We just went through a SOC 2 Type II examination: our security and operational controls, tested over time, not at a point in time, by an auditor with nothing to gain from a clean result. That's not a financial statement audit, and I don't want to blur the two.

But the principle underneath it, independent testing by someone with no stake in whether the story holds, is exactly what's missing at the financial-statement-audit level when the thing being tested is AI.

I've spent the last few months in 70+ conversations with CFOs, controllers, and auditors on that gap specifically. What I found: no major U.S. audit firm or regulator has published a framework for testing AI-touched workflows in financial audits, despite AI already sitting inside revenue recognition, close processes, and contract intelligence at most of the companies I talked to. (The UK's Financial Reporting Council published the first regulator guidance in March. The U.S. hasn't followed yet.)

Firms are hesitant, not silent. KPMG is piloting agent-driven audit work, and firms are submitting comment letters as recently as this June. The emerging position is "audit the input and the output, not the model." But that leaves real gaps: what documentation counts, how a controls walkthrough works when an agent touched the number, what "explainable" even means to an auditor.

Boards aren't waiting for the framework. They're already asking: What's your AI roadmap? What are the risks? Who owns drift? Most finance teams can't answer cleanly, because probabilistic outputs can't be the system of record, and most companies can't reliably say what AI touched during a reporting period.

The clock: Q4 audit conversations start this summer. First-time auditors are already deferring engagements to Q4 2026 or Q1 2027. Whatever gets agreed on before mid-September becomes the reference point for the whole cycle. The vocabulary for this is being set right now, whether anyone means it to be or not.

I wrote up the twelve questions worth bringing to your next partner conversation, organized around four things that actually matter:

  • Lineage & traceability: can you tie a revenue entry back to the contract it came from, and re-derive it the same way in 90 days?
  • Failure modes: does your team know the difference between a loud failure and a quiet one, and could a junior auditor walk the evidence?
  • Data & drift: who owns it when systems stop reconciling, and does anyone catch it before it propagates downstream?
  • Documentation & readiness: could you assemble an audit packet today, model card included, with a clean chain of custody?

None of these require a position on AI in finance. They just require someone to ask them before the audit does.

Full piece, with all twelve: The AI-in-Audit Guidance Gap →