DÉJÀ-VU: Bank Failures & Audit Quality Risks

For anyone who lived through the 2008 global financial crisis, the recent banking headlines feel like déjà-vu. As Shakespeare said, the past is prologue, and sure enough, we are seeing multiple banks like Signature Bank and Silicon Valley Bank (“SVB”) collapse. There will undoubtedly be robust root cause analyses and in-depth regulatory investigations, but the common issue facing banks right now is the significant increase in interest rates.


As interest rates rise, the value of fixed income securities tends to fall. Conceptually, a 15-year bond issued in 2020 when interest rates were rock bottom will lose value as interest rates rise. The reason being, in the current market, investors can purchase a 15-years bond with today’s higher interest rates, meaning, that the same bond issued in 2020 with lower interest rates is worth less today and would sell at a discount on the open market.


That’s great, but what does this have to do with banks? Well, banks take deposits from customers and invest the cash according to various risk considerations; many of these investments are in more stable fixed income securities. Even if a bank held US treasuries, arguably the most risk-averse investment, given the significant rise in interest rates over the past couple years, these fixed income portfolios have lost value. If the securities are held to maturity, the bank will receive 100% of the principal, so from a long-term perspective, the bank is fine. However, in the short term, if customers lose confidence in the bank and there is a run, the bank would ultimately become insolvent because it would not recover the face value of the lower-interest-rate bonds in today’s high-interest-rate market. Thus, as was the case with SVB, once there was a run on the bank, it had to shut down within hours.


There will be more detailed accounts to follow, but let’s take a moment and reflect on the rise in interest rates and the threat facing many banks. From the 1980’s through the 2008 global financial crisis and even further through the pandemic, we’ve been living in a declining interest-rate environment. For young auditors, this may be the first time they’ve seen rising interest rates. So, what are the relevant audit considerations for a bank engagement? And what are the possible audit concerns for all other companies and industries?


Banking Engagements

 

Going Concern

Financial statements are predicated on the concept of going concern, that an entity can continue operating for at least another twelve months from the date of auditor’s report. For context, SVB’s financial statements were issued on February 24, 2023. Two weeks later, on March 10, 2023, the bank was closed. There was no explanatory paragraph or emphasis of matter and no critical audit matter (CAM) disclosed in the auditor’s report, and yet, all it took was two weeks. In this case, one might conclude there was no going concern discussion either because the bank’s liquidity was strong, or the watch dog was too weak to bark.

 

As teams consider the going concern assumption, we encourage you to engage in dialogue with management and really challenge management’s assertions.


  • Look at the bank’s liquidity. Look at the investment portfolio mix. Deposits, by their very nature, tend to be short-term liabilities. What is the bank’s mix of short-term and long-term bonds? Short term bonds (because they tie up money for less time) are impacted less by interest rate hikes compared to long term bonds.


  • Review management’s asset and liability stress tests. What happens if there is a decrease in valuation of investments and an increased demand for deposits? If management doesn’t perform stress tests, first consider the impact on internal controls and then consider performing your own stress tests.


  • Ask management how it intends to weather the current rising interest rate environment. Given higher borrowing costs, many customers will likely try to use cash, pulling from deposits, in lieu of borrowing. How is management hedging this risk? Because inquiry alone is never enough, corroborate management’s assertions.


  • Consider analysts ratings and external information about the bank. While external information may be biased, it can have a significant impact on credibility and confidence in the bank. All banks have capital reserves and some liquid cash to offset returns of deposits, but a mass run on a bank (typically due to lack of confidence) can bankrupt the bank. Analysts have a lot of power over confidence in a company.


  • Consider the bank’s exposure to any other banks and/or credit institutions.

 

Valuation

Rising interest rates also impact valuations. Let’s take a look at some of the more prevalent concerns:


  • Investments – Equities and Fixed Income: As we’ve all seen, the equity market took a hit last year and has been slow to recover. As well, the rising interest rates have taken a hit on the value of fixed income securities. Essentially, investments are down right now. Audit teams will need to evaluate whether the decreased valuations are indicative of other-than-temporary-impairment (OTTI). Considering there is no current interest rate relief planned (in fact, the Fed continues to raise interest rates in light of bank failures), there are strong indicators of potential impairment. What seemingly used to be “just a disclosure”, OTTI related disclosures have now become very sensitive information used to assess how much of the bank’s investments are under-water and for how long.  This begs a question that engagement teams should also consider: classification of investments as held-to-maturity. For many banks, this may no longer be an option; again, what are management’s intentions and more importantly can banks hold onto under-water investments long enough to withstand customers’ demands to withdraw cash?


  • Investments – Derivatives: Engagement teams should pay particular attention to the valuation of derivatives that incorporate interest rates. Bank failures and overall monetary tightening have introduced new credit risks which could impact the effectiveness of any number of derivatives. Wall Street has created derivatives for everything, so be sure to read the fine print in every contract and understand the inputs into the valuations. While the unrealized positions for derivatives may appear immaterial at times, don’t underestimate the notional value which can be many times the unrealized position and presents real risk if triggers linked to interest rates are met.


  • Impairment – Goodwill and Intangibles: With increased interest rates comes increased discount rates which brings lower net present values for any discounted cash flow projection. Thus, the risk of impairment for goodwill and intangible assets has increased by default. Given the drastic increases in just over a year, large cushions enjoyed in recent years may easily disappear within a year (or less). Add in the uncertainty in the markets with high inflation rates and the “looming” recession expectations, engagement teams need to really dig into accounting estimates, understand the methods and changes from prior year, validate the data and challenge assumptions. Again, what is management doing to understand and evaluate the sensitivity of significant assumptions?

 

Allowance for Credit Losses

The most challenging part of any bank audit is the allowance for credit losses (ACL). This is commonly cited as a critical audit matter and is one of the most common findings on PCAOB inspections. While an interest rate increase does not directly correlate to an increase in the ACL, the general economic environment contributing to the increased rates has a direct impact.

 

In KPMG’s CAM on the ACL in SVB, one of its audit procedures included “evaluating the historical observation period, focusing on the relevance of the full economic cycle relative to the Company’s current portfolio.” What does “full economic cycle” mean in today’s environment? For context, it has been approximately 15 years since the last financial crisis. Interest rates dropped and though there was some recovery pre-pandemic, interest rates remained low and bottomed out during the pandemic. While banks use lookback reviews to develop models for the ACL, most models have no recent, relevant data for the current economic environment: high inflation, rising interest rates, quantitative tightening and significant economic uncertainty. 

 

Though auditing an estimate doesn’t change in light of the economic environment, engagement teams should increase their professional skepticism and seek to understand (and challenge) how management identifies potential credit concerns amongst its loan portfolios. Dig into the assumptions and understand what has changed in the model year over year. Considering many models may not have the most relevant historical data, what adjustments have been made to qualitative factors to adjust for the current economic conditions? Or if there were no changes, is that appropriate?

 

Communication and Disclosures

As banks prepare financial statements, consider the sufficiency of risk disclosures. SVB had a significant concentration of customers in the venture capital industry. Are customer concentrations appropriately disclosed? Based on the disclosures, ask management how it hedges these risks?

 

In addition to disclosures, consider also the need for communication with the audit committee. If there is significant doubt about an entity’s ability to continue as a going concern, this should be discussed with the audit committee, and potentially, also be a CAM or included in an explanatory paragraph in the auditor’s report. And do not forget about communications from banking supervisors and regulators, both Federal and State. These regulatory findings may indicate potential troubles in bank’s liquidity management.

 

All Other Engagements


While banks are currently the most at-risk for rising interest rates, all companies are impacted by both the rise in interest rates as well as the potential bank failures.


Going Concern

Similar to banks, many other companies will need to consider the potential risk to going concern. For companies with large cash positions, what would be the impact on going concern if that cash was no longer available? Inflation, rising interest rates, and a looming recession will impact future revenue growth and increase borrowing costs. What is management doing to mitigate liquidity concerns? What do the stress tests demonstrate?


Valuation

Most companies will be impacted by many of the same considerations on valuation, as discussed above. However, certain industries will have greater risks and/or concerns. For instance, insurance companies use insurance premiums to invest in alternative funds; many of these funds are impacted by the rising interest rates and the depressed market. For any company with significant leases, rising interest rates mean rising incremental borrowing costs which will impact lease valuation.


Debt Covenants

Rising interest rates often impact balance sheets unexpectedly which in turn can trigger unforeseen non-compliance with debt covenants. Teams should be sure to fully understand all terms and conditions pertaining to debt covenants. If a covenant is breached, inquire with management how it is proceeding with the creditor and then corroborate it. If the bank agrees to waive non-compliance, what evidence is there from the bank to support this assertion? How long will the bank waive the non-compliance? A waiver for one quarter may mean the company is okay at year-end, but failure to indicate future waiver could directly jeopardize the going concern assumption, depending on the amount of debt. Considering that banks/creditors rarely provide waivers, what other means of survival does the entity have?


Communication and Disclosures

Similar to banks, non-banking companies need to review risk disclosures. Engagement teams should specifically consider various credit risk disclosures such as cash positions over the FDIC insurance limits and concentrations in banks. And similar to banks, consider any appropriate audit committee communications and potential CAMs to be included in the audit report.


SVB was unexpected and then shortly after, we had another episode of déjà-vu when Credit Suisse made headlines, being given a lifeline by the Swiss regulators before being bought by UBS. And despite the risks facing the banking industry, the Federal Reserve still increased rates in March, albeit only 25 basis points (bps), as opposed to the anticipated 50 bps. The point is, we’re not through the thick of it yet. The risks are real and as auditors who perform risk-based audits, we need to ensure we understand how the current environment is impacting our clients, their customers and their creditors. Everything is more interconnected than we might imagine, so take time to thoroughly evaluate the risks and design appropriate audit procedures to address those risks, which might also include expanding explanatory paragraphs or including an emphasis of matter in the auditors’ report.


Key Takeaways


  • Going concern is key to financial statements. Thoroughly evaluate the going concern assertion. Understand management’s plans and intentions and corroborate the critical factors that support its assertion, including performing stress tests to identify potential risks.
  • The current economic environment is uncertain. Higher interest rates directly impact fixed income securities as well as any fair value derived through discounted cash flows (i.e. impairment analyses, leases, etc.). The current economic uncertainty is also making it difficult to forecast cash flow projections; be sure to understand the method/model, validate the relevance and reliability and/or completeness and accuracy of data used and challenge (and obtain support for) the reasonableness of assumptions.
  • The ACL is already difficult to audit, but with so much uncertainty and considering that most historical data does not reflect the current economic environment, engagement teams need to critically evaluate the current year assumptions and understand how qualitative factors are being adjusted to account for changes in the macro-economy.
  • Communicate appropriately with the audit committee and management, as necessary and/or required under the auditing standards. This is an unprecedented time for many auditors and many in management, so talk it out and ensure collective understanding of the risks, the appropriate audit procedures, and any pertinent (or required) disclosures in the financial statements.
  • It’s always a good time to remind teams about the importance of increased professional skepticism. Ask yourself: who is my client? A bank? Its investors? Deposit holders? And let’s keep our names out of the headlines; we don’t want to be the “watchdog that didn’t bark.”
July 27, 2026
The Cost of Standing Still: Why Inspection Fear Can Create AI Quality Risk In our recent article AI Governance Belongs in the Boardroom, Not the Server Room , we explained why firm leadership must take responsibility for AI governance rather than treating AI as a technology issue. In When AI Becomes a Quality Risk: Why Governance Alone is Not Enough , we examined what happens when governance exists, but validation, monitoring, implementation, and ongoing evaluation fail to keep pace with adoption. This article examines a different risk: what happens when inspection uncertainty causes firms to delay AI adoption? While caution is appropriate, avoiding AI altogether may preserve the very quality challenges firms are trying to solve. The question is no longer simply whether AI can be used safely. The better question is whether the firm can govern AI use intentionally enough to improve audit quality without creating unmanaged risk. Fear of Inspection Can Become a Quality Management Issue Caution around AI is understandable. Regulators continue to emphasize sufficient appropriate audit evidence, professional skepticism, supervision, documentation, and accountability. AI does not change those expectations, it simply requires firms to demonstrate how AI-assisted work was governed, validated, supervised, and documented. That is why the issue belongs within the system of quality management. AI adoption should not begin with a technology question. It should begin with a quality risk question: where could governed use of AI help the firm respond to recurring quality challenges, and what safeguards must exist before teams rely on the tool? What Inspectors Are Likely to Ask Is Familiar A common misconception is that inspection risk increases simply because a firm uses AI. The more practical risk is that the firm cannot explain how AI use fits within existing audit and quality management expectations. When AI supports audit execution or quality management activities, firms should be prepared to explain: Why the tool was used for a specific audit objective or quality response; How the firm evaluated the reliability, completeness, and relevance of inputs; How outputs were validated before teams relied on them; How professional judgment and skepticism remained central to the conclusion; ·How engagement teams documented AI involvement and related review procedures; and How firm leadership monitored adoption, consistency, exceptions, and emerging issues. They apply existing expectations to a new way of executing or supporting audit work. A firm that can answer them with clarity is better positioned than a firm that avoids formal AI adoption while informal or inconsistent practices develop outside the quality management framework. Avoidance Can Create Its Own Quality Risks Choosing not to adopt AI may feel like the lower-risk path, particularly for engagements subject to heightened regulatory scrutiny. But avoidance does not eliminate quality risk. In some cases, it preserves deficiencies that technology could help address if implemented with appropriate governance, validation, and monitoring. For example, prolonged hesitation may: Limit the firm’s ability to analyze larger or mor complete populations of data; Maintain manual procedures that are difficult to supervise consistently across engagement teams; Delay improvements to methodology, documentation, training, and review practices; Reduce the firm’s ability to respond to recurring inspection or internal monitoring observations; Create uneven practices where some teams experiment informally while others avoid AI entirely; and Make it harder to attract and retain professionals who expect modern tools and clear guidance. The quality risk is not that every firm must immediately deploy AI broadly. The risk is that leadership may mistake inaction for control. If the firm does not define what is permitted, what is prohibited, and what must be validated, teams may fill the gap themselves. Case Study: When Formal Caution Leads to Informal AI Use Consider a firm that has not approved AI for use in audit execution because leadership is concerned about inspection scrutiny. The firm allows AI for general administrative tasks, but it has not issued detailed guidance addressing engagement-level use, documentation expectations, validation requirements, confidentiality restrictions, or supervision responsibilities. At the engagement level, teams continue to face time pressure, complex documentation requirements, and recurring review notes. Some team members begin using publicly available AI tools to summarize contracts, identify potential risk considerations, draft workpaper language, or explain technical accounting concepts. They do so with good intentions and do not view the use as problematic because the firm has not clearly defined boundaries. Several issues emerge: Governance is unclear because no one has formally approved the use case; Validation practices vary by team member and engagement; Supervision does not fully account for AI involvement; Documentation does not explain how AI-assisted outputs were evaluated; Confidentiality and data protection considerations are inconsistently addressed; and Leadership lacks visibility into how broadly AI is being used in practice. The firm intended to reduce inspection risk by delaying adoption. Instead, it created a more difficult risk profile: informal AI use without a consistent governance structure. From a quality management perspective, the issue is not simply that AI was used. The issue is that the firm did not create a controlled path for responsible use. The Better Question: How Should We Govern Responsible Adoption? Progress begins when firms shift the conversation from whether AI should be used to how AI can be governed as part of the system of quality management. That does not mean approving every tool or every use case. It means creating disciplined pathways for evaluating where AI may support audit quality and where the risks outweigh the benefits. Before expanding AI use, leadership should be able to answer: Which AI use cases are approved, restricted, or prohibited? Which quality risks does each approved use case address? What new risks does the use case introduce? What validation is required before outputs can be used? What documentation should appear in the workpapers or quality management records? Who owns the tool, the methodology, the training, and the monitoring process? How will leadership identify inconsistent uses, exceptions, or emerging concerns? These questions make AI adoption more inspection-ready because they connect the technology to governance, methodology, documentation, supervision, and monitoring. They also help firms avoid the false choice between broad, unmanaged adoption and complete avoidance. Inspection Readiness Comes From Control, Not Inaction Inspection readiness does not require firms to wait for AI-specific regulation. It requires firms to demonstrate that AI use remains grounded in existing audit quality principles: accountability, reliable evidence, professional judgment, supervision, and documentation. A governed approach, including approved uses cases, validation procedures, documentation standards, training, and monitoring, allows firms to innovate while maintaining control. Avoiding AI without addressing informal use often leaves leadership with less evidence of control, not more. Key Takeaways Avoidance is itself a governance decision. Existing audit principles, not new AI rules, remain the foundation for inspection readiness. Informal AI use may create greater inspection risk than transparent, governed adoption. Firms should evaluate AI as a quality response, not only as a technology initiative. Responsible adoption requires approved use cases, validation expectation, accountability, training, documentation standards, and ongoing monitoring. Standing still may preserve known quality challenges while allowing uncontrolled AI practices to develop beneath the surface. Final Thoughts The firms that will be most successful in the AI era are unlikely to be those that adopted AI the fastest or avoided it the longest. They will be the firms that can demonstrate thoughtful governance, disciplined implementation, and continuous oversight. Inspection readiness comes from evidence of control, not evidence of hesitation. Johnson Global Advisory supports firms in developing and evaluating AI governance frameworks, including approved use cases, validation practices, documentation standards, monitoring activities, and accountability structures. An independent review can help leadership assess whether the firm’s approach to AI is disciplined, transparent, and inspection-ready without allowing fear of inspection to slow responsible innovation.
July 16, 2026
In March 2026, the Public Company Accounting Oversight Board (PCAOB) issued a Request for Public Comment as part of its effort to develop a new 2026–2030 strategic plan and reassess future standard-setting priorities. The Board sought stakeholder input on several fundamental questions, including the future direction of inspections and enforcement, the impact of its new quality control standard (QC 1000), enhancements to inspection reporting, standard-setting priorities, international alignment, the role of technology and artificial intelligence, and opportunities to improve transparency with stakeholders. The PCAOB indicated that this feedback would help shape both its strategic plan and future regulatory focus areas.  The response was significant. Stakeholders from across the audit ecosystem—including audit firms, investors, regulators, academics, technology providers, and professional organizations—submitted comment letters addressing how audit oversight should evolve over the next several years. JGA contributed to this dialogue through its own submission to the PCAOB, offering perspectives on inspection modernization, quality management, transparency, and the future of audit oversight. The breadth of feedback provides a valuable view into the challenges, priorities, and expectations shaping the next phase of audit regulation. JGA reviewed 69 comment letters submitted in response to the PCAOB’s request for comment and identified recurring themes across stakeholders. While perspectives vary on implementation, a broader message emerged. Firms are increasingly being asked to demonstrate that audit quality is embedded throughout their organizations, not only within individual engagements. Across stakeholders, there is growing emphasis on system-level quality management, enhanced monitoring, more transparent reporting, stronger emerging technologies, and the ability to respond effectively to evolving regulatory expectations. For many firms, the challenge is no longer simply complying with requirements but demonstrating that audit quality can be sustained at scale. The responses do not call for incremental refinement. They point toward structural change. A System Under Pressure A clear pattern emerged across the comment letters: audit quality is increasingly dependent on access to skilled professionals. For firm leaders, these pressures create practical challenges that extend beyond compliance. Audit firms face increasing difficulty recruiting and retaining experienced professionals while simultaneously responding to expanding regulatory expectations. Many firms must invest in quality control infrastructure, training programs, monitoring activities, and technology enhancements at a time when talent resources are already constrained. This concern is framed not as a near-term challenge, but as a foundational risk to audit quality. The sustainability of the profession, both in terms of talent and institutional capacity, is emerging as a critical issue. At the same time, smaller firms frequently highlighted the disproportionate cost and scalability challenges associated with regulatory compliance, with several respondents warning that increasing complexity may reduce participation among smaller audit providers. Together, these pressures point to a broader tension: how to maintain rigorous oversight while supporting a sustainable and competitive audit market. Reimagining the Inspection Model The most consistent and concentrated feedback across the comment letters relates to the PCAOB’s inspection model. The comment letters suggest that stakeholders increasingly expect inspection programs to provide more context, better severity differentiation, and clearer connections between inspection findings and firm-level quality management systems. Several responses also suggest moving away from binary or pass/fail-style evaluations toward graded or tiered models that better reflect the severity and context of findings. For audit firms, inconsistent inspection outcomes can create uncertainty regarding regulatory expectations, remediation priorities, and resource allocation. When firms are unable to clearly distinguish between systemic quality concerns and less significant documentation deficiencies, it becomes more difficult to prioritize corrective actions and demonstrate the effectiveness of remediation efforts. Taken together, this feedback signals a clear direction- inspection programs must evolve from retrospective, engagement-focused reviews into frameworks that assess how firms operate as systems. Quality Control as the Foundation of Audit Oversight Closely tied to inspection reform is the growing emphasis on quality control systems as the primary driver of audit quality. Perhaps the strongest signal from the comment letters is the growing expectation that audit oversight should focus on the effectiveness of firm’s quality management systems rather than solely on engagement-level outcomes. This includes alignment with emerging frameworks such as QC 1000 and a greater focus on firm-level processes over individual audit outcomes. The implication is significant. Quality is increasingly viewed as systemic, rather than situational, requiring oversight models that evaluate governance, processes, and internal controls at the organizational level. Increasing emphasis on quality control systems requires firms to demonstrate how governance, monitoring, root cause analysis, corrective actions, training, resource management, and accountability mechanisms collectively support audit quality across the organization. From Periodic Review to Continuous Monitoring Another defining theme is the push toward a more data-driven model of audit oversight. Technology providers, data organizations, audit firms, and individual respondents frequently advocated the use of centralized audit data, structured reporting, and analytics-enabled monitoring to support real-time or near real-time oversight. This represents a shift away from periodic, sample-based inspections toward continuous visibility into audit activity. For many firms, this shift raises operational challenges related to data availability, technology infrastructure, governance, and monitoring capabilities. Organizations may need to evaluate whether current systems can support more timely reporting, analytics-enabled monitoring, and greater transparency into quality-related metrics. Technology, in this context, is not viewed as an enhancement, but as an enabler of a fundamentally different oversight model—one built on accessibility, comparability, and timeliness of data. Transparency and Investor Relevance A consistent concern across investors and market participants is the limited usefulness of current reporting outputs. Audit reports, and in particular Critical Audit Matters (CAMs), are frequently described as lacking clarity and specificity. Respondents note that disclosures often fail to provide meaningful insight into what was audited, how risks were addressed, or what the outcomes were. Similarly, PCAOB inspection reports are seen as insufficiently detailed and not clearly connected to investor decision-making. The feedback reflects a broader expectation that audit oversight should produce information that is more transparent, comparable, and meaningful to investors. At a fundamental level, this reflects a broader expectation: that audit oversight should produce outputs that are not only accurate, but usable. AI: A Transformational Force with Governance Implications AI is consistently identified as a transformative force in auditing. Stakeholders recognize its potential to enhance analytics, improve anomaly detection, and increase efficiency. Common recommendations include greater transparency around the use of AI, clear accountability for outcomes, and safeguards to ensure that human judgment remains central to audit conclusions. Interestingly, respondents devoted relatively little attention to AI’s capabilities and significantly more attention to governance, accountability, transparency, and validation. That shift suggests the profession is becoming less concerned with whether AI will be adopted and more concerned with how its use will be governed. The Need for Coordination and Alignment Finally, many respondents highlight the importance of coordination across regulatory and standard-setting bodies. Feedback includes calls for clearer delineation of responsibilities between the PCAOB and other regulators, as well as greater alignment with international standard setters such as the International Auditing and Assurance Standards Board (IAASB). As capital markets continue to operate globally, stakeholders are increasingly focused on consistency across jurisdictions and the reduction of duplication in regulatory requirements. For firms operating across multiple regulatory environments, inconsistent requirements can increase compliance complexity, duplicate effort, and create challenges in maintaining globally consistent methodologies and quality management systems. What makes these themes particularly noteworthy is not that they represent entirely new concerns. Rather, stakeholders from across the audit ecosystem appear to be converging around a common view of where oversight should evolve. The emerging emphasis on quality management systems, transparency, technology-enabled monitoring, and governance suggests that firms may face increasing expectations to demonstrate not only audit execution quality, but also the effectiveness of the systems designed to support it. Converging Signals, Persistent Tensions While the themes across the comment letters are highly consistent, they also reveal important tensions that will shape the next phase of reform: The need for transparency alongside regulatory and legal constraints The balance between innovation and control, particularly in the use of AI The challenge of maintaining investor protection while supporting smaller firms The trade-off between standardized oversight and operational flexibility These tensions are not contradictions. They reflect the complexity of modern audit oversight. What Audit Firms Should Do Now While the future direction of PCAOB oversight will continue to evolve, firms do not need to wait for final regulatory action to prepare. In the near term, audit firms should consider: Evaluating whether their quality control systems are designed, implemented, and documented in a manner that demonstrates firm-level accountability for audit quality. Assessing whether inspection findings, internal monitoring results, and root cause analyses are connected to systemic corrective actions. Reviewing how audit technology, data analytics, and AI-enabled tools are governed, documented, and subject to human oversight. Enhancing transparency in audit committee communications, CAM evaluations, and other reporting outputs. Preparing for oversight models that may place greater emphasis on consistency, scalability, responsiveness, and continuous monitoring. Conclusion While the future direction of PCAOB oversight remains uncertain, the themes emerging from these comment letters point toward a more systemic, transparent, and technology-enabled approach to audit quality oversight. Firms that begin strengthening their quality management systems, monitoring capabilities, governance structures, and reporting practices today may be better positioned to respond to future regulatory expectations and demonstrate sustainable audit quality in an increasingly complex environment. JGA helps audit firms assess, design, and enhance quality control systems, inspection-readiness processes, remediation programs, audit methodology, training, and governance frameworks for emerging technologies. As audit oversight continues to evolve, firms that proactively evaluate their systems, documentation, and monitoring activities will be better positioned to respond to future regulatory expectations.
June 29, 2026
In our recent article, AI Governance Belongs in the Boardroom, Not the Server Room, we explored why firm leadership, not technology teams alone, must take ownership of AI governance. Governance establishes accountability. However, accountability alone does not prevent quality deficiencies. As firms increasingly deploy AI-enabled tools across audit execution and quality management processes, a new challenge is emerging. The very technology intended to improve consistency, efficiency, and audit quality may introduce new risks if governance, validation, and monitoring practices fail to keep pace. For Managing Partners, Chief Quality Officers, and SQMS leaders, the question is no longer whether AI should be adopted. The question is whether the firm’s system of quality management is prepared to govern its use. In this article, we examine a practical question that follows naturally from that discussion: What happens when governance exists, but the firm’s quality management processes fail to keep pace with technology adoption? Governance is Only the Beginning The governance discussion often focuses on who is responsible for AI. Equally important is how firms integrate AI into their systems of quality management. When firms deploy AI-enabled tools to support risk assessment, testing, supervision, or documentation, those tools become part of the firm’s quality response. Technology-related issues rarely present themselves as technology problems. More often, they appear as deficiencies in audit execution, supervision, documentation, or quality management. By the time those deficiencies become visible, the underlying technology considerations may have already affected multiple engagements. As firms evaluate the role of AI within their quality management, one governance question deserves particular attention: Who is accountable when the tool gets it wrong? While technology teams may support implementation, responsibility for how AI-enabled tools influence audit quality resides with firm leadership and the system of quality management. Leadership should evaluate whether AI-enabled tools align with firm methodology, support professional judgement, and introduce risks that require additional oversight. Firms create unnecessary quality risk when they treat AI primarily as an innovation or IT initiative rather than a quality management consideration. How AI Creates Quality Risks The use of AI does not change the auditor’s responsibilities. Requirements relating to audit evidence, professional skepticism, supervision, review, and documentation continue to apply. What changes is the way those risks may manifest. AI can accelerate processes, but it can also accelerate the consequences of weak controls, insufficient oversight, or flawed assumptions. The very technology implemented to improve audit quality may become the source of future inspection findings. AI introduces several audit quality risks, including: Over-reliance on automated outputs Reduced professional skepticism Inconsistent application across engagements Limited transparency around how conclusions are generated Insufficient documentation of judgment Unlike traditional technology risks, these issues may not be immediately visible. Deficiencies often emerge only after engagement teams have relied upon the technology across multiple audits. Firms may use AI-enabled tools to identify unusual journal entries or summarize large data populations. However, when engagement teams rely on AI-generated outputs without sufficiently applying professional judgment, skepticism, and client-specific knowledge, important risk indicators may be overlooked or insufficiently documented. This distinction is important because technology-related issues rarely present themselves as technology problems during an inspection, internal review, or remediation effort. More often, they appear as deficiencies in audit execution, supervision, documentation, or quality management. Through our work supporting firms with inspections, remediation initiatives, and quality management programs, we have observed that the underlying technology considerations are often identified only after broader quality concerns begin to emerge. Case Study: Accelerated Technology and AI Implementation Across our work with firms of varying sizes, we are observing a consistent pattern. Leadership focuses heavily on tool selection and implementation timelines, while significantly less attention is devoted to validation, monitoring, and ongoing evaluation. As a result, firms are discovering quality concerns only after the technology has already been deployed broadly across engagements. Consider a firm that adopted an AI-enabled risk assessment tool as part of its response to inspection findings related to audit execution and documentation. Leadership viewed the implementation as part of its remediation strategy and expected the technology to improve consistency across engagements. However, because validation, methodology updates, training, and monitoring failed to keep pace with implementation, engagement teams began relying on outputs that had not been sufficiently evaluated. Several challenges emerged. The firm had not fully validated the tool’s audit functionality, methodology updates were incomplete, training was limited, and accountability for oversight had not been clearly established. Subsequent post-issuance reviews identified engagement deficiencies directly tied to improper reliance on the tool’s outputs. By that stage, the tool had already been deployed across multiple engagements, amplifying the impact of those deficiencies. The lesson extends beyond implementation. Firms often devote significant effort to deploying new technology but considerably less attention to evaluating outcomes after deployment. Leadership should periodically ask a simple question: Is the tool improving quality? Without ongoing evaluation, firms may assume technology is achieving its intended objectives while quality risks continue to develop beneath the surface. Trusting AI Requires Validation Effective governance requires more than approving technology investments. At its core, validation is about answering a fundamental question: How do we know the output can be trusted? Leaders must understand how the firm validates AI-generated outputs and demonstrates that those outputs support audit objectives. How would the firm demonstrate to an inspector, peer reviewer, or internal reviewer that the tool was appropriately validated and monitored? Before deploying AI-enabled tools, firm leadership should be able to answer: How does this technology support the firm’s audit methodology? What quality risks does it introduce? How will outputs be validated? How will use be monitored across engagements? Final Thoughts Governance establishes accountability, but accountability alone does not ensure audit quality. Firms create risk when they treat AI implementation as a technology project instead of a quality response. The most significant AI risk facing firms today may not be the technology itself. It may be the assumption that implementation alone is sufficient. As firms continue adopting AI-enabled tools, leadership should consider a simple question: If this technology contributes to an engagement deficiency next year, can we demonstrate that we appropriately governed, validated, implemented, and evaluated its use? At Johnson Global Advisory, our perspective is informed by work performed across inspections, remediation efforts, technology risk assessments, and quality management initiatives. As firms continue integrating AI into audit execution and quality management processes, understanding how these areas intersect may become just as important as the technology itself.
June 29, 2026
WASHINGTON, D.C.: Johnson Global Advisory is proud to support Santa Monica College through a donation to its STEM Program—investing in educational opportunities that prepare students for careers in science, technology, engineering, and mathematics. Santa Monica College’s STEM Program provides students with access to high-quality academic resources, hands-on learning experiences, and pathways to transfer to four-year institutions and enter in-demand fields. By fostering critical thinking, innovation, and technical skills, the program helps equip students with the tools they need to succeed in an evolving workforce. Katherine Moe writes, “We are deeply grateful to Johnson Global Advisory for its sponsorship of Santa Monica College’s Launch the Future campaign and its investment in the next generation of STEM leaders and innovators. This support expands access to hands-on research, industry-standard technology, scholarships, mentorship, and professional connections—ensuring financial barriers do not stand in the way of talented students pursuing careers that will shape the future of science, healthcare, technology, and innovation.” "My connection to California makes this especially meaningful, " said Jackson Johnson, JGA President. "Supporting the Santa Monica College STEM program reflects our broader commitment to education, access, and we’re proud to invest in opportunities that help shape the next generation of leaders." About Johnson Global Advisory Johnson Global partners with leadership of public accounting firms, driving change to achieve the highest level of audit quality. Led by former PCAOB and SEC staff, JGA professionals are passionate and practical in their support to firms in their audit quality journey. We accelerate the opportunities to improve quality through policies, practices, and controls throughout the firm. This innovative approach harnesses technology to transform audit quality. Our team is designed to maintain a close pulse on regulatory environments around the world and incorporate solutions which navigate those standards. JGA is committed to helping the profession in amplifying quality worldwide. Visit www.johnson-global.com to learn more about Johnson Global.
June 29, 2026
As discussed in our prior articles, What Regulators Expect to See When AI is Used and AI Governance Belongs in the Boardroom, Not the Server Room, firms increasingly recognize that AI governance belongs within the system of quality management. However, inspection experience shows that even well-designed governance frameworks do not eliminate risk. Significant failures occur not only at the policy level, but also at the engagement level, where AI outputs are relied upon as audit evidence without sufficient validation. This article focuses on that execution gap. Specifically, it examines why validation of AI is emerging as one of the most significant audit evidence risks facing public company auditors today. For public company auditors, AI validation is no longer a technical exercise. It is an audit quality issue — and increasingly, an inspection issue. In the eyes of regulators, AI does not reduce evidentiary requirements; it changes how evidence must be evaluated, corroborated, and defended . How AI Changes Audit Evidence—and Raises the Validation Stakes PCAOB auditing standards governing audit evidence have not been rewritten for AI. The fundamental requirement remains the same: auditors must obtain sufficient appropriate audit evidence to support their opinion. What has changed is the evidence pipeline: when AI is used, outputs are often indirect (generated through models rather than procedures alone), abstracted (summaries, risk flags, or scores rather than raw data), and less intuitive to evaluate using traditional audit instincts. This creates a new risk: auditors may rely on AI assisted outputs without fully validating how those outputs were produced, what they mean, or whether they are reliable. From an inspection perspective, AI introduces a simple but critical question: How does the auditor know the AI result is reliable enough to rely on as audit evidence? Inspectors are increasingly focused on whether the engagement team can demonstrate the completeness and accuracy of inputs, the reasonableness of assumptions/logic (including prompts), the consistency and explainability of outputs, and the auditor’s independent evaluation and corroboration. A common misconception is equating firm tool approval (vendor diligence, IT review, or risk assessment) with audit evidence validation. Approval is necessary, but it is not sufficient: validation must occur at the engagement level, in the context of the specific audit objectives, data, and risks. Where AI Validation Commonly Breaks Down In practice, AI validation risk often arises in predictable ways:
June 8, 2026
Johnson Global Advisory is pleased to announce that Jackson Johnson, CPA, President, has been appointed to serve on the AICPA & NASBA International Qualifications Appraisal Board (IQAB). The IQAB is responsible for evaluating international accounting qualifications and facilitating mutual recognition agreements between the United States and other countries, helping to support global mobility and consistency in professional standards. “It’s an honor to serve on the IQAB and contribute to efforts that strengthen the global accounting profession,” said Johnson. “As the profession continues to evolve, collaboration across jurisdictions is critical to maintaining high standards and enabling greater mobility for accounting professionals worldwide.”
May 20, 2026
Few technologies have generated as much excitement—and as much promise—for accounting firms as artificial intelligence (“AI”). The potential to streamline audit execution, reduce hours, and enhance firm profitability is real and already being realized. However, AI does not simply change how audits are performed; it fundamentally alters how firms must think about oversight, responsibility, and quality management. As regulators sharpen their focus on AI‑enabled audits, firm leadership must move beyond adoption and address a more complex challenge: establishing clear and scalable AI governance. This article outlines why AI governance is now a strategic imperative for accounting firm leadership. As discussed in JGA’s article What Regulators Expect to See When AI is Used , inspectors do not evaluate AI tools in isolation. They evaluate whether the engagement team obtained sufficient appropriate audit evidence, exercised professional skepticism, and applied appropriate supervision and review when AI was used. Those expectations are grounded in existing auditing standards and apply regardless of whether AI was used for risk assessment, testing, or documentation support. Against that backdrop, AI governance is not simply about approving tools or managing technology risk. It is about ensuring the firm’s system of quality management supports consistent, supervised, and well-documented use of AI that aligns with audit objectives and withstands inspection scrutiny. When firms treat AI as an IT matter, governance discussions tend to center on 1) Data security, 2) System access, 3) Vendor due diligence, and 4) Infrastructure controls. Those topics matter—but they are only the baseline. Inspectors do not evaluate whether AI systems are well engineered; they evaluate whether AI enabled audit work complies with standards, supports professional judgment, and is governed within the firm’s system of quality management. In short, AI governance is a firmwide audit quality issue, not a back office technology function. Using AI does not change the auditor’s responsibilities. Requirements still apply when AI is used for 1) Audit evidence, 2) Professional skepticism, 3) Supervision and review, 4) Engagement partner accountability and 5) Firm level quality controls. From an inspection standpoint, AI introduces new audit quality risks, including: Over reliance on automated outputs Reduced professional skepticism (automation bias) Inconsistent application across engagements Insufficient documentation of judgment Lack of transparency around how conclusions were reached These are not IT risks—they are audit quality risks. AI Touches Nearly Every Component of a QC System Under modern quality management frameworks (including PCAOB QC 1000 , AICPA SQMS No. 1, IAASB ISQM 1), AI affects nearly every component of a firm’s QC system, not just technology or data governance. 
May 20, 2026
Johnson Global Advisory ("JGA") is proud to announce that Joe Lynch, Shareholder, will be speaking on a panel at the 41st Midyear SEC Reporting & FASB Forum . Joe will deliver the PCAOB update on June 5, with attendance available both in person and virtually. This panel will summarize the activities of the PCAOB including: Recite new requirements for the lead auditor’s use of other auditors Anticipate the new standard, “The Auditor’s Use of Confirmation” Enumerate the new requirements of QC 1000, “A Firm’s System of Quality Control” Recall the guidance of the new auditing standard “General Responsibilities of the Auditor in Conducting an Audit” Understand the amendments addressing aspects of audit procedures that involve technology-assisted analysis of information in electronic form Learn about the proposal to replace existing auditing standards related to an auditor’s use of substantive analytical procedures Anticipate other Standard-Setting and Research Projects Summarize PCAOB inspection findings and enforcement activities Understand recent PCAOB publications, including: Spotlight Publications Audit Focus Publications Data Points Publications Click here to register and learn more. Johnson Global partners with leadership of public accounting firms, driving change to achieve the highest level of audit quality. Led by former PCAOB staff, JGA professionals are passionate and practical in their support to firms in their audit quality journey. We accelerate the opportunities to improve quality through policies, practices, and controls throughout the firm. This innovative approach harnesses technology to transform audit quality. Our team is designed to maintain a close pulse on regulatory environments around the world and incorporates solutions which navigates those standards. JGA is committed to helping the profession in amplifying quality worldwide. 
May 15, 2026
Johnson Global Advisory (JGA) has submitted its response to the PCAOB’s request for input on its 2026–2030 strategic priorities. Drawing on extensive experience supporting firms subject to PCAOB oversight, JGA’s comments emphasize a more modern, risk-based approach to regulation focused on audit quality, scalability, and transparency. View JGA's comments here. Johnson Global partners with leadership of public accounting firms, driving change to achieve the highest level of audit quality. Led by former PCAOB staff, JGA professionals are passionate and practical in their support to firms in their audit quality journey. We accelerate the opportunities to improve quality through policies, practices, and controls throughout the firm. This innovative approach harnesses technology to transform audit quality. Our team is designed to maintain a close pulse on regulatory environments around the world and incorporates solutions which navigates those standards. JGA is committed to helping the profession in amplifying quality worldwide.
April 28, 2026
In our work with firms, we have seen a clear shift in how monitoring and remediation are viewed under modern quality management frameworks. They are no longer treated as retrospective compliance exercises. Instead, engagement deficiencies are increasingly used as meaningful inputs into an ongoing, risk-based system designed to identify issues early, address them thoughtfully, and reduce the likelihood of recurrence. Regulatory messaging reinforces this evolution. Oversight bodies are signaling a shift in focus from isolated engagement outcomes and more on whether firms have a system of quality management that consistently detects quality risks, responds appropriately, and demonstrates that remediation is working in practice. Based on our experience, while individual engagement deficiencies remain important, the more critical question is becoming how firms analyze, respond to, and learn from those issues over time. Engagement Deficiencies Are Signals, Not Endpoints Engagement deficiencies can surface through many channels, including pre-issuance reviews, internal inspections, post-issuance reviews, peer reviews, and regulatory inspections. Regardless of source, firms benefit most when these findings are evaluated through a consistent quality management lens. In practice, we encourage firms to look beyond whether a single engagement fell short . The more meaningful consideration is whether the deficiency points to potential weaknesses in governance, methodology, training, supervision, resourcing, or monitoring activities. We often observe that when issues are quickly labeled as engagement-specific, without assessing whether they reflect broader quality risks, valuable insight is lost. Modern quality management frameworks are designed to use these signals to strengthen the system, not simply close individual findings. What Effective Monitoring and Remediation Looks Like in Practice Firms that navigate this environment effectively tend to apply a disciplined and repeatable approach when deficiencies are identified. Based on our experience supporting firms across a range of practice areas, several elements consistently make a difference: Assess whether the issue may be systemic Recurring observations across engagements, service lines, or time periods often indicate system-level risk. Similar documentation gaps, inconsistent application of methodology, or supervision challenges rarely arise in isolation. Perform meaningful root cause analysis Effective root cause analysis typically moves beyond surface explanations. Firms benefit from evaluating whether policies and procedures were designed appropriately, implemented as intended, and supported by sufficient training, time, and resources. Design remediation that directly responds to the quality risk Remediation is most effective when it is clearly linked to the underlying risk. Depending on the circumstances, this may include enhancements to methodology, targeted training, revised review requirements, or changes to engagement acceptance, staffing, or oversight processes. Validate remediation through timely monitoring Implementing corrective actions is only part of the process. In our experience, firms are most successful when they also confirm that remediation operates as intended. Follow-up monitoring performed early enough to prevent recurrence is a critical component of this step. Failure to validate remediation remains one of the most common and consequential weaknesses we observe across firms. Case Study: When Remediation Is Not Validated In one situation we encountered, a firm identified engagement deficiencies through post-issuance reviews. The issues mirrored observations that had previously been noted during peer review and were communicated as having been addressed by the group responsible for report issuance. However, responsibility for validation was not clearly assigned, and no follow-up procedures were performed to evaluate whether the revised processes were effective. Subsequent post-issuance reviews, triggered by an organizational change, revealed that similar and additional deficiencies had re-emerged. From a quality management perspective, this was not an engagement execution failure. It reflected a breakdown in monitoring and remediation. The firm had information indicating quality risk but did not adjust its monitoring activities to confirm that remediation was working. Viewed through a system lens, this represents a system-level deficiency rather than an isolated engagement issue. Quality Management Applies Across All Engagement Types Modern quality management frameworks apply across a firm’s assurance and attestation practice, including private company audits, public company audits, SOC engagements, nonprofit audits, and other services. Deficiencies identified in any practice area may signal broader weaknesses in: Governance and leadership Methodology and training Monitoring activities Remediation processes In our experience, firms struggle to maintain an effective system of quality management when certain practices are treated as exempt from system-level evaluation. Key Takeaways Engagement deficiencies are inputs into the system, not endpoints. Recurring issues often indicate systemic quality risk. Remediation should be validated, not assumed. Monitoring activities should evolve as risks emerge. Quality management applies across all engagement types. Firms that treat monitoring and remediation as a continuous feedback loop, rather than a periodic exercise, are typically better positioned to improve engagement quality and respond to evolving regulatory expectations. Looking for an independent perspective on whether engagement deficiencies have been fully addressed? Based on our experience working with firms across assurance and attestation practices, Johnson Global Advisory supports clients by performing independent reviews, validating remediation efforts, and strengthening monitoring processes. If you would like support refining policies, training, workflows, or documentation standards, or would benefit from an objective assessment ahead of regulatory, peer, or internal inspections, contact your JGA audit quality advisor to discuss your needs.