web analytics
Financial Reporting Rules for AI

AICPA AI Guidance

Auditor Guidance on AI Systems

The one-paragraph answer

AICPA AI guidance shapes how external auditors evaluate AI use at their clients. The American Institute of Certified Public Accountants issues guidance for CPAs conducting audits of private and mid-sized companies. Its guidance now covers AI risk assessment, AI in financial systems, AI in ICFR, and audit evidence considerations when AI is involved. Companies being audited need to understand what their auditors are looking for.

The pain AICPA AI guidance is causing our customers

Companies used to think AI adoption was an operational decision. It is now an audit topic. When an external auditor arrives for the year-end audit, they ask about AI systems in the financial close, in revenue recognition, in expense classification, and in fraud monitoring. If the answers are vague, the audit gets harder. Well-prepared companies have documentation ready; unprepared companies scramble.

What AICPA AI guidance covers

Risk assessment

Auditors must consider AI-related risks in planning the audit, including risks of material misstatement, ICFR risks, and specific AI risks like model drift, bias, or unauthorized changes.

AI in financial systems

AI used in revenue recognition, expense recording, receivables valuation, or other financial processes affects audit procedures. Auditors need to understand the AI, test its controls, and assess its outputs.

Third-party AI

AI provided by third parties (SaaS AI features, embedded LLM services) is subject to SOC reports and other assurance mechanisms that auditors evaluate.

AI use by the auditor

Auditors themselves use AI in audit procedures. AICPA AI guidance also addresses when AI tools are appropriate for audit work.

Why AICPA AI guidance matters to you

If you are audited by a CPA firm, AICPA AI guidance shapes what your auditor asks for. Being prepared reduces audit time, reduces fee escalation, and reduces the chance of audit findings.

What the research says about AICPA AI guidance

The academic literature on AICPA AI guidance is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“The introduction of AI algorithms in public services modifies the chain of responsibility.”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“it remains challenging for practitioners to identify the harmful repercussions of their own systems prior to deployment”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about AICPA AI guidance arrives from the board, the buyer, or the regulator.

How to get compliant with AICPA AI Guidance: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under AICPA AI guidance. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities AICPA AI guidance reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation AICPA AI guidance expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, AICPA AI guidance becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about AICPA AI guidance

Does AICPA AI guidance apply to my company?

Indirectly. It applies to your auditor, who applies it to your audit. What your auditor requires of you follows.

Where does AICPA AI guidance fit in SRJ's work?

The Internal Audit Workpaper Log in Volume III of The Operating Discipline for AI Library™ is designed to be usable as evidence during external audits, coordinated with AICPA expectations.

What your auditor will actually ask under AICPA AI guidance

Expect four lines of questioning. What AI systems touch amounts recorded in the financial statements, and how? What controls exist over those systems, specifically over who can change the model and how changes are approved? How do you know the AI is still working, meaning what monitoring detects drift or degradation? And what happened when it did not work, meaning show the incidents and the remediation. AICPA AI guidance pushes auditors toward evidence, not assurances.

Third-party AI is the hardest part of the conversation

When the AI is embedded in a SaaS platform your finance team uses, the auditor still needs comfort over it. That comfort usually comes from a SOC report, and many AI vendors either do not have one or have one that does not cover the AI functionality specifically. Where the report has a gap, the audit effort moves back onto you, which means more testing, more time, and a larger fee.

How to make the audit cheaper

Have the inventory ready before the auditor asks. Map each AI system to the financial statement assertion it affects. Keep the change log. Keep the monitoring output. Keep the incident record. Firms that assemble this once and maintain it spend materially less on audit than firms that reconstruct it every year under deadline, and the difference compounds as AICPA AI guidance expectations tighten.

Primary sources on AICPA AI guidance

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning AICPA AI guidance that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including AICPA AI Guidance, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation