What Will Your Auditor Actually Ask About AI in 2027?

Auditors are adding a new line to their document request lists: your firm's AI governance documentation. Most controllers don't yet know what to hand over.

This isn't a hypothetical. The Public Company Accounting Oversight Board amended AS 1105 (Audit Evidence) and AS 2301 (The Auditor's Response to the Risks of Material Misstatement) to spell out what auditors must do when they rely on technology-assisted analysis of your data. The amendments took effect for fiscal years beginning on or after December 15, 2025, which for most companies means the audit covering 2026 activity, in early 2027.

The underlying rule is old and simple: auditors document the evidence behind their conclusions. What's new is that when a tool, not a person, sampled the population or flagged the exception, the auditor still has to show the basis for trusting it. Someone has to hand them proof your side of the process held up too.

Where the scrutiny lands hardest

The scrutiny concentrates where AI touches a judgment call in the financial statements: revenue recognition, loan loss reserves, impairment testing, lease modifications. If AI helps decide a number in one of those areas, expect it to come up by name.

How this differs from a normal document request

A standard PBC (prepared-by-client) list asks for things you already have on file. AI governance documentation is different because most firms have never been asked to produce it before, so it doesn't exist in organized form yet. The risk isn't that the AI did something wrong. It's that nobody can show their work.

What Is an AI Audit Trail, and Why Does COSO Care?

An AI audit trail records what an AI tool read, what rule it applied, what it changed and who reviewed the output before it became a number in your books.

It's the difference between "the software did it" and "here's exactly what the software did and who signed off." COSO is the group behind the internal control framework nearly every audit in the country already runs on. In February 2026, it published new guidance called Achieving Effective Internal Control Over Generative AI. Same five-part structure auditors already know: control environment, risk assessment, control activities, information and communication, monitoring activities. Applied to AI, for the first time.

What COSO's guidance actually asks for

COSO sorts AI use into eight categories, from simple data ingestion up through judgment calls and orchestration between tools. For each one, it lays out a six-step roadmap: govern, inventory, assess, design, implement, monitor. The guidance is explicit that this roadmap is meant for an external auditor to use, not just kept internally. Prompts and configuration settings count as part of the trail. So does every version change to the model or the rules it follows. None of this requires new software. It requires deciding, in advance, what gets written down every time AI touches a number in the financial statements.

The Five-Item Evidence Checklist Every Finance Team Needs

Strip away the standards language and the ask is short: five things, organized by financial process, kept current instead of assembled after the fact.

Evidence itemWhat it provesWho owns it
AI use inventoryEvery tool touching financial data, what it does and which accounts it affectsController or finance systems owner
Decision and change logsWhat the tool did, what inputs it used and when the model or rules changedTool owner or IT, reviewed monthly
Human review sign-off recordWho reviewed each AI-assisted output before it posted, and whenPreparer and reviewer, at the transaction or batch level
Vendor audit-trail exportProof the vendor's own system can produce a traceable record on demandVendor, requested and stored quarterly
Exception and override logEvery time a human overruled the AI, and whyPreparer, logged at the time of override

AI use inventory

Start with a plain list: the tool, what it touches (accounts payable, reconciliations, revenue recognition) and what data flows into it. If you can't produce this list in ten minutes today, that's the first gap to close.

Decision and change logs

This is the part COSO calls out specifically. Every time the model or the business rules behind it change, someone needs a dated record of the old version, the new version and why it changed. Most AI vendors can export this. Few finance teams have asked for it yet.

Human review sign-off record

An AI tool producing a number isn't evidence on its own. A person confirming that number, with a timestamp, is. A reviewed-by field and a date on the transaction record is often enough.

Vendor audit-trail export

Kognitos, an AI vendor that launched a new accounts payable tool in August 2026, built its pitch around this exact idea: every decision traces back through a connected graph of your firm's own approval rules. That's what "audit-trail-by-design" looks like in practice. Whatever vendor you use, ask them the same question: can you pull a complete decision trail for one transaction, on demand, in under a minute?

Exception and override log

When a person overrides what the AI recommended, that moment often tells an auditor more than a hundred clean transactions. Log it every time, with the reason.