Skip to content

AI in Audit Regulation, 2026

14 min read · PDF · 16 pages · Published

  • 0 of 6of the largest UK firms formally measure their tools' audit quality impact
  • ~90%of audit partners call their largest client's AI governance early stage
  • 15 Decwhen QC 1000, AS 2901 and the revised ISAs (UK) all take effect

Overview

Three things happened in 2026, and read together they set the year’s real position. In March the FRC became the first audit regulator anywhere to publish guidance on generative and agentic AI. In July it reported that it had seen “limited use of GenAI on audits” in the past year, while noting in the same document that firms “are now deploying GenAI tools to perform audit procedures and generate audit documentation.” Then it announced a thematic review of how the largest firms govern that deployment.

Firms have gone ahead. The regulator has not yet found the evidence in the files. It has said it is coming to look.

This paper collects what changed across the UK, the US, Germany, Australia and the international standard setters, what is already dated for the year ahead, and the short list of documents a firm would want in the file before an inspector asks for them.

What you’ll learn

  • Why the FRC’s unit of certification is “an AI tool in the context of a use case”, so a firm that approved a vendor once and pointed it at four jobs has certified one of them.
  • What the FRC’s thematic review of BDO, Deloitte, EY, Forvis Mazars, KPMG and PwC found, including the single gap that applied to all six with no qualifier.
  • Why no US standard is coming yet, what the largest firms asked for instead, and how QC 1000 picks up AI governance on 15 December without using the words “artificial intelligence” anywhere.
  • What the IAASB exposure drafts change by replacing “automated tools and techniques” with “technological tools”, and why that is more than housekeeping.

What’s inside

  1. The year in three facts
  2. The UK moved first, and made it voluntary
  3. What the FRC found: six firms, one flat gap
  4. Three quieter moves, and a change in supervision
  5. No standard in the US: the firms asked it not to
  6. On the record: our PCAOB comment letter
  7. Elsewhere: Germany, Australia, IESBA
  8. What’s coming, and what is already dated
  9. What to have on file

Who it’s for

Audit partners, heads of audit quality and innovation leads who will be asked what their firm decided about AI, why, and what they can show. It assumes no prior reading of the source documents and cites every one of them, so it works as a briefing for a committee as well as a reading list for one person.

Where we have an interest

We build audit software, so we have a commercial interest in how regulators answer these questions. We said so in our comment letter to the PCAOB and we say it in the paper. Every claim in it quotes a named regulator and links the source, so it can be checked against the originals rather than against us. Our reading of the March guidance is in the FRC article, and what our own tools do and decline to do is in ai/checklist.

GDPR compliant

Your data stays in the EU. dnl processes all data under GDPR on EU-based infrastructure.