01The PCAOB codified auditor responsibility without naming AI
On June 12, 2024, the PCAOB adopted amendments to AS 1105 (Audit Evidence) and AS 2301 (The Auditor's Responses to the Risks of Material Misstatement). The SEC approved the amendments on August 20, 2024, with an effective date for audits of fiscal years beginning on or after December 15, 2025. The amendments address "technology-assisted analysis of information in electronic form." The term AI does not appear. Because the language is technology-neutral, however, any audit procedure that uses AI falls within scope.
Three new requirements were introduced. First, when analyzing electronic information, auditors must evaluate reliability by testing IT general controls and automated application controls. Second, when technology-assisted analysis serves more than one audit purpose, each objective must be independently achieved. Third, when items meeting specified criteria are identified, auditors must determine whether those items — individually or in the aggregate — reveal misstatements or control deficiencies. Each requirement asks not just what the tool produced, but how the auditor evaluated the output.
02Full-population testing eliminates sampling risk but creates new ones
Traditional auditing relied on statistical sampling. A subset of transactions was selected, tested, and the results extrapolated to the whole. Because the process was inferential, the possibility that misstatements lurked in untested transactions could not be eliminated. This is sampling risk.
AI-driven full-population testing changes this structure. In April 2026, EY announced the integration of agentic AI into EY Canvas, its global audit platform. The platform processes 1.4 trillion journal entry lines annually and supports approximately 160,000 audit engagements. When every transaction can be screened for anomalous patterns, sampling-based oversights disappear. Low-frequency irregularities — a fraudulent journal entry that occurs only once or twice a year — are difficult to catch through sampling but become visible under full-population testing.
Full-population testing, however, trades sampling risk for other risks. If data completeness is not assured, the analytical premise collapses. If the algorithm's design carries bias, certain anomalies will be missed. And at the most fundamental level, interpreting what a flagged transaction means — deciding whether it constitutes a misstatement — is a human task.
03The IAASB redefined audit evidence for a digital environment in its ISA 500 exposure draft
On August 5, 2026, the IAASB published proposed revisions to ISA 330 (Risk Response), ISA 500 (Audit Evidence), and ISA 520 (Analytical Procedures). The comment deadline is December 15, 2026. The objective is to revise the definition of audit evidence for digital environments and to strengthen the requirements for evaluating the relevance and reliability of information used as evidence.
The current version of ISA 500 became effective in 2009. At that time, most data auditors handled consisted of paper vouchers or structured data extracted from ERP systems. Seventeen years later, auditee business systems have migrated to API integrations and real-time cloud processing. The evidence auditors receive has shifted accordingly — from PDF invoices to database query results and AI-generated analytical reports. The exposure draft requires auditors to evaluate the provenance and creation process of such evidence.
The draft also reinforces the application of professional skepticism. Multiple sections require auditors not to take evidence reliability for granted and to actively seek contradictory information.
04Japan's JICPA mapped AI audit challenges in Research Document No. 11
The Technology Committee of the Japanese Institute of Certified Public Accountants (JICPA) published Research Document No. 11, "Research Document on the Use of AI in Auditing," on August 9, 2024. An English translation followed in April 2025. The document acknowledges that major audit firms have advanced the development and deployment of AI audit tools and organizes the practical challenges that accompany their use.
The challenges fall into three categories. First, development risk: the quality and bias of training data can affect audit conclusions. Second, deployment risk: audit teams may over-rely on AI tool outputs and neglect to re-examine flagged anomalies. Third, information security risk: sending auditee financial data to external AI services raises questions of confidentiality compliance.
Research Document No. 11 is not a binding standard. It is, however, the first official JICPA publication to address the relationship between CPAs and AI, and it signals the direction of future standard-setting.
| Body | Document / Standard | Timing | Approach to AI |
|---|---|---|---|
| PCAOB | AS 1105 & AS 2301 amendments | Adopted June 2024, effective December 2025 | Technology-neutral language brings AI within scope |
| IAASB | ISA 330, 500 & 520 exposure draft | Published August 2026, comments due December 2026 | Strengthens evidence evaluation for digital environments |
| JICPA | Technology Committee Research Document No. 11 | Published August 2024 | Maps AI audit tool challenges; non-binding |
05Professional skepticism applies to AI output as much as to any other evidence
Professional skepticism is the attitude of critically evaluating information and evidence, consistently required of auditors across all auditing standards. PCAOB AS 1015 defines it as "a questioning mind." IAASB ISA 200 describes it as "an attitude that includes a questioning mind" and "a critical assessment of audit evidence."
When AI performs part of the audit procedure, the scope of that skepticism expands. Accepting an AI-generated list of anomalous transactions without challenge means declining to consider transactions not on the list. Failing to re-examine areas the AI deemed problem-free amounts to abdicating judgment. Researchers at Nyenrode Business Universiteit have identified automation bias as the primary risk to auditor skepticism: the tendency to act on the assumption that machine output is correct. This phenomenon has been documented repeatedly in aviation and healthcare human-factors research, and the same dynamic applies to auditing.
The PCAOB's amended AS 1105 requires auditors to exercise judgment at each stage when using technology-assisted analysis: design, information reliability, and result evaluation. This structure explicitly excludes the stance of "the AI said so, therefore it is correct."
06In pharmaceutical audits, clinical trial accruals and revenue recognition become AI verification targets
Pharmaceutical financial reporting contains areas where AI-driven full-population testing is particularly valuable: clinical trial cost accruals and revenue recognition.
Clinical trials span multiple years, and payments to CROs (contract research organizations) are recognized based on progress. CRO invoicing and actual progress do not always align, and period-end accrual amounts involve estimation. When an auditor samples only a handful of contracts, verifying the reasonableness of accruals across hundreds of trials is difficult. AI that cross-references milestone completion status against payment records for every contract can comprehensively test estimation accuracy.
Revenue recognition under the IFRS 15 five-step model raises additional issues. The allocation of transaction prices across license agreements, milestone payments, and royalties varies by company, and accounting treatment involves judgment. AI that checks consistency against comparable past contracts and flags unusual allocation patterns allows auditors to focus their judgment on the most consequential items.
The final determination of whether an accrual is reasonable, however, rests with the auditor. AI can flag a contract whose accrual deviates from historical trends. Whether that deviation reflects a legitimate business decision or an error is a question that requires understanding the business context — a human task.
07The opinion signatory must retain the authority to override AI output
Big Four AI investment is accelerating. KPMG has committed $2 billion to cloud and AI capabilities. EY has embedded agentic AI into the platform used by 130,000 assurance professionals. Deloitte projects a 25% cost reduction in finance functions through AI agents. Yet the person who signs the audit opinion is an individual CPA, not a firm. Unless the signatory can understand AI output and override it when necessary, audit quality assurance does not function.
Three practical structures are needed. First, the audit team must design the criteria for determining which AI-detected anomalies warrant investigation; threshold-setting cannot be left entirely to algorithms. Second, the correspondence between AI output and auditor judgment must be documented in working papers — a record stating, for example, that "of 1,200 anomalies detected, 50 were selected for focused investigation; the remainder were assessed as not requiring additional procedures based on materiality and prior experience." Third, procedures for evaluating the impact of AI tool version changes and training data updates on audit conclusions must be built into the quality management system.
This is precisely what the PCAOB's AS 1105 amendments require. Regardless of how technology evolves, the responsibility for evaluating whether audit evidence is sufficient and appropriate belongs to the auditor.
Information reliability evaluation
Evaluate completeness and accuracy of data fed into AI through testing of IT general controls and automated application controls. If the data is unreliable, the AI output is unreliable.
Pre-designed anomaly criteria
Auditors participate in defining thresholds and patterns the AI uses for detection, avoiding full delegation to algorithms. Industry- and entity-specific judgment is essential.
Output-to-judgment documentation
Document the number of anomalies detected, the rationale for selecting investigation targets, and decisions on whether additional procedures are needed. This supports third-party quality review.
Tool change impact assessment
Changes to training data or algorithms may produce different detection patterns year over year. Identifying changes and ensuring audit consistency is a quality management requirement.
08"The AI said so" is not a defense in auditing
The speed at which AI is being integrated into audit procedures is high. EY's announcement indicates plans to apply agentic AI across all audit phases by 2028. Once the IAASB's ISA 500 exposure draft is finalized, international audit standards will be aligned with digital environments. Full-population testing adds to auditing the capacity to detect low-frequency anomalies that statistical sampling could never find.
Yet standard-setters are consistent on one point: technological progress does not reduce the auditor's responsibility. The PCAOB's amendments state explicitly that the auditor is responsible for determining whether technology-assisted analysis produces sufficient appropriate audit evidence. JICPA's Research Document No. 11 lists over-reliance on AI tool output as a key challenge. If an audit opinion proves wrong, "the AI made that determination" will not serve as a defense before a board of accountancy.
What the era of full-population testing demands of auditors is not the ability to work without AI, but the discipline to maintain skepticism toward AI output, to document their own judgments, and to accept the responsibility that comes with signing.
- The PCAOB amended AS 1105 and AS 2301 in 2024, codifying three responsibilities for auditors using technology-assisted analysis: information reliability evaluation, achievement of each audit objective, and judgment on results. Although AI is not named, technology-neutral language brings it within scope.
- AI-driven full-population testing eliminates sampling risk while introducing new risks around data completeness, algorithmic bias, and automation bias. Professional skepticism applies to AI output just as it does to any other form of audit evidence.
- The CPA who signs the audit opinion bears the obligation to understand AI output, override it when necessary, and document the rationale in working papers. "The AI said so" is not a defense in disciplinary proceedings.
Full-population testing enhances audit detection power. The ability to find a single anomalous journal entry in a year's worth of transactions is something sampling never offered. But detection and judgment are distinct acts. Between finding an anomaly and determining that it constitutes a misstatement lies a gap that requires business understanding and professional skepticism. The PCAOB, the IAASB, and the JICPA are all updating their standards to accommodate technological change, but on the question of accountability, they are unanimous: it stays with the person who signed. No matter how much AI transforms the audit, that principle does not change.
- PCAOB. PCAOB Updates Its Standards To Clarify Auditor Responsibilities When Using Technology-Assisted Analysis. June 12, 2024. https://pcaobus.org/news-events/news-releases/news-release-detail/pcaob-updates-its-standards-to-clarify-auditor-responsibilities-when-using-technology-assisted-analysis
- SEC. SEC Approves New and Updated PCAOB Audit Standards. August 20, 2024. https://www.sec.gov/newsroom/press-releases/2024-100
- IAASB. Proposed Revisions for Audit Evidence & Risk Response: ISA 330, ISA 500 & ISA 520. August 5, 2026. https://www.iaasb.org/publications/proposed-revisions-audit-evidence-risk-response-isa-330-isa-500-isa-520
- JICPA. Technology Committee Research Document No. 11: Research Document on the Use of AI in Auditing. August 9, 2024. https://jicpa.or.jp/specialized_field/20240813dfu.html
- EY. EY launches enterprise-scale agentic AI to redefine the audit experience for the AI era. April 7, 2026. https://www.ey.com/en_gl/newsroom/2026/04/ey-launches-enterprise-scale-agentic-ai-to-redefine-the-audit-experience-for-the-ai-era
- Nyenrode Business Universiteit. AI in auditing: balancing quality, professional skepticism, and responsibility. 2025. https://www.nyenrode.nl/en/news/n/ai-auditing-quality-skepticism-responsibility
- Deloitte Japan. Explanation of Technology Committee Research Document No. 11. January 2025. https://www.deloitte.com/jp/ja/services/audit-assurance/perspectives/kaikeijyoho-202501-02.html
- The CAQ. Auditors and AI in the New Era of Audit. 2025. https://www.thecaq.org/aia-auditors-and-ai-in-the-new-era-of-audit