A recent AccountingWeb piece on external audit and AI adoption describes a shift that finance leaders at small and mid-market companies should take seriously: auditors are no longer treating AI tools as a footnote. They are treating them as a control area, with the same rigor applied to journal entry approvals or revenue recognition.
The five questions auditors are asking
Based on the patterns described in the article and what we see in client audits, expect these questions during FY2026 fieldwork:
- What AI tools touch financial data, and who approved each one?Not just the ERP add-on IT signed off on. The categorization tool a bookkeeper added to speed up coding, the AI-assisted reconciliation feature turned on inside the accounting platform, the chatbot used to draft memo language.
- Who reviews the output, and how often?Auditors want a named role, not "someone checks it." If the answer is the controller reviews AI-flagged exceptions weekly, write that down and be ready to show a sample.
- What happens when the AI gets it wrong?This is where most teams stall. Auditors want at least one documented instance of an error being caught, not a claim that errors do not happen.
- Is there an audit trail for AI-assisted entries?A log showing what the tool suggested, what a human changed, and when.
- Who has access to adjust the AI's parameters or training data?This maps to the same access-control logic auditors already apply to ERP permissions, extended to model configuration.
Why this is happening now
ISA 315 (revised 2019) already requires auditors to understand a client's IT environment and related controls as part of risk assessment. AI tools that touch general ledger entries, revenue estimates, or accruals fall squarely inside that scope. PCAOB guidance points the same direction for US issuers. Auditors are not inventing a new standard; they are applying an existing one to a category of tool that most finance teams have not documented yet.
A short case in point
A 40-person manufacturing client of ours adopted an AI-based invoice coding tool in Q1 2025. The tool worked well and cut coding time by roughly 30%. When the FY2025 audit started in February 2026, the auditor asked for the control narrative around it on day three of fieldwork. None existed. The controller spent four days reconstructing usage logs and approval history from email threads, and the close slipped by three days while the audit team waited.
The fix was not complicated. It took one afternoon to build: a one-page inventory of the tool, the name of the person who approved it, the review cadence, and two examples of caught errors pulled from support tickets.
What to have ready before your next audit
- An inventory of every AI tool used in finance, including ones adopted outside it is formal process.
- A named reviewer and review cadence for each tool's output.
- At least one documented case of a human catching an AI error.
- An access list showing who can change model settings, prompts, or training data.
- A short written policy, even one page, describing when AI output can be used without independent review and when it cannot.
None of this requires new software. It requires someone to write down what is already happening. Firms that do this before fieldwork starts turn a multi-day audit delay into a five-minute conversation.

