AI in Audit Regulation, 2026: What Changed and What Comes Next
· Andreas Schindler, CEO | dnl.ai

In March the FRC became the first audit regulator anywhere to publish guidance on generative and agentic AI. In July it reported it had seen “limited use of GenAI on audits” over the past year, and noted in the same document that firms “are now deploying GenAI tools to perform audit procedures and generate audit documentation.” Then it announced a thematic review of how the largest firms govern that deployment.
Firms have gone ahead. The regulator hasn’t found the evidence in the files. It has said it’s coming to look.
The detail almost everyone has missed
The FRC’s guidance sets out three risks, deficient output, misuse of output and non-compliant methodology, and four categories of mitigation. One of those categories is certification, and the definition is the part that matters.
The unit of certification is “an AI tool in the context of a use case.”
Not the tool. The tool and the job you’re using it for. A firm that approved a vendor once and then pointed it at four different procedures has certified one of them.
There’s a second detail doing quiet structural work. The guidance is voluntary. It cites ISQM (UK) 1 once, and that single citation is the whole architecture, because the obligation to design and operate a system of quality management is not optional. The guidance tells you what good looks like. The standard underneath it is what you get inspected against. Our fuller reading of the March guidance is in a separate piece.
Behind both sits the FRC’s thematic review on certification of automated tools and techniques, published 26 June 2025, which examined BDO, Deloitte, EY, Forvis Mazars, KPMG and PwC. All six have certification processes in place before deployment. What the review found was that “the maturity of these processes was found to vary and in some cases were not supported by formal documented policies.”
Two findings from it deserve more attention than they’ve had.
The first is a flat statement with no qualifier attached: “There was no formal monitoring performed by the firms to quantify the audit quality impact of using ATTs.” Six firms, none of them measuring whether the tools improved the audit.
The second is what the firms said themselves. They “acknowledged that the use of AI within an ATT presented additional risks that may not be addressed by existing certification processes.” The largest audit firms in the country told their regulator that the process they use to approve tools may not cover the tools they are now buying.
Three continents, one posture
The pattern across markets is more consistent than the coverage suggests.
The PCAOB has been researching data and technology since 2022 and has produced no standard. When it opened its agenda to public comment this summer, all four of the Big Four told it not to write one. EY’s letter said broad or prescriptive standard setting isn’t warranted at this time. KPMG preferred staff guidance. Grant Thornton asked for targeted guidance in lieu of standard setting. Every one of them backed a task force instead.
Meanwhile QC 1000 takes effect on 15 December, and its requirements on technological resources never use the words “artificial intelligence” anywhere in the standard.
The SEC’s 2026 agenda contains no AI item. The AUASB has published nothing at all. The FCA said in January it has no plans for AI-specific rules, and the Bank of England has committed to staying technology-agnostic.
So there is no AI rulebook coming for auditors, and the obligation hasn’t gone anywhere. It has moved into quality management requirements written before anyone was thinking about this, where it’s harder to see and considerably harder to demonstrate.
Where we put our own view on the record
We filed a comment with the PCAOB on 7 August, responding to Release No. 2026-005. We have a commercial interest in how the Board answers this, and we said so in the letter.
Our position was that the Board should issue staff guidance now rather than wait out a full standard-setting cycle, and that the guidance should describe properties rather than endorse products. The three we proposed: traceability, so every AI-assisted conclusion can be traced back to the specific evidence it rests on. Reproducibility, meaning inputs, model versions, configurations and outputs documented in enough detail that a reviewer can re-perform the procedure, because re-performance is what an inspection depends on. And human accountability, because the tool proposes, and the auditor decides and signs.
We also named where the gap sits in the existing standards. AS 2315 assumes selection from a population rather than examination of all of it, so full-population testing strains it. AS 1215 doesn’t yet say what documentation of a model’s inputs, versions and outputs makes an AI-assisted procedure re-performable on inspection. And AS 2810 doesn’t say what would support reliance on a tool that checks disclosures against the full population of applicable requirements rather than against a manually maintained checklist.
The argument underneath all of it is the one former Board member Christina Ho set out in her speech “AI and the Pursuit of Audit Quality: A Regulatory Perspective.” A firm that uses AI to test every journal entry does more work than one taking a manual sample. But absent clear standards it can’t predict what an inspector will ask about the model, the data and the method, so it retreats to sampling because sampling is easier to defend. The safe choice becomes the weaker audit.
What’s dated
15 December 2026 carries most of it. QC 1000 and AS 2901 take effect and the first Form QC period opens. The revised ISA (UK) 700, 701 and 720 apply, as do ISA (UK) 240 and 570 for periods beginning on or after that date. ASA 240 (Revised) applies in Australia. IESSA takes effect. And the IAASB’s comment deadline on its audit evidence exposure drafts falls on the same day.
Those drafts are worth reading before then rather than after. They replace “automated tools and techniques” with “technological tools,” which sounds like housekeeping and isn’t. It reframes technology from something applied to the audit into a resource the audit is conducted with.
The FRC’s thematic review on GenAI governance is committed but undated. If previous thematic reviews are any guide, its findings become the working expectation for firms well outside the six it examines.
21 October is the only scheduled event in these markets where a regulator will talk about this at length: IAASA’s Audit Committee Briefing in Dublin, given over to AI in audit, financial reporting and governance.
What this means in practice
A firm waiting for the standard that defines good practice will be waiting a while. A firm inspected against its own system of quality management will be asked what it decided, and why, and what it can show.
In most cases that comes down to a small number of documents that don’t currently exist: an inventory by tool and by use case rather than by vendor, a certification record for each of those pairs, a decommissioning policy, a stated reassessment cadence, and engagement-level documentation showing what the auditor checked rather than accepted.
None of that is a compliance project. It’s a file.
The long version of this piece sets out each of those documents against the FRC’s own framework, with the five recertification triggers the guidance lists and the thematic review findings across all six firms. It is available as AI in Audit Regulation, 2026.
The awkward part
The Center for Audit Quality found in July that nearly 90% of audit partners describe AI governance at their largest client as developing or early stage. In the same quarter, EY put agentic AI into its audit platform across an assurance practice running 160,000 engagements a year, and Deloitte shipped an agentic version of Omnia.
The auditors are further ahead on adoption than the companies they audit, and the regulators are behind both. There’s a version of the next few years where the profession is assuring AI governance in its clients that it hasn’t yet documented in itself.
Which is an uncomfortable position to be inspected in, and a reasonable one to be standing in early.