Canada’s audit regulator has already looked directly at AI tools in the audit process, and its answer is more specific than the general caution showing up across other regulated professions: AI can assist, but a human-led, skeptical review does not become optional because a tool did the first pass.
Key takeaways
CPAB, the Canadian Public Accountability Board is Canada’s independent audit regulator, and it has published guidance on exactly this question rather than leaving the profession to work it out unaided. Its September 2024 publication observed that AI adoption in the public-company audit files it inspects was “in its early stages, with limited implementations”, while also anticipating increased use of AI-enabled tools — and set out, in the same document, what it expects from firms and individual auditors using them.
CPAB’s guidance is direct about where the line sits: “as the use of AI-enabled tools increases, auditors still need to employ a human-led approach when performing an audit”. That single sentence is the through-line of the whole publication — auditors are told to maintain a heightened level of professional skepticism, consider the risks, limitations and potential bias of each tool, and verify the accuracy of any reference to or interpretation of professional standards obtained by querying a language model, rather than accepting it as settled once the tool has answered.
Rather than inventing a freestanding AI rule, CPAB routes firm-level responsibility through the Canadian Standard on Quality Management, which it says already requires firms to have policies ensuring technological resources — AI tools included — function as intended and generate reliable outputs. In practice that means certifying and testing tools before deployment, training auditors on their limitations, and monitoring how they are actually used across engagements, all framed as an extension of quality-management duties the profession already carries rather than a bolt-on AI policy.
CPAB’s guidance flags that “AI tools lack the capacity for ethical reasoning”, which it says can produce incorrect assumptions, fictitious citations or support, and other integrity failures that need active management by the firm. The Canadian Centre for Cyber Security’s own generative-AI guidance makes the same point from a different angle, for any Canadian business, not just audit firms: generative AI carries a real risk that users “may unknowingly provide sensitive corporate data or personally identifiable information” in a prompt, and a separate risk of “loss of intellectual property” through exactly that channel. For an accountant handling a client’s financial records, both risks describe the same everyday action: pasting real client data into a general-purpose AI tool to save time.
The Cyber Centre’s guidance and CPAB’s land on the same practical instruction from two different directions: AI output “can be incorrect”, and a user “should always be aware of and validate” whether it is accurate. For accounting work outside a formal audit — bookkeeping, financial statement preparation, tax working papers — no regulator-specific guidance exists yet, but the underlying risk is identical to what CPAB has already named for audits, and the same discipline applies: the tool can draft, reconcile or summarize, but a professional still has to verify the result against the underlying records before relying on it.
Accounting is not the only regulated profession working through disclosure questions like this. The Law Society of Alberta’s survey of the legal profession’s own AI guidance sets out a four-factor test for whether a professional needs to tell a client AI was used on their file: whether the use will be disclosed publicly anyway, whether the client expects the work to be done a certain way, whether reputational risk is involved, and whether client-confidential information is being input into the tool. That test was built for lawyers, and it is worth saying plainly that applying it to accounting work is reasoning by analogy, not a rule accountants are bound by — but the underlying factors translate reasonably well to a client’s engagement letter or file notes on AI use in their own accounting work.
A bookkeeper uses a generative tool to reconcile a client’s messy transaction records and draft a first-pass set of financial statements. Following CPAB’s standard even outside a formal audit context means treating that draft the way CPAB tells auditors to treat an AI-assisted working paper: verify the categorization against source documents rather than accepting the tool’s output, check for the kind of plausible-but-wrong entries a language model can produce with total confidence, and avoid pasting unredacted client banking data into a general-purpose tool whose data-handling terms the bookkeeper has not actually reviewed. A companion piece on this hub would call the checklist relevant here: is the client expecting this specific task done by a person, and is confidential financial information going into the tool at all.
Yes — CPAB, Canada's public-company audit regulator, published specific guidance on AI use in the audit in September 2024, making this one of the more directly regulated professional uses of AI in Canada rather than an open question left to general principles.
Not directly — CPAB regulates public-company audits specifically. Its underlying standard, a human-led approach with verified output, is a reasonable one to apply to other accounting work by analogy, but it is not a binding rule outside the audit context CPAB actually oversees.
Feeding sensitive client financial information into a general-purpose AI tool without knowing how that tool handles, stores or reuses the input — a risk the federal Cyber Centre names for any Canadian business, and one that lands harder for a profession built on confidential financial records.
The professional relying on the tool remains responsible for the work product, which is precisely why CPAB's guidance frames AI as an assistant to professional judgment rather than a replacement for it — verifying the output before it is relied on is the step that stands between an AI error and a client-facing mistake.
Related: AI and evidence in Canadian courts and licensing your own content to an AI firm.
Where client data actually flows once an AI tool is wired into a workflow is exactly what an integration engagement has to map out.