External auditors have heard the AI pitch for three years running. What has changed in 2026 is that agentic tools, systems that can plan a sequence of steps and execute them with limited human input rather than just answer a single prompt, are now being tested against real audit workpapers instead of marketing demos. AccountingWeb's recent guide on agentic automation for external auditors is a useful prompt to separate the parts of an audit that agents can carry today from the parts that still need a licensed signature and professional judgment.
What agentic automation actually changes in an audit file
Robotic process automation, the prior generation of audit tooling, followed fixed rules: pull this report, populate this cell, flag this variance. Agentic automation goes a step further. It can read a PBC (prepared-by-client) list, compare it against what has actually been uploaded to the file, chase the gaps against a deadline, and summarize the outstanding items for the engagement manager, all without a human writing a script for each step.
For a mid-size firm running 8 to 12 statutory audits a quarter, that alone removes a meaningful chunk of administrative back-and-forth. The audit is not finished faster because the opinion arrives sooner; it is finished faster because staff stop spending Monday mornings reconciling PBC trackers by hand.
Four places to start, in order of risk
- PBC and evidence intake.Lowest risk, highest volume payoff. An agent can flag missing or mismatched client documents against the request list before fieldwork begins.
- Journal entry testing.An agent can screen entries against materiality thresholds and unusual account combinations, then route exceptions to a senior. A firm testing 400 to 600 entries per quarter can expect the agent to clear 70 to 80 percent of entries as low-risk, leaving staff time for the remainder.
- Walkthrough documentation.Agents can draft a first-pass narrative from interview transcripts or recorded client calls. Staff still edit and confirm it against ISA 315 or PCAOB AS 2110 requirements, but they are editing, not drafting from nothing.
- Confirmation follow-up.Chasing bank and receivable confirmations by email is repetitive and time-boxed. An agent can send reminders on a schedule and log responses, with a human reviewing anything that comes back with a discrepancy.
Where the guide draws the line
None of the four areas above touch professional judgment: assessing control risk, evaluating going concern, or forming the audit opinion. That distinction matters for two reasons. First, standards bodies including the PCAOB and the AICPA have been explicit that the engagement partner remains accountable for conclusions regardless of what tooling produced supporting analysis. Second, clients and regulators will ask, in a peer review or an inspection, exactly which steps were agent-assisted and who reviewed the output. Firms that cannot answer that question precisely are the ones that will run into trouble, not firms that used the tools.
A rollout sequence that keeps sign-off intact
- Pick one audit area (PBC intake is the easiest first case) and run the agent in parallel with the existing manual process for one full engagement cycle.
- Document every point where a human reviews, edits, or overrides agent output. This becomes your control narrative for peer review.
- Set explicit thresholds for what routes to the agent versus what always goes to a senior, regardless of what the agent flags.
- Re-run the comparison on a second engagement before removing the manual parallel process entirely.
Agentic automation in audit is not about removing auditors from the file. It is about making sure the hours a qualified auditor spends are spent on the entries, the narratives, and the judgments that actually need a qualified auditor. Firms that treat the pilot phase as seriously as the standards bodies expect them to will be the ones with a defensible answer when a regulator asks how the work got done.

