web analytics
Financial Reporting Rules for AI

PCAOB AI Guidance

Public Company Audit Standards for AI

The one-paragraph answer

PCAOB AI guidance governs audits of public companies. The Public Company Accounting Oversight Board sets standards for auditors of SEC registrants. Its AI-related guidance addresses how auditors evaluate AI use by clients, how AI affects ICFR audits, and how auditors themselves may use AI in audit procedures. Public companies face PCAOB scrutiny through their audit firms, and the standards are stricter than AICPA guidance for private companies.

The pain PCAOB AI guidance is causing our customers

Public company CFOs, controllers, and audit committee chairs are being asked more detailed questions than ever about AI in financial systems. PCAOB inspections drive audit firm behavior; audit firm behavior drives client requirements. When PCAOB signals that AI is an inspection priority, audit firms escalate their AI-related questions to clients. Documentation, control testing, and remediation costs all rise.

What PCAOB AI guidance covers

ICFR audits with AI

Section 404 requires public company management to assess ICFR and auditors to test it. AI systems in financial reporting must be included. PCAOB expects specific testing procedures for AI-driven controls.

Auditor risk assessment

Auditors must consider AI-related risks in planning, including model drift, unauthorized change, bias, and third-party AI dependencies.

Auditor use of AI

PCAOB has addressed when audit firms may use AI in audit procedures, what documentation is required, and what human review is expected.

Emerging standards

PCAOB is developing new standards specifically addressing AI in financial reporting. These will refine expectations further.

Why PCAOB AI guidance matters to you

Every public company faces PCAOB oversight through its audit firm. Any AI system in the financial close, ICFR, or reporting flow is now on the audit radar. Audit committee inquiries and management representation letters increasingly address AI.

What the research says about PCAOB AI guidance

The academic literature on PCAOB AI guidance is ahead of most corporate practice, and it is unusually blunt. Two findings are worth putting in front of any executive who thinks this is a compliance formality.

“AI adoption significantly enhances corporate governance effectiveness and improves risk management”

That is the gap between having AI and governing it. The second finding is the one that tends to change the room.

“it remains challenging for practitioners to identify the harmful repercussions of their own systems prior to deployment”

Neither of these is a fringe position. Both come from peer-reviewed work, and both describe the condition most organisations are actually in when the question about PCAOB AI guidance arrives from the board, the buyer, or the regulator.

How to get compliant with PCAOB AI Guidance: a 5-step path

This is the sequence that works, and it is not the sequence most organisations choose. They start with the framework and work backwards toward reality. Start with reality.

  1. Inventory the AI in scope. List every AI system that could fall under PCAOB AI guidance. Record what it does, what decision it influences, what data it touches, and who owns it. You cannot govern AI you cannot name, and almost every organisation we assess is running more AI than its leadership believes.
  2. Determine whether you are actually in scope. Work out precisely which of your AI systems and activities PCAOB AI guidance reaches, and write the determination down with its reasoning. Do this in writing. A documented scope determination, right or wrong, is defensible. An undocumented assumption is not.
  3. Assign one accountable owner. Name a person, not a committee, with the authority to stop a deployment. Governance without someone who can say no is documentation, not control.
  4. Build the evidence file. Assemble the documentation PCAOB AI guidance expects: the scope, the risk assessment, the controls, the testing evidence, and the incident record. Assemble it before anyone asks. Reconstructing it under a regulator's deadline costs several times more and looks exactly like what it is.
  5. Set a review cadence and hold it. Re-run the assessment on a schedule and after any material change to the model, the data, or the use case. Alignment decays. A control tested once is a snapshot, not a control.

Done in this order, PCAOB AI guidance becomes tractable. Done out of order, it becomes a document nobody uses and a control nobody exercises.

Frequently asked questions about PCAOB AI guidance

Does PCAOB AI guidance apply to private companies?

No. Private companies follow AICPA guidance. Public companies follow PCAOB standards.

Where does PCAOB AI guidance fit in SRJ's work?

The public company addendum in Volume III of The Operating Discipline for AI Library™ addresses PCAOB-driven documentation for AI in ICFR.

How PCAOB AI guidance reaches you through your audit firm

You are not inspected by the PCAOB. Your auditor is. When AI becomes an inspection focus, audit firms respond by tightening what they demand from clients, because an inspection finding is far more expensive to the firm than the incremental audit hours are to you. The practical consequence of PCAOB AI guidance is therefore a heavier information request, more control testing, and a higher fee, arriving without any change in your own obligations.

AI inside ICFR is the pressure point

Section 404 requires management to assess internal control over financial reporting and the auditor to attest to it. If an AI system contributes to a control, that control now has a model behind it, and the auditor must test the model's design and operating effectiveness. That means change management over the model, access restrictions on who can retrain it, evidence of ongoing monitoring, and validation that the output is fit for the control's purpose. Very few AI deployments were built with any of this in mind.

What to fix before year end

Identify every AI system that touches a financial reporting control. For each, produce the change log, the access list, the monitoring evidence, and the validation record. If any of those four do not exist, they need to exist before the auditor asks, because building them retroactively under PCAOB AI guidance scrutiny is how material weaknesses get disclosed.

Primary sources on PCAOB AI guidance

The authoritative texts and agency pages behind this summary. We keep this page current, but where a compliance decision turns on exact wording, read the source. Anything concerning PCAOB AI guidance that carries legal consequence should be confirmed against the enrolled text or the issuing body, not against a secondary summary, including this one.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including PCAOB AI Guidance, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation