start with the July 2024 staff Spotlight on GenAI outreach. Staff interviewed U.S. global network firms and several non-affiliated firms auditing more than 100 issuers. In 2024, most use was still admin and research work, though firms already saw real potential in planning and performing the audit. Two years on, that potential is no longer hypothetical. Two points still hold: firms did not name existing standards as the obstacle, and assigning a task to a tool doesn't move responsibility off the engagement team.

Then the December 2024 priorities Spotlight called out increased use of technology, including generative AI at public companies and broker-dealers, as an inspection focus.

No standard or staff guidance specific to AI has been issued. The Data and Technology project covers AI but sits in research, not standard-setting. That absence has already drawn a regulating-by-inspection concern in public board-member remarks.

Which PCAOB standards apply to AI-assisted audits?

Take the PCAOB's technology-assisted analysis amendments, adopted in 2024 and effective for fiscal years beginning on or after December 15, 2025. They update the audit-evidence and risk-response standards (AS 1105 and AS 2301) to spell out what auditors owe when they run procedures over large volumes of electronic data with technology-based tools. The adopting release doesn't mention artificial intelligence. The standards are technology-neutral, so they govern AI-assisted work by their own terms. A sample an agent pulled connects back to the assessed risk the same way a sample a senior pulled by hand does.

A firm-approved tool's output still needs evidence-level evaluation. The team has to know what data the tool used and whether the output is relevant and reliable for the assertion being tested. When the tool runs on client-produced data, you still owe support that the data is complete and accurate. Read the vendor's disclaimers, too: someone has to decide what those stated limits do to reliability.

Firm-level governance has its own deadline. QC 1000 asks whether your technology is reliable and secure enough to hold up your quality control system and your engagements. It's risk-based, and it takes effect December 15, 2026.

Before anyone points the tool at client data, a reviewer will want a simple approval trail. Approver and date. A short basis for approval that describes what the tool does and what client data it touches, with any vendor-stated limits. Evidence in the engagement file that the approved tool was used on the procedure it was approved for. Everything else in your technology policy hangs off that trail, and GenAI sits squarely inside it.

What do PCAOB inspectors look for in AI-assisted audits?

Start where the inspector will start: the procedure and the approval trail. The file should connect the procedure to the risk addressed and the evidence tested. Audits involving generative AI sit among the heightened deficiency-risk areas the PCAOB continues to watch, per then-Chair Erica Williams in a September 2025 interview. The inspections division set up a target team focused on emerging risks, including the use of software audit tools in selected audits.

In practice, that means walking an inspector through the procedure and the decisions behind it, not handing over a standalone tool-usage log. Expect the walkthrough to cover:

  • The risk the procedure was designed to address
  • Why the population the agent worked from was complete
  • How items were selected
  • What the preparer did when a result didn't tie
  • Who approved the conclusion

The conversations with chairs Spotlight put two AI risks on the audit committee agenda: overreliance on automation making auditors complacent, and new auditors struggling to build the skill to challenge AI responses. When your firm can walk a committee through exactly how AI outputs get validated, that conversation stops being a risk review and starts being a selling point.

What documentation does an AI-assisted audit need?

AI-assisted work generates output fast, so the documentation has to keep pace. A reviewer can only rely on what the file captured while the work happened.

AI-assisted workpapers are judged on the work, not the tool

Your workpaper still has to show the procedure performed and why the evidence supports the conclusion reached. For AI-assisted work, that means the file documents source-data completeness and accuracy, preserves the output itself, and captures the team's work on exceptions and contradictions.

Here's the shape of it. When an agent flags an exception, the reviewer's first stop is what the tool was fed and what the preparer did next. The workpaper needs the item the agent actually read, the preparer's note on whether the difference was a cutoff timing question or a misstatement, and the additional evidence that cleared it. The header alone leaves the evidence question wide open.

AI adds one more thing the file has to capture. Hallucination is one of the AI risks at issue: the tool can cite a source that doesn't support the point, so its output can't go in on faith. Ask it for its sources, check them against the response with the same skepticism you'd apply anywhere else, and leave that check in the workpaper.

A preparer who did the work and left nothing behind gives the inspector a file that's hard to defend.

AI-drafted files still face the experienced-auditor test

An experienced auditor with no prior connection to the engagement has to pick up your file and understand the work performed, including how the evidence supports the conclusion. That test doesn't bend because AI drafted the workpaper.

In practice, the file names the tool and the task it was given. It shows the data the tool used. It follows the team's output testing through approval and exception resolution. If the reader has to guess at any of that, you have the setup for a documentation deficiency.

One more clock to watch. The amended AS 1215 cuts the window to assemble the complete final set from 45 days to 14 days after the report release date, effective December 15, 2026. Teams that leave output validation to the assembly window are doing evidence work under a deadline built for collation. That's where firms actually diverge.

How do AI agents document audit work in the engagement file?

Keeping the work, the execution, the sign-off, and the file trail together takes an operating model, not a bolt-on. That's what Agent Workforce is built for. Field Agents validate uploaded evidence, run test procedures, and document draft results. Your practitioners direct the engagement and review agent outputs before anything becomes final.

The record builds during the engagement, not after it. Every agent run produces a Trace that captures inputs, outputs, and reasoning, with direct source references on the surfaces that support them. When a preparer picks up an agent's output, the Preparer Review Experience gives them a dedicated workspace to append notes and evidence before it moves to the manager. The human work sits next to the AI response, in the same file.

The governance comes with the platform, not something the firm has to prove on its own. Schellman certified Fieldguide as the first AIUC-1 platform for audit and advisory, which gives reviewers a concrete record for how agent-level behavior was evaluated. Fieldguide also holds organization-level AI governance certification, so the review covers both the tool and how agent behavior is monitored over time.

The same trail that holds up under inspection is where the time savings come from. In Fieldguide's case study, UHY reported a 20–30% reduction in engagement time, with some tasks going from three hours to 15 minutes.

Run AI-assisted audits you can defend

Inspection gets easier when documentation discipline is built into the tools your team already uses. Fieldguide covers the engagement lifecycle on a single platform, with the Agent Workforce executing the work and the file trail captured in the same workflow. The AIUC-1 certification gives you documented evidence to point to when a reviewer asks how the tool was evaluated and monitored. The platform captures the record; your firm retains the professional judgment. To walk through an AI-assisted engagement file end to end, request a demo.

Amanda Waldmann

Amanda Waldmann

Increasing trust with AI for audit and advisory firms.

fg-gradient-light