PCAOB 2026 focus: AI in audit and ICFR — external auditors cannot rely on client AI logs alone
—PCAOB AS 2201 AI audit scrutiny
Regulatory exposure — commonly overlooked:
Company uses AI for financial close — CFO owns SOX attestation, AI vendor owns nothing. · Federal agencies disagree on AI approach — but examiners agree internal logs are insufficient.
TAM / Exposure
Every public company · SOX AI controls emerging requirement
Insurance lines
D&O · E&O · Fidelity
Exhibit authority
US Federal Exhibit — SOX §404 AI Control Evidence Pack
Global leaders
PCAOB · Big Four · SEC · NYSE · NASDAQ · NAIC · FTC · EEOC
ICFR AI
Material weakness from AI error in revenue recognition — receipt proves control operated.
Auditor independence
Auditor using AI on same data — circular trust problem solved by independent verify.
SEC comment letters
2026 AI disclosure requests — material AI risk requires governance evidence.
[United States (Federal)] Agency pincer
FTC, CFPB, EEOC, and DOJ all active on AI — one receipt chain satisfies cross-agency discovery.
[United States (Federal)] Federal preemption fight
State laws filling void — multistate operators need jurisdiction-tagged receipts.
[Text / Chat] Modality hook
Baseline — all frameworks apply to text decisions.
7 mandate layers (live)
Regulatory ClockCountdown to operative regulatory deadline — NAIC adoption, GSE mandate, EU transposition.Open →
Domain ClassifierIndustry-specific SAFE/CRISIS/VIOLATION with regulatory framework mapping.Open →
Exhibit / Filing PackRegulator-ready external validation — NAIC Exhibit D, Fannie QC, EU FRIA, FDA Part 11.Open →
Mandate RegistryEnroll deployers/insureds under vertical-specific governance mandate.Open →