Mai jos este traducerea integrală în engleză, păstrând structura, sensul și registrul profesional al textului.
On 5 August 2026, the IAASB put before the profession three proposed revised standards: ISA 330, ISA 500 and ISA 520. These are not yet the new rules of audit. That is precisely what makes the present moment important. The texts are open for consultation, and auditors, professional bodies, regulators and other stakeholders can now examine the proposed solutions and their consequences before they are finalised. The IAASB has opened both the full response process and a separate consultation for users of financial statements, and it is organising technical sessions on the proposals in September and October. (IAASB)
The significance of the package does not come simply from the fact that the IAASB has issued an Exposure Draft. Such consultations are a normal part of the work of a standard-setting body. Its importance comes from the subject of the revision. The IAASB describes audit evidence and responses to assessed risks as foundational aspects of every audit and says that completing the project would mark an important stage in the roughly decade-long modernisation of the International Standards on Auditing. At the same time, one of the stated reasons for the revision is the increasingly intensive use of technology in business activity, financial reporting and audit. (IAASB)
The issue predates the AI boom
It would nevertheless be wrong to read the 2026 project as a response to ChatGPT or to the current development of generative artificial intelligence. Its history begins in March 2019, when the IAASB launched its project on audit evidence. In October 2022, this was followed by an Exposure Draft for ISA 500, designed for an environment in which entities and auditors were making increasing use of technology and automated tools. (IAASB)
The 2022–2023 consultation, however, brought an important issue to the surface. Part of the audit profession considered that the modernisation did not go far enough. ICAEW, the Institute of Chartered Accountants in England and Wales, explicitly stated that the revision of ISA 500 needed to respond more fully to the use of technology in obtaining audit evidence and expressed disappointment that issues such as evidence derived from technology-based sources or technology-enabled testing were not addressed sufficiently. In a separate response concerning the IAASB work programme, ICAEW also warned against a fragmented adaptation of the standards. (ICAEW)
PwC framed the issue in similar terms. Technology had already become an integral part of the audit process, and the questions emerging in practice could not be resolved through an isolated revision of ISA 500 alone. The firm explicitly listed data analytics, artificial intelligence, machine learning, robotic process automation and other tools, and called for a broader approach to how such technologies contribute to the design of procedures and to obtaining relevant and reliable audit evidence. (IAASB)
The current project reflects precisely this broader approach. The IAASB now considers ISA 500 alongside ISA 330 and ISA 520, treating ISA 500 as the reference point for judgments concerning audit evidence, while ISA 330 and ISA 520 address key components of risk response and analytical procedures. The work developed under the Audit Evidence project up to March 2024 was incorporated into the new Audit Evidence and Risk Response project, and the three Exposure Drafts were developed in a coordinated manner. (IAASB)
This is also one of the most useful ways to read the 2026 consultation. It is not simply about a new definition of audit evidence. The IAASB is seeking a more coherent basis for auditors’ judgments about evidence, stronger evaluation of the relevance and reliability of information, a clearer link between the purpose of a procedure and the procedure actually performed, more consistent application of professional skepticism, and standards that remain usable in a rapidly changing technological environment. (IAASB)
Practice is already changing
Meanwhile, the AI discussion has moved from conceptual debate into day-to-day professional activity. Experiences reported across the profession already reveal a fairly common set of use cases: reviewing and comparing documents, searching previous files and reports, preparing and reviewing working papers, checking consistency across documents, analysing data, identifying patterns and supporting risk assessment.
But the same conversations also reveal an important degree of caution. The usefulness of such tools should not be confused with the much stronger claim that AI “performs the audit”. Professionals point to exactly the kind of issue that is becoming relevant for the standards: an output may be well written and persuasive while still introducing a conclusion that is not supported by the underlying source documents, and a system may perform an analysis quickly without resolving the question of who remains responsible for the result.
The distinction is essential. A system’s ability to perform a procedure, or part of a procedure, does not mean that the auditor’s professional judgment has been transferred to the system.
Suppose that, within a population of 500,000 transactions, a tool identifies 137 operations that it considers unusual. From a technical perspective, the result may be impressive. From an audit perspective, that is precisely where the important questions begin.
Why were those 137 transactions selected? Which characteristics drove the classification? Were the data processed by the system complete and accurate? How are transactions that were not flagged treated? Can the analysis be reproduced? How transparent is the selection logic? What must be independently verified, and what weight can the auditor place on the result?
AI can dramatically reduce the cost of identifying an unusual item. It does not remove the obligation to determine whether that item is significant and whether the information obtained can support an audit conclusion.
This is why the relationship between technology and the proposed changes concerning audit evidence goes much deeper than the use of a particular piece of software. The IAASB proposes a revised definition of audit evidence for the digital environment and strengthened requirements for evaluating the relevance and reliability of information, while keeping the standards principles-based so that they can support innovation without being built around a technology that may quickly become obsolete. (IAASB)
When the auditor can look beyond the sample
A very concrete demonstration of this change in scale comes from the audit of European Union funds.
Through the Technical Support Instrument, the European Commission funded the AI4Audit project for Portugal’s audit authority, Inspeção-Geral de Finanças, together with NOVA Information Management School. The project focused on developing predictive models for detecting and anticipating irregularities in EU funds and using them to improve the efficiency and effectiveness of audit work. (Reforms and Investments)
The starting point was very practical. Auditing EU funds involves a large workload, high volumes of operations and significant costs when sampling leads to complex cases or when inconclusive results require additional procedures close to reporting deadlines. The idea behind the project was to use the information available across the population more intelligently for risk prediction and selection. (Reforms and Investments)
The results published by the European Commission are substantial enough to move the discussion from promises to measurable effects. For the same sample size, the predictive models increased precision by 35%. Alternatively, the sample size could be reduced by up to 60% without loss of precision. A separate methodology based on monetary risk achieved precision gains of 21–28% and sample-size reductions of 38–52% compared with the existing strategy. (Reforms and Investments)
The case should be interpreted carefully. It does not demonstrate that sampling becomes unnecessary, nor that a predictive model can substitute for the auditor. What it does demonstrate is that technology allows information about the entire population to be used in ways that can materially change how cases are selected for audit attention.
Under the traditional paradigm, an operation may become the focus of attention because it was included in a sample or because a known risk factor triggered its examination. In a system capable of analysing very large populations, a transaction may become relevant simply because the relationships within the data make it unusual compared with the rest of the population.
This is also an important change for audited entities. The ability of systems to automatically compare information from different sources and identify relationships that are difficult to detect through manual procedures means that what changes is not only the auditor’s toolkit, but also what can become visible during the audit.
More data does not automatically mean better evidence
This is where one of the most interesting tensions of the coming period emerges.
The more technology allows the auditor to see, the more important it becomes to know whether the auditor can trust the tool through which that information is being seen.
Analysing 500,000 transactions does not automatically produce better audit evidence than analysing 500. The quantity of information and the quality of evidence are not the same thing.
Artificial intelligence also introduces a category of issues that is becoming increasingly difficult to separate from audit methodology. Some models are nondeterministic. Results may depend on the prompt, context or model version. The tool itself may change between two stages of the audit. An output may be highly persuasive and eloquent while still containing an unsupported inference. Automation itself may also create automation bias, the tendency of users to place more confidence in a system-generated recommendation than the available evidence justifies.
Not all of these issues are, or necessarily should be, addressed in detail through ISA 330, ISA 500 or ISA 520. The IAASB deliberately seeks principles-based standards rather than rules for every technology. That is precisely why one of the important questions raised by the current consultation is how well the proposed principles work when applied to tools that can analyse enormous populations, generate their own interpretations and do not always behave like traditional software. (IAASB)
The consultation also matters to those outside the audit profession
The IAASB is seeking views not only from auditors, but also from regulators, investors, analysts, creditors, preparers of financial statements, those charged with governance, academics and other stakeholders. For users of financial statements, there is even a focused consultation on selected issues, including technology-driven changes and the evaluation of the relevance and reliability of information intended to be used as audit evidence. (IAASB)
That is understandable. Changes in how audit can examine information do not concern only those who perform the audit.
Companies, public institutions, accountants, consultants and beneficiaries of EU funds will increasingly operate in an environment in which audit can combine sources, analyse very large volumes of data and direct procedures towards relationships and unusual items that might previously have remained outside the scope of ordinary examination.
This does not mean that every transaction or operation will be audited individually, nor that every unusual item identified by an algorithm will become an audit finding. It does mean, however, that the boundary between what can practically be examined and what until now remained outside the auditor’s field of view is gradually shifting.
An analysis worth continuing during the consultation
The consultation on ISA 330, ISA 500 and ISA 520 remains open until 15 December 2026. The texts are not final, and that is precisely what makes this period particularly useful for examining the differences between the current standards, the proposed solutions and the technological reality in which they will have to operate. (IAASB)
AIdapted will continue this series by analysing the proposals and their technical implications for the use of AI, including through a work breakdown structure of audit activity: research, collection and verification of information, reconciliation, risk assessment, testing of controls, substantive procedures, analytical procedures, population analysis, identification of unusual items, evaluation of audit evidence, documentation and formulation of conclusions.
The question is: what changes in each of these activities when the auditor has access to tools capable of reading, correlating and analysing volumes of information that, until very recently, could not be examined at the same scale?
Comments
Comments are moderated before publication.
No approved comments yet.