August 31, 2026
Ms. Dawn E. Brenner, CPA
Chair, AICPA Peer Review Board
220 Leigh Farm Road
Durham, NC 27707-8110
Via email: PR_expdraft@aicpa.org
Re: PRB Proposed Strategic Plan 2027–2030
Dear Ms. Brenner:
Oath CPAs PLLC appreciates the opportunity to comment on the PRB Proposed Strategic Plan 2027–2030.
Oath CPAs PLLC is a licensed CPA firm that performs financial statement audits using an AI-native methodology. Automated and technology-assisted procedures perform a substantial share of the evidence gathering on our engagements, with licensed professionals retaining responsibility for risk assessment, professional judgment, supervision, and the opinion. We are enrolled in the AICPA Peer Review Program. We therefore have a direct and immediate interest in how the program evaluates technology-enabled audits, and we offer these comments in that spirit.
We support the strategy’s overall direction. The Board has correctly identified the pressures facing the program, and we particularly support Initiative C’s commitment to anticipating emerging assurance trends and Initiative E’s recognition that practice monitoring itself must be reimagined. Our comments are limited to four points, each tied to a specific consultation question. We have deliberately not commented on matters where others in the peer review community are better positioned to advise the Board.
1. The premise that varying technology adoption widens “disparity in firm methodologies and risk profiles” warrants revision (Question 2)
Under “Evolving technology landscape” on page 4, the strategy states that approaches to technology adoption vary significantly by firm, widening the disparity in firm methodologies and risk profiles. Related language appears in Initiative E on page 7, which refers to the growing disparity in assurance approaches across firms.
We ask the Board to reconsider this formulation, for two reasons.
First, it couples methodological differences to risk. As drafted, a firm whose methodology differs from prevailing practice is characterized as presenting a wider risk profile by virtue of that difference. We do not believe the peer review standards or the auditing standards support that inference. Whether an engagement was performed with due care and produced sufficient appropriate audit evidence is a question about the evidence obtained and the judgments exercised, not about whether the procedures resemble those most commonly used at the time.
Second, the page 4 language does more work than the page 7 language. “Factors Driving Our Strategy” is the analytical basis on which the five initiatives rest. If the Board’s stated starting position is that methodological variation is a condition to be narrowed, the initiatives built on that premise will tend toward detecting differences rather than evaluating quality. We do not believe that is the Board’s intent, but we think it is a fair reading of the current text, and it is the reading a reviewer encountering an unfamiliar methodology is most likely to carry into the field.
We suggest the Board describe the phenomenon as growing variation in methodologies and technology-enabled approaches across firms, and state affirmatively — in the strategy itself, not only in later implementation guidance — that practice monitoring evaluates whether a firm’s methodology complies with professional standards and produces sufficient appropriate audit evidence, without regard to how closely it resembles conventional approaches. That framing preserves the Board’s full ability to identify genuinely deficient work while making clear that difference alone is not a finding.
2. AI-enabled auditing needs evaluation criteria, not only reviewer training (Questions 4 and 5)
The strategy names AI-enabled auditing in several places. Under Initiative C, the Board commits to enhancing reviewer training on AI-enabled auditing and to strengthening coordination with the ASB, PEEC, and other standard setters on AI and technology-enabled auditing. We support both actions.
We observe, however, that across all five initiatives, technology-assisted auditing appears only as a training subject and a coordination topic. No strategic action commits the program to developing the criteria a peer reviewer would apply in concluding that a technology-assisted procedure produced sufficient appropriate audit evidence, or the documentation a firm would be expected to maintain to support that conclusion.
Training reviewers on a subject for which no evaluation framework exists does not produce consistency. It produces confident inconsistency: capable reviewers reaching materially different conclusions on comparable engagements, each in good faith. For firms, that outcome is worse than acknowledged silence, because it is unpredictable and difficult to remediate. For the program, it creates the risk that peer review results on technology-enabled engagements reflect reviewer assignment as much as audit quality — which would undermine precisely the consistency and credibility Initiative B is intended to protect.
We recommend adding a strategic action under Initiative C to develop practical evaluation criteria and documentation expectations for technology-assisted audit procedures. In response to Question 5, we believe this belongs at the forefront of the Board’s standard-setting agenda. The elements we would find most useful, and that we expect reviewers would as well, include the following:
What a reviewer should examine to evaluate an automated or AI-assisted procedure, including how full-population testing is assessed relative to a sampling-based approach.
Documentation expectations sufficient for a reviewer to understand and evaluate an automated procedure without proprietary access to the underlying system.
How a firm’s controls over the tools themselves relate to its quality management responsibilities, including the resources component of SQMS No. 1.
Illustrative examples of both conforming and nonconforming applications, so that expectations are calibrated by example rather than left to individual judgment.
Developing these before technology-enabled engagements become common in the review population is materially easier than developing them afterward, when reviewer expectations have already diverged and firms have already built to inconsistent signals.
3. The program should apply a consistent standard to its own use of AI and to firms’ (Questions 3 and 4)
Initiative A commits the program to modernizing PRIMA or its successor by leveraging AI, automation, and streamlined workflows. Initiative E commits it to exploring the integration of automation and AI into future practice monitoring models to improve efficiency and enhance the program’s ability to detect systemic quality issues. We support both, and we agree with the Board’s candid assessment that its current infrastructure underutilizes these capabilities.
We note that the strategy treats these two facts differently. Within the program, AI adoption is characterized as modernization and improved detection. Within firms, it is characterized as widening disparity and risk. We do not believe the Board intends this asymmetry, and resolving it would strengthen the document considerably.
In adopting AI into its own monitoring processes, the Board will have to answer a version of the same question firms face: what evidence establishes that an automated process performs reliably, how is that evidence documented and retained, and what human review is required before its output is relied upon. We encourage the Board to develop those answers deliberately and to publish them. Doing so would give firms and reviewers a shared reference point, and it would place the program in the strongest possible position — holding itself to the standard it applies to the firms it monitors.
4. Stakeholder engagement and pilot participation (Question 7)
The stakeholders identified on page 2 are comprehensive with respect to the profession’s existing institutional structure. We suggest two additions.
First, firms operating technology-native audit methodologies. This is a small group today, but it is the population whose engagements will most directly test the program’s evaluation frameworks, and it encounters the questions Initiative C anticipates before they appear in aggregate peer review results. Engaging these firms directly would give the Board earlier and more specific signal than horizon scanning alone can provide.
Second, providers of audit technology platforms. Their design decisions — what a system records, what it retains, and what it can reproduce for an external party — will substantially determine what evidence is available to a peer reviewer. Engaging them while practice monitoring is being redesigned is considerably less costly than asking them to retrofit auditability afterward.
Initiative E includes strategic actions to develop a phased rollout road map incorporating stakeholder engagement and pilot testing, and to make a go/no-go decision on a redesigned model. Oath CPAs PLLC would welcome the opportunity to provide feedback to the Board or to a task force as that work develops, and to participate in pilot testing of any redesigned practice monitoring approach. The questions the Board will need to resolve in designing that model are questions we are working through now, on live engagements, and we would rather help develop the answers than see them settle by default.
We appreciate the Board’s consideration of these comments and would be glad to discuss any of them at your convenience.
Sincerely,
Christina Ho, CPA
Chief Assurance Officer
Oath CPAs PLLC