Gana Misra
By Gana MisraCEO, Finrep
Wed Aug 12 2026

AICPA Ethics Code AI Changes: What Audit Committees Must Know

Share
AICPA Ethics Code AI Changes: What Audit Committees Must Know

On June 1, 2026, the American Institute of CPAs announced it is seeking public comment on 2027-2030 strategic plan proposals drafted by its Professional Ethics Executive Committee (PEEC) and Peer Review Board (PRB). The deadline for feedback is August 31, 2026.

That deadline is 19 days away.

The PEEC and PRB are the two AICPA bodies most directly responsible for the ethics framework that governs every CPA firm that audits a public or private company. <cite index="42-1">PEEC promotes ethical behavior by AICPA members and others subject to the AICPA Code of Professional Conduct. The PRB oversees a practice monitoring program for firms of varying practice types and sizes, with an emphasis on remediation if problems are identified.</cite>

<cite index="41-1">Both strategic plan proposals cite significant issues impacting accounting, including technology shifts such as the increased use of AI and automation, new business models and alternative practice structures, emerging areas of assurance such as sustainability and cybersecurity, the continued pace of mergers and acquisitions within the profession, and increasing business and regulatory complexity.</cite>

This blog is distinct from the AICPA PE independence rules blog published earlier in this session, which covered the June 15, 2026 effective rules for PE-backed audit firm independence. That blog covered what the rules already require. This blog covers what is coming: the four areas PEEC is signalling it will address in its 2027-2030 strategy, what those areas mean for audit committees, and whether companies should submit comment letters before August 31.

One clarification on scope: the August 31 deadline is on the PEEC's 2027-2030 strategic plan, not on a specific proposed rule or exposure draft. The strategic plan sets the agenda for which standard-setting projects PEEC will pursue over the next four years. It does not itself change the ethics code. But the strategic plan signals which areas will be the subject of formal exposure drafts and rule changes starting in 2027, and those signals matter for audit committees planning their auditor oversight agenda.

What Is the AICPA PEEC and What Is It Proposing to Change?

The Professional Ethics Executive Committee serves as the AICPA's senior ethics committee and promotes ethical behavior for AICPA members through its Code of Professional Conduct. PEEC's strategic plan sets out the framework for how it will develop standards, support implementation, and engage with stakeholders over the four-year period beginning in 2027.

The PEEC's Code of Professional Conduct governs every CPA who is an AICPA member, whether they work at an audit firm, in a corporate accounting function, as a government accountant, or in another capacity. For public company auditing purposes, it governs the ethical and independence obligations of audit partners, senior managers, and other engagement team members at CPA firms.

The PEEC's proposed 2027-2030 strategy focuses on maintaining high-quality standards in the public interest, strengthening implementation support, enhancing stakeholder engagement, and modernizing operations. Key factors shaping the strategy include technological advancements such as AI, increasing regulatory complexity, evolving firm structures, expanding assurance needs including sustainability and cybersecurity, and the need for alignment across standards and oversight functions.

AICPA Vice President Carl Mayes described the current environment: "In today's practice environment, practitioners are navigating unprecedented levels of change. In the face of that complexity, these draft strategic plans for the AICPA's Peer Review Board and Professional Ethics Executive Committee provide CPAs with the clarity they need, outlining how we will continue to promote assurance quality and ethical conduct in the years ahead.

The strategic plan is not yet a specific rule change. It is PEEC's declaration of what rule changes it intends to pursue. Audit committees that want to shape those future rule changes have until August 31 to submit comments. <cite index="42-1">Comments should be sent to ethics-exposuredraft@aicpa.org.

What Are the Four Areas the PEEC 2027-2030 Strategic Plan Covers?

Both strategic plan proposals cite four significant issue areas impacting accounting and the ethics framework. The four areas are: technology shifts including AI and automation, new business models and alternative practice structures, emerging areas of assurance including sustainability and cybersecurity, and the continued pace of mergers and acquisitions within the accounting profession.

Each of these areas corresponds to a category of ethics and independence questions that PEEC anticipates will require standard-setting activity during its 2027-2030 planning cycle.

Technology and AI: what ethical obligations apply when CPAs and their firms use AI tools in audit and other assurance engagements? How should the ethics code address AI-generated work product that is not independently verified? What are the competence and due diligence obligations (familiar from the IRS OPR Alert 2026-19 covered in this cluster) when AI is used in a licensed professional service context?

Alternative practice structures: how should independence rules apply to PE-backed audit firms, firms that share ownership with non-CPAs, and other alternative structures that have grown rapidly in the past five years? PEEC has already issued the June 15, 2026 PE independence rules, but the strategic plan signals that additional standard-setting in this area is anticipated as the PE-backed firm landscape continues to evolve.

Emerging assurance areas: sustainability and cybersecurity attestation are becoming significant practice areas for CPA firms. The ethics code's independence, objectivity, and competence requirements were designed primarily for financial statement audits. How do they extend to sustainability attestation, cybersecurity system and organisation controls reports, and other non-financial assurance engagements?

M&A within the profession: the pace of accounting firm mergers, including both traditional firm combinations and PE-backed acquisitions, creates ethics and independence questions when merged firms have client relationships, former partners, or alumni relationships that affect independence under existing rules.

The AI Ethics Question: What Rules Apply When Your Auditor Uses AI in Your Engagement?

The IRS OPR Alert 2026-19 (covered in the companion blog in this cluster) addressed how Circular 230 applies to AI use in tax practice. The PEEC's 2027-2030 strategic plan signals that a parallel question will be addressed for audit and attestation practice under the AICPA Code of Professional Conduct.

The specific ethics questions that AI raises for CPAs performing audit or attestation services:

Competence under ET Section 1.300.010: the Code requires members to undertake professional services that they or their firm can reasonably expect to complete with professional competence. The growing use of AI tools in audit procedures raises the question of whether professional competence now includes understanding how the AI tools used in an engagement work, where they may produce errors, and when their outputs require human verification.

Due care under ET Section 0.300.040: the Code requires members to observe the profession's technical and ethical standards, strive continually to improve competence and the quality of services, and carry out professional responsibilities to the best of their abilities. The due care obligation applied to AI output is analogous to the OPR Alert 2026-19's Section 10.22 due diligence requirement: AI output does not satisfy due care if the CPA accepted it without independent review.

Objectivity and independence: if an AI tool used in an audit is provided by, or shares data with, a vendor that has a financial relationship with the audit client, does that relationship create an independence threat? The existing threats-and-safeguards framework in the Code addresses specific categories of independence threats, but AI tool vendor relationships are not explicitly addressed.

For audit committees, the AI ethics question has a practical dimension that is actionable now, before PEEC issues any new standards. The PCAOB inspection blog in this cluster (published August 14) noted that PCAOB inspectors are currently asking auditors what AI tools they use, how those tools are supervised, and how outputs are documented. The AICPA ethics framework, once updated, will add another layer of formal obligation to those practices. Audit committees should ask their engagement partner not only what AI tools are being used (the PCAOB question) but also whether the firm has assessed the ethical and independence implications of those tools under the current AICPA Code.

The PE-Backed Firm Independence Question: How Does the June 15 Rule Interact With What's Coming in the PEEC Plan?

The AICPA PE independence rules effective June 15, 2026 are already in effect. They established specific independence obligations for AICPA members affiliated with PE-backed accounting firms, addressing financial interests, employment relationships, and other independence threats that arise when a CPA firm has private equity ownership.

The June 15 rules are the first formal AICPA standard specifically addressing PE-backed firm independence. They represent PEEC's response to the most immediate and concrete independence threats identified in its 2025-2026 work on PE-backed audit firms.

The PEEC's 2027-2030 strategic plan signals that additional work in this area is anticipated. The PE-backed firm landscape is evolving rapidly. New structures (partial PE ownership, PE-backed firm acquisitions of traditional firms, multi-firm PE platforms) continue to emerge, and the June 15 rules addressed a specific set of circumstances identified at the time of their development. The 2027-2030 strategy signals PEEC's recognition that the rules will need to be revisited and expanded as new structures emerge.

For audit committees of companies whose auditors have PE ownership or PE-affiliated structures: the June 15 rules established the minimum current compliance framework. The PEEC's strategic plan signals that additional rules are likely to follow in the 2027-2030 cycle. Audit committees should now be asking two questions:

Is the engagement team in compliance with the June 15, 2026 PE independence rules currently in effect? This is an immediate compliance question that should be part of every Q3 or Q4 audit committee meeting agenda for companies with PE-backed auditors.

What additional independence requirements is PEEC likely to introduce in the 2027-2030 cycle? The strategic plan consultation paper, available for download at aicpa-cima.com, provides the most specific available signal of what PEEC anticipates addressing. Reading the consultation paper and understanding what additional PE independence rules PEEC is contemplating is the forward-looking preparation audit committees can begin now.

The Cybersecurity Ethics Question: What New Confidentiality Obligations Are Being Proposed?

Cybersecurity assurance is one of the fastest-growing practice areas for CPA firms. The SOC for Cybersecurity (System and Organisation Controls for Cybersecurity) framework developed by the AICPA allows CPA firms to provide attestation services on an entity's cybersecurity risk management programme. SOC 2 reports, which cover security, availability, processing integrity, confidentiality, and privacy, are increasingly required by customers, regulators, and investors.

The PEEC's 2027-2030 strategic plan specifically identifies expanding assurance needs in cybersecurity as one of the four key factors shaping its strategy. The ethical questions that cybersecurity attestation raises under the current Code of Professional Conduct include:

Confidentiality of cybersecurity information under ET Section 1.700.001: auditors performing cybersecurity attestation obtain access to detailed information about the client's security architecture, vulnerabilities, and controls. That information is highly sensitive. The current confidentiality provisions of the Code were designed for financial statement information. The PEEC's strategic plan signals that specific guidance on confidentiality obligations in cybersecurity attestation may be part of its 2027-2030 agenda.

Independence in cybersecurity attestation: CPA firms that also provide cybersecurity consulting services face the same independence threat in cybersecurity assurance as in financial audit: a firm that designed the security controls being attested to may not be independent in assessing those controls. The current threats-and-safeguards framework applies, but specific guidance on cybersecurity independence may be forthcoming.

Competence for cybersecurity attestation: performing a SOC for Cybersecurity engagement requires technical knowledge of cybersecurity systems, controls, and risks that may exceed the traditional accounting and audit competencies addressed in the Code's competence provisions.

For audit committees that rely on SOC 2 reports from service organisations, or that engage their own auditor for cybersecurity attestation services, the PEEC's cybersecurity ethics agenda is relevant to auditor oversight.

What Should Audit Committees of PE-Audited Companies Know About the Comment Period?

The comment period closes August 31, 2026. Comments are sought from all stakeholders, not only from CPA firm members. <cite index="42-1">PEEC welcomes comments from all stakeholders to help shape the future direction of ethics and independence standards.</cite>

Audit committees of companies whose auditors have PE ownership structures are specifically positioned to provide relevant input. The PEEC's standard-setting process benefits from input by those who observe the practical effects of ethics standards from the user side of the auditor relationship. An audit committee's perspective on how PE ownership affects auditor independence, communication, and quality provides information that PEEC staff may not obtain from firm-side or practitioner-side commenters.

The consultation paper poses seven specific questions to guide stakeholder input. The consultation paper is available for download at the AICPA Ethics resources page (aicpa-cima.com/resources/landing/aicpa-ethics). The seven questions address how PEEC should prioritise its work, which areas are most urgent, what implementation challenges the current standards create, and how PEEC should engage with stakeholders in its 2027-2030 cycle.

Audit committees do not need to be ethics experts to submit a comment. A one-page letter describing the audit committee's experience with PE-backed auditor independence, or its concerns about AI use in the engagement, or its questions about how cybersecurity attestation independence is governed, provides exactly the kind of stakeholder input the comment process is designed to elicit.

Should Your Company Submit a Comment Letter and What Would You Say?

Most companies do not submit comment letters on professional ethics standard-setting processes because they perceive those processes as being for accounting firms, not for corporate issuers. That perception is incorrect.

The AICPA Code of Professional Conduct governs the behaviour of the CPAs who audit your financial statements. The independence, objectivity, and competence requirements in the Code directly affect the quality of your audit. Audit committees have a direct and legitimate interest in how those requirements are set and enforced.

The three most relevant areas for an audit committee comment letter are:

PE-backed firm independence: describe the audit committee's experience monitoring PE-backed auditor independence under the June 15, 2026 rules. Are the current disclosure and documentation requirements from the auditor sufficient? What additional information would the audit committee need to assess PE-related independence threats? What aspects of the current rules are unclear or operationally difficult to monitor from the audit committee's perspective?

AI use in audit engagements: describe what the audit committee currently knows (or does not know) about AI tool use in its auditor's engagement. What information does the audit committee receive from the engagement partner about AI tool use, supervision, and output verification? What competence and due care disclosures would the audit committee find useful in assessing AI-assisted audit quality?

Cybersecurity ethics: if the company uses SOC 2 reports or engages its auditor for cybersecurity attestation, describe how the audit committee currently assesses independence in those engagements. What guidance from PEEC would make that independence assessment more straightforward?

Comments submitted to ethics-exposuredraft@aicpa.org by August 31, 2026 will be considered by the PEEC as it finalises its 2027-2030 strategic plan and begins developing its standard-setting agenda for that cycle.

What Is the Timeline From Comment Period to Final Ethics Code Changes?

The August 31, 2026 comment period closes the consultation on the PEEC's strategic plan. The strategic plan itself is not a standard change; it is the framework that determines which standard changes PEEC will pursue in the 2027-2030 cycle.

The process from strategic plan to final ethics code changes:

Step 1 (completed by August 31): public comment period on the 2027-2030 strategic plan.

Step 2 (late 2026 to early 2027): PEEC reviews comment letters and finalises the 2027-2030 strategic plan.

Step 3 (beginning 2027): PEEC begins specific standard-setting projects in the prioritised areas (AI ethics, PE independence, cybersecurity ethics). Each project begins with staff research and board deliberation.

Step 4: exposure draft publication for each specific rule change. Comment periods typically run 60 to 90 days.

Step 5: final rule issuance and effective date. Ethics code changes typically have effective dates 6 to 18 months after issuance.

The realistic timeline for the first specific ethics code changes resulting from the 2027-2030 strategic plan: 2028 at the earliest for the areas that are most urgently needed (AI ethics), with some areas potentially not finalised until 2029 or 2030.

The June 15, 2026 PE independence rules are already in effect and are separate from the 2027-2030 strategic plan process. Those rules are the current compliance requirement. The 2027-2030 process may produce additional or updated PE independence rules beginning in 2028.

What Should Your Audit Committee Add to Its September Meeting Agenda About This?

Three specific September audit committee agenda items arising from the AICPA PEEC August 31 deadline and the 2027-2030 strategic plan.

First: ask the engagement partner to describe the firm's current compliance with the June 15, 2026 PE independence rules if the firm has PE ownership. The June 15 rules are in effect now. The audit committee should confirm compliance before Q4, not discover a compliance gap during the year-end audit.

Second: ask the engagement partner to describe the firm's current AI tool use policy and how it addresses the ethical and independence considerations the PEEC is signalling will be the subject of standard-setting in its 2027-2030 cycle. Even without final PEEC AI ethics standards, the current Code's competence and due care provisions apply to AI use. The engagement partner should be able to describe how the firm's AI tool use satisfies those existing obligations.

Third: assess whether the audit committee wants to submit a comment letter to the PEEC before August 31. If yes, assign the task to one or two board members or to the company's general counsel or external legal team, with a deadline of August 25 to allow review before submission. The comment letter should be concise (one to three pages), focused on one or two of the four PEEC strategic plan areas, and grounded in the audit committee's specific experience rather than general policy statements.

Frequently Asked Questions

What is the AICPA PEEC comment deadline?

The PEEC has released its proposed strategy for 2027-2030 and is seeking stakeholder input. Comments are due August 31, 2026 and should be submitted to ethics-exposuredraft@aicpa.org.</cite> The comment period is on the PEEC's 2027-2030 strategic plan, not on a specific proposed rule or exposure draft. The plan signals the areas PEEC intends to address through standard-setting in its next four-year cycle.

What is the AICPA proposing to change about the ethics code for AI?

The PEEC has identified AI and automation as one of four key factors shaping its 2027-2030 strategy. The specific ethics code changes PEEC will pursue in the AI area have not yet been proposed in a formal exposure draft. The strategic plan signals that PEEC will address AI-related competence, due care, and potentially independence questions in its 2027-2030 standard-setting cycle. The comment period allows stakeholders to input on how those questions should be prioritised and addressed.

Does the PEEC proposal affect PE-backed audit firms?

Yes. New business models and alternative practice structures, including PE-backed audit firms, is one of the four key factors in the PEEC's 2027-2030 strategic plan. The June 15, 2026 PE independence rules already effective are separate from this strategic plan process. The 2027-2030 plan signals that PEEC anticipates additional standard-setting in the PE-backed firm area as the landscape continues to evolve.

Should companies submit comment letters to the AICPA PEEC?

PEEC welcomes comments from all stakeholders.</cite> Audit committees of public companies have a direct interest in the ethics standards that govern their auditors. Companies with PE-backed auditors, companies whose auditors use AI tools in their engagements, and companies that rely on cybersecurity attestation services are particularly well-positioned to provide relevant input to the PEEC's 2027-2030 standard-setting agenda.

When will the new AICPA ethics code changes take effect?

The comment period closes August 31, 2026. The PEEC's 2027-2030 strategic plan will be finalised in late 2026 or early 2027. Specific rule changes in the prioritised areas (AI, PE independence, cybersecurity ethics) will be proposed through formal exposure drafts beginning in 2027, with final rules likely in 2028 to 2030 depending on the project and its complexity.

Key Takeaways

  • The AICPA announced on June 1, 2026 that it is seeking public comment on its 2027-2030 strategic plan proposals from its Professional Ethics Executive Committee (PEEC) and Peer Review Board (PRB). The comment deadline is August 31, 2026.</cite>
  • Comments should be submitted to ethics-exposuredraft@aicpa.org. PEEC welcomes input from all stakeholders, not only from CPA firm members.</cite>
  • The four key areas shaping the PEEC's 2027-2030 strategy are: AI and automation, new business models and alternative practice structures (including PE-backed firms), emerging assurance areas (sustainability and cybersecurity), and M&A within the accounting profession.</cite>
  • The comment period is on the strategic plan, not on a specific rule change. The plan signals what standard-setting projects PEEC will pursue beginning in 2027. Final ethics code changes in the prioritised areas are expected to begin taking effect in 2028 to 2030.
  • The June 15, 2026 PE independence rules are already in effect and are separate from the 2027-2030 strategic plan process. Audit committees of PE-backed firm clients should confirm current compliance with those rules before Q4 without waiting for the 2027-2030 cycle.
  • The PEEC's AI ethics agenda will address competence, due care, and potentially independence questions when CPAs use AI tools in audit and attestation engagements, parallel to the IRS OPR Alert 2026-19 framework for tax practice. Audit committees should proactively ask engagement partners how the firm's current AI tool use satisfies the existing competence and due care provisions of the Code.
  • Three September audit committee agenda items: confirm current PE independence rule compliance, ask about AI tool ethics posture, and decide whether to submit a comment letter before August 31.

Run your financial reporting on Finrep