Auditing standards are built on a set of assumptions so foundational that nobody thought to write them down as assumptions. One of them is that when a standard refers to an expert, it means a person. That assumption has held for the entire history of the modern audit, and the international standard setter has now put it explicitly on the table for reconsideration.

Key Takeaway

An IAASB technology working document notes that the ISA 500 package on audit evidence either explicitly refers to an expert as human or implies it, observes that new technologies including AI and robotic process automation are in some ways designed to reduce or eliminate the need for human involvement, and states the Board should continue to consider whether the assumption that experts must be human, or at least involve a human in the loop, remains valid today. Separately, the IAASB has issued proposed revisions to ISA 330, ISA 500 and ISA 520, with comments requested by December 15, 2026, taking a deliberately principles-based rather than technology-specific approach. Against this, Canada's audit regulator provides a useful corrective: CPAB observed that adoption of AI technologies in audit tools is in its early stages, with limited implementations noted in the public company audit files it had inspected. The standards are being rewritten faster than the technology is actually appearing in Canadian audit files.

The Reality Check From Canada's Audit Regulator

It is worth beginning with the least exciting and most useful fact available, because it calibrates everything that follows. The Canadian Public Accountability Board, the regulator that inspects public company audits in Canada, published a paper on the use of artificial intelligence in the audit in which it observed that the adoption of AI technologies in audit tools is in its early stages, with limited implementations noted in the public company audit files it had inspected to date, while anticipating increased use of AI-enabled tools going forward[1].

This is a regulator reporting what it actually found in files it actually opened, which is a different evidentiary category from vendor claims or profession commentary about transformation. It does not mean AI is absent from auditing or that it will remain so; CPAB explicitly anticipates the opposite. It means that a Canadian business owner reading that AI has revolutionized the audit should hold that claim loosely, and that the standard-setting activity described in the rest of this article is largely anticipatory rather than reactive.

Two Different Questions, Constantly Conflated

Discussion of AI and auditing routinely runs together two questions that have different answers and different governing standards, and separating them makes the whole topic tractable.

The first is what happens when the audited entity uses AI. A company using AI for complex calculations, estimates, or transaction processing has introduced something into its financial reporting environment that the auditor must understand and assess. This is primarily an ISA 315 question.

The second is what happens when the auditor uses AI. An audit firm using AI tools to select samples, test populations, or analyze data is generating information it intends to rely on as audit evidence, which raises questions about the relevance and reliability of that information and about how the work is documented. This is primarily an ISA 500 and ISA 230 question.

A business owner talking to their auditor about AI should be clear which conversation they are having, because the obligations, and the questions worth asking, differ substantially between them.

When The Client Uses AI: ISA 315

ISA 315 (Revised 2019), Identifying and Assessing the Risks of Material Misstatement, requires auditors to understand an entity's information system and IT environment. Where an entity uses AI in its financial reporting, for example for complex calculations or estimates, auditors must understand that part of the IT environment, identify associated risks including potential biases in the AI model, and evaluate relevant controls[2].

Three obligations sit in that sentence and they escalate in difficulty. Understanding the AI component of the IT environment is demanding but tractable. Identifying associated risks including model bias requires expertise many audit teams are still building. Evaluating relevant controls presupposes the entity has controls over its AI to evaluate, which, as this publication has discussed in the context of shadow AI and model governance, is frequently not the case at small and mid-sized businesses.

The practical consequence for a business is direct: if you have introduced AI anywhere into a process that feeds your financial statements, your auditor now has work to do that they did not have before, and the quality of your own documentation about that system determines how expensive that work is.

When The Evidence Comes From AI: ISA 500

ISA 500, Audit Evidence, governs the auditor's responsibility to obtain sufficient appropriate audit evidence. As AI tools become more prevalent, auditors must critically assess the relevance and reliability of information generated by or through AI systems when that information is used as audit evidence[2].

The words "relevance and reliability" are the operative standard, and they are considerably harder to satisfy for AI-generated information than for a bank confirmation or a signed contract. Reliability of a traditional evidence source turns on its provenance and integrity. Reliability of AI-generated information turns additionally on the model's construction, the data it was trained or run on, its known failure modes, and whether the specific output can be traced. This connects directly to the reliability limitations this publication has examined elsewhere, where benchmark research found leading models collapsing from high accuracy on simple lookups to near-zero on multivariate calculations, precisely the kind of derived figure an auditor might otherwise be tempted to accept.

The Expert Question

The most conceptually interesting development is in an IAASB technology working document, and it deserves quoting closely because of what it concedes. The document notes that the ISA 500 (Revised) package either explicitly refers to the expert as human or implies it, observes that new technologies including artificial intelligence and robotic process automation are in some ways designed to reduce, and in some cases eliminate, the need for human involvement, and states that the Board should continue to consider whether the assumption in IAASB standards that experts must be humans, or at least involve human interaction, that is, a human in the loop, remains valid today[3].

This matters because the auditor's expert is a defined role in the standards with an established framework around it: the auditor evaluates the expert's competence, capabilities and objectivity, understands their field, agrees the scope of work, and evaluates the adequacy of the resulting work. That framework was built around a person who has professional obligations, can be questioned, and can explain their reasoning. Whether and how it maps onto a model is genuinely unresolved, and the IAASB is not pretending otherwise.

It is worth noting the document's own framing of urgency: it records that the Board believes it is premature to assign priority to developing non-authoritative materials on the issue[3]. This is a question identified and parked, not a question being answered imminently.

Automated Tools And Techniques

The IAASB's own umbrella term for this territory is worth knowing because it appears throughout the guidance and is deliberately imprecise. "Automated tools and techniques" (ATT) is described as a broad term for the tools and techniques auditors use in performing audit procedures, and the IAASB states the term is deliberately broad because technologies and related audit applications will continue to evolve, citing artificial intelligence applications and robotics automation processes as examples[4].

The IAASB has published a body of non-authoritative material under this heading, covering audit planning when using ATT, using ATT in identifying risks of material misstatement, using ATT in performing audit procedures, audit documentation when using ATT, investigating exceptions and the relevance of performance materiality when using ATT, and, notably, an FAQ specifically on the risk of overreliance on technology[4]. The IAASB has also introduced a Technology Position to guide how it adapts its work at the intersection of audit, assurance and technology[4].

The Documentation Problem

The IAASB's Technology Working Group published non-authoritative support material on the auditor's documentation when using automated tools and techniques such as data analytics, robotic process automation, or AI applications, assisting auditors in understanding how ATT use may affect documentation under ISA 230, Audit Documentation, and other relevant ISAs[5]. The material is explicit that it does not constitute an authoritative pronouncement, does not amend, extend or override the standards, and is not a substitute for reading them[5].

The underlying difficulty is worth naming. ISA 230's documentation principle is that the working papers should enable an experienced auditor with no previous connection to the audit to understand the work performed and the conclusions reached. That standard is comparatively easy to meet when the work performed is "we selected 40 items and vouched them." It is meaningfully harder when the work performed is "a model scored the population and surfaced these exceptions," because reproducing that understanding requires documenting the tool, its configuration, the population, and the basis for accepting its output, none of which the traditional working paper format was designed to capture.

The Live Consultation Closing December 2026

This is an active rather than settled area, and businesses and practitioners have a window to comment. The IAASB has issued proposed revisions to ISA 330, The Auditor's Responses to Assessed Risks; ISA 500, Audit Evidence; and ISA 520, Analytical Procedures, with responses requested by December 15, 2026[6].

The proposals include a revised definition of audit evidence to reflect today's digital environment, greater emphasis on the intended purposes of audit procedures, strengthened requirements for evaluating the relevance and reliability of information used as audit evidence, and clarification of the roles of tests of controls, substantive procedures and analytical procedures[6]. They also include guidance to help auditors exercise professional judgment about appropriate use of technology[6]. The IAASB has indicated it will offer additional engagement opportunities including a user survey and webinar series during the consultation period[6].

For context on how long this has been developing: the IAASB established a working group in January 2019 to explore issues related to audit evidence, recognizing the evolution in the business environment and audit practice including technology use by both the entity and the auditor, and approved a project to update ISA 500 in December 2020[7]. An earlier exposure draft of ISA 500 (Revised) sought comments by April 24, 2023[8]. This is a seven-year project and still open.

Why Principles-Based Rather Than Technology-Specific

The IAASB has been explicit about its methodological choice, and the reasoning deserves attention because it is the same choice OSFI made in Guideline E-23 as discussed elsewhere in this publication. The proposals reflect the IAASB's conclusion that a principles-based rather than technology-specific approach is the best way to maintain robust and relevant standards in the face of rapid technological evolution, enabling innovation while preserving the core principles of high-quality auditing[6].

The convergence is instructive. Two independent standard setters, in different domains and jurisdictions, examined the same problem and reached the same answer: do not write rules about specific technologies, because the rules will be obsolete before they take effect. Write principles about what must be achieved, and require the practitioner to demonstrate they achieved it whatever tool they used. This is almost certainly correct, and it has a predictable cost: principles-based standards transfer judgment, and therefore risk, to the practitioner, who must decide what "sufficient appropriate" means for a novel tool with no worked precedent to rely on.

A Worked Case: The Sample That Wasn't A Sample

An audit team testing a large transaction population used an AI-enabled tool that scored every transaction for anomaly risk and surfaced 60 items for examination, rather than selecting a statistical sample in the traditional sense. Every one of the 60 was examined and cleared. The engagement partner asked a question that turned out to be harder than expected: what does clearing those 60 items actually let us conclude about the other 400,000?

With a statistical sample, the answer is well-established: the sample supports an inference about the population within a calculable confidence interval, and the methodology for that inference is decades old. With a risk-scored selection, the 60 items are by construction the least representative items in the population, deliberately so. Their clearance says something valuable about the highest-risk transactions and something considerably less clear about the remainder, and the strength of that second inference depends entirely on whether the model reliably identifies the transactions that matter, which is a property of the model rather than of the sample.

The team's resolution was to treat the AI selection as a targeted procedure supplementing rather than replacing a separate representative sample, and to document the model's role, configuration and known limitations as part of the basis for that decision. The transferable point is that AI tools in auditing do not merely make existing procedures faster; some of them produce a different kind of evidence with different inferential properties, and the standards are still catching up to that distinction.

What This Means If Your Business Is Audited

Three practical implications for a business subject to audit, whether statutory or lender-required.

Document your own AI use before your auditor asks. Under ISA 315 your auditor must understand and assess AI in your financial reporting environment. A business that can hand over a clear description of what tools it uses, for what, with what controls, converts an expensive discovery exercise into a short conversation. A business that cannot will pay for the auditor to work it out.

Ask your auditor what they use, and how they document it. This is a reasonable question and a revealing one. Firms with a considered answer, covering tool selection, validation, and documentation approach, are further along than firms that describe capability without describing controls.

Do not assume AI in the audit means a cheaper or faster audit. CPAB's finding of limited implementation suggests the transformation is more anticipated than realized, and the documentation and evaluation obligations discussed above are additional work rather than substitutions for it, at least during transition.

The Overreliance Risk The IAASB Names Directly

It is worth ending on a risk the standard setter itself has singled out for dedicated guidance: the IAASB's ATT material includes an FAQ specifically addressing the risk of overreliance on technology[4], and the ISA 500 revision project has as an explicit objective emphasizing the role of professional skepticism when making judgments about information intended to be used as audit evidence and when evaluating the evidence obtained[8].

The concern is recognizable from the algorithm-appreciation research discussed elsewhere in this publication: a tool that produces authoritative-looking output on a task where correctness is hard to independently verify invites acceptance rather than scrutiny. An auditor who would rigorously challenge a client's manual schedule may be less inclined to challenge a comparable figure produced by a sophisticated tool, not through carelessness but because the output carries an unearned presumption of rigour. Professional skepticism was always the profession's answer to that tendency, and the IAASB's emphasis suggests it considers the tendency to be strengthening rather than weakening.

The Limits Of This Analysis

Several caveats matter. This article discusses International Standards on Auditing; Canadian audits are conducted under Canadian Auditing Standards, which are based on the ISAs but are adopted through the Canadian standard-setting process, and readers should confirm the Canadian position rather than assume identity with the international text. The ISA 500 revision is a live consultation with responses due December 15, 2026, so the proposals described here may change materially before finalization and nothing in them is currently in force. The characterization of the expert question is drawn from an IAASB working document cataloguing issues and possible actions, which by its nature records matters under consideration rather than settled positions or commitments. Finally, this article is written for business owners rather than practitioners; auditors should work from the standards, the exposure drafts, and their firm's methodology rather than from a general summary.

Frequently Asked Questions

Is AI actually widely used in audits right now?
Less than coverage suggests, at least in Canada. The Canadian Public Accountability Board observed that adoption of AI technologies in audit tools is in its early stages, with limited implementations noted in the public company audit files it had inspected, while anticipating increased use going forward.
Can an AI system be treated as an auditor's expert under the standards?
Unresolved. An IAASB working document notes the ISA 500 package either explicitly refers to the expert as human or implies it, and states the Board should continue to consider whether that assumption remains valid given technologies designed to reduce or eliminate human involvement. The Board has indicated it considers it premature to prioritize non-authoritative material on the question.
What changes if my business uses AI in its financial reporting?
Under ISA 315, your auditor must understand that part of your IT environment, identify associated risks including potential model bias, and evaluate relevant controls. Practically, that is additional audit work, and how expensive it is depends substantially on whether you can document your own AI use clearly.
Are the auditing standards being changed for AI?
Yes, though deliberately not in a technology-specific way. The IAASB has proposed revisions to ISA 330, ISA 500 and ISA 520 with comments due December 15, 2026, including a revised definition of audit evidence for the digital environment and strengthened requirements on relevance and reliability. The IAASB has concluded a principles-based rather than technology-specific approach is preferable.
What are "automated tools and techniques"?
ATT is the IAASB's deliberately broad umbrella term for tools and techniques auditors use in performing audit procedures, chosen for breadth because technologies will continue to evolve. It covers data analytics, robotic process automation, and AI applications, and the IAASB has published non-authoritative guidance on using ATT across planning, risk identification, procedures, and documentation.
Does AI in the audit make my audit cheaper?
Not reliably, at least during the current transition. Adoption appears limited in practice per CPAB's inspections, and the obligations to understand, evaluate and document AI-related work are additional rather than substitutive. Efficiency gains may come, but treating them as already available would be premature.
IB

About The Insight Bureau Research Desk

The Insight Bureau is GSH Financial's research publication, written for Canadian business owners and the students who will eventually advise them. This article draws on IAASB published material and Canadian audit regulator findings, and distinguishes proposals under consultation from standards in force; see References below.

References

  1. Canadian Public Accountability Board. (2024). The Use Of Artificial Intelligence In The Audit. CPAB Thought Leadership. cpab-ccrc.ca/.../2024-use-of-artificial-intelligence-in-the-audit-en.pdf
  2. Egger, J. (2025, May 22). AI In Auditing: Is Our Rulebook Ready For The Digital Age? Everyday AI, describing the application of ISA 315 (Revised 2019) and ISA 500 to AI. medium.com/everyday-ai/ai-in-auditing-is-our-rulebook-ready-for-the-digital-age
  3. International Auditing and Assurance Standards Board. (2025, November). Technology Position: Catalog of Issues and Possible Actions. ifacweb.blob.core.windows.net/.../IAASB-Technology-Catalog-of-Issues-Proposed-Actions.pdf
  4. International Auditing and Assurance Standards Board. Technology focus area, on Automated Tools and Techniques and the IAASB Technology Position. iaasb.org/focus-areas/technology
  5. International Auditing and Assurance Standards Board Technology Working Group. (2020, April 23). Non-Authoritative Support Material: Audit Documentation When Using Automated Tools and Techniques. iaasb.org/publications/non-authoritative-support-material-audit-documentation-att
  6. International Auditing and Assurance Standards Board. (2026). Proposed Revisions for Audit Evidence & Risk Response: ISA 330, ISA 500 & ISA 520, comments requested by December 15, 2026. iaasb.org/publications/proposed-revisions-audit-evidence-risk-response-isa-330-isa-500-isa-520
  7. International Auditing and Assurance Standards Board. Proposed International Standard on Auditing 500 (Revised), Audit Evidence, Explanatory Memorandum, on the January 2019 working group and December 2020 project approval. bdo.global/.../IAASB-Exposure-Draft-ISA-500-Audit-Evidence.pdf
  8. International Auditing and Assurance Standards Board. (2022). Proposed International Standard on Auditing 500 (Revised), Audit Evidence, and Proposed Conforming and Consequential Amendments, exposure draft with comments requested by April 24, 2023. iaasb.org/publications/proposed-international-standard-auditing-500-revised-audit-evidence
  9. International Auditing and Assurance Standards Board. Audit Evidence project page. iaasb.org/consultations-projects/audit-evidence

This article discusses international auditing standards, proposals under active consultation, and Canadian audit regulator findings, and is provided for general informational purposes. It is not audit or assurance advice. Canadian audits are performed under Canadian Auditing Standards; confirm the applicable Canadian position with a licensed practitioner rather than relying on the international text described here.