概述
They apply the same rules on evidence, supervision and documentation to technology-assisted procedures as to manual ones. An audit firm that uses AI is still responsible for three things: the data the tool reads must be reliable, the procedure must fit its purpose, and the work papers must let an experienced auditor understand and re-create what was done. This matters because investors rely on audit opinions, and a fast automated procedure does not make a weak conclusion any stronger.
深入探讨
The Public Company Accounting Oversight Board (PCAOB) sets auditing standards for audits of companies registered with the SEC. It regulates the work, not the tool. Several standards govern any procedure, whether a person does it or software does. AS 1105 (Audit Evidence) requires evidence to be sufficient and appropriate, and appropriateness depends on relevance and reliability. AS 2301 sets out how the auditor responds to assessed risks. AS 1201 covers supervision. AS 1215 (Audit Documentation) requires work papers that would let an experienced auditor with no prior link to the engagement understand the work performed, the evidence obtained and the conclusions reached. In 2024 the PCAOB adopted amendments to AS 1105 and AS 2301 that deal directly with technology-assisted analysis of information in electronic form. They take effect for audits of fiscal years beginning on or after December 15, 2025. The amendments make three points. When an analysis serves more than one purpose, such as risk assessment and substantive testing, the auditor must meet the objective of each purpose. The auditor must evaluate the reliability of electronic information, including information the company received from outside sources. And items that a tool flags as meeting the auditor's criteria must be investigated. They cannot be set aside. The PCAOB has also said publicly that its staff is monitoring how firms use generative AI. Its broader quality control standard, QC 1000, treats technological resources as part of a firm's quality control system. Two misconceptions are common. The first is that testing 100% of a population removes the need for judgment. A full-population test built on incomplete or altered data is still unreliable, and the flagged items still need to be evaluated. The second is that AI output counts as audit evidence in its own right. The evidence is the underlying information plus a procedure that was designed, performed and reviewed properly. A summary or score produced by a model is only as good as the checks performed on it.
战略影响
风险与安全
灾难性和日常的人工智能危害都取决于谁了解风险以及谁能够采取行动。
更清晰的判决
公众和专业素养决定强有力的安全政策在政治上是否可行。
打破炒作
清晰的解释可以减少炒作、实验室公关和模糊道德剧场的影响。
The Future of PCAOB Standards and AI in Audits
The 2024 amendments give firms a clearer framework for data analytics, and the first audits under them will show how inspectors read the investigation requirement for flagged items. Generative AI raises questions the current standards answer only indirectly. Examples include how to document a model's role in drafting memos, and how much re-checking of extracted content is enough. The PCAOB has signalled interest through staff outreach, but a firm should not assume new guidance is coming on any particular timeline. For now, the safest approach is to treat every AI-assisted step as a procedure that must be relevant, reliable, supervised and documented under the existing standards.
现实世界的实施
A team runs an analysis over every revenue journal entry for the year and flags entries posted on weekends by users who rarely post to revenue. The flagged entries must then be followed up, because running the analysis does not by itself count as evidence.
An engagement team uses a generative AI tool to pull renewal, termination and pricing terms out of 300 customer contracts. Before relying on the extracted terms, it checks a sample of them against the signed contracts.
Before feeding the company's system-generated aged receivables report into an analytics tool, the auditor tests whether the report is complete and accurate, because it counts as information produced by the company.
A reviewer's work papers record the tool version, the parameters used, the data source, and a reconciliation of the extracted ledger to the trial balance, so another auditor could re-perform the analysis.
风险与防护栏
将存在风险视为科幻小说,同时能力复合。
混淆了表面产品安全与高度自治下的对准。
只给非英语和非专业观众留下低质量的资源。
实施路线图
单独的产品危害、误用和失控/失调风险。
询问哪些证据会改变您对时间表和严重性的看法。
比起营销主张,更喜欢主要来源和具体评估。
确定一条行动路径:职业、政策、资金或技能——而不仅仅是意识。
不断探索
Free newsletter
Get the daily AI briefing
Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.
One email each weekday. Unsubscribe in one click. We never sell or share your address.
Test yourself
Take the PCAOB Standards and AI in Audits quiz
Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.
Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation
常见问题
What is PCAOB Standards and AI in Audits?
PCAOB standards neither ban AI nor give it special approval. They apply the same rules on evidence, supervision and documentation to technology-assisted procedures as to manual ones. An audit firm that uses AI is still responsible for three things: the data the tool reads must be reliable, the procedure must fit its purpose, and the work papers must let an experienced auditor understand and re-create what was done. This matters because investors rely on audit opinions, and a fast automated procedure does not make a weak conclusion any stronger.
2024 年关于技术辅助分析的修正案改变了哪两项 PCAOB 标准?
2024 年修正案更改了 AS 1105(审计证据)和 AS 2301(对评估风险的回应)。它们阐述了审计员如何评估电子信息以及如何使用技术辅助分析。
对所有收入日记帐分录的分析标记出 40 个符合审计员标准的分录。修订后的指导意见有何期望?
修正案明确规定,必须对确定为符合审计师标准的项目进行调查。生成标志列表并不是一个完整的过程。
在将公司生成的账龄应收账款报告放入分析工具之前,审计师应该评估什么?
公司制作的报告是公司制作的信息。在审核员依赖它之前,必须对其可靠性(包括完整性和准确性)进行评估。
根据 AS 1215,谁应该能够理解人工智能辅助程序的工作底稿?
AS 1215 设置了经验丰富的审核员测试。文件必须让这样的人了解所做的工作、获得的证据和得出的结论。
单一技术辅助分析用于风险评估和实质性测试。审核员必须做什么?
修正案规定,当一项分析服务于多种目的时,审计师必须实现每一个目的。实质性测试通常比风险评估要求更精确。
继续学习
相关指南
为此主题精选的更多指南