On Sept. 9, California set some of the nation’s first rules for who may audit artificial intelligence. I spent four years on the board that regulates public company auditors, often as its lone dissenter, and the state got more right than wrong. The problem with the policies is that nothing requires proof that an AI audit got the numbers right, which defies the whole point.
Financial auditors, like everyone else, are increasingly adopting AI in their work, but faster audits are useful only if they avoid the persistent, costly mistakes we keep making. In 2024, federal agencies reported an estimated $162 billion in improper payments, despite most receiving clean opinions on their financial statements. In the private sector, researchers estimated that corporate fraud destroys $830 billion annually at 2021 valuations. These losses are not all audit failures, but they do show how wide the gap has grown between passing an audit and getting the numbers right.
That gap can pose steep costs to businesses, which pay their accountants by the hour for work that spends too much time box-checking processes and not enough on verifying the results themselves. No matter how good a process is, if it produces a wrong conclusion, it should be marked as failed, even if the inspection finds the process was followed. Consider Macy’s. A single employee hid over $100 million in expenses over nearly three years, falsifying documentation along the way. In December 2024, Macy’s said neither its own financial controls nor its auditor’s assessments of them could be trusted. The controls were signed off on, but the numbers were wrong anyway.
California did get two big things right, and the first is competition. The Big Four accounting firms audit nearly every large public company in the United States, leaving customers little choice in their provider. California opens AI auditing to smaller CPA firms, technology companies, nonprofit groups, and academic consortia that demonstrate expertise. Qualified entrants can bring better tools, lower costs, and more choice about whom to trust. Even OpenAI calls for the government to help build a competitive market of AI auditors and develop standards that assess safety and security risks without imposing unnecessary burdens on small companies.
Second, California required safeguards against conflicts of interest. When Arthur Andersen served as both auditor and consultant to Enron, the arrangement famously exposed the danger of competing interests. Customers need to trust that an auditor’s conclusions are free from influence, which is why certain financial and operational relationships have to be firewalled. Independence is essential to that trust.
These are fine steps, but the next one is the hard one, and no government body has taken it.
Markets work best when regulators say plainly what they expect. Right now, no one knows what will count as adequate proof. Buyers cannot tell good tools from bad ones, and a firm that adopts what it thinks is the former still cannot be sure a regulator will accept its results. The technology is ready to be put to use. What is missing is business confidence. Regulatory clarity unlocks a market where 1) auditors are chosen on demonstrated performance and capability, 2) smaller firms win on the evidence they can comply, and 3) companies learn about a problem in March instead of the following January.
I left the Public Company Accounting Oversight Board to help build Oath Verified because machine checking machine, with a human answering for the result, is how the profession earns back trust. Sacramento’s formula is “trust, but verify.” At Oath, we believe in the reverse order. Verify the outputs first. When the outputs are right, the trust naturally follows.
Christina Ho is chief assurance officer of Oath Verified. She served on the Public Company Accounting Oversight Board, 2021-26
