Auditor Guidance on AI Systems
The one-paragraph answer
AICPA AI guidance shapes how external auditors evaluate AI use at their clients. The American Institute of Certified Public Accountants issues guidance for CPAs conducting audits of private and mid-sized companies. Its guidance now covers AI risk assessment, AI in financial systems, AI in ICFR, and audit evidence considerations when AI is involved. Companies being audited need to understand what their auditors are looking for.
Companies used to think AI adoption was an operational decision. It is now an audit topic. When an external auditor arrives for the year-end audit, they ask about AI systems in the financial close, in revenue recognition, in expense classification, and in fraud monitoring. If the answers are vague, the audit gets harder. Well-prepared companies have documentation ready; unprepared companies scramble.
Auditors must consider AI-related risks in planning the audit, including risks of material misstatement, ICFR risks, and specific AI risks like model drift, bias, or unauthorized changes.
AI used in revenue recognition, expense recording, receivables valuation, or other financial processes affects audit procedures. Auditors need to understand the AI, test its controls, and assess its outputs.
AI provided by third parties (SaaS AI features, embedded LLM services) is subject to SOC reports and other assurance mechanisms that auditors evaluate.
Auditors themselves use AI in audit procedures. AICPA AI guidance also addresses when AI tools are appropriate for audit work.
If you are audited by a CPA firm, AICPA AI guidance shapes what your auditor asks for. Being prepared reduces audit time, reduces fee escalation, and reduces the chance of audit findings.
The academic literature on AICPA AI guidance is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.
“The introduction of AI algorithms in public services modifies the chain of responsibility.”
That is the gap between having AI and governing it. The second finding is the one that tends to change the room.
“it remains challenging for practitioners to identify the harmful repercussions of their own systems prior to deployment”
Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about AICPA AI guidance arrives from the board, the buyer, or the regulator.
This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.
Done in this order, AICPA AI guidance becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.
Indirectly. It applies to your auditor, who applies it to your audit. What your auditor requires of you follows.
The Internal Audit Workpaper Log in Volume III of The Operating Discipline for AI Library™ is designed to be usable as evidence during external audits, coordinated with AICPA expectations.
Expect four lines of questioning. What AI systems touch amounts recorded in the financial statements, and how? What controls exist over those systems, specifically over who can change the model and how changes are approved? How do you know the AI is still working, meaning what monitoring detects drift or degradation? And what happened when it did not work, meaning show the incidents and the remediation. AICPA AI guidance pushes auditors toward evidence, not assurances.
When the AI is embedded in a SaaS platform your finance team uses, the auditor still needs comfort over it. That comfort usually comes from a SOC report, and many AI vendors either do not have one or have one that does not cover the AI functionality specifically. Where the report has a gap, the audit effort moves back onto you, which means more testing, more time, and a larger fee.
Have the inventory ready before the auditor asks. Map each AI system to the financial statement assertion it affects. Keep the change log. Keep the monitoring output. Keep the incident record. Firms that assemble this once and maintain it spend materially less on audit than firms that reconstruct it every year under deadline, and the difference compounds as AICPA AI guidance expectations tighten.
The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning AICPA AI guidance that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including AICPA AI Guidance, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →