The rapid development of Artificial intelligence ("AI") continues to transform the audit profession. However, there is a growing divide between the largest audit firms and the wider market in both the pace and scale of AI uptake.
The "Big 6" audit firms have invested heavily in developing and deploying AI, embedding the technology across a range of audit functions. AI is increasingly being used to analyse large volumes of financial data, support risk assessments and identify patterns that may indicate fraud, error or other anomalies. AI is not simply driving efficiencies but also enhancing audit quality by enabling deeper analysis and more targeted scrutiny.
By contrast, much of the wider market appears to be waiting to see how the cards fall before committing significant resources to AI implementation. Many firms are continuing to assess the costs, risks and regulatory implications associated with AI adoption, while also considering the impact that automation may have on traditional team structures and career pathways.
Recognising the opportunities AI brings to the audit profession, the Financial Reporting Council ("FRC") has recently published guidance on its expectations for the use of AI in audit[1] which acknowledges that AI is increasingly moving from experimentation to deployment on live audit engagements.
The FRC's AI in Audit Guidance – Key Takeaways for Audit Firms
On 30 March 2026, the FRC published its guidance "Generative and Agentic AI – Risks, mitigations and illustrative examples". The FRC was keen to emphasise that it supports innovation and the appropriate use of AI. The guidance focuses on generative and agentic AI (i.e. using large language models) rather than non-generative AI.
The FRC's guidance does not create new auditing standards. Instead, it explains how existing auditing, quality management and documentation requirements apply when firms use AI-enabled tools.
The FRC sets out three risk categories:
- risk of deficient output (i.e. that the output from the AI tool is deficient)
- risk of misuse of output
- risk of non-compliant methodology (where a firm's methodology which permits the use of AI is not compliant with auditing standards).
The guidance examines how each of these risks may arise throughout the audit lifecycle and the potential impact they may have on audit quality, reliability of audit evidence and regulatory compliance.
The FRC outlines how these risks can be mitigated through a combination of technology controls, governance frameworks and human oversight i.e. safeguards which include designing and adopting the correct system, robust testing and validation procedures, certification processes, staff training and effective review mechanisms.
A central theme of the guidance is that the use of AI does not alter existing accountability frameworks, and that AI should support, rather than replace, professional judgement. The responsibility for audit quality remains with the audit firm and engagement partner.
Practical Implications
For Responsible Individuals, the practical implication is that AI outputs cannot simply be accepted at face value. Engagement teams must understand the limitations of the tools they are using. The FRC makes clear that it will be a matter of professional judgement how AI is used in each case and how much confidence is placed in the quality of the output. The FRC emphasises that the level of explanation required will depend on the circumstances, but audit teams should be able to justify why an AI-generated output is reliable and appropriate for the purpose for which it is being used.
For firms, there are a wide range of responsibilities which they must fulfil. Firms are expected to understand how AI tools operate, assess the risks associated with their use and undertake appropriate testing before deployment. Where audit procedures are supported by AI, firms should ensure that team members have appropriate training and there are clear processes for reviewing and verifying outputs before reliance is placed upon them. The guidance signals increasing regulatory scrutiny of AI governance. Firms should consider whether their quality management systems adequately address AI risk, including tool approval processes, monitoring arrangements, model validation, data quality controls and documentation requirements.
Professional Liability in an AI-Assisted Audit Environment
AI does not change professional responsibility and accountability
Perhaps the most important message in the FRC's guidance is that while AI may assist the audit process, this does not diminish the duties imposed by auditing standards, professional regulation or common law. The FRC has emphasised that AI outputs must be subject to appropriate human review and challenge, rather than accepted uncritically. Responsibility for the audit opinion remains firmly with the auditor. Thus, auditors remain responsible for ensuring that sufficient appropriate audit evidence has been obtained and that appropriate professional judgement has been exercised throughout the engagement.
Negligence and Professional Liability Risks
It seems likely to us that as AI becomes increasingly embedded within audit methodologies, where errors occur, the focus will be on whether it was used appropriately by the auditor and the audit firm rather than on the AI product. Although this has yet to be tested, we think liability is unlikely to shift onto the technology provider which, just as for IT consultants of yesteryear, will no doubt deploy a range of exculpatory terms and exclusions in their standard terms.
Traditional professional negligence principles will apply to AI-assisted audits. The fact that an AI system produced an erroneous result is unlikely, by itself, to provide a defence or lower the expected standard of care of auditors. Instead, auditors will be expected to demonstrate that they undertook reasonable due diligence, validation and monitoring before and when deploying the technology.
The following are obvious potential liability risks:
- AI-generated outputs are relied upon without adequate review or validation.
- Anomalies identified by AI are not appropriately investigated or followed up.
- Engagement teams place excessive reliance on automated conclusions.
- Staff lack sufficient understanding of the limitations of the technology being used.
- Firms fail to implement adequate governance, testing or monitoring procedures.
- Deficiencies in AI-enabled audit methodologies result in non-compliance with auditing standards.
Regulatory Exposure and Enforcement Risk
As for regulatory exposures facing firms, the FRC has made clear that AI governance should be incorporated within firms' quality management frameworks. Its guidance stresses the importance of documentation, explainability, risk assessment and validation procedures. For audits subject to FRC investigation, the FRC will expect firms to have adequate records demonstrating:
- why a particular AI tool was selected;
- the testing and validation undertaken before deployment;
- the extent to which the tool was used during the engagement;
- what review procedures were applied to its outputs; and
- why the audit team considered the results sufficiently reliable.
Firms that cannot explain how an AI-generated conclusion was reached, or why it was trusted, may face greater scrutiny or criticism and regulatory sanction when AI derived errors are identified.
In short, where audit failures occur, enquiries are likely to extend beyond the immediate engagement team and into the firm's broader systems of quality management.
This reflects a broader shift in regulatory thinking. Increasingly, the focus is not simply on individual audit decisions but on whether firms have established systems and controls capable of managing emerging technological risks.
Governance: What Should Audit Firms Be Doing Now?
Firms seeking to adopt AI for audits will therefore need to consider:
- Establishing a formal AI governance framework.
- Conducting legal and regulatory risk assessments before deployment.
- Implementing robust model validation and testing procedures.
- Maintaining clear documentation on audit files.
- Training personnel on the capabilities and limitations of AI tools as well as specifically training them on the tools on used.
- Updating engagement methodologies and quality management systems.
- Conducting data protection impact assessments where appropriate.
- Monitoring regulatory developments in the UK and internationally.
Looking Ahead
The direction of travel is clear, generative-AI will become an increasingly embedded feature of audit engagements and firms must embrace the need for necessary changes to their systems and processes when using AI.
While the technology is evolving, the legal and regulatory framework remains unchanged. Professional judgement, scepticism and accountability continue to sit with the auditor. Having robust documentation evidencing the exercise of professional judgment when using AI will be critical to managing regulatory and liability risks.
[1] Generative and Agentic AI Guidance – 30 March 2026 (Generative and Agentic AI Guidance)