• Slide title

    Write your caption here
    Button
  • Slide title

    Write your caption here
    Button
  • Slide title

    Write your caption here
    Button
  • Slide title

    Write your caption here
    Button
  • Slide title

    Write your caption here
    Button
  • Slide title

    Write your caption here
    Button
  • Slide title

    Write your caption here
    Button
  • Slide title

    Write your caption here
    Button
  • Slide title

    Write your caption here
    Button

Receive our
Monthly JGA Advisor


Subscribe

Johnson Global partners with leadership of public accounting firms, driving change to achieve the highest level of audit quality. Led by former PCAOB staff, JGA professionals are passionate and practical in their support to firms in their audit quality journey. We accelerate the opportunities to improve quality through policies, practices, and controls throughout the firm. This innovative approach harnesses technology to transform audit quality. Our team is designed to maintain a close pulse on regulatory environments around the world and incorporates solutions which navigates those standards. JGA is committed to helping the profession in amplifying quality worldwide.

August 24, 2026
Introduction For many audit firms, obtaining registration with the Public Company Accounting Oversight Board (PCAOB) is viewed as a milestone that opens the door for firms to audit public companies (SEC registrants) and broker-dealers. While firms often focus heavily on completing the registration form, paying the registration fee, and obtaining PCAOB approval, many underestimate the significant ongoing responsibilities and risks that accompany registration. The result is that some newly registered firms quickly discover that PCAOB registration is not simply a licensing exercise and gateway to additional audit revenue. Rather, it subjects the firm to a comprehensive oversight regime involving inspections, reporting requirements, quality control expectations, disciplinary authority and enforcement which results may be made public, and heightened scrutiny from regulators, investors, and audit committees. This article highlights several pitfalls that firms frequently fail to consider before becoming PCAOB registered. Registration Is Merely the Beginning, Not the End Many firms approach PCAOB registration as a compliance hurdle. In reality, registration represents the starting point of an ongoing regulatory relationship. Once registered, firms become subject to PCAOB inspection authority, reporting obligations, investigations, and disciplinary proceedings. Registered firms must take on recurring PCAOB filing requirements, including annual reporting and special reporting when specified events occur. Failure to comply can lead to sanctions, revocation proceedings, and reputational damage. Firms that register solely because a potential client requests the firm to do so often underestimate the resources required to maintain compliance year after year. PCAOB Inspections Can Be Far More Demanding Than Peer Review One of the most common misconceptions is that a firm with a successful AICPA peer review is well-positioned for PCAOB inspection. Although both peer reviews and PCAOB inspections evaluate audit quality, they are fundamentally different. PCAOB inspectors focus intensely on audit execution, documentation, professional skepticism, risk assessment, internal controls, and overall compliance with PCAOB standards and rules. Inspection findings can be severe even when a firm has received a clean peer review. Firms entering the public company audit space frequently discover that methodologies and documentation practices acceptable in the private-company environment may not withstand PCAOB inspection scrutiny. Thus, firms should be factoring into their decision-making that they will need to subscribe to modules within their current methodology that include PCAOB procedures to be performed for an audit and/or supplement their audit methodology with certain tools and templates. This would be specifically applicable for areas such as auditing estimates, testing internal controls over financial reporting, and evaluation of critical audit matters. JGA has seen situations where even though a firm has subscribed to a PCAOB-standards module in an auditing platform, the firm still had to supplement this with additional templates. Quality Control Systems Often Need Significant Enhancement Many firms register before fully assessing whether their quality control system can support PCAOB engagements. Areas commonly underestimated include: Engagement quality reviews – does the firm have sufficient EQR resources? Are the EQRs proficient in the requirements of AS 1220? Independence monitoring – does the firm have a well-established platform/repository to track its audit professionals’ investments and relationships as well as track and keep up to date the affiliate relationships of its audit clients? Consultation processes – are there appropriate experts within the firm that can be consulted on when questions arise related to SEC independence rules or PCAOB auditing standards? Or will the firm need to consult externally? Monitoring and remediation activities – does the firm have the appropriate experienced resources to maintain an effective monitoring program? Evaluation of technical competency of professionals working on PCAOB audits Training programs – will the firm have to call on external experts who are experienced in PCAOB standards to upskill its audit professionals in proper understanding of the requirements of the PCAOB auditing standards? Client acceptance procedures – does the firm have the appropriate access to affiliate and related party information to make informed client acceptance decisions? Audit methodology governance A firm may technically qualify for registration yet lack the infrastructure needed to execute PCAOB audits consistently. We have seen all-to-often this gap becoming visible during the firm's first PCAOB inspection with criticism of the firm’s technical competency cited as a pervasive deficiency in the first PCAOB inspection report. Independence Requirements Become More Complex Another overlooked challenge involves auditor independence. Firms accustomed to serving privately held businesses may not fully appreciate the complexity of SEC and PCAOB independence requirements. Relationships, services, and financial interests that may be permissible in other environments can create independence violations for issuer audits under SEC and PCAOB independence rules which would include: Providing bookkeeping assistance Valuation services Tax consulting arrangements Business relationships with audit clients Family and employment relationships Financial interests held by firm personnel Even inadvertent violations can have significant consequences, potentially requiring audits to be re-issued or resulting in regulatory scrutiny or enforcement repercussions. Public Company Audits Require Specialized Expertise Many firms assume experienced auditors can transition easily into issuer audits. Public company audits involve unique requirements related to areas such as: SEC reporting Internal control over financial reporting (ICFR) Critical audit matters (CAMs) Fraud considerations, including journal entry testing Related-party transactions PCAOB auditing standards such as testing estimates and audit committee communications Form AP reporting Without personnel who possess sufficient public company experience, firms may struggle to perform audits that meet PCAOB expectations. Our experience has been that firms need to invest in education and training programs/curriculum for its audit professionals so that they can obtain the necessary understanding of the PCAOB standards. The Cost of Compliance Is Often Underestimated Firms typically budget for registration fees but fail to appreciate the broader financial commitment. Costs frequently include: Upgrades required to firm’s audit methodology Costs to attract and retain experienced personnel Specialized training focused on PCAOB standards Technical accounting resources External consultations Internal inspection programs, that in many instances are outsourced to external consultants with PCAOB inspection experience Quality control enhancements Additional engagement quality reviewers Legal and regulatory support For smaller firms with only a handful of SEC clients, compliance costs can exceed initial expectations and significantly affect profitability. A firm should not ‘dabble’ in the PCAOB arena but should target to grow into this space. Increased Litigation and Regulatory Exposure Becoming a PCAOB-registered firm increases visibility and risk. Public company audits frequently attract: SEC scrutiny PCAOB investigations should a firm have poor inspection results Shareholder litigation when fraud or restatements arise Class-action lawsuits Audit committee scrutiny. Many firms focus on revenue opportunities without fully evaluating whether their risk management framework, insurance coverage, and legal resources are sufficient to support a public-company practice. PCAOB Reporting Requirements Can Be Overlooked Some firms do not recognize the extent of ongoing reporting obligations after registration. Registered firms must file annual reports and timely special reports for specified events. Certain changes which may inadvertently get overlooked involve things like changes to firm ownership, legal proceedings, disciplinary actions against partners, governance matters, or firm leadership may trigger reporting obligations within prescribed deadlines. Failure to maintain accurate and timely reporting can become a regulatory issue independent of audit quality concerns. Audit Committees Expect More Than Technical Compliance Public company audit committees increasingly perform due diligence when selecting auditors and they may consider factors such as: PCAOB inspection history Industry specialization of the firm Staffing models, leverage plans, and the appropriate use of overseas resources Technical resources of the audit professionals Enforcement history Audit quality indicators.  A newly registered firm may discover that obtaining registration does not automatically establish credibility in the marketplace. Building a reputation among audit committees can take years. Exit Strategies Are Rarely Considered Few firms consider what happens if they later decide to leave the public company audit market. Exiting the PCAOB environment can also require planning because withdrawal is subject to PCAOB approval and may be affected by pending oversight matters. The PCAOB maintains procedures governing withdrawal requests, and the Board may delay withdrawal while inspections, investigations, or disciplinary matters remain pending. Firms should understand these obligations before entering the regulated environment including if your SEC client needs a consent letter up to 2 years after the firm may have discontinued the relationship with that client. Cybersecurity and Governance Expectations Are Growing Regulatory expectations continue to evolve. Recent PCAOB initiatives, including QC 1000, reflect a more formalized focus on firm governance, risk assessment, monitoring, remediation, and reporting around the quality control system. Firms that view registration as a static compliance exercise may be surprised by expanding disclosure and oversight expectations. As firms become more reliant on technology and external service providers, weaknesses in cybersecurity, data governance, and vendor oversight can become significant regulatory and business risks. Conclusion PCAOB registration can create valuable growth opportunities and enhance a firm's market position. However, registration is only one step in a much broader commitment to audit quality, regulatory compliance, and public accountability. With that being said, most firms do succeed in the PCAOB environment. Typically, it is those firms that evaluate the full lifecycle implications of registration at the outset of their registration. They invest in quality control infrastructure, specialized personnel, independence monitoring, technical training, and governance processes well before accepting their first public company engagement. JGA, with its team of established PCAOB experts, has been able to successfully help many of its clients navigate the risks and shortcomings of firms as they enter the PCAOB space. We can help firms transform their risk profile, operational expectations, and regulatory responsibilities, so that they can gain the reputation and stature of leading audit quality in the PCAOB arena. Note that sources consulted include PCAOB registration and reporting guidance, including Form 1, Form 1-WD, Form 2, Form 3, Form AP, PCAOB inspection priorities and audit committee resources, and PCAOB QC 1000 implementation materials.
July 27, 2026
The Cost of Standing Still: Why Inspection Fear Can Create AI Quality Risk In our recent article AI Governance Belongs in the Boardroom, Not the Server Room , we explained why firm leadership must take responsibility for AI governance rather than treating AI as a technology issue. In When AI Becomes a Quality Risk: Why Governance Alone is Not Enough , we examined what happens when governance exists, but validation, monitoring, implementation, and ongoing evaluation fail to keep pace with adoption. This article examines a different risk: what happens when inspection uncertainty causes firms to delay AI adoption? While caution is appropriate, avoiding AI altogether may preserve the very quality challenges firms are trying to solve. The question is no longer simply whether AI can be used safely. The better question is whether the firm can govern AI use intentionally enough to improve audit quality without creating unmanaged risk. Fear of Inspection Can Become a Quality Management Issue Caution around AI is understandable. Regulators continue to emphasize sufficient appropriate audit evidence, professional skepticism, supervision, documentation, and accountability. AI does not change those expectations, it simply requires firms to demonstrate how AI-assisted work was governed, validated, supervised, and documented. That is why the issue belongs within the system of quality management. AI adoption should not begin with a technology question. It should begin with a quality risk question: where could governed use of AI help the firm respond to recurring quality challenges, and what safeguards must exist before teams rely on the tool? What Inspectors Are Likely to Ask Is Familiar A common misconception is that inspection risk increases simply because a firm uses AI. The more practical risk is that the firm cannot explain how AI use fits within existing audit and quality management expectations. When AI supports audit execution or quality management activities, firms should be prepared to explain: Why the tool was used for a specific audit objective or quality response; How the firm evaluated the reliability, completeness, and relevance of inputs; How outputs were validated before teams relied on them; How professional judgment and skepticism remained central to the conclusion; ·How engagement teams documented AI involvement and related review procedures; and How firm leadership monitored adoption, consistency, exceptions, and emerging issues. They apply existing expectations to a new way of executing or supporting audit work. A firm that can answer them with clarity is better positioned than a firm that avoids formal AI adoption while informal or inconsistent practices develop outside the quality management framework. Avoidance Can Create Its Own Quality Risks Choosing not to adopt AI may feel like the lower-risk path, particularly for engagements subject to heightened regulatory scrutiny. But avoidance does not eliminate quality risk. In some cases, it preserves deficiencies that technology could help address if implemented with appropriate governance, validation, and monitoring. For example, prolonged hesitation may: Limit the firm’s ability to analyze larger or mor complete populations of data; Maintain manual procedures that are difficult to supervise consistently across engagement teams; Delay improvements to methodology, documentation, training, and review practices; Reduce the firm’s ability to respond to recurring inspection or internal monitoring observations; Create uneven practices where some teams experiment informally while others avoid AI entirely; and Make it harder to attract and retain professionals who expect modern tools and clear guidance. The quality risk is not that every firm must immediately deploy AI broadly. The risk is that leadership may mistake inaction for control. If the firm does not define what is permitted, what is prohibited, and what must be validated, teams may fill the gap themselves. Case Study: When Formal Caution Leads to Informal AI Use Consider a firm that has not approved AI for use in audit execution because leadership is concerned about inspection scrutiny. The firm allows AI for general administrative tasks, but it has not issued detailed guidance addressing engagement-level use, documentation expectations, validation requirements, confidentiality restrictions, or supervision responsibilities. At the engagement level, teams continue to face time pressure, complex documentation requirements, and recurring review notes. Some team members begin using publicly available AI tools to summarize contracts, identify potential risk considerations, draft workpaper language, or explain technical accounting concepts. They do so with good intentions and do not view the use as problematic because the firm has not clearly defined boundaries. Several issues emerge: Governance is unclear because no one has formally approved the use case; Validation practices vary by team member and engagement; Supervision does not fully account for AI involvement; Documentation does not explain how AI-assisted outputs were evaluated; Confidentiality and data protection considerations are inconsistently addressed; and Leadership lacks visibility into how broadly AI is being used in practice. The firm intended to reduce inspection risk by delaying adoption. Instead, it created a more difficult risk profile: informal AI use without a consistent governance structure. From a quality management perspective, the issue is not simply that AI was used. The issue is that the firm did not create a controlled path for responsible use. The Better Question: How Should We Govern Responsible Adoption? Progress begins when firms shift the conversation from whether AI should be used to how AI can be governed as part of the system of quality management. That does not mean approving every tool or every use case. It means creating disciplined pathways for evaluating where AI may support audit quality and where the risks outweigh the benefits. Before expanding AI use, leadership should be able to answer: Which AI use cases are approved, restricted, or prohibited? Which quality risks does each approved use case address? What new risks does the use case introduce? What validation is required before outputs can be used? What documentation should appear in the workpapers or quality management records? Who owns the tool, the methodology, the training, and the monitoring process? How will leadership identify inconsistent uses, exceptions, or emerging concerns? These questions make AI adoption more inspection-ready because they connect the technology to governance, methodology, documentation, supervision, and monitoring. They also help firms avoid the false choice between broad, unmanaged adoption and complete avoidance. Inspection Readiness Comes From Control, Not Inaction Inspection readiness does not require firms to wait for AI-specific regulation. It requires firms to demonstrate that AI use remains grounded in existing audit quality principles: accountability, reliable evidence, professional judgment, supervision, and documentation. A governed approach, including approved uses cases, validation procedures, documentation standards, training, and monitoring, allows firms to innovate while maintaining control. Avoiding AI without addressing informal use often leaves leadership with less evidence of control, not more. Key Takeaways Avoidance is itself a governance decision. Existing audit principles, not new AI rules, remain the foundation for inspection readiness. Informal AI use may create greater inspection risk than transparent, governed adoption. Firms should evaluate AI as a quality response, not only as a technology initiative. Responsible adoption requires approved use cases, validation expectation, accountability, training, documentation standards, and ongoing monitoring. Standing still may preserve known quality challenges while allowing uncontrolled AI practices to develop beneath the surface. Final Thoughts The firms that will be most successful in the AI era are unlikely to be those that adopted AI the fastest or avoided it the longest. They will be the firms that can demonstrate thoughtful governance, disciplined implementation, and continuous oversight. Inspection readiness comes from evidence of control, not evidence of hesitation. Johnson Global Advisory supports firms in developing and evaluating AI governance frameworks, including approved use cases, validation practices, documentation standards, monitoring activities, and accountability structures. An independent review can help leadership assess whether the firm’s approach to AI is disciplined, transparent, and inspection-ready without allowing fear of inspection to slow responsible innovation.
July 16, 2026
In March 2026, the Public Company Accounting Oversight Board (PCAOB) issued a Request for Public Comment as part of its effort to develop a new 2026–2030 strategic plan and reassess future standard-setting priorities. The Board sought stakeholder input on several fundamental questions, including the future direction of inspections and enforcement, the impact of its new quality control standard (QC 1000), enhancements to inspection reporting, standard-setting priorities, international alignment, the role of technology and artificial intelligence, and opportunities to improve transparency with stakeholders. The PCAOB indicated that this feedback would help shape both its strategic plan and future regulatory focus areas.  The response was significant. Stakeholders from across the audit ecosystem—including audit firms, investors, regulators, academics, technology providers, and professional organizations—submitted comment letters addressing how audit oversight should evolve over the next several years. JGA contributed to this dialogue through its own submission to the PCAOB, offering perspectives on inspection modernization, quality management, transparency, and the future of audit oversight. The breadth of feedback provides a valuable view into the challenges, priorities, and expectations shaping the next phase of audit regulation. JGA reviewed 69 comment letters submitted in response to the PCAOB’s request for comment and identified recurring themes across stakeholders. While perspectives vary on implementation, a broader message emerged. Firms are increasingly being asked to demonstrate that audit quality is embedded throughout their organizations, not only within individual engagements. Across stakeholders, there is growing emphasis on system-level quality management, enhanced monitoring, more transparent reporting, stronger emerging technologies, and the ability to respond effectively to evolving regulatory expectations. For many firms, the challenge is no longer simply complying with requirements but demonstrating that audit quality can be sustained at scale. The responses do not call for incremental refinement. They point toward structural change. A System Under Pressure A clear pattern emerged across the comment letters: audit quality is increasingly dependent on access to skilled professionals. For firm leaders, these pressures create practical challenges that extend beyond compliance. Audit firms face increasing difficulty recruiting and retaining experienced professionals while simultaneously responding to expanding regulatory expectations. Many firms must invest in quality control infrastructure, training programs, monitoring activities, and technology enhancements at a time when talent resources are already constrained. This concern is framed not as a near-term challenge, but as a foundational risk to audit quality. The sustainability of the profession, both in terms of talent and institutional capacity, is emerging as a critical issue. At the same time, smaller firms frequently highlighted the disproportionate cost and scalability challenges associated with regulatory compliance, with several respondents warning that increasing complexity may reduce participation among smaller audit providers. Together, these pressures point to a broader tension: how to maintain rigorous oversight while supporting a sustainable and competitive audit market. Reimagining the Inspection Model The most consistent and concentrated feedback across the comment letters relates to the PCAOB’s inspection model. The comment letters suggest that stakeholders increasingly expect inspection programs to provide more context, better severity differentiation, and clearer connections between inspection findings and firm-level quality management systems. Several responses also suggest moving away from binary or pass/fail-style evaluations toward graded or tiered models that better reflect the severity and context of findings. For audit firms, inconsistent inspection outcomes can create uncertainty regarding regulatory expectations, remediation priorities, and resource allocation. When firms are unable to clearly distinguish between systemic quality concerns and less significant documentation deficiencies, it becomes more difficult to prioritize corrective actions and demonstrate the effectiveness of remediation efforts. Taken together, this feedback signals a clear direction- inspection programs must evolve from retrospective, engagement-focused reviews into frameworks that assess how firms operate as systems. Quality Control as the Foundation of Audit Oversight Closely tied to inspection reform is the growing emphasis on quality control systems as the primary driver of audit quality. Perhaps the strongest signal from the comment letters is the growing expectation that audit oversight should focus on the effectiveness of firm’s quality management systems rather than solely on engagement-level outcomes. This includes alignment with emerging frameworks such as QC 1000 and a greater focus on firm-level processes over individual audit outcomes. The implication is significant. Quality is increasingly viewed as systemic, rather than situational, requiring oversight models that evaluate governance, processes, and internal controls at the organizational level. Increasing emphasis on quality control systems requires firms to demonstrate how governance, monitoring, root cause analysis, corrective actions, training, resource management, and accountability mechanisms collectively support audit quality across the organization. From Periodic Review to Continuous Monitoring Another defining theme is the push toward a more data-driven model of audit oversight. Technology providers, data organizations, audit firms, and individual respondents frequently advocated the use of centralized audit data, structured reporting, and analytics-enabled monitoring to support real-time or near real-time oversight. This represents a shift away from periodic, sample-based inspections toward continuous visibility into audit activity. For many firms, this shift raises operational challenges related to data availability, technology infrastructure, governance, and monitoring capabilities. Organizations may need to evaluate whether current systems can support more timely reporting, analytics-enabled monitoring, and greater transparency into quality-related metrics. Technology, in this context, is not viewed as an enhancement, but as an enabler of a fundamentally different oversight model—one built on accessibility, comparability, and timeliness of data. Transparency and Investor Relevance A consistent concern across investors and market participants is the limited usefulness of current reporting outputs. Audit reports, and in particular Critical Audit Matters (CAMs), are frequently described as lacking clarity and specificity. Respondents note that disclosures often fail to provide meaningful insight into what was audited, how risks were addressed, or what the outcomes were. Similarly, PCAOB inspection reports are seen as insufficiently detailed and not clearly connected to investor decision-making. The feedback reflects a broader expectation that audit oversight should produce information that is more transparent, comparable, and meaningful to investors. At a fundamental level, this reflects a broader expectation: that audit oversight should produce outputs that are not only accurate, but usable. AI: A Transformational Force with Governance Implications AI is consistently identified as a transformative force in auditing. Stakeholders recognize its potential to enhance analytics, improve anomaly detection, and increase efficiency. Common recommendations include greater transparency around the use of AI, clear accountability for outcomes, and safeguards to ensure that human judgment remains central to audit conclusions. Interestingly, respondents devoted relatively little attention to AI’s capabilities and significantly more attention to governance, accountability, transparency, and validation. That shift suggests the profession is becoming less concerned with whether AI will be adopted and more concerned with how its use will be governed. The Need for Coordination and Alignment Finally, many respondents highlight the importance of coordination across regulatory and standard-setting bodies. Feedback includes calls for clearer delineation of responsibilities between the PCAOB and other regulators, as well as greater alignment with international standard setters such as the International Auditing and Assurance Standards Board (IAASB). As capital markets continue to operate globally, stakeholders are increasingly focused on consistency across jurisdictions and the reduction of duplication in regulatory requirements. For firms operating across multiple regulatory environments, inconsistent requirements can increase compliance complexity, duplicate effort, and create challenges in maintaining globally consistent methodologies and quality management systems. What makes these themes particularly noteworthy is not that they represent entirely new concerns. Rather, stakeholders from across the audit ecosystem appear to be converging around a common view of where oversight should evolve. The emerging emphasis on quality management systems, transparency, technology-enabled monitoring, and governance suggests that firms may face increasing expectations to demonstrate not only audit execution quality, but also the effectiveness of the systems designed to support it. Converging Signals, Persistent Tensions While the themes across the comment letters are highly consistent, they also reveal important tensions that will shape the next phase of reform: The need for transparency alongside regulatory and legal constraints The balance between innovation and control, particularly in the use of AI The challenge of maintaining investor protection while supporting smaller firms The trade-off between standardized oversight and operational flexibility These tensions are not contradictions. They reflect the complexity of modern audit oversight. What Audit Firms Should Do Now While the future direction of PCAOB oversight will continue to evolve, firms do not need to wait for final regulatory action to prepare. In the near term, audit firms should consider: Evaluating whether their quality control systems are designed, implemented, and documented in a manner that demonstrates firm-level accountability for audit quality. Assessing whether inspection findings, internal monitoring results, and root cause analyses are connected to systemic corrective actions. Reviewing how audit technology, data analytics, and AI-enabled tools are governed, documented, and subject to human oversight. Enhancing transparency in audit committee communications, CAM evaluations, and other reporting outputs. Preparing for oversight models that may place greater emphasis on consistency, scalability, responsiveness, and continuous monitoring. Conclusion While the future direction of PCAOB oversight remains uncertain, the themes emerging from these comment letters point toward a more systemic, transparent, and technology-enabled approach to audit quality oversight. Firms that begin strengthening their quality management systems, monitoring capabilities, governance structures, and reporting practices today may be better positioned to respond to future regulatory expectations and demonstrate sustainable audit quality in an increasingly complex environment. JGA helps audit firms assess, design, and enhance quality control systems, inspection-readiness processes, remediation programs, audit methodology, training, and governance frameworks for emerging technologies. As audit oversight continues to evolve, firms that proactively evaluate their systems, documentation, and monitoring activities will be better positioned to respond to future regulatory expectations.
Show More