What Will Your Auditor Actually Ask About AI in 2027?
Auditors are adding a new line to their document request lists: your firm's AI governance documentation. Most controllers don't yet know what to hand over.
This isn't a hypothetical. The Public Company Accounting Oversight Board amended AS 1105 (Audit Evidence) and AS 2301 (The Auditor's Response to the Risks of Material Misstatement) to spell out what auditors must do when they rely on technology-assisted analysis of your data. The amendments took effect for fiscal years beginning on or after December 15, 2025, which for most companies means the audit covering 2026 activity, in early 2027.
The underlying rule is old and simple: auditors document the evidence behind their conclusions. What's new is that when a tool, not a person, sampled the population or flagged the exception, the auditor still has to show the basis for trusting it. Someone has to hand them proof your side of the process held up too.
Where the scrutiny lands hardest
The scrutiny concentrates where AI touches a judgment call in the financial statements: revenue recognition, loan loss reserves, impairment testing, lease modifications. If AI helps decide a number in one of those areas, expect it to come up by name.
How this differs from a normal document request
A standard PBC (prepared-by-client) list asks for things you already have on file. AI governance documentation is different because most firms have never been asked to produce it before, so it doesn't exist in organized form yet. The risk isn't that the AI did something wrong. It's that nobody can show their work.
What Is an AI Audit Trail, and Why Does COSO Care?
An AI audit trail records what an AI tool read, what rule it applied, what it changed and who reviewed the output before it became a number in your books.
It's the difference between "the software did it" and "here's exactly what the software did and who signed off." COSO is the group behind the internal control framework nearly every audit in the country already runs on. In February 2026, it published new guidance called Achieving Effective Internal Control Over Generative AI. Same five-part structure auditors already know: control environment, risk assessment, control activities, information and communication, monitoring activities. Applied to AI, for the first time.
What COSO's guidance actually asks for
COSO sorts AI use into eight categories, from simple data ingestion up through judgment calls and orchestration between tools. For each one, it lays out a six-step roadmap: govern, inventory, assess, design, implement, monitor. The guidance is explicit that this roadmap is meant for an external auditor to use, not just kept internally. Prompts and configuration settings count as part of the trail. So does every version change to the model or the rules it follows. None of this requires new software. It requires deciding, in advance, what gets written down every time AI touches a number in the financial statements.
The Five-Item Evidence Checklist Every Finance Team Needs
Strip away the standards language and the ask is short: five things, organized by financial process, kept current instead of assembled after the fact.
| Evidence item | What it proves | Who owns it |
|---|---|---|
| AI use inventory | Every tool touching financial data, what it does and which accounts it affects | Controller or finance systems owner |
| Decision and change logs | What the tool did, what inputs it used and when the model or rules changed | Tool owner or IT, reviewed monthly |
| Human review sign-off record | Who reviewed each AI-assisted output before it posted, and when | Preparer and reviewer, at the transaction or batch level |
| Vendor audit-trail export | Proof the vendor's own system can produce a traceable record on demand | Vendor, requested and stored quarterly |
| Exception and override log | Every time a human overruled the AI, and why | Preparer, logged at the time of override |
AI use inventory
Start with a plain list: the tool, what it touches (accounts payable, reconciliations, revenue recognition) and what data flows into it. If you can't produce this list in ten minutes today, that's the first gap to close.
Decision and change logs
This is the part COSO calls out specifically. Every time the model or the business rules behind it change, someone needs a dated record of the old version, the new version and why it changed. Most AI vendors can export this. Few finance teams have asked for it yet.
Human review sign-off record
An AI tool producing a number isn't evidence on its own. A person confirming that number, with a timestamp, is. A reviewed-by field and a date on the transaction record is often enough.
Vendor audit-trail export
Kognitos, an AI vendor that launched a new accounts payable tool in August 2026, built its pitch around this exact idea: every decision traces back through a connected graph of your firm's own approval rules. That's what "audit-trail-by-design" looks like in practice. Whatever vendor you use, ask them the same question: can you pull a complete decision trail for one transaction, on demand, in under a minute?
Exception and override log
When a person overrides what the AI recommended, that moment often tells an auditor more than a hundred clean transactions. Log it every time, with the reason.
Free CPA AI Policy Checklist
Before staff paste client data into AI, check the rules your firm is missing.
Get the free checklist and join the Dispatch for practical AI controls, vendor questions, and client-data safeguards for accounting teams.
Free. No spam. You will also get the Nexairi Dispatch.
Isn't a Policy Document Enough?
No. A written AI policy tells an auditor what your firm intends to do, not what it actually did on any given transaction.
This is the most common mistake finance teams make. Auditors test for evidence that a control operated, not that it exists on paper. A binder of logs beats a binder of policies every time.
How Is This Different From Ordinary IT Audit Documentation?
Standard IT controls cover access and system availability. The AS 1105 and AS 2301 amendments go further, requiring proof that AI's own analysis was reliable enough to trust.
That's a narrower question than "does your system have access controls." It's asking whether the AI's own output can be trusted, and on what basis. This sits alongside, not instead of, the access and change-management controls your firm already documents for Sarbanes-Oxley (SOX) internal control over financial reporting (ICFR) purposes. Under AU-C 230, the general documentation standard auditors already work under, the requirement was always to document the procedure and the evidence behind it. The AS 1105/2301 amendments sharpen that specifically for cases where a tool, not a person, did the analyzing.
Why the assurance-readiness gap matters here
KPMG's 2026 Global AI in Finance survey of 1,013 senior finance leaders found active AI use in finance jumped from 30% to 75% since 2024. Assurance-ready firms? Only 42%. That's the real weak spot, not adoption. Firms that can produce AI audit evidence efficiently see three to six times better outcomes: 33% report meaningful error reduction versus 6% for those who can't, and 42% report confidence in scaling AI versus 14%. Read against the new PCAOB and COSO material, the pattern holds. Firms that treat evidence collection as a habit, not a scramble before fieldwork, come out ahead well past the audit itself.
What Should Your Firm Do Before the 2027 Audit Season Starts?
Start with the inventory. You can't log what you haven't counted, so build the full list of AI tools touching your books first.
Once every tool is on one list, assign an owner to each of the other four checklist items and set a recurring review date, quarterly works for most firms. Ask every AI vendor you use today whether they can produce a decision trail on demand. If they can't, that's worth knowing before an auditor asks the same question.
None of this needs a formal mandate to start. Both standard-setters already describe what auditors will be looking for. Build the binder now. Handing it over next year takes five minutes instead of a scramble during fieldwork.
Nexairi tracks PCAOB and COSO guidance like this as it lands. Subscribe to Nexairi Dispatch for the next update.
Sources
- Journal of Accountancy: COSO creates audit-ready guidance for governing generative AI
- PCAOB: Updates to standards clarifying auditor responsibilities for technology-assisted analysis
- KPMG: AI adoption in finance doubles, but assurance readiness determines who wins
- Kognitos launches Context Graph for Finance
Related Articles on Nexairi
Free Assessment
Is your firm ready for AI?
A 5-minute governance check for CPA firms using ChatGPT, Copilot or AI accounting software. Get your score and your top gaps — free.
Jim Smart is the founder and editor in chief of Nexairi. A Business Intelligence Developer with experience building data systems for Verizon, U.S. Army operations, and enterprise finance teams, Jim spent years turning complex data into decisions that executives could act on — dashboards, forecasting models, and automation pipelines across telecom and government contracting. He founded Nexairi to apply that same clarity to AI: making emerging technology understandable and actionable for the operators, accountants, and business owners who need it most. Jim holds GenAI certifications from the University of South Florida Bellini College of AI and completed Springboard's Data Science Career Track.

