FRC Guidance on Generative and Agentic AI in Audit (March 2026)
The FRC has published guidance on generative and agentic AI in audit. Here is who it is for, the three risks it names and how firms build confidence in outputs.
In March 2026 the Financial Reporting Council (FRC) published guidance on generative and agentic AI in audit. It is aimed at audit firms and sets out how they can manage the risks to audit quality that these tools create, while still using them to improve quality and efficiency. This guide summarises what the FRC has published, who it is for, the risks it names and the way it expects firms to build confidence in AI outputs. It is written for auditors, audit managers, and anyone planning CPD for an audit team. If you want the earlier picture first, see our guide to PCAOB and FRC guidance on AI in audit.
A note on the sources: this summary draws on the FRC's news item of 30 March 2026, its audit guidance listing, and its factsheet on the guidance. The HTML version of the factsheet is labelled by the FRC as an AI-converted version of a PDF that has not been human-verified, so check the original PDF before relying on any detail. We have not reproduced the full guidance document here.
What the FRC published
The FRC's guidance page lists two documents dated 30 March 2026: the Generative and Agentic AI Guidance, and a factsheet that summarises it. The guidance covers audit quality risks associated with generative AI and agentic AI tools, along with possible mitigations. It also sets out principles for using professional judgement to obtain appropriate confidence in tool outputs, and gives illustrative examples of risks and mitigations for two use cases.
The FRC describes it as the first guidance of its kind from any audit regulator globally, and the second guidance it has issued on AI in audit. It says the guidance is not a response to identified quality failures. It codifies good practice and provides a conceptual foundation for future FRC work. An earlier document, published on 26 June 2025, is called AI in audit: Illustrative example and documentation guidance. It looks at the potential use of AI to enhance procedures over journals and provides guidance on documenting tools that use AI.
Who the guidance is for
According to the factsheet, the guidance is aimed primarily at central functions in audit firms that develop generative and agentic AI tools and the supporting methodologies. It may also interest engagement teams, audit committees and third-party technology providers, which the factsheet treats as secondary audiences. The FRC says it developed the guidance through its technology working group, which includes representatives from eight audit firms. The news item names audit firms and Responsible Individuals as the audience.
How the FRC defines the terms
The factsheet describes generative AI as AI that generates content in response to prompts, using patterns learned from large training datasets. Large language models are a specific form that handles text. It describes agentic AI as systems that orchestrate and carry out multiple components or tasks towards a goal, with some autonomy, typically using one or more large language models as both the orchestrating layer and part of the execution layer.
Current uses the FRC lists
The factsheet gives examples of how firms use these tools today, including matching supporting documents to samples automatically, mathematical checks of financial statements, summarising meeting minutes, audit query chatbots, document translation, contract classification, and agentic tools that automate some audit procedures. The news item adds two illustrative examples from the guidance: summarising board minutes, and using an AI tool to review contracts for revenue recognition testing.
The three risks to audit quality
The factsheet names three risks:
- Misuse of output. A user misreads an output, or relies on a plausible-looking output that was produced for a different task.
- Deficient output. Input problems or system design produce a poor output that is then relied upon. The factsheet says this risk cannot be eliminated because large language models have inherent limitations.
- Non-compliant methodology. A firm's methodology permits AI-based approaches that do not meet auditing standards, partly because AI outputs are hard to compare with traditional audit evidence.
Cybersecurity and data risks are outside the scope of the guidance.
How firms build confidence in outputs
The factsheet describes four categories of mitigation that together lead to appropriate confidence in the quality of an output: system design and development, certification, staff education and governance, and human-in-the-loop review and oversight. It says performing some activities from each category may be appropriate. How much of each is a matter of professional judgement, and efficiency varies by tool and use case.
Accountability does not move
The FRC's news item says regulatory accountability is unchanged and the human auditor remains accountable under auditing standards. The factsheet says the firm and the engagement partner keep full responsibility for audit quality, in line with ISQM (UK) 1 for the firm and ISA (UK) 220 for the engagement partner. The news item encourages firms to fit their use of AI into their wider quality management obligations under ISQM (UK) 1.
The pages we reviewed do not set out documentation requirements for the new guidance, so check the full PDF for those. Our guide to AI in audit and ISA 315 covers how AI sits alongside risk assessment standards.
Planning training for your team (our suggestions)
The following ideas are Learnsignal's own and are not FRC guidance. The FRC names staff education and governance as one category of mitigation, so a team that uses AI tools could reasonably plan for it. Useful starting points are making sure users know what each approved tool is meant to do, and what it is not, so they can spot outputs produced for a different task. It also helps to agree who reviews outputs and how that review is recorded. Our article on AI training for auditors looks at professional development options.
Frequently asked questions
Does the guidance change who is responsible for audit quality?
No. The FRC says regulatory accountability is unchanged and the human auditor remains accountable under auditing standards.
Is the guidance mandatory?
The FRC describes it as guidance that codifies good practice. The pages we reviewed do not describe it as a new rule, so read the FRC's own wording before drawing conclusions for your firm.
Where can I read the full guidance?
The FRC publishes the Generative and Agentic AI Guidance and its factsheet on its audit guidance pages.
To keep your team's knowledge current, explore our CPD courses. This article is a summary of FRC publications and is not professional advice.
This page was last updated:
Learnsignal Healthcare Education Team
The Learnsignal Healthcare Education Team creates CPD and compliance training content for nurses, allied health professionals, and care providers, drawing on current regulatory guidance from bodies including NMBI and equivalent professional regulators.
View all posts by Learnsignal Healthcare Education Team


