AI for CFOs · Independent decision intelligenceSource-backed reporting · No paid editorial rankings
CFO AI Ledger

An independent finance-leadership publication that examines where AI changes planning, close, cash, control, disclosure, and capital decisions—and what evidence a CFO must require before relying on it.

CFO briefings

PCAOB keeps AI audit-evidence questions open

The CFO and audit committee should treat AI-assisted reporting and audit evidence as a current reliance decision, not wait for a future PCAOB answer or assume that existing practice has already settled every evidence question.

Answer capsule

The CFO and audit committee should treat AI-assisted reporting and audit evidence as a current reliance decision, not wait for a future PCAOB answer or assume that existing practice has already settled every evidence question.

What the source establishes

  • PCAOB Release No. 2026-005, issued June 23, 2026, asks for public input on future standard-setting and research priorities; comments are open through August 7, 2026.
  • The release reports stakeholder views that AI is changing how audit evidence is generated and evaluated.
  • Commenters identified risk assessment, internal controls, sufficient appropriate audit evidence, documentation, supervision, governance, and human review as AI-related areas the PCAOB could address.
  • The PCAOB says there was no consensus on staff guidance versus standard setting and that its existing Data and Technology research project will consider relevant AI developments.

Make today's reliance decision under today's standards

The direct finance answer is not to suspend every AI-supported workflow until the PCAOB completes future work. It is to decide whether the evidence available today supports the specific reporting, control, or audit use under the standards and responsibilities already in force. The CFO, controller, audit committee, and external auditor have different roles, but each needs the same factual baseline: what AI touched, which data and assertions were involved, how the output was evaluated, where human judgment entered, and what evidence remains unavailable.

The consultation makes uncertainty visible rather than removing current accountability. A provider assurance statement, an audit firm's methodology, or a successful pilot cannot by itself establish that evidence is sufficient for a particular assertion. Finance should preserve the exact use, population, period, model or service version, source information, reviewer, exceptions, and downstream decision. The accountable conclusion is whether that record supports reliance now, with any limits stated plainly.

The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.

Separate company AI from auditor AI

The PCAOB release discusses both companies' use of AI and AI-enabled audit work. Those are related but separate evidence paths. A preparer may use AI to classify transactions, investigate variances, draft disclosures, or assemble support. An auditor may use technology to identify items, analyze populations, or evaluate evidence. Management still owns its financial statements and controls, while the auditor still owns the audit procedures and opinion. One party's tool review does not automatically satisfy the other's responsibility.

The CFO should therefore avoid a blended statement that the process was reviewed by AI and by the auditor. The decision record should show which outputs management relied on, what management independently verified, which controls operated, what information was supplied to the auditor, and which audit procedures remain the auditor's work. If the audit firm uses its own AI-enabled tools, the audit committee can ask how supervision and evidence conclusions are governed without attempting to direct the audit methodology.

The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.

Keep documentation and human review substantive

The release records calls for attention to documentation of AI-assisted procedures and the extent of human involvement and supervision. That does not mean adding a generic human-reviewed label. A meaningful record identifies the question the reviewer was qualified to decide, the information visible at review, the exceptions challenged, the changes made, and the authority to approve or stop reliance. A person who sees only a polished answer may be unable to evaluate missing records, unsupported transformations, or model-driven selection effects.

Documentation should also preserve disagreement and uncertainty. If an output is plausible but its source path is incomplete, that is not the same conclusion as an output supported by reconciled records. If a reviewer sampled results, the population and selection logic matter. If a vendor changed a model or retrieval service, the prior review may no longer describe the configured workflow. Finance needs a reconstructable evidence path, not a narrative added after the reporting decision.

The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.

Track the consultation without turning it into a rule

Release No. 2026-005 is a request for comment, and the PCAOB expressly says the appropriate response to AI developments is still under consideration. The CFO should not present its questions as new binding requirements or predict the final form, timing, or content of future guidance. The useful decision signal is that evidence generation, risk assessment, internal controls, documentation, supervision, governance, and human review are active standard-setting questions rather than settled by the presence of a familiar vendor.

A current reliance decision should state which existing accounting, control, audit, legal, and company requirements govern it and which emerging questions are being watched. It should also name the event that reopens review, such as a material workflow change, a new PCAOB release, changed auditor methodology, an unexplained exception pattern, or loss of source evidence. That structure lets finance move with bounded evidence while avoiding a claim that either future rulemaking or current uncertainty has already decided the outcome.

The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.

Decision test

Ask whether the source changes the decision itself, the evidence required, the implementation sequence, or only the language used to describe an existing capability. Record which claims are directly supported, which are provider statements, which require an independent test, and which remain unknown. A source-linked review should make uncertainty easier to see, not bury it inside a blended score.

Questions to take into review

  • Is the AI itself in scope for change and access controls?
  • Can evidence provenance survive export and retention?
  • Which source supports each number and assertion?
  • How is materiality assessed outside the model?
  • What evidence links a suggestion to the subledger and general ledger?
  • Who can accept a proposed match or explanation?
  • Which planning model and dimensions ground the answer?
  • Can every assumption be traced to an owner and date?
The publication supports research and executive decision preparation. It does not provide legal, financial, accounting, employment, clinical, cybersecurity, investment, procurement, or implementation advice.