
The amendments the PCAOB adopted in Release No. 2024-007, approved by the SEC, are effective for audits of financial statements for fiscal years beginning on or after 15 December 2025. That is the calendar-2026 audits being planned this month.
The Pitch and the Standard Point in Different Directions
They amend AS 1105 on audit evidence and AS 2301 on responding to risks of material misstatement, and they exist for one reason: to specify what an auditor is responsible for when a technology-based tool does the analysis.
The commercial case for AI in audit is coverage. Stop testing 60 journal entries and test all 400,000 of them. It is a genuinely good argument, and it is the argument in every demo.
Now read what the amended standard actually requires. The auditor must evaluate the relevance and reliability of information obtained or processed using technology-based tools. Where the auditor tests controls over that electronic information, the testing must include IT general controls relevant to it, where applicable. And when performing tests of details using technology-assisted analysis, the auditor must investigate the items identified to determine whether they individually or in aggregate indicate misstatements or control deficiencies.
Coverage does not appear. Provenance and follow-through do.
Coverage Is the Cheap Part
This is worth sitting with, because it inverts how most firms are budgeting for this.
Testing 100% of a population is a compute question. Once the data is in the tool, the marginal cost of testing everything rather than a sample is close to nothing. That is precisely why the pitch leads with it.
The two things the standard asks for do not get cheaper with scale. They get more expensive.
Establishing the reliability of the population means answering where the extract came from, whether it is complete, whether it reconciles to the trial balance, and whether the system it came out of has controls worth relying on. Sampling let an auditor mostly sidestep that by examining original documents item by item. Full population analysis makes the extract itself the evidence, and the standard now says so explicitly.
And investigating identified items scales with the number of items. A tool that flags 4,000 exceptions in a population of 400,000 has not saved the engagement; it has created 4,000 obligations, each of which has to be resolved into either a misstatement, a control deficiency, or an explanation.
The Regulator Sees the Tension Too
This is not a case of a standard setter being oblivious.
Speaking at a conference in September 2025, PCAOB board member Christina Ho argued the Board should move from being an anchor that weighs down innovation to an engine that catalyses it, and used a hypothetical in which unclear guidance discourages a firm from testing 100% of journal entries and pushes it back to manual sampling. Her question was whether that outcome protects investors.
That is a fair question and it cuts both ways. Clarity about responsibilities is what makes the technology usable. It is also what makes the second and third requirements unavoidable.
What This Actually Asks of an Engagement
Two practical things, and neither is a software purchase.
The first is provenance. Somebody has to be able to say, months later, exactly which extract was tested, when it was pulled, who pulled it, and what it reconciled to. That is a documentation discipline, and it is the part most likely to be thin when the extract came over email during fieldwork.
The second is capacity to investigate. Resolving a flagged item almost always means going to a document behind it: the invoice, the contract, the approval, the correspondence explaining an unusual entry. The tool identifies the item. A person still has to find the paper.
MetaWurks works on that second half. It ingests the client's invoices, contracts, statements and correspondence and lets an auditor query the whole set in plain English, so resolving a flagged entry means asking what supports this rather than requesting a document and waiting two days. Role based access controls decide who can open which client's records, audit logs record who opened what and when, and documents ingested into the platform are not used to train models or exposed to other users.
It is not audit software, it does not test populations, and it has no view on whether an extract is reliable. What it changes is the cost of the follow-through the amended standard now requires, which is the cost that grows in direct proportion to how much of the population you tested.
Test everything, by all means. Then be ready to explain where the everything came from, and to account for each thing it found.
Join the Conversation
On your last engagement that used technology-assisted analysis, how many flagged items were resolved by opening a source document, and how long did the average one take to find?