Professional Auditing Standards, Quality Control, and Regulatory Oversight
Regulatory Context and Historical Development of Auditing Standards
Historical Regulatory Environment:
Prior to , auditing standards were subject to minimal regulatory oversight.
Quote on Regulation: "In today's regulatory environment, it's virtually impossible to violate rules." — Bernard Madoff, money manager, stated approximately one year prior to his arrest for embezzling from investors in a Ponzi scheme.
The McKesson & Robbins Case ():
Served as a major catalyst for formal auditing standard-setting in the United States.
Auditors from PriceWaterhouse accepted false management assertions regarding inventory and accounts receivable ( ) balances without conducting independent verification procedures.
Evolution of Standard-Setting Bodies:
AICPA Auditing Standards Board (ASB):
Produced Statements on Auditing Procedure from through .
Replaced by Statements on Auditing Standards (SAS) from to the present.
Waves of Financial Scandals ():
Widespread accounting scandals in the early led to significant regulatory restructuring.
Public Company Accounting Oversight Board (PCAOB):
Created by federal statute to establish Auditing Standards (AS) for public companies (issuers) from to the present.
Auditing Standard-Setting Framework and Authoritative Hierarchy
Division of Standard-Setting Authority:
Audits of Public Entities (Issuers):
Applies to entities that issue stock to the general public.
Regulated primarily by PCAOB Auditing Standards (AS).
Includes standards issued by the ASB prior to April that have not been amended or superseded by the PCAOB (referred to as Interim Standards).
Audits of Nonpublic Entities (Non-issuers):
Applies to private entities that do not issue stock to the general public.
Regulated by AICPA Statements on Auditing Standards (SAS) issued by the ASB.
PCAOB standards are not applicable to nonpublic entity audits.
Hierarchy of Generally Accepted Auditing Standards (GAAS):
GAAS encompasses three levels of authoritative guidance:
Fundamental Principles (Most Authoritative): Guide the overall conduct of audit engagements.
PCAOB Auditing Standards and ASB Statements on Auditing Standards: Provide specific requirements supporting the fundamental principles.
Interpretive Publications (Least Authoritative): Provide practical guidance on applying GAAS.

Fundamental Principles and the Ten Basic Auditing Standards
Objectives of GAAS:
Identify required auditor qualifications and characteristics while guiding audit execution.
Ensure the audit achieves two primary objectives:
Obtain reasonable assurance about whether financial statements are free of material misstatements, whether caused by fraud or error.
Issue a formal report on the financial statements and communicate findings in accordance with audit results.
Mapping Fundamental Principles to the Ten Basic Auditing Standards:
Responsibilities Principle (formerly General Standards):
10 Basic Standards: Training and proficiency; Independence in mental attitude; Due professional care.
Core Principle Requirement: Auditors must possess appropriate competence/capabilities, comply with ethical requirements (independence and due care), and maintain professional skepticism and professional judgment.
Performance Principle (formerly Standards of Fieldwork):
10 Basic Standards: Planning and supervision; Understanding of the entity and its environment to assess risk of material misstatement; Obtaining sufficient appropriate evidence.
Core Principle Requirement: To obtain reasonable assurance, auditors must plan work, supervise assistants, determine/apply materiality levels, assess risks of material misstatement, and gather sufficient appropriate evidence.
Reporting Principle (formerly Standards of Reporting):
10 Basic Standards: Financial statements in accordance with GAAP; GAAP applied consistently (report only if inconsistent); Adequacy of disclosures (report only if inadequate); Express or disclaim an opinion.
Core Principle Requirement: Express an opinion or state that an opinion cannot be expressed, evaluating financial statements against the applicable financial reporting framework.
Stages of an Audit Engagement:
Obtain (or retain) clients Evaluated against competence and capabilities.
Engagement Planning Plan work, supervise assistants, and determine materiality levels.
Risk Management Assess risks of material misstatement.
Audit Evidence Gather sufficient appropriate evidence.
Reporting Express an opinion (or state that an opinion cannot be expressed) based on framework conformity.
Overarching Framework: Ethical requirements (independence and due care), professional skepticism, and professional judgment govern every stage.

The Responsibilities Principle
Competence and Capabilities:
Requires appropriate technical expertise, formal education, and practical audit experience.
Ethical Requirements:
Independence:
Independence in Fact: Maintaining an unbiased, objective mental state throughout the audit.
Independence in Appearance: Presenting an uncompromised posture to external financial report users.
Scenarios: An auditor may possess independence in fact but lack independence in appearance, or vice versa.
Threats to Independence: Financial relationships with audit clients, managerial relationships with audit clients, and the auditor-client "revolving door" phenomenon (employment transitions between firms and clients).
Due Professional Care:
The standard of diligence expected of a prudent auditor.
Evaluated by comparing the auditor's performance against what a reasonable auditor would do under similar circumstances.
Professional Skepticism and Professional Judgment:
Professional Skepticism:
Maintaining a questioning mind and critically assessing audit evidence.
Requires auditors to assume management is neither inherently dishonest nor perfectly honest.
Requires independent corroboration of management assertions using objective evaluation.
Professional Judgment:
Application of accumulated training, knowledge, and experience to make informed decisions.
Required because audit decisions are rarely objective or binary; judgment quality depends directly on auditor competency and independence.
The Performance Principle and Audit Evidence
Goal of Reasonable Assurance:
The Performance Principle aims to provide reasonable assurance that financial statements are free of material misstatements.
Absolute Assurance is Impossible Due To:
Nature of Financial Reporting: Financial statements rely on complex estimates and management judgments rather than purely factual data.
Nature of Audit Procedures: Audits rely on sampling techniques and persuasive (rather than conclusive) audit evidence.
Time and Cost Constraints: Regulatory reporting deadlines require audit completion within for large accelerated filers, for accelerated filers, and for other public companies, alongside practical cost limitations.
Components of Performance:
Planning and Supervision: Developing a written, structured audit plan and properly overseeing team members.
Materiality: Establishing quantitative and qualitative thresholds that influence user decision-making, applied throughout the audit lifecycle.
Risk Assessment: Developing an understanding of the entity and its environment (including internal controls) to determine the nature, timing, and extent of substantive testing.
Sufficient Appropriate Audit Evidence.
Characteristics of Audit Evidence:
Appropriateness (Quality):
Relevance: The degree to which evidence addresses the specific financial statement assertion of interest.
Reliability (Hierarchy from High to Low):
Auditor's direct personal knowledge (e.g., physical inspection, direct observation) — Highest Reliability.
External documentary evidence (obtained directly from external third parties).
Internal documentary evidence (generated and maintained by the client) — Lowest Reliability.
Sufficiency (Quantity):
Refers to the total sample size and volume of transactions or accounts examined.
Directly affected by internal control quality:
Effective Internal Controls Lower Control Risk Lower volume of evidence required.
Ineffective Internal Controls Higher Control Risk Higher volume of evidence required.
Detection Risk:
The risk that audit procedures fail to detect an existing material misstatement.
Decreases as the auditor collects higher quality (more appropriate) and higher quantity (more sufficient) evidence.
The Reporting Principle and Audit Opinions
Reporting Mandate:
Auditors must express a formal opinion on financial statements or explicitly declare that an opinion cannot be expressed.
Financial Reporting Frameworks:
The criteria used to measure, recognize, present, and disclose financial items.
Examples include U.S. GAAP, International Financial Reporting Standards (IFRS), or special purpose frameworks (e.g., cash basis, tax basis).
Structure of the Standard PCAOB Audit Report:
Opinion Section: Explicitly states the auditor's opinion regarding framework conformity.
Basis for Opinion: Details management and auditor responsibilities, outlines audit scope, notes compliance with PCAOB standards, and affirms that the audit provides a reasonable basis for the opinion.
Critical Audit Matters (CAMs): Communicates complex, subjective, or challenging matters arising during the current period audit that were reported to the audit committee and relate to material accounts or disclosures.
Sign-off Block: Contains firm signature, audit firm city and state, audit report date, and auditor tenure year.
Example Audit Report Details (AT&T Inc.):
Title: Report of Independent Registered Public Accounting Firm.
Addressee: To the Stockholders and Board of Directors of AT&T Inc.
Financial Statements Audited: Consolidated balance sheets as of December 31, and , and related consolidated statements of income, comprehensive income, cash flows, and stockholders' equity for each of the three years in the period ended December 31, .
Signing Auditor: Ernst & Young LLP (Dallas, Texas; February 19, ; auditor tenure since ).
Four Major Types of Audit Opinions:
Unmodified / Unqualified: Financial statements present fairly in conformity with GAAP in all material respects. (Note: Nonpublic engagements use "Unmodified"; public entity engagements use "Unqualified").
Qualified: Financial statements present fairly except for specific, limited departures or scope limitations.
Adverse: Financial statements do not present fairly in conformity with GAAP due to widespread material misstatements.
Disclaimer: No opinion is expressed, typically due to severe scope limitations or pervasive uncertainty.
System of Quality Control and Firm Supervision
Purpose of Quality Control:
Audit quality is an unobservable, intangible service, often realized by investors only after financial failures occur.
A Quality Control System provides reasonable assurance that a firm and its personnel comply with professional standards and legal requirements, issuing appropriate audit reports.
Six Required Elements of Quality Control:
Leadership responsibilities for quality within the firm ("tone at the top").
Relevant ethical requirements.
Acceptance and continuance of client relationships and specific engagements.
Human resources management.
Engagement performance.
Monitoring procedures.
Case Study: BF Borgers CPA PC Fraud
Firm Profile:
Based in Lakewood, Colorado; operated as a top-10 active public audit firm in the United States by client volume, serving smaller public companies.
Prominent Client: Trump Media & Technology Group.
Regulatory Enforcement (May ):
SEC permanently shut down the firm, labeling it a "sham audit mill".
Fraudulent Practices:
Fabricated audit documentation, conducted nonexistent audit procedures, and staged fake audit planning meetings.
Managing partner Benjamin Borgers directed staff to copy prior-year client workpapers, change dates, and present them as current-year workpapers.
Scope and Impact:
Fraud affected more than regulatory SEC filings between January and June .
Prior inspection reviews revealed a audit deficiency rate across reviewed files.
Sanctions and Penalties:
Permanent lifetime ban prohibiting BF Borgers CPA PC and Benjamin Borgers from practicing before the SEC.
Civil Financial Penalties: Firm paid ; Benjamin Borgers paid .
Client Disruption: Over public company clients were forced to immediately dismiss the firm and secure replacement PCAOB-compliant auditors.
PCAOB Inspections, Deficiencies, and Regulatory Oversight
Inspection Frequency Requirements:
Public accounting firms auditing public entities: Inspected annually ( cycle).
Public accounting firms auditing public entities: Inspected every .
Inspection Report Structure:
Part I (Part I.A): Identifies specific audit deficiencies where the firm failed to obtain sufficient appropriate evidence to support its audit opinion (immediately published).
Part II: Details internal firm quality control deficiencies (made public only if the firm fails to remediate the identified deficiencies within ).
Analysis of Part I.A Audit Deficiencies (2020–2024 Data):
Distribution by Auditing Standard (2022 PCAOB Inspection Analysis):
AS 2201 (ICFR Audit / Integrated Audit): of all Part I.A deficiencies.
AS 1105 (Audit Evidence):
AS 2301 (Responses to Assessed Risks):
AS 2501 (Accounting Estimates / Fair Value):
AS 2810 (Evaluating Audit Results):
Overall Defective Engagement Trend Across Inspected Firms:
: of reviewed audits contained Part I.A deficiencies.
: of reviewed audits contained Part I.A deficiencies.
: of reviewed audits contained Part I.A deficiencies.
: of reviewed audits contained Part I.A deficiencies.
: of reviewed audits contained Part I.A deficiencies.
2024 Deficiencies by Financial Statement Line Item ( Engagements Inspected Across Six U.S. Global Network Firms):
Revenue and related accounts: engagement deficiencies.
Inventory: engagement deficiencies.
Allowance for credit losses: engagement deficiencies.
Business combinations: engagement deficiencies.
Goodwill and intangibles: engagement deficiencies.

International Findings and Inspection Leak Scandals
Global Inspection Findings (IFIAR Report):
The International Forum of Independent Audit Regulators (IFIAR) reported that of global inspected audits contained at least one deficiency finding (March ).
Global Deficiency Rates: () () ().
Top 5 deficiency areas globally: Accounting estimates, internal control testing, audit sampling, group audits, and revenue recognition.
KPMG Inspection Leak Scandal (–):
Scott Marcello (U.S. Vice Chair of Audit at KPMG), four other partners, and an employee were terminated or separated due to illicit acquisition of confidential PCAOB inspection selection data.
Officials received advance notice identifying specific audit engagements selected for upcoming PCAOB inspections.
Internal Whistleblower: An internal KPMG source notified firm leadership that a former PCAOB employee hired by KPMG was providing confidential inspection lists; KPMG reported the leak to the PCAOB.
Criminal Charges (January ): Five former KPMG partners were charged with conspiracy and wire fraud. A sixth individual (former PCAOB employee) pled guilty to conspiracy and received a permanent auditing ban.
Three of the six individuals involved were former employees of the PCAOB.
PCAOB Response: Initiated a complete internal review of information technology controls, data security protocols, and organizational ethical standards.