Flag.Verify.Sign.
Blog · 7 September 2026 · 7 min read

How to Use AI as an Auditor: What Works, What Does Not, and the Rules

A practical guide to using AI as an auditor — the tasks it genuinely speeds up, the ones that quietly create a documentation problem, and what the current standards actually require.

An audit opinion has a name attached to it. That single fact decides almost everything about where AI belongs in the work and where it does not. The tools are genuinely useful for drafting, summarising and flagging — and genuinely dangerous the moment their output gets treated as the conclusion rather than a lead to check. This is the practical companion to will AI replace auditors, which looked at the risk to the role. This one is about using the tools well without creating a problem you have to explain to a reviewer.

Start with what the standards actually require

The rules did not appear from nowhere in response to generative AI — they were updated deliberately. The PCAOB amended AS 1105, Audit Evidence, and AS 2301 to address technology-assisted analysis specifically, effective for audits of fiscal years beginning on or after 15 December 2025. The core requirement is unchanged in spirit but sharper in practice: evidence produced by a tool still has to be evaluated for relevance and reliability before you rely on it, and you have to be able to explain why.

On the private-company side, AICPA guidance on audit and quality management standards treats AI the same way as any other automated tool under AU-C 500 — audit evidence may be gathered manually or through data analytics, machine learning and similar techniques, but the auditor remains responsible for assessing whether that evidence is sufficient and appropriate. Neither standard bans AI. Both make clear that a flagged anomaly or a generated summary is a starting point for audit work, not a substitute for it.

Practically, that gives you three tiers. Client and engagement data that never goes into a general consumer tool. Work that is fine in a properly vetted enterprise tool with no training on your inputs. And judgement calls that stay entirely with you regardless of which tool touched them first.

What it is genuinely good at

The pattern across every item below: the tool produces a draft or a flag, and you supply the audit judgement that turns it into evidence.

  1. Flagging anomalies across a full population rather than a sample. Given a year of transactions, a properly set up tool can surface every payment that deviates from the pattern for that vendor, account or time of year — more comparisons than a manual sample would ever cover. The flag is not the finding; investigating it is.
  2. Drafting a first-pass workpaper narrative. Turning a set of test results into a documented conclusion in the house format, so you are editing rather than writing from a blank page.
  3. Reading a long agreement against a specific question. "Where does this lease say anything about early termination fees" is a search problem over a document already in front of the tool, and that is the category these tools handle most reliably.
  4. Summarising a variance for a management letter point. You already know why gross margin moved; the tool saves you writing the explanation out in full for the tenth client this quarter.
  5. Drafting a prepared-by-client request list from a standard engagement template, then editing it for what is actually different about this client.
  6. Rehearsing a difficult conversation. Ask it to argue the client's likely position on a contested item before you raise it, so you walk in having already heard the pushback once.

A worked example

A tool scans a full year of a client's invoice register and flags eleven payments to the same vendor, each just under the $10,000 threshold that would have triggered a second approval. That flag is genuinely valuable — no manual sample of that population would reliably have surfaced the pattern. What it is not is an audit conclusion. The actual audit work is asking why the payments were split that way, checking the underlying purchase orders, and documenting what you found and whether it changes your assessment of control effectiveness. The tool did the finding. You still have to do the auditing.

Where it will quietly get you into trouble

  • Treating a flagged anomaly as sufficient evidence on its own. Under the updated AS 1105, the auditor has to evaluate the reliability of the analysis and corroborate what it surfaces — a flag with no follow-up procedure documented behind it is exactly the gap the amendment was written to close.
  • Accounting or auditing standard citations produced from memory rather than looked up. A confident paragraph number and a plausible-sounding requirement are not the same as the actual text of the standard. Open the primary source every time, the same discipline covered generally in how to use AI as an accountant.
  • Materiality, going concern, or fraud-risk judgements dressed up as questions. "Does this indicate going concern risk" gets you an answer with the tone of authority and none of the accountability. That call stays with the engagement team regardless of how the question was framed.
  • Client or engagement data going into a general consumer tool without a firm policy behind it. Confidentiality obligations do not pause because the tool is convenient, and once information is submitted you have limited visibility into how it is retained.
  • Accepting an automated reconciliation's exceptions list without opening it. The matching can be automated; reviewing what did not match cannot be skipped, which is the same principle behind the exception-review routine in how to use AI as a bookkeeper.

Getting started without a project plan

  1. Write down your firm's data rule before using any tool on client information, even if it is one sentence borrowed from an existing template. A rule beats no rule.
  2. Pick one recurring, checkable task first — workpaper narrative drafting is the usual right answer, because you can judge the output instantly against what you already know. Find the repetitive part is a short test if the choice is not obvious.
  3. Run that one task both ways for a few engagements and keep the time saved. You want evidence of value, not a general impression.
  4. Treat every generated citation and every flagged anomaly the same way: as a lead you personally verify against the primary source or the underlying transaction, never as the finished answer. Checking an AI answer when you are not the expert is the general version of that habit.
  5. Expand to a second task only once the first is routine. Rolling out several uses at once tends to end with the team using none of them properly.

The part that actually protects the role

The tasks most exposed here are the ones furthest from judgement — sampling, matching, first-draft documentation. Those were already under pressure from ordinary data analytics before generative AI arrived. What is left is judgement and accountability, which the standards explicitly will not let a tool hold. The useful stance is neither refusing the tools nor deferring to them: it is being the auditor who gets a flag or a draft in a fraction of the time and then does the actual verification the standard requires, every time, on every item that matters.

That verification habit is also the one most worth practising deliberately, because these systems fail in the same way regardless of how experienced you are: fluently, confidently, and only occasionally. AI answers questions covers which kinds of questions are reliable and which are not, and the sorting test in it applies directly to anything a tool hands you mid-engagement.

The short version

Use AI to flag, draft, search and summarise — on data your firm has cleared for it — and treat every output as a lead rather than a conclusion. Corroborate every flagged anomaly, verify every citation against the primary standard, and keep every materiality or fraud-risk judgement with the engagement team where the current rules put it. Write down a data policy before you start, pick one checkable task, measure it, and expand only once it is dull.

Coursium teaches exactly that layer — practical use of the tools plus the checking habit that has to go with it, in short lessons rather than a compliance manual. Stay ahead of AI by learning them on your phone.

Coursium

Stay ahead of AI — learn the tools on your phone.

Get the app