GUIDA della Società

Standard PCAOB e intelligenza artificiale negli audit

PCAOB standards neither ban AI nor give it special approval.

  • 4 minuti di lettura
  • Ultimo aggiornamento
In questa pagina4 minuti di lettura
  1. Panoramica
  2. Immersione profonda
  3. Impatto strategico
  4. The Future of PCAOB Standards and AI in Audits
  5. Implementazione nel mondo reale
  6. Rischi e guardrail
  7. Tabella di marcia per l'implementazione
  8. Continua a esplorare
  9. Domande frequenti

Panoramica

They apply the same rules on evidence, supervision and documentation to technology-assisted procedures as to manual ones. An audit firm that uses AI is still responsible for three things: the data the tool reads must be reliable, the procedure must fit its purpose, and the work papers must let an experienced auditor understand and re-create what was done. This matters because investors rely on audit opinions, and a fast automated procedure does not make a weak conclusion any stronger.

Immersione profonda

The Public Company Accounting Oversight Board (PCAOB) sets auditing standards for audits of companies registered with the SEC. It regulates the work, not the tool. Several standards govern any procedure, whether a person does it or software does. AS 1105 (Audit Evidence) requires evidence to be sufficient and appropriate, and appropriateness depends on relevance and reliability. AS 2301 sets out how the auditor responds to assessed risks. AS 1201 covers supervision. AS 1215 (Audit Documentation) requires work papers that would let an experienced auditor with no prior link to the engagement understand the work performed, the evidence obtained and the conclusions reached. In 2024 the PCAOB adopted amendments to AS 1105 and AS 2301 that deal directly with technology-assisted analysis of information in electronic form. They take effect for audits of fiscal years beginning on or after December 15, 2025. The amendments make three points. When an analysis serves more than one purpose, such as risk assessment and substantive testing, the auditor must meet the objective of each purpose. The auditor must evaluate the reliability of electronic information, including information the company received from outside sources. And items that a tool flags as meeting the auditor's criteria must be investigated. They cannot be set aside. The PCAOB has also said publicly that its staff is monitoring how firms use generative AI. Its broader quality control standard, QC 1000, treats technological resources as part of a firm's quality control system. Two misconceptions are common. The first is that testing 100% of a population removes the need for judgment. A full-population test built on incomplete or altered data is still unreliable, and the flagged items still need to be evaluated. The second is that AI output counts as audit evidence in its own right. The evidence is the underlying information plus a procedure that was designed, performed and reviewed properly. A summary or score produced by a model is only as good as the checks performed on it.

Impatto strategico

Rischio e sicurezza

I danni catastrofici e quotidiani dell’IA dipendono entrambi da chi comprende i rischi e da chi può agire.

Decisioni più chiare

L’alfabetizzazione pubblica e professionale determina la possibilità politica di una forte politica di sicurezza.

Tagliare il clamore

Spiegazioni chiare riducono la cattura da parte di montature pubblicitarie, PR di laboratorio e vaghi teatrini etici.

The Future of PCAOB Standards and AI in Audits

The 2024 amendments give firms a clearer framework for data analytics, and the first audits under them will show how inspectors read the investigation requirement for flagged items. Generative AI raises questions the current standards answer only indirectly. Examples include how to document a model's role in drafting memos, and how much re-checking of extracted content is enough. The PCAOB has signalled interest through staff outreach, but a firm should not assume new guidance is coming on any particular timeline. For now, the safest approach is to treat every AI-assisted step as a procedure that must be relevant, reliable, supervised and documented under the existing standards.

Implementazione nel mondo reale

A team runs an analysis over every revenue journal entry for the year and flags entries posted on weekends by users who rarely post to revenue. The flagged entries must then be followed up, because running the analysis does not by itself count as evidence.

An engagement team uses a generative AI tool to pull renewal, termination and pricing terms out of 300 customer contracts. Before relying on the extracted terms, it checks a sample of them against the signed contracts.

Before feeding the company's system-generated aged receivables report into an analytics tool, the auditor tests whether the report is complete and accurate, because it counts as information produced by the company.

A reviewer's work papers record the tool version, the parameters used, the data source, and a reconciliation of the extracted ledger to the trial balance, so another auditor could re-perform the analysis.

Rischi e guardrail

  • Trattare il rischio esistenziale come fantascienza mentre le capacità si aggravano.

  • Confondere la sicurezza del prodotto superficiale con l'allineamento in condizioni di elevata autonomia.

  • Lasciando il pubblico non inglese e non esperto solo con fonti di bassa qualità.

Tabella di marcia per l'implementazione

  1. Separare i rischi di danni al prodotto, uso improprio e perdita di controllo/disallineamento.

  2. Chiedi quali prove cambierebbero la tua opinione sulle tempistiche e sulla gravità.

  3. Preferire fonti primarie e valutazioni concrete alle affermazioni di marketing.

  4. Identifica un percorso d’azione: carriera, politica, finanziamenti o competenze, non solo consapevolezza.

Continua a esplorare

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the PCAOB Standards and AI in Audits quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

Inizia il quiz

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

Domande frequenti

What is PCAOB Standards and AI in Audits?

PCAOB standards neither ban AI nor give it special approval. They apply the same rules on evidence, supervision and documentation to technology-assisted procedures as to manual ones. An audit firm that uses AI is still responsible for three things: the data the tool reads must be reliable, the procedure must fit its purpose, and the work papers must let an experienced auditor understand and re-create what was done. This matters because investors rely on audit opinions, and a fast automated procedure does not make a weak conclusion any stronger.

Which two PCAOB standards did the 2024 amendments on technology-assisted analysis change?

The 2024 amendments changed AS 1105 (Audit Evidence) and AS 2301 (responses to assessed risks). They address how auditors evaluate electronic information and how they use technology-assisted analysis.

An analysis of all revenue journal entries flags 40 entries that meet the auditor's criteria. What does the amended guidance expect?

The amendments make clear that items identified as meeting the auditor's criteria must be investigated. Producing a list of flags is not a completed procedure.

Before putting a company-generated aged receivables report into an analytics tool, what should the auditor evaluate?

A company-produced report is information produced by the company. Its reliability, including its completeness and accuracy, must be evaluated before the auditor relies on it.

Under AS 1215, who should be able to understand the work papers for an AI-assisted procedure?

AS 1215 sets the experienced-auditor test. Documentation must let such a person understand the work performed, the evidence obtained and the conclusions reached.

A single technology-assisted analysis is used for both risk assessment and substantive testing. What must the auditor do?

The amendments say that when an analysis serves multiple purposes, the auditor must achieve the objective of each one. Substantive testing usually demands more precision than risk assessment.