Using AI in audits: Practical guardrails for every accounting firm

Technology

The AI debate has moved on from “does AI belong in accounting?” to “where do AI tools sit in our practice, and when should we not use AI?”, writes Louis Quintal.

07 October 2026 • By Louis Quintal • 5 minutes read
Share this article on:

I’d like to share AI insights learned as part of my leadership role in technology transformation and adoption for RSM Australia’s national audit practice.

AI is already broadly used across global and local accounting firms, most commonly in operational and client services divisions and focused on tasks including drafting, summarising, meeting notes, research and client onboarding.

More mature AI users are implementing AI to assist with the audit function, particularly in planning and risk assessment.

There are questions every accounting firm, whether a national network or sole practitioner, needs to address when building use of AI into their business.

These centre around whether use of AI is right for your business currently, how it can be used to clearly improve work (and time management), and what the responsible use of artificial intelligence looks like in audit evidence.

Underpinning these questions is the big one: “What can never be handed over to AI?” Part of answering this question involves clarifying how your firm can ensure its use of AI is legal and ethical.

This is where it’s important to run risk management around client confidentiality and permissions, ethical and regulatory obligations and use of any AI vendor’s model.

 
 

Set up wisely; put practical guardrails in place

Don’t start at the question of what AI tool your firm should invest in. To get the best value from this investment, first step through the discovery process of what you are trying to improve (for example, is it consistency, capacity, or quality?).

Ensure that your firm’s data is reliable, you have standardised documents, and your systems and processes allow for automation.

Finally, before implementing your AI strategy, training is required to ensure your people have the capability to critically use and monitor/evaluate AI tools.

It can be useful to initiate key guardrails that keep your audit team’s use of AI on track.

Guardrail One: list your firm’s approved AI tools and outline a clear usage policy.

Guardrail Two: disclose your use of AI within engagement files.

Guardrail Three: always review procedures around AI-assisted work. Apply the lessons from each assignment to streamline future use and document best practice.

Guardrail Four: when you train your team, don’t just train them on how to operate the software. Humans rule: ensure they are taught how to challenge AI output.

5 audit non-negotiables for humans, not AI

You can delegate tasks to AI, but not responsibility. Here are five key audit essentials that should never be delegated to AI:

  1. Professional judgement (and scepticism)

    AI can only inform an auditor’s judgement. For auditors, an answer from an AI model deserves the same scepticism and challenge as that from a human CEO. It’s important that scepticism not be eroded by the human tendency to defer to a machine’s answer.

  2. Evaluation of AI’s output

    In audit, it is never acceptable to say “our AI tool said so” – ensure a competent human within your team can explain why the output is reliable, and whether the finding makes sense against everything else known about the entity.

  3. Human direction, supervision and review

    This is the responsibility of the engagement partner, who must know where AI was used so they know where to point their challenge.

  4. Audit conclusions

    There must be partner accountability for everything from an individual assertion through to the final opinion.

  5. Ethical obligations

    The auditor’s obligations to independence, objectivity and confidentiality can never be delegated to AI. This means keeping client data out of the reach of unapproved tools and requires explicit rather than assumed client permission.

Whether you are a large firm with a proprietary AI platform, or a small firm assembling your AI from third-party vendor tools, the audit quality framework is consistent.

In Australia, Auditing Standard ASQM 1 applies with equal force, asking four questions every firm must be able to answer before AI touches an engagement: what quality risk does this introduce, what control mitigates it, who is accountable and what evidence will be retained?

If you can’t answer these four questions, your chosen AI tool should not be used in an audit.

AI is most useful where it is used to feed human judgement and most dangerous where it is mistaken for human judgement – at its heart, an audit file absolutely must show that a human understood, challenged and took responsibility for the output.

Louis Quintal (pictured) is an audit and assurance partner in the Sydney office of national firm RSM Australia, leading RSM’s technology transformation and adoption across their national audit practice.

Accountants DailyWant to see more stories from trusted news sources?
Make Accountants Daily a preferred news source on Google.
Tags: