Current developments in regulation, or: making failure great again?

Here’s a stimulating LinkedIn commentary from internal audit professional John Johnson:

  • Something interesting is happening in the auditing profession right now.

    1. Regulators are pulling back on formal mandates. Some examples:

    – The NYSE proposed extending the internal audit function requirement for newly listed companies from one year to five.
    – The SEC proposed raising the public-float threshold that triggers SOX Section 404(b) auditor attestation (i.e. relating to design and effectiveness of internal control)  from $700M to $2B.
    – The SEC also proposed allowing bi-annual reporting, rather than quarterly.
    – Federal banking regulators rewrote model risk management guidance to state explicitly that it “does not set forth enforceable standards.”

    2. At the same time, expectations for auditors are increasing:

    – The PCAOB overhauled its quality control standards.
    – The SEC created a dedicated Financial Reporting and Accounting Unit within its Enforcement Division.
    – The IIA is rolling out new topical requirements on cybersecurity, resilience, and third-party risk.
    – The EU’s DORA now names internal audit directly as the independent assurance function for ICT risk and operational resilience at financial entities.
  • So it seems that while less may be mandated, the bar for audit quality and rigor is higher.
  • There’s a reasonable case that rising expectations are good for the profession. But quality costs money, and a lighter mandate means less pressure to spend it. That’s the trap. If internal audit isn’t required, fewer companies keep a real function, which means fewer of the companies can appropriately assure the public that their operational and financial results can be relied upon.
  • Light-touch governance in service of capital formation isn’t an unreasonable policy. However, removing the requirement for auditors doesn’t remove the risk; it removes the validation that the company actively manages risk.
  • None of this accounts for the fact that AI is rapidly creating new risks with data integrity and automated decision-making.
  • While regulators shift the compliance pendulum, here’s the question for corporate executives and boards – Is internal audit a box to check and an expense to reduce, or do you actually want to know what’s happening inside your own company?

The SEC indicated in the proposal cited above that if the proposed amendments were in place today, 19.2% of current public companies would be “large accelerated filers” (basically those subject to the highest level of regulation)—compared to 35.4% today. And even then, new companies belonging in that category (such as Elon Musk’s SpaceX) would be given a major break: a newly-listed company wouldn’t be considered a large accelerated filer until after sixty consecutive months of trading. The SEC brands all of this, in typically puerile Trump-era manner, as a campaign to “Make IPOs Great Again.” But the prospects of such a triumphant rebirth seem remote:

  • “Under the guise of modernizing its framework for registered securities offerings, the SEC proposes to allow public companies to provide investors with less information,” said Benjamin Schiffrin, director of securities policy for Better Markets. “Yet the SEC itself recognizes that the purpose of the federal securities laws is to protect investors by requiring ‘full and fair disclosure’ in public markets, and it is this transparency that has made our public markets the envy of the world.”
  • Schiffrin pointed out that the SEC recognizes that its proposed rule changes could lead to “issuer behavior that results in harm to investors.” But the SEC is pursuing these changes to increase the number of public offerings.
  • “The SEC believes that the current rules governing public offerings prompt some issuers ‘to raise capital through other means, such as an exempt offering or private financing,’” he said. “As we have said previously, however, the reason companies choose to stay private today is because the SEC has expanded the private markets to the point that companies can raise as much money as they need without accessing the public markets. It is the expansion of the private markets that has led to companies shunning public offerings, and it is this expansion that the SEC does not address in today’s proposals.”

We’ve suggested several times in this space (here for instance) that the increasing expectations placed on audit quality and reliability often seem in conflict with other trends and developments, although the focus there was more on tensions within the audit firms themselves (relating to hiring and retention for instance). Johnson (who of course is writing as an advocate for his field of expertise) is no doubt right that companies shouldn’t leap to dilute their internal control and compliance structures just because that’s allowed by degraded regulation. But it’s also foreseeable that some companies will do exactly that (what’s the likelihood of the SEC issuing a coded invitation that no one accepts?) Audit firms can’t compensate for whatever additional risk flows from that reversal – it’s not their job, and in any event, as noted, they have their own well-documented problems. No one can predict how that all shakes out, but my own guess – not particularly well…

The opinions expressed are solely those of the author.

Leave a comment