AI agents for accounting firms and finance teams.
Gaper builds and deploys supervised agents for accounting and finance, reconciliation, AP/AR exceptions, close prep, and document processing, wired into your ledger with approvals and a full audit trail.
An AI agent for accounting is software that reads financial documents and systems, reconciles transactions, chases and resolves exceptions, and drafts the close, with human approval on anything that posts.
Accounting is full of repeatable, exception-heavy work that still eats senior time. Rules-based automation breaks on the messy cases, and the judgment is exactly where the cost is.
- Does it touch real systems?
- Can the outcome be measured?
- Where does human approval stay?
- Who owns it after launch?
Book a free assessment. We will identify one high-leverage workflow, make the build-vs-buy call, and scope the smallest production release.
From strategy to production, owned by your team.
- 01
Map the workflow
We start from the documents, systems, and edge cases your team handles today, then turn the repeatable path into an agent workflow map.
- 02
Build the supervised agent
We build on the right model for the job, with retrieval, evals, guardrails, and human approval gates where the work carries risk.
- 03
Connect your systems
The agent gets the data, APIs, and write-backs it needs to finish work inside your systems of record, not beside them.
- 04
Sandbox, verify, go live
We launch in a sandbox, verify every run, then move into supervised production with traces, rollback, and an owner.
Agents wired into the systems you already run.
Reconciliation
Match transactions across systems and surface the breaks that need a human.
AP / AR exceptions
Resolve mismatches, chase missing data, and route approvals to the right owner.
Invoice & receipt processing
Read messy documents, extract the fields, and post with a human gate.
Close prep
Assemble schedules, flag anomalies, and draft the entries for review.
Audit support
Pull samples, tie out documentation, and keep an evidence trail.
Categorization
Classify transactions consistently against your chart of accounts.
Client communication
Draft grounded, on-policy client requests and follow-ups.
Reporting
Generate the recurring reports and variance notes finance asks for.
Beyond rules: agents that handle the exceptions
Scripted automation breaks the moment a document is messy or a number does not tie out. Agents reason about the exception, gather what they need, and escalate the judgment call to a person.
- Reads unstructured documents
- Resolves, not just routes
- Escalates the close calls
- 01Triggerevent arrivesdone
- 02Retrievecontext + policydone
- 03Decideconfidence scoreddone
- 04Actor escalatelive
p95 latency 1.2s
eval pass 12/12
rollback ready
Auditable by design
Every action the agent takes is logged, sourced, and reversible, and nothing posts without a human approval where it matters. The trail is built for your reviewers and your auditors.
- Full audit trail
- Approvals before posting
- Evidence tied to every entry
Low confidence, policy exception, or protected data.
Where accounting SaaS stops
Practice-management and ledger products cover the standard path; the firm-specific workflows and integrations are where they leave you. We build custom where it pays off, and say so when a product wins.
- Custom where products fall short
- Wired into your ledger
- Honest build-vs-buy call
Use a product when the workflow is standard and the data path is simple.
Fast startLess controlBuild when integration, compliance, or differentiation decide the outcome.
Your stackYour codeWhat an AI agent does in the transaction coding step of a close
It picks up the bank feed. It proposes a category for each transaction, matches receipts, and flags what it cannot resolve. A person approves before anything posts.
That approval step is not caution added by nervous firms. It is how the products themselves are built. Intuit tells the user to confirm the suggestion is right before you select Post.
A useful agent does three things a rule cannot. It reads the exception. It writes a short note on what it thinks happened. It routes the item to a named queue.
The output of a good run is a short exception list with a draft note per item. It is not a finished close.
What the coding step leaves untouched
Coding the bank feed is one step of a close. It is not the close.
The agent does not touch the balance sheet reconciliations. It does not touch prepaid and accrual schedules, payroll clearing, fixed assets and depreciation, sales tax, intercompany or loan amortisation. That is where close hours actually go at a CAS practice.
Judgment stays with a person. Accrual timing, revenue cut-off, related party classification, and anything needing a call with the owner all sit outside the agent's reach.
Firms are already using AI this way, not deeper. A 2026 survey of 486 bookkeeping and accounting professionals reports its task figures on an AI-active base, not the full sample.
On that base, use ran 75% for drafting client emails and communication, 71% for summarizing documents or meetings, and 69% for research.
Core work sat far lower: 42% for transaction categorization, 24% for bank reconciliation, 9% for tax return preparation.
Read that ordering before you scope anything. Communication and research first. Ledger work last.
Does QuickBooks tell you when its AI is guessing?
It does, and it is worth knowing how. The banking page grades its own suggestions into confidence tiers. The lowest tier says plainly that QuickBooks has limited data behind the suggestion.
The top tier is worth reading too. Intuit describes it as strong data behind the suggestion, with a clear pattern in your history. That is pattern matching against the client's own file, not understanding.
This explains something every practice lead has noticed. A five year client gets good suggestions. A new engagement in month one gets poor ones, because there is no history to match.
Any agent you deploy should expose the same signal. Give it a confidence value per field, and a threshold that sends low confidence items to a human queue.
How many bank rules can one QuickBooks file hold?
Intuit caps it at up to 2,000 bank rules per file. Each rule is bounded too, at a single rule with up to 5 conditions.
Most firms never reach 2,000. They hit something else first. The rule set stops being maintainable, nobody remembers why rule 340 exists, and a staff change orphans the whole set.
That is the point where an agent earns its place. The residue left after the rules is where the hours sit.
How much of a 1040 document set can be finished without a person?
Thomson Reuters publishes the only hard vendor number here. SurePrep states that 1040SCAN eliminates the need to verify OCR data for 65% of standard documents.
Read the other half of that sentence. About a third of standard documents still go to a person. Non-standard documents are not in the 65% denominator at all.
The tool does tell the preparer which fields to check. SurePrep's Review Wizard marks a field OCR is uncertain about and routes it for verification.
So the honest number is high, not total. Build for the remainder, because the remainder is what March feels like.
Does an agent cut the review workload or move it?
It moves it. The PCAOB regulates audits of issuers and registered brokers, so its standards do not bind a firm doing private company work. Its research still describes what happens to any team.
Examining a whole population, the PCAOB notes, may return dozens or even hundreds of items meeting the auditor's criteria.
The IAASB lands in the same place from a different direction. In its worked example, procedures run with automated tools do not provide sufficiently persuasive audit evidence on their own.
Two standard setters, one conclusion. Flagging is not finishing. If the agent triples the exception queue and nobody staffed the queue, the firm has bought work, not time.
Who signs the workpaper when the agent prepared it?
A person does. The AICPA's tax standards say that tools should be used to enhance or improve the member's understanding of a tax issue, not to supplant the member's professional judgment.
The same section is blunt about transfer. That responsibility cannot be transferred entirely to reliance on a tool.
The standards are not anti automation. They allow reliance, stating that a member may reasonably rely on tools used in providing tax services to a taxpayer.
Practically, every posted entry needs a named human approver stored with it. If your log shows a service account as approver, the firm has automated away its own evidence.
Which standards actually bind your firm?
Start with the one that names AI outright. The AICPA's tax standards define a tool to include data analytics, statistical models, artificial intelligence among others. That has been in force since 1 January 2024.
If you do attest work, SQMS No. 1 is already live. It is effective for a firm's accounting and auditing practice as of December 15, 2025. Your system of quality management should already address it.
It reaches AI through the resources component. That section notes a resource from a service provider could be a methodology, an IT application, or people used in an engagement. An AI vendor lands squarely there.
The audit evidence standard is older than most firms assume. SAS 142 has been effective for audits of financial statements for periods ending on or after Dec. 15, 2022.
Only firms auditing issuers or registered brokers work under PCAOB rules. For those firms, AS 1201 states that the engagement partner is responsible for the engagement and its performance, including supervision of the team.
Is it illegal to put client tax data into an AI tool?
It can be criminal. Under IRC section 7216, a preparer who knowingly or recklessly discloses return information shall be guilty of a misdemeanor. The statute allows a fine and imprisoned not more than 1 year.
A civil penalty sits on top. Section 6713 sets a penalty of $250 for each such disclosure or use, capped at $10,000 per calendar year.
Multiply $250 by your 1040 count before the next vendor call. That is the shape of the exposure.
None of this puts AI off limits. It makes where the data goes a partner decision, not an IT one.
Does a summary count as tax return information?
Yes. The regulation covers anything the preparer builds out of return data. It states that tax return information also includes information the tax return preparer derives or generates from tax return information.
That closes the most common workaround. Sending a model a summary, a redacted extract, or a draft memo does not put you outside the rule.
The base definition is already broad. It reaches a taxpayer's name, address, or identifying number furnished in connection with preparing the return.
So scope the question properly. Ask what the agent touches, not what it stores.
Is your AI vendor itself a tax return preparer?
Very likely yes. The definition reaches a person who develops software that is used to prepare or file a tax return, along with anyone providing auxiliary services.
The regulation repeats the point for contractors. They are tax return preparers under section 7216 because they are performing auxiliary services in connection with tax return preparation.
This reframes vendor selection. You are not picking a SaaS tool. You are bringing another preparer into the engagement.
Ask the vendor whether they accept that in writing. The answer tells you how carefully they have read the rule.
Does it matter which country the model runs in?
It decides whether you need written client consent. If a person receiving return information sits outside the country, the taxpayer's consent under § 301.7216-3 prior to any disclosure is required. That holds even when the person works for your own firm.
The regulation treats remote viewing as disclosure. In its own example, a contractor abroad views data held on a US server, and Firm is required to obtain T's consent first.
For 1040 clients the default is redaction. A US preparer must redact or otherwise mask the taxpayer's SSN before the tax return information is disclosed outside of the United States.
Consent is available, but only through a narrow exception at 301.7216-3(b)(4)(ii). That route requires an adequate data protection safeguard as defined by the Secretary. The firm must also verify that safeguard inside the consent request itself.
Read that as an actual redaction step in the pipeline. Know your hosting region and your vendor's support locations before you scope anything.
What has to be in the contract with an AI vendor?
There is a no-consent lane for contractors, and it is narrow. It covers the programming, maintenance, repair, testing, or procurement of equipment or software used for return preparation, and applies only to the extent necessary for the person to provide the contracted services.
It carries a condition most firms skip. Everyone receiving the data must receive a written notice that informs them of the applicability of sections 6713 and 7216 to them.
The FTC Safeguards Rule adds three duties on service providers, verbatim:
- Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue - Requiring your service providers by contract to implement and maintain such safeguards - Periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards
The IRS gives you a ready bar for that contract. Its sample WISP states that any third-party service provider that does require access to information must be compliant with the standards contained in this WISP at a minimum.
Does running the agent in your own cloud settle the 7216 question?
No, and it is worth being exact about what it does change. Firm ownership puts the credentials, the logs and the hosting region under your control. It also lets you see what the agent did without asking a vendor.
It does not remove anyone from the section 7216 analysis. The team that builds and maintains the agent receives return information, which makes them a preparer under the same rule quoted above. If the agent calls a hosted model, the model provider receives the data too.
So the written notice and the contract terms still apply. So does the hosting region question, and the SSN redaction step for 1040 files.
Some vendors do state their training position clearly. Karbon says that Karbon does not use your firm's data to train AI models. Owning the deployment does not replace that assurance. It just puts you in a position to check it.
Two technical floors apply either way. The Safeguards Rule requires you to protect by encryption all customer information held or transmitted by you both in transit over external networks and at rest, and to implement multi-factor authentication for any individual accessing any information system.
What has to be written down before you switch anything on
A written information security plan, updated for the new tool. The rule names your firm directly. An accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution.
The IRS says the same thing in plainer words. Tax and accounting professionals are considered financial institutions, regardless of size, and your WISP must be written and accessible.
The underlying risk assessment is written too. The rule states flatly that the risk assessment shall be written.
Two limits get misread constantly. The carve-out for smaller firms removes four specific requirements rather than the written program itself, and the FTC breach clock runs 30 days from discovery. Both are worked through against the rule text, with the four excepted paragraphs named, in what the Safeguards Rule asks of an accounting firm.
Do you have to tell clients you are using AI?
No rule forces it today. The Journal of Accountancy reports that no specific federal law or professional standard applicable to CPAs mandates disclosure when generative AI is used.
The AICPA Code is stricter about third-party providers generally. Before disclosing confidential client information, the member should inform the client, preferably in writing, that the member may use a third-party service provider. If the client objects, the firm drops the provider or declines the engagement.
There is a carve-out, and its edge is the live question. No notice is required for record storage, software application hosting, or authorized e-file tax transmittal services. Whether an agent that drafts and classifies is merely hosting is not settled anywhere.
Insurers are nudging firms toward telling clients anyway. McGowan's John Raspante recommends engagement letter language disclosing AI use, plus a clause letting clients opt out entirely.
Is a line in the engagement letter enough?
Probably not on its own. The same column cites the ABA's position that merely adding general, boiler-plate provisions to engagement letters purporting to authorize the lawyer to use generative AI is not sufficient.
Where section 7216 consent is required, the rules are explicit. The consent must be knowing and voluntary. And conditioning the provision of any services on the taxpayer's furnishing consent will make the consent involuntary.
Business clients are easier than 1040 clients. For a taxpayer outside the Form 1040 series, consent may be in any format, including an engagement letter to a client.
That split matters for a CAS practice. Entity clients can often be covered in the letter. Individual clients cannot.
Who is liable when the agent is confidently wrong?
The firm. Aon's Nicole Graham puts it plainly: generative AI can be confidently wrong. She adds that if the tool is wrong and nobody checks, a client will come after the firm, not the AI tool.
The claims data does not exist yet. Aon's Stan Sterna says there really hasn't been a lot of claims or large dollar amounts paid on claims. Pretending otherwise would mean inventing a number.
There is one live example of what unchecked output costs. In Clinco, T.C. Memo. 2026-16, three of the four cases cited in a taxpayer's brief did not exist.
Judge Holmes wrote that submitting a brief with fictitious caselaw is a recipe for sanctions.
The Journal of Accountancy reports that Clinco appears to be the first Tax Court case to address potential AI hallucinations.
The control is documentation, and it is cheap. Aon's guidance is to record in the client file the prompts used, how the outputs were verified, and who performed the review.
What your insurer will ask at renewal
They will ask for your AI policy. Sterna says carriers are going to ask a firm about their AI policy and procedures. They expect the same basic risk management protocols that they would have in place for engagement letters or client acceptance.
Treat that as a deadline, not a suggestion. A written policy, a named owner, and a review record are what a renewal questionnaire reaches for.
What the IRS says about which AI a firm may use
Not "no". On 24 June 2026 the IRS Office of Professional Responsibility issued Alert 2026-19, Introductory Guidelines for Responsible AI Use in Federal Tax Practice.
The AICPA summarizes the position fairly. OPR's message is not that practitioners may never use AI. Rather, AI must be used with human oversight, professional judgment, due diligence, confidentiality safeguards and accountability.
On review, OPR is specific. Practitioners must thoroughly review all AI-created documents before they reach a client or the IRS. They cannot rely solely on AI.
On where the data goes, it is equally direct. Practitioners must strictly handle all client data using only secure, enterprise-approved AI.
Vendor diligence is a duty, not a preference. OPR states that outsourced or third-party AI tools should be vetted, with the steps documented to show adherence to Circular 230 section 10.36.
Where firms actually are with AI today
Less far along than the marketing implies. Thomson Reuters surveyed 639 firm professionals. It found that about half (49%) of the respondents to this year's survey estimate that one-quarter of their tax workflows are automated, while 21% said that up to half are automated. A further 18% said they use no automation at all.
Breadth is high, depth is low. Intuit commissioned a May 2026 survey of 725 US accounting professionals. In it, 88% used AI for at least one client service in the last 12 months. But only 30% say AI is embedded as the default in day-to-day work, and the largest group (54%) uses AI situationally.
Among AI users, a quarter have not touched the accounting. The 2026 Financial Cents survey found that 24% of AI users aren't using AI for any core accounting tasks. Both surveys are vendor published, so read them as directional.
The blocker is time, not fear. The 2025 National MAP Survey of 1,073 firms found the biggest barrier to implementing emerging technologies was lack of time to explore or implement (41%), with staff resistance or fear of change, at 6%.
Most firms also have nobody who can build. In the 2024 CPA.com and AICPA CAS Benchmark Survey of 206 self-selected respondents, only 13% build automation with an internal team. Meanwhile more than 67% are partnering with software vendors to provide these kinds of tools. That report concedes its own self-selection bias, which is worth repeating rather than hiding.
If your firm runs a chatbot for research and nothing else, you are the median. Not behind.
What firms want the agent to do
Not run on its own. In the Intuit survey, only 6% want AI to execute autonomously.
The shape they do want is draft plus approve. In the same survey, 40% want AI as a support tool and 34% want AI to draft, with a human reviewing and signing off.
Trust levels match that. Financial Cents found only 19% trust AI enough to use it with limited review. On consequential decisions, Intuit found 64% say the work was entirely or primarily human-driven.
Firms are clear about what stays theirs. In the Financial Cents survey, 90% say human judgment matters more, not less in the AI era. The report calls it the most agreed statement it recorded.
Standards describe the same thing differently. The AICPA notes that audit standards require auditors to think critically and maintain professional skepticism. A model output cannot perform that on itself.
So build for draft plus approve. An autonomy pitch sells against what the buyer has already decided.
What it costs, and the cost lines nobody quotes
No independent survey of AI agent build costs at accounting firms exists. Every range in circulation traces back to a company selling the build. Treat all of them as marketing.
What is sourced is the set of cost categories. The AICPA's Eva Simpson names software licensing costs, implementation expenses, governance requirements, and the significant investment needed to train professionals to use these tools well.
Firms are spending and repricing already. The MAP survey found 94% of firms planned to raise their overall tech spending up to 20% over the prior year, while 35% of firms didn't have a specific budget for AI and automation.
Payback is the weak link. Financial Cents found that only 1 in 5 firms can point to a measurable return on their AI investment. Ask any builder for build cost, monthly running cost, model usage cost, and the year two number separately, in writing.
Does using AI mean lowering your fees?
The IRS has raised the question, and almost nobody warns partners about it. OPR states that billing clients for manual labor or time that was not actually spent or double billing for AI-assisted tasks may violate § 10.27. It adds that cost savings should be passed on openly.
The AICPA has pushed back. It calls that an overly simplistic view that ignores the full economics of AI adoption, and is seeking clarification from the IRS.
This is unresolved, and no page should pretend otherwise.
The practical move is to settle pricing before the build. A firm on hourly billing that cuts close hours has cut its own revenue.
Limits no agent removes
The 8879 chase is the clearest one. The IRS caps identity checks. If the taxpayer fails the knowledge based authentication questions after three attempts, the ERO must get the taxpayer's handwritten signature.
That is a limit on remote signing specifically. A client who fails the check is back to signing in the preparer's presence or on paper. It becomes a scheduling problem, and no agent solves scheduling.
Vendor accuracy claims are a different kind of limit. Xero markets that Xero reconciles your transactions at 97% accuracy, with no test method, sample size, or document mix published on the page.
Ask any vendor, including this one, what the denominator is. A number without a stated sample tells a partner nothing they can price against.
How to start without betting busy season on it
Pick one workflow. Run it on a closed prior period. Compare the output against what the team actually did.
Intake and document sorting are the usual first move. A mistake there shows up immediately as a misfiled page, not silently as a wrong number. Sorting and indexing are also not a substantive determination about the client's tax liability.
Be honest about which risk that lowers. Indexing carries the lowest judgment risk, not the lowest data risk. The tool still receives complete W-2s, 1099s and brokerage statements, with names, addresses and SSNs on them. Every vendor question in the sections above applies unchanged.
Name an owner before the build starts. Make it a manager who knows the chart of accounts and can decide, not a partner in February.
Expect a messy stack, because most are. Among CAS practices surveyed, only 46% of respondents report using a specific set of software applications that are fully integrated.
How to tell in 90 days whether it worked
Baseline three numbers from your own systems first. Exception queue volume, days to close, and reviewer time per file. Nobody can reconstruct these afterwards, and a vendor dashboard is not a baseline.
There is no independent published benchmark for time saved on close or workpaper work. Every figure circulating on this topic is a vendor estimate about that vendor's product.
Measuring is where most firms stop short. In the MAP survey, 40% said they had not yet figured out how to track efficiencies due to technological advancements.
Watch one more number. If prep got faster and review got slower, the firm traded cheap hours for expensive ones.
Can an agent run AP and AR without opening a fraud hole?
An agent can do the matching and the chasing. It should not be the control that releases money or edits a vendor bank record.
Business email compromise targets exactly that seam. The FBI's advice is to use secondary channels or two factor authentication to verify requests for changes in account information with the intended recipient, per IC3 guidance on BEC. An agent holding both vendor master edit rights and payment release collapses that check into one system. Keep the two in different hands.
On the AR side, an agent can apply cash, age balances and draft reminders. Short pay reasons, credit limits and write offs stay judgments.
The part worth automating first sits upstream of the payment run. Publication 1281, the IRS guide to the backup withholding rules under section 3406, tells payers that for all payees the initial TIN solicitation is made when the payee opens the account or when the transaction occurs. An agent that will not create a vendor without a W-9 on file is working on the cause, not the January symptom.
Human gate: the person who releases payment, and who verifies any banking change out of band.
Where does an agent have to stop in a payroll cycle?
At the signature, and at worker classification.
The Form 941 instructions list who is authorized to sign for each type of entity: the individual who owns a sole proprietorship, the president, vice president or another principal officer duly authorized to sign for a corporation, a responsible and duly authorized partner, member or officer having knowledge of its affairs for a partnership, and the fiduciary for a trust or estate. The same instructions add that Form 941 may be signed by a duly authorized agent of the taxpayer if a valid power of attorney has been filed, and that corporate officers or duly authorized agents may sign by rubber stamp, mechanical device or computer software program under Rev. Proc. 2005-39. A software signature is permitted, so read that carefully. What the software applies is still a named person's authorization.
The same instructions draw the second line. A reporting agent with a valid Form 8655 on file generally skips the paid preparer section, but must complete it if the reporting agent offered legal advice, for example advising the client on determining whether its workers are employees or independent contractors. The IRS also says there is no magic or set number of factors that makes a worker one or the other, and no one factor stands alone, in its classification guidance. That is a judgment, not a lookup.
Ceiling: an agent can compute the lookback period, the deposit schedule and the next day trigger, since the same instructions state that accumulating a $100,000 tax liability on any day in a deposit period makes you a semiweekly depositor the next day. It cannot carry the consequence. Where trust fund taxes are not withheld, deposited or paid over, the instructions state the trust fund recovery penalty is 100% of the unpaid trust fund tax, and may be imposed on the persons the IRS determines were responsible for collecting, accounting for or paying over those taxes and who acted willfully in not doing so.
Human gate: the authorized signer.
Can an agent tell us when a client crosses economic nexus in another state?
It can watch the numbers. It cannot make the registration call, and there is no single national threshold for it to code against.
South Dakota v. Wayfair upheld a law covering sellers that, on an annual basis, deliver more than $100,000 of goods or services into the state or engage in 200 or more separate transactions for the delivery of goods and services into the state. California instead reaches a retailer once total combined sales of tangible personal property for delivery in California by the retailer and all related persons exceed $500,000, with no transaction count at all, per the CDTFA. Two states, two different tests, and a client can be well past one while clear of the other.
The Court also left the door open, saying Congress may legislate to address these problems if it deems it necessary and fit to do so. Absent one federal test, an agent is coding against each state's own rule, so any threshold table it uses is a snapshot of legislation that keeps moving. Whether a vendor refreshes that table is a contract term, not something you can assume.
Honest scope: a rolling sales by destination view, an exception raised as a client approaches a stated threshold, and a recorded date when each threshold was last checked against the state.
Human gate: whoever approves a registration, and owns the back period exposure and any voluntary disclosure that follows.
How much of 1099 season can an agent actually take off us?
File assembly and the exception list. Not the TIN problem, and not the classification call.
The mechanics are codeable. The IRS states that starting with tax year 2023, if you have 10 or more information returns you must file them electronically, counted in aggregate across form types, in its IRIS guidance. Form 1099-NEC goes to the recipient and the IRS on or before January 31, while 1099-MISC is due to the IRS by February 28 on paper or March 31 electronically, per the form instructions. An agent can build the payee file, tie it to the ledger, and flag missing or malformed identifiers.
It cannot validate a TIN by looking at it. The IRS TIN Matching service is what checks a TIN and name combination before you submit an information return, and the IRS says it is only for payers and their authorized agents that submit information returns, with the payer listed in the IRS Payer Account File. Payers are added to that file if they filed Forms 1099 within the last two years to report backup withholding, so a firm that assumes it has access should check before it designs a workflow around it.
Backup withholding is where the clock is short. Publication 1281 gives a payer 15 business days from the date of a CP2100 or CP2100A notice, or the date it was received if that is later, to send a B Notice, and says to begin backup withholding at 24% no later than 30 business days after that date on payments to payees who do not return a signed Form W-9.
Human gate: a named owner of the solicitation and B Notice calendar.
Can an agent maintain a fixed asset schedule and depreciation?
It can maintain the schedule. It cannot make the two decisions that determine whether the schedule is right.
The first is repair or improvement. Under Reg. 1.263(a)-3(d), a unit of property is improved, and the related amounts generally must be capitalized, if the amounts paid for activities performed after the property was placed in service are for a betterment to the unit of property, restore it, or adapt it to a new or different use. Those are conclusions about facts, not fields on an invoice.
The second is the placed in service date. Publication 946 states that property is placed in service when it is ready and available for a specific use, that this is therefore not necessarily the date it is first used, and gives the example of a machine delivered in one year but not installed and operational until the next, which counts as placed in service in the later year.
The de minimis safe harbor is codeable, and strict. Reg. 1.263(a)-1(f) sets, for a taxpayer with an applicable financial statement, a limit of $5,000 per invoice or per item as substantiated by the invoice, written accounting procedures in place at the beginning of the taxable year, and an election made by attaching a statement to a timely filed original federal return including extensions. The election cannot be revoked. For a taxpayer without an applicable financial statement the regulation still reads $500, and Notice 2015-82 increased that limit to $2,500, so the operative figure is not the one printed in the CFR text.
Human gate: the preparer who signs the return the election rides on.
If an agent does the close, what does SSARS require on the statements we issue?
Nothing about the agent, and that is the problem. The current AR-C sections do not mention artificial intelligence, machine learning or automated tools anywhere in the text.
What they require is about the output. AR-C 70.14 says the accountant should ensure a statement is included on each page of the financial statements indicating, at a minimum, that no assurance is provided, and if the accountant cannot do that, the options are to issue a disclaimer, perform a compilation, or withdraw. AR-C 70.21 says the accountant should not prepare statements that omit substantially all disclosures required by the framework if, in the accountant's professional judgment, they would be misleading to users. AR-C 70.22 puts the documentation floor at two items: the engagement letter or other suitable written agreement, and a copy of the statements the accountant prepared.
So nothing in the standard puts the agent, its instructions or its version in the file. If your file does not show them, that is a policy choice you made, not a gap you can point at later. SSARS is an AICPA professional standard rather than a rule in the CFR, which changes who enforces it, not whether it governs the work.
Ceiling: recurring accruals, intercompany eliminations that net to zero and roll forwards are mechanical. Judgmental accruals, reserves and eliminations that do not net are not.
Human gate: the accountant who takes on the preparation engagement.
Can an agent build a client forecast or projection?
It can build the model. The professional standards stop you from issuing the result without the assumptions written down.
AR-C 70.19 states that the summary of significant assumptions is essential to the user's understanding of prospective financial information, and that accordingly the accountant should not prepare prospective financial information that excludes disclosure of it, nor a financial projection that excludes either an identification of the hypothetical assumptions or a description of the limitations on the usefulness of the presentation.
If you go further and examine a forecast, AT-C 305.12 says a practitioner should not examine a forecast or projection that discloses none of the significant assumptions, and AT-C 305.23 says the practitioner should evaluate the support for the significant assumptions individually and in the aggregate. The preface to those same attestation standards adds that although a practitioner may assist the responsible party in developing or presenting the subject matter, the responsible party remains responsible for it.
That is the real constraint on tooling. Output you cannot decompose into named assumptions cannot meet those requirements, however good the number looks.
Human gate: client management, adopting the assumptions in writing before anything leaves the firm.
Will our peer reviewer look at the AI agent we built?
Only if the agent touched an accounting or auditing engagement, and only in one of the two review types.
The AICPA program states that the scope of a peer review "does not encompass other segments of a CPA practice, such as tax services or management advisory services, except to the extent they are associated with financial statements" (AICPA peer review questions and answers). The same document says that if a firm does not perform services that include issuing reports purporting to be in accordance with AICPA professional standards, "it is not required to enroll in a practice monitoring program," and tells firms to consult their State Board of Accountancy about whether its rules require enrollment anyway.
If you do issue audit reports, the agent is reachable. "You must have a System Review even if your firm only performs one audit." Firms eligible for an Engagement Review are not examined this way, because "Review of a firm's documentation or procedures related to its system of quality management is outside the scope of an engagement review" (Peer Review Standards Update No. 2).
That update makes the quality management revisions effective "for peer reviews with years ending on or after December 31, 2025." Peer review is an AICPA program requirement and, where a state board says so, a licensing one. It is not a federal rule.
Is an AI agent inside the quality management standard, and what does it make us document?
It depends which practice the agent runs in. SQMS No. 1 applies to "all firms that perform any engagement included in a firm's accounting and auditing practice," and defines that practice as audit, attestation, review, compilation "and any other services for which standards have been promulgated by" the Auditing Standards Board or the Accounting and Review Services Committee. Where other AICPA technical committees write standards, "engagements performed in accordance with those standards are not encompassed in the definition of an accounting and auditing practice." Tax return preparation is not on the ASB or ARSC list, so an agent used only in tax work falls outside this particular standard.
Where it does apply, paragraph 33f requires a quality objective that "Appropriate technological resources are obtained or developed, implemented, maintained, and used to enable the operation of the firm's system of quality management and the performance of engagements." Paragraph 14 required compliant systems to be designed and implemented by December 15, 2025, with the evaluation of the system performed within one year after that date.
There is no required AI checklist. Paragraph A105 says the firm "may consider" matters including whether outputs "achieve the purpose for which they will be used" and "the need to develop procedures that set out how the IT application operates." On the peer review side the relevant text is application material rather than a requirement: paragraph .A48 of Peer Review Standards Update No. 2 names "human, intellectual, or technology resources" among the areas where inattention "may result in a deficiency or significant deficiency in a report with a peer review rating of pass with deficiencies or fail."
Does the prompt or the model version have to go in the workpaper file?
No requirement names either one. AU-C 230.09 requires the auditor to record the identifying characteristics of the specific items tested, who performed the audit work and the date it was completed, and who reviewed it and when. The tool shows up only in application material: .A4 lists "the audit methodology and tools used" as one of the factors the form, content and extent of documentation depend on.
GAAS does name the technology once, in an example. AU-C 500.A4 says "Examples of other automated tools and techniques are artificial intelligence, machine learning, remote observation tools, and robotic process automation." That is explanatory material, not a documentation rule.
The agent gets into the file because your own policy puts it there. AU-C 220.A68 says the firm's policies or procedures "may require the engagement team to take certain actions before using an IT application that is not firm approved," including "testing of the operation and security of the IT application" and "specific documentation to be included in the audit file." That is permissive, and it is addressed to the firm rather than set by the standard. AU-C 220.28 does require the engagement partner to take responsibility for using the resources assigned to the engagement team appropriately, and AU-C 220 is effective for engagements for periods beginning on or after December 15, 2025. So a file that does not show which model ran on what input reflects a choice your firm made, not a gap in the standards.
If the agent developed our analytical expectation, what does the file have to show?
The expectation itself, plus the factors behind it. AU-C 520.08a requires the audit documentation to include "The expectation referred to in paragraph .05c and the factors considered in its development when that expectation or those factors are not otherwise readily determinable from the audit documentation."
That is the requirement an output you cannot decompose will fail. Paragraph .05b also requires evaluating the reliability of the data the expectation was developed from, "taking into account the source, comparability, and nature and relevance of information available and controls over preparation," and .05c requires evaluating whether the expectation is sufficiently precise to identify a misstatement that could make the financial statements materially misstated. AU-C 520 says nothing anywhere about tools, technology or automation, so there is no accommodation in it to read in for an agent.
GAAS names the failure mode elsewhere. AU-C 220.A36 lists "Overreliance on automated tools and techniques, which may result in the engagement team not critically assessing audit evidence" among conditions that may impede professional skepticism, and .A65 adds that inappropriate use of technological resources "may, however, increase the risk of overreliance on the information produced for decision-making purposes."
If the agent scans every transaction, does the judgment move to the tool?
No. AU-C 500.A61 contemplates that the auditor "might use automated tools and techniques to scan an entire population of transactions," then says the procedure also provides evidence about the items not flagged "because the auditor has determined, exercising professional judgment, that the items not selected for further audit procedures are less likely to be materially misstated." Full coverage changes what you looked at, not who is doing the judging.
For audits of public companies the PCAOB has written both halves out. Amended AS 2301.49 requires that the auditor's investigation of identified items "should include determining whether these items individually or in the aggregate indicate" misstatements to be evaluated under AS 2810 or deficiencies in the company's internal control over financial reporting, and .50 requires the auditor to determine whether there is a reasonable possibility that remaining items not selected for testing include a misstatement that would have a material effect. Those amendments are effective for audits of financial statements for fiscal years beginning on or after December 15, 2025.
The PCAOB says it oversees "the audits of public companies" and "the audits of brokers and dealers registered with the Securities and Exchange Commission" (PCAOB). A firm with none of those clients is not subject to its standards, so for most mid-size firms this is direction of travel, not a rule that binds you.
Can we still sign the opinion if we built the agent for an attest client?
Probably not, and running it afterward is the separate problem. This is an independence question, so it only arises for a client you also audit, review or attest for.
ET section 1.295.145 of the AICPA Code of Professional Conduct defines a financial information system as "a system that aggregates source data underlying the financial statements or generates information that is significant to either the financial statements or financial processes as a whole," and adds that it "includes a tool that calculates results" unless the tool performs only discrete calculations, the client accepts responsibility for the input and assumptions, and the client has enough information to understand the calculation and the results. Paragraph .05 then says that when a member designs or develops an attest client's FIS, threats "would not be at an acceptable level and could not be reduced to an acceptable level by the application of safeguards and independence would be impaired." The Code's revision table records the interpretation as effective January 1, 2023.
Running it is where firms get caught. Paragraph .21 says post-implementation maintenance, support and monitoring impair independence if they involve the client "outsourcing an ongoing function, process, or activity to the member that would result in the member assuming a management responsibility," with examples including a member who operates the client's network, "such as managing the attest client's systems or software applications." Paragraph .22 leaves room only for services that are "individually separate, distinct, and not ongoing engagements" with no function outsourced to you.
The Professional Ethics Division's nonattest services toolkit is a checklist, not a rule, and the Code itself flags the related information systems practice aid as nonauthoritative. The checklist is still the fastest way to see where you stand: it lists "Accepting responsibility for designing, implementing, or maintaining internal control" and "Performing ongoing evaluations of the client's internal control as part of its monitoring activities" as examples of management responsibilities, and asks whether the client agreed, before the work started, to oversee the service through someone with "suitable skill, knowledge, and/or experience." If the answer is no, "independence is impaired and you can stop here."
How long do the agent's logs have to survive, and does anyone have to reproduce its output?
Your file retention is fixed. The second question has no answer yet.
AU-C 230.17 says the retention period "should not be shorter than five years from the report release date," with the final audit file assembled "no later than 60 days following the report release date" under .16. For audits of public companies and SEC registered brokers and dealers, PCAOB AS 1215.14 requires seven years.
Neither standard sets a retention period for an agent's inputs, prompts, traces or model version, and neither requires that a rerun produce the same answer. AU-C 230.08 sets the test as documentation sufficient to enable "an experienced auditor, having no previous connection with the audit," to understand the nature, timing and extent of the procedures performed, the results, and the significant professional judgments made. Whether a model's output clears that bar is a call you have to make and defend.
PCAOB staff recorded the problem rather than resolving it, reporting that preparers raised the "black-box" nature of some GenAI tools and "the lack of consistent output produced by GenAI, which raise questions around the auditability of certain GenAI-created output." That July 2024 document says on its face that it represents the views of staff and "is not a rule, policy, or statement of the Board" (GenAI Spotlight). Until someone rules, the only things closing the gap between a vendor's log retention and your file retention are your contract and your own policy.
Questions buyers ask us.
What is an AI agent for accounting?+
How is it different from rules-based automation?+
What accounting workflows can you automate?+
Is the work auditable?+
Does it work with our accounting system?+
Who owns it after launch?+
Ready to deploy your first agent?
Book a free 30-minute assessment. We'll map the highest-leverage workflow and scope the smallest thing worth shipping, live in as little as 24 hours.