What a peer reviewer will ask about the AI your firm uses
The AICPA peer review standards never mention artificial intelligence. Here is what your reviewer will actually test when an agent touched the workpapers.
Nothing written specifically about artificial intelligence, because no such question exists in the standards. What a reviewer will ask is whether your documentation, your analytical procedures and your system of quality management still hold. Artificial intelligence does not change those questions. It makes them harder to answer, and it makes a thin file look thinner.
Is there a peer review standard on artificial intelligence?
No. The AICPA Standards for Performing and Reporting on Peer Reviews contain no reference to artificial intelligence at all, in either the June 2021 PRP Section 1000 or the clarified standards effective for peer reviews commencing on or after May 1, 2022.
The clarified standards use the word technology exactly once in roughly 89,000 words, and it has nothing to do with your firm. It is a qualification for the CPA on staff at an administering entity, who should "be proficient with technology to effectively manage the program."
That is the honest state of play. If you read an article saying the peer review standards now address AI, the text does not support it.
What a peer reviewer actually tests
The reviewer tests whether you complied with your own system and with professional standards. The illustrative System Review report in the standards states it in the firm's own report: "The firm is responsible for designing a system of quality control and complying with it to provide the firm with reasonable assurance of performing and reporting in conformity with applicable professional standards in all material respects."
That sentence is not buried in guidance. It is the wording of the report your firm receives.
This is why the absence of an AI standard is not comforting. The reviewer does not need a rule about agents. The reviewer opens the file and applies the rules that already exist. An agent that leaves no trace in the workpapers has not reduced your exposure, it has removed your evidence.
Does an agent's output have to go in the audit file?
The standard does not ask about the agent, it asks about the work, and the answer depends on whether the work is in the file at all. AU-C 230.08 requires documentation "sufficient to enable an experienced auditor, having no previous connection with the audit, to understand" the nature, timing and extent of the procedures performed, the results and evidence obtained, and the significant findings, conclusions and "significant professional judgments made in reaching those conclusions."
An experienced auditor is defined in the same section as someone with practical audit experience and a reasonable understanding of audit processes, GAAS, the business environment and the industry's reporting issues.
So the test is not "did you keep the prompt". The test is whether a competent stranger can follow what was done and why. A prompt and a response usually fail that test on their own. A workpaper that records what was examined, what came back and what the engagement team concluded usually passes it, whether or not a tool was involved.
Who performed the work, and what does the file say?
This is the question that is easiest to leave undecided. AU-C 230.09 requires the auditor to record "who performed the audit work and the date such work was completed" and "who reviewed the audit work performed and the date and extent of such review."
The standard says who, not what. It was written when the only candidates were people. If an agent drafted a tie out and a senior signed it off, the file should reflect the work the senior actually did, not a sign off on a review that never happened. Nothing in AU-C 230 permits an agent to occupy the preparer field, and nothing addresses the situation, which is precisely the gap.
Decide your convention now and write it down, before a reviewer asks you to explain it on the spot.
What if an agent produced the analytical procedure?
Then you still owe everything AU-C 520.05 requires, and the documentation requirement gets sharper rather than looser. For substantive analytical procedures the auditor must "evaluate the reliability of data from which the auditor's expectation of recorded amounts or ratios is developed, taking into account the source, comparability, and nature and relevance of information available and controls over preparation", and must "develop an expectation of recorded amounts or ratios and evaluate whether the expectation is sufficiently precise."
Then AU-C 520.08 requires the file to include "the expectation referred to in paragraph .05c and the factors considered in its development."
Read that last phrase slowly. The factors considered in its development. If a model generated the expectation and nobody can say what drove it, there are no factors to document. That is a documentation failure under a standard written in 2011, with no reference to AI needed.
Is an agent's output audit evidence?
It can be, and SAS No. 142, Audit Evidence is the standard that names artificial intelligence directly. Effective for audits of financial statements for periods ending on or after December 15, 2022, it says at paragraph A4 that "Examples of other automated tools and techniques are artificial intelligence, machine learning, remote observation tools, and robotic process automation."
Note where that sentence sits. It is application material, an example, not a requirement. The requirements are at paragraphs 7 and 8: evaluate the relevance and reliability of information to be used as audit evidence, including its source, assess whether it is "sufficiently precise and detailed for the auditor's purposes", and obtain evidence about its accuracy and completeness.
Paragraph A27 lists the attributes that affect reliability, accuracy, completeness, authenticity and susceptibility to management bias, and then adds: "These attributes are also relevant when automated tools and techniques are used to obtain audit evidence."
That is the whole of SAS 142's treatment of it. The profession's answer to AI generated evidence is that the existing reliability framework applies.
What SQMS No. 1 changed, and why it matters now
SQMS No. 1 brought technology inside the quality management system for the first time. Under the prior standard, the resources component addressed only human resources. The AICPA's own executive summary says SQMS No. 1 "expands this to address all resources that the firm needs both to operate the system and to perform engagements", and names "Technological resources. For example, audit tools or IT applications used by the firm for independence monitoring."
Systems of quality management had to be designed and implemented by December 15, 2025, with the evaluation performed within one year following. Under SAS No. 146 the engagement partner must consider the resources assigned to the engagement, "technological, intellectual and human", and take appropriate action if they are insufficient or inappropriate.
So the AI question arrives at peer review through the quality management door, not through an AI rule. Your reviewer can ask what technological resources you identified, what quality risks you assessed around them and what responses you designed. That is a requirement, and the deadline has passed.
Is a practice aid a requirement?
No, and the distinction is worth protecting. SQMS No. 1 and the AU-C sections are standards. The AICPA also publishes practice aids, toolkits and templates to help firms implement them, and those are support material, not authority.
A reviewer evaluates compliance with the standard. If your firm adopted a template and the template did not contemplate the way you now work, the template is not a defence. This is the same trap that has caught firms with written information security plans built from samples that were never updated.
A note on PCAOB material
Check whether the guidance you are reading applies to you at all. The Public Company Accounting Oversight Board was established by Congress "to oversee the audit of companies that are subject to the securities laws", as 15 U.S.C. 7211(a) puts it.
If your firm does not audit those companies, PCAOB standards and PCAOB inspection findings are not what your peer reviewer applies. A good deal of the writing about AI in audit is PCAOB flavoured, and reading it as though it governs a private company practice will send you to the wrong controls.
The five questions to be able to answer
Write the answers down before the reviewer arrives, because an unprepared answer here sounds like an unmanaged process.
What tools are used, on which engagements, and who approved them. What the engagement team did with the output, as recorded in the workpaper rather than in the tool. Who is recorded as having performed and reviewed each procedure. For any expectation an agent helped develop, what factors went into it. And what quality risks you identified for technological resources under SQMS No. 1, with the responses you designed.
None of these require an AI standard to exist. All of them are answerable today.
Where Gaper fits
Gaper builds and deploys production AI agents that the client owns, running in the client's own cloud, which means the prompts, outputs and logs stay inside the firm's control and can be produced on request. That addressability is the part that matters for a file a reviewer will read. If you want to talk it through, the lead form is at gaper.io/appointment and general enquiries go to hello@gaper.io.
What this means for your firm
The absence of an AI peer review standard is not permission, it is exposure, because the existing documentation and evidence rules apply unchanged to work an agent touched. Your nearest real deadline is SQMS No. 1, where technological resources are now inside the system you were required to design and implement by December 15, 2025. Start by writing down which tools are in use on engagements and what the workpaper says about them, because that is the record your reviewer will read.
Free assessment. No commitment. General enquiries: hello@gaper.io
Frequently asked questions
Is there a peer review standard on artificial intelligence?
Does an agent's output have to go in the audit file?
Who performed the work, and what does the file say?
What if an agent produced the analytical procedure?
Is an agent's output audit evidence?
Is a practice aid a requirement?
How to Scale an Accounting Firm Without Hiring More Staff
A nine person firm reclaims about 857 hours in year one. That is either $99,000 of advisory capacity or a $72,000 avoided hire, never both. Scaled by firm size.
Aug 16, 2026
Manual vs Automated Accounting: A Firm Partner's Guide

Scaling Startups Without Hiring? The AI Agent Strategy No One Talks About
Ready to turn AI into execution?
Book a free assessment of one workflow. We map it, make an honest build versus buy call before any code, and if an off the shelf product covers the job we will tell you so.