The topic of artificial intelligence (AI) is inescapable in 2026. Every accounting firm, from sole practitioner to national network, now faces the same practical question:
Where do AI tools belong in our practice, and where do they not?
Note that the question is no longer whether AI has a place in professional services. It plainly does. The harder questions are:
- whether it is right for your business now
- where it genuinely improves the work rather than merely decorating it
- what can never be handed over to an AI
- what responsible use of AI looks like in audit evidence.
We will examine those questions, beginning with the firm as a whole and narrowing to the specific demands of audit and assurance.
Does every accounting firm need AI?
Before turning to audit, it is worth acknowledging how broadly AI is already at work across accounting firms. The most common and lowest risk applications sit in operations and client service rather than in assurance. These include:
- drafting and summarising correspondence
- first pass preparation of file notes and meeting minutes
- accelerating research in tax and advisory work
- tidying bookkeeping classifications
- streamlining client onboarding.
What unites these use cases is that the output is internal, provisional and produces a draft for a human to finish, not a deliverable in itself. That is precisely why they are the sensible front door for most firms.
However, AI is not suitable for every accounting or professional services firm. It certainly should not be adopted by every firm at the same pace. Asking, “what tool should we buy?” at the outset is the wrong approach. A more disciplined approach would involve working through a short sequence of questions.
First, what outcome are you trying to improve?
Is it quality, turnaround, capacity or consistency? Is AI genuinely necessary to achieve that outcome, or would better processes do the job?
Second, are you ready to unlock the full value of an AI tool?
Is your data available and reliable, are your documents reasonably standardised, are your processes mature enough to automate, and do your people have the capability to use these tools critically?
Third, what constraints apply to how you can legally and ethically use AI?
Consider client confidentiality and permissions, independence and ethical obligations where assurance is involved, regulatory expectations, and the risks that come with any vendor's model.
Only after considering these questions carefully can your firm choose a starting point that is deliberately low risk, internally facing, with clear human review and measurable success criteria and make an honest decision:
- to proceed
- to pilot and learn
- to pause and address the gaps first.
A firm that pauses for good reasons is making a better decision than a firm that proceeds for bad ones. Whatever the path, governance responsibilities should be documented from day one, a named owner for AI use, an approval route for new tools, and someone accountable for monitoring how they perform in practice.
Common failure points when implementing AI
The most common failure modes are by now well-documented, and they are rarely technological.
Firms buy AI tools before they’ve defined the problems they want it to solve.
They feed poor quality data into capable systems and are surprised by poor quality answers.
Some firms will train their people to operate AI tools but not to challenge the output. This cultivates over-reliance.
And some treat governance as a document rather than a practice, discovering only at review time that nobody can say which engagements used which tools for what. Every one of these failures is avoidable, and every one of them is cheaper to avoid than to remediate.
Where AI is genuinely improving audit
Within audit specifically, the honest 2026 answer is that the value of AI is real but unevenly distributed. The most favourable balance of benefit and risk are found during the engagement planning and fieldwork stages of the audit.
Planning and risk assessment
Planning and risk assessment is where AI earns its keep for auditors. It can quickly summarise board minutes, prior year files, contracts and industry information, which accelerates the audit team’s understanding of the entity. Applying AI pattern analysis across the trial balance can also surface unusual movements early and sharpens where we direct the risk assessment. Generative tools have also proven genuinely useful in suggesting fraud and risk scenarios the engagement team might not otherwise have considered.
These work as AI use-cases because planning outputs feed human judgement rather than constituting audit evidence. The information AI produces helps inform the planning discussions, but everything gets reviewed and challenged during the discussion. What used to consume a senior's full day of reading becomes a two-hour exercise in review and challenge, which enables better use of senior talent.
However, the final risk assessment remains the responsibility of the audit team, and that judgement cannot be delegated to AI.
Fieldwork
Audit fieldwork is simultaneously where AI capability is most impressive and human discipline most necessary.
The flagship example for using AI in audit fieldwork is its ability to perform full population analytics and anomaly detection in journal entry testing. This is a genuine upgrade to evidence gathering. Rather than sampling (testing only a sample of journal entries), AI can assess every posting made throughout the year and flag entries that genuinely warrant scepticism. This is changing how audit teams think about data sampling as a practise. When a whole population can be examined for characteristics of interest, the auditor's role shifts from selecting samples to to investigating and understanding exceptions. As a result, audit quality increasingly depends on how intelligently exceptions are triaged.
AI is maturing quickly in its ability to intelligently review large volumes of documents. AI tools that can extract key terms from populations of leases and contracts are now accessible to mid-tier firms through reputable vendors rather than proprietary platforms.
However, some claims about AI go beyond what the technology can realistically deliver. Be wary of anything that implies autonomous conclusions, tools marketed as ‘auditing’ a balance, assessing going concern, or drafting an opinion. No tool available today can conclude, and any suggestion otherwise should sharpen a buyer's scepticism, not their appetite.
Human in the loop
In short, AI offers audit teams real productivity gains in documentation and reporting. Using AI to prepare first drafts of memos and testing summaries is a sensible, low-risk entry point that can save considerable time, provided a human critically reviews the output and takes ownership of the final product.
An AI drafted memo that nobody has genuinely read is worse than no memo at all, because it presents the appearance of work that was never performed.
AI in big 4 firms vs small and mid-size practices
AI adoption naturally looks different across the profession. The largest audit and accounting firms have scale, standardised methodologies, vast data access and the capital to build proprietary platforms, with governance structures to match. Small and mid-sized practices are instead assembling ecosystems of third-party vendor tools, but there is nothing inherently inferior to this approach.
The vendor route is faster to deploy and cheaper to run, but it shifts the burden of diligence to the end-user. When the model is someone else's, the firm must understand what it does, where client data goes, how the vendor manages change and error, and what happens when the tool is wrong. In- house platforms trade that vendor risk for development and maintenance risk. Neither route is inherently safer, they simply demand different oversight.
In either case, the quality framework remains consistent. In Australia, Auditing Standard ASQM 1 applies with equal force to a proprietary platform and a subscription too. It asks four questions every firm should be able to answer before any AI touches an engagement:
- What quality risk does this introduce
- What control mitigates it
- Who is accountable
- What evidence will be retained?
A firm that cannot answer those four questions for a tool should not use that tool in an audit, regardless of the firm's size.
In practical terms, the minimum controls look largely the same for every firm. These include:
- a defined approval process for tools
- vendor due diligence proportionate to the tool's role
- mandatory human review of output
- ongoing monitoring of how the tool performs across engagements
- documentation that makes all of this visible.
Five things to treat as non-delegable
None of this changes who signs the opinion. Our standards were deliberately written technology neutral, and that neutrality is the point; responsibility cannot be outsourced to a tool any more than to a junior or a component auditor.
At RSM, we treat five things as non-delegable:
1. Professional judgement and scepticism.
I can inform judgement but cannot exercise it, and scepticism now has a second target, because a confident, fluent answer from a model deserves precisely the same challenge as a confident, fluent answer from a CFO.
2. Evaluating the tool's output.
Someone with appropriate competence must be able to explain why the output is reliable and whether it makes sense against everything else known about the entity. "The tool said so" is never an acceptable audit answer.
3. The engagement partner's responsibilities for direction, supervision and review.
These responsibilities apply regardless of how work is performed, which means reviewers must know where AI was used so they know where to point their challenge.
4. Audit conclusions.
Everything from an individual assertion through to the opinion is a human conclusion carrying the partner's accountability.
5. Ethical obligations.
We can never delegate our ethical obligations to independence, objectivity and confidentiality.
That last point deserves elaboration, because independence and ethics questions arise more often than firms expect. Client data must never reach unapproved tools, and client permission deserves explicit thought rather than assumption. Independence threats emerge where a firm has advised on or implemented the very systems a client now runs, or where a deep vendor relationship creates self-interest or familiarity pressures. And scepticism itself can be eroded by automation bias: the human tendency to defer to a machine's answer.
Practical AI guardrails for audit engagements
Effective AI governance does not need to be complex, but it does need to be visible and consistently applied. Some effective guardrails include:
- approved tool lists and clear usage policies
- disclosure of AI use within engagement files
- review procedures that target AI-assisted work
- training that teaches people to challenge output, rather than merely operate software.
Documentation best practices
Good documentation follows directly from these principles, and the test has not changed: an experienced auditor with no prior connection to the engagement should be able to understand what was done, what was found and the judgements made.
Applied to AI, the file should show:
- which approved tool was used and for what purpose
- what data went in and how the completeness and accuracy of that data were established
- what output the tool produced
- how exceptions or anomalies were investigated and resolved
- evidence that someone competent evaluated the output, tested it against expectation, and either accepted, corrected or rejected it before any conclusion was drawn.
Too many firms overlook that last point. They document what the technology produced but not how auditors assessed its reliability.
A useful rule of thumb is to document AI-assisted work as you would work performed by a specialist: understand it, evaluate it, evidence your evaluation, own the conclusion.
What comes next and where to start
Practitioners should expect the regulatory environment to firm up rather than transform over the next 12-24 months. Both internationally and in Australia, regulators and standard-setters are approaching AI through the existing architecture. We see technology neutral standards applied with increasing rigour and evolving audit evidence requirements, which press auditors to evaluate the reliability of information and the tools that process it rather than take either on faith. Ethics boards are similarly sharpening expectations around technology, independence and competence, and audit regulators have made clear that inspection attention will follow adoption.
Firms should expect to be asked how they govern AI and how the audit file evidences that governance. None of this should be feared; a firm that has honestly answered ASQM 1's four questions is moving in the same direction as regulators.
For those wondering where to begin, a practical first step is to pick one low risk, internally facing use-case. Summarising your own planning documentation is a fine candidate for this. Run it with explicit human review, write down what worked and what did not, and use that experience to draft your firm's first one-page AI policy, naming who approves tools and who monitors them. That single cycle of use, review and governance will teach you more than any vendor demonstration, and it builds the muscle every subsequent decision will rely on.
If there is one message to carry away, it is this. You can delegate tasks to artificial intelligence, but you cannot delegate responsibility. AI is most useful where it feeds human judgement and most dangerous where it is mistaken for it and if the file does not show that a human understood, challenged and owned the output, then as far as our profession is concerned, the work was never done.
Your local adviser
We use your approximate location to show relevant local contacts. For more accuracy, may we access your device location?