September 28, 2026
 

Audit Committee Insights | September 2026

As Labor Day gives way to fall, this issue highlights recent regulatory activity and several thought leadership pieces for audit committees heading into the final quarter of the year. Whether you are following PCAOB inspection modernization, refreshing your AI governance approach, or are interested in what is top of mind for fellow audit committee members, we have a little bit of everything. Read on to learn what’s new.

We welcome input; please let us know what you think. Create your CAQ Dashboard and sign up for our newsletters so that you never miss an update from the CAQ.

In This Issue:

  • PCAOB Leadership, Inspections, and Crypto
  • CAQ Comment Letters: A Consistent Call for a Focused, Transparent PCAOB
  • Governance Over AI and Beyond 
  • ERM, Cybersecurity, and AI Governance: Top Areas for Audit Committees
  • Join Us for the Audit Committee Effectiveness Webinar 
  • CAQ’s Audit Committee Council Spotlight: Tammy Romo, Audit Committee Chair, Tenet Healthcare Corporation
  • ICYMI: CAQ Public Policy Technical Alert (PPTA), July and August 2026
  • Game, Set, Second Life: Where U.S. Open Tennis Balls Go Next

PCAOB Leadership, Inspections, and Crypto

Several developments from the PCAOB and SEC offer audit committees a view into the direction of audit oversight and securities regulation.

PCAOB leadership – Kyle S. Hauptman was sworn in as a PCAOB Board member after being appointed by the SEC in January of this year. Prior to his swearing in as a PCAOB Board Member, Board Member Hauptman was the Chairman of the National Credit Union Administration (NCUA). His term expires on October 24, 2029, and he noted a particular interest in the “technological changes that are transforming both the audit industry and the PCAOB itself”. In his first public statement at an open meeting where the PCAOB adopted amendments to QC 1000, he shared that another focus area of his will be ending the practice of “regulation by enforcement” which includes “regulation by inspection”.

Separately, SEC Chair Paul S. Atkins opened the appointment process for another PCAOB seat, a position reserved for an individual who has never been a certified public accountant. The application deadline was September 8, 2026.

Inspections – The PCAOB released inspection reports for the six U.S. Global Network Firms (GNFs). The 2025 inspection results showed improvements for each of the six GNFs with an average deficiency rate of 13% compared to 26% in 2024. Of the 312 audits inspected in 2025, only one inspection resulted in a restatement.

The PCAOB published discussion materials – including an illustrative example of a modernized inspection report – from the Inspections Modernization Council’s (IMC) July and August meetings. The materials address a quality-control-informed inspection approach, technology, inspection reporting, and remediation.

Together, the release of the GNF inspection reports along with the release of the materials from the IMC give audit committees an opportunity to see where the PCAOB is currently and where they could be going in the modernization of their inspection program.

As a key stakeholder, the PCAOB is seeking feedback as to what information is useful to you in your role. What would be more useful? Share feedback on the IMC materials or other ideas directly with the PCAOB at advisorygroups@pcaobus.org.

SEC Regulation Crypto Assets – The SEC proposed Regulation Crypto Assets, a tailored securities offering framework for certain investment contracts involving crypto assets. The proposal includes two registration exemptions and a conditional safe harbor from the term “investment contract” in the definition of a “security”. Audit committees at companies  participating in, investing in, or otherwise exposed to crypto asset markets may want to follow how the proposal could affect financial reporting, controls, compliance, and assurance needs. If you are interested in sharing input, comments can be submitted here by October 20, 2026.

SEC “Innovation Exemption” – The SEC issued an order granting temporary exemptive relief allowing certain firms, known as Tokenized Securities Venues (TSVs), to trade digital versions of publicly traded stock. As SEC Chair Paul Atkins noted in a statement, this exemption includes conditions intended to protect investors: only certain participants can trade tokenized securities; tokenized securities must provide the same rights and privileges as traditional securities; and issuers have the right to object and prevent their security from being traded as a tokenized security. Audit committees may want to consider whether their organization would participate in a blockchain-based market structure and, if so, the potential implications for financial reporting, internal controls, compliance, cybersecurity, and investor communications.

CAQ Comment Letters: A Consistent Call for a Focused, Transparent PCAOB

Two recent CAQ comment letters to the PCAOB share a common message: the PCAOB’s next chapter should pair ambitious modernization with disciplined priorities, transparent processes, and practical implementation support.

In its standard-setting letter, the CAQ supported a publicly available conceptual framework grounded in transparency, stakeholder engagement, rigorous analysis, effective implementation and post-implementation support, and domestic and international coordination. The letter also recommended continued research in emerging topics and the prioritization of projects related to Noncompliance with Laws and Regulations (NOCLAR) and fraud, auditor independence, and going concern.

In its letter on the PCAOB’s draft 2026–2030 strategic goals and objectives, the CAQ supported the plan and highlighted four implementation priorities:

  • Organizational culture, professional development, and expertise;
  • Execution, prioritization, and coordination with SEC;
  • Evolution of inspections and inspection reporting; and
  • Enhancing the role of the Office of the Chief Auditor in standard setting, implementation support, and interpretation.

Our key message is that clearer priorities and more transparent, coordinated execution can make PCAOB oversight more meaningful to the stakeholders who rely on it. As the PCAOB continues along this path, audit committees are encouraged to monitor how stakeholder input is reflected in the PCAOB’s final plans and how changes to standards and inspections translate into the audit process and auditor communications.

Governance Over AI and Beyond 

AI remains a major boardroom priority, but recent governance resources suggest that boards should broaden the lens. The next oversight challenge is not a single technology. It is the organization’s ability to govern multiple, fast-moving technologies while maintaining accountability, resilience, and a clear connection to strategy.

Treat AI as a business transformation. The rapid adoption of AI is impacting many areas within organizations and should not be viewed as a singular technology initiative. PwC’s Board Oversight of AI Transformation encourages boards to oversee management not only in the deployment of AI but also to consider how areas like operations, talent, financial reporting, compliance, and others are being transformed. Here are six actions board members can take to ensure that management is focused on the right areas:

  1. Govern AI like a transformation, not a tech initiative
  2. Align on where to lead, lag, or exit
  3. Steer the talent and culture needed to unlock AI
  4. Guide the shift to a workforce of people and AI agents
  5. Oversee the risks and controls that let AI scale
  6. Monitor outcomes and risks

Use of AI by boards is early and uneven. In contrast to what is happening in other areas of organizations, the board room is an area where AI has had slower expansion. A recent survey by Deloitte indicates that adoption at the board level is still in its early stages and inconsistent. Deloitte finds, that “many companies have not formally enabled or standardized AI/GenAI for board activities, with nearly half of public companies not expressly supporting its use. Respondents overall are “unsure” whether their boards use AI/GenAI for board activity, and known adoption and use cases vary across organizations.” Boards should look to have conversations and align on the acceptable uses of AI tools and whether board-specific AI policies and guidance are warranted.

Look beyond AI. While the current buzzword may be AI, there are several other adjacent technologies to keep in mind. Tapestry shared Beyond AI: New technologies on the horizon, which highlights quantum computing, AI-enabled cyber threats, and stablecoins as other areas that boards and audit committees should pay close attention to. Across these technologies, the report emphasizes several connected governance themes: data is foundational; the pace of change can outrun existing governance processes; AI can amplify both opportunity and risk; and significant exposures may sit with third parties and infrastructure providers.

Questions for audit committees to consider:

  • Does management have a complete view of where AI and other emerging technologies are being used, including through third parties?
  • Are the organization’s data inventory, encryption strategy, and retention practices keeping pace with long-lived and emerging risks?
  • Do board and committee responsibilities for technology oversight remain clear as issues cut across strategy, cyber, risk, talent, and financial reporting?
  • Are controls and escalation processes designed for machine-speed risks, or do they still depend on human review at every step?
  • How is the board measuring both the value created by AI investments and the risks introduced as adoption scales?

ERM, Cybersecurity, and AI Governance: Top Areas for Audit Committees

Deloitte’s Center for Board Effectiveness and the CAQ released the fifth edition of the Audit Committee Practices Report. This latest edition highlights how committees are balancing their foundational responsibilities with an expanding oversight agenda shaped by emerging risks, cybersecurity, AI governance and expectations for stronger engagement. Based on 248 survey responses from audit committee chairs and members, this year’s report examines not only where oversight responsibility resides, but also whether committees feel equipped with the confidence, visibility and experience needed to oversee these areas effectively.

Highlights from the report:

  • Emerging risks reshape priorities – Beyond the audit committee’s core remit to oversee financial reporting and internal controls, ERM emerged as the number one priority for audit committees, cited by 39% of respondents and outranking cybersecurity for the first time since the survey’s inception. ERM was ranked a top-three priority for 77% of respondents. More than half of respondents (54%) say their committee has grown more focused on emerging risks over the past year.
  • A gap between AI responsibility and readiness – 75% of respondents identified AI governance as a top-three priority, up from 35% last year, and 70% cited technology (including AI) as the top skill needed to enhance committee effectiveness. However, only 56% of respondents are confident in their committee’s ability to oversee AI governance.
  • Cybersecurity oversight is a moving target – Cybersecurity remains pervasive, appearing on 87% of committees’ top-three priority lists, based on survey responses. While most audit committees overseeing cybersecurity feel confident in their ability to effectively oversee it (82%), that confidence still trails nearly every other oversight area surveyed, likely reflective of an evolving risk landscape.
  • Engagement and consistency set the standard – Higher-quality discussion and challenge during meetings is the top-rated opportunity to strengthen audit committee effectiveness, cited by 41% of respondents. Engagement team leadership, experience and continuity is the top response for what audit committees value most in the independent auditor, cited by 52% of respondents.

Audit committees can use these findings to benchmark agendas, assess whether they have the skills and information needed to oversee emerging risks, and identify where deeper dialogue with management and auditors may be warranted. The report also can help committees prioritize education, refine meeting agendas, and strengthen oversight of ERM, cybersecurity, AI governance, and auditor engagement.

Join Us for the Audit Committee Effectiveness Webinar 

Register here for the CAQ’s upcoming webinar on October 15th featuring PCAOB Board Member Steve Laughton and Weyerhaeuser Audit Committee Chair Sara Lewis, and moderated by Vanessa Teitelbaum, Senior Director, Professional Practice at the CAQ. The discussion will focus on the PCAOB’s current priorities and initiatives and practical implications for audit committee oversight in today’s evolving regulatory landscape. One CPE credit is available for those who attend the webinar live.

CAQ’s Audit Committee Council Spotlight: Tammy Romo, Audit Committee Chair, Tenet Healthcare Corporation

We sat down with Tammy Romo, a member of the CAQ’s Audit Committee Council, to shed light on her career and journey to the audit committee. Read on to learn about Tammy’s journey.

How did you get started in accounting? What was your first and last job?

After earning my degree in accounting at the University of Texas, I stepped directly into public accounting by joining Coopers & Lybrand.

After advancing to audit manager, I pursued an opportunity to join Southwest Airlines as a financial reporting manager. I held various roles throughout my time there including Investor Relations, Controller, Treasurer, SVP Planning and ultimately CFO.

After 33 rewarding years, I retired from Southwest Airlines in 2025, concluding my executive career by serving as EVP and CFO for over a decade. I’m grateful for my start in accounting, which set the stage for a career full of continuous learning, countless rewarding challenges, and working with wonderful people and leaders all along the way.

What was the first corporate board that you joined? How did you get on that board?

My first corporate board appointment was as an independent board director with Tenet Healthcare Corporation in 2015, where I currently serve as the Chair of the Audit Committee. This opportunity came through an executive search firm and with the support of Southwest’s Chairman and CEO. My background matched well with the experience they were prioritizing for that seat.

What do you enjoy most about serving on an audit committee? How is it different from other board committees?

I enjoy the all-around collaboration to drive strong governance and transparency. It’s rewarding to move beyond high-level strategy into the mechanics of building trust, fostering a culture of integrity and accountability. The audit committee allows for a deep dive into financial reporting, internal controls, and emerging risks. This granular focus provides an informed, broad view of the entire organization, helping me understand management’s challenges and connect compliance to the overall strategic plan. Ultimately, this work helps build lasting trust with investors and external stakeholders.

What else do you do outside of board service?

Outside of board service, I enjoy spending time with family and friends and staying active. Getting away for the weekend or taking a long walk is a favorite pastime and a great way to recharge. I also dedicate time to mentoring, continuous learning, and giving back to the profession.

What trends or risks do you think audit committees will need to focus on in the next few years?

Today’s volatile, tech-driven operating environment makes it clear that audit committees will need to prioritize cybersecurity, AI governance, and enterprise risk management right alongside traditional financial oversight. This will require an ongoing, deliberate effort to close the digital talent gap through smart, intentional upskilling. Cultivating the technological fluency and expertise necessary to match an organization’s digital pace will be a key driver for future success.

In addition to Tammy’s role as the chair of the audit committee for Tenet Healthcare, she also serves on the audit and finance committees for Ryder System, Inc., and is a member of the McCombs School of Business Advisory Council. She joined the CAQ’s Audit Committee Council in April of 2026.

ICYMI: CAQ Public Policy Technical Alert (PPTA), July and August 2026

Each month, the PPTA highlights and examines the regulatory, standard-setting, legislative, and broader financial reporting developments impacting the public company audit profession. The CAQ’s July and August 2026 Alerts included these featured articles.

FRC Annual Review of Audit Quality Equips Investors and Audit Committees to Make Better Decisions

The FRC published its Annual Review of Audit Quality 2026. Alongside the report, the FRC has published data on Audit Firm Metrics. The FRC will host a webinar on September 23, 2026, to discuss the Annual Review of Audit Quality and its approach to supervision.

New International Ethics Standards Board for Accountants (IESBA) Staff Publication Highlights Ethical Considerations for Accountants Using Emerging Technologies

The Staff of the IESBA released a new publication, Emerging Technologies: A Characteristics-Based Approach to Ethical Considerations for Professional Accountants, to support professional accountants as they develop, implement, or use emerging technologies in public practice and business.

AICPA Provides New Guidance on Stablecoins, Mining Revenue, and Current Auditing Standards

The AICPA released an updated version of its practice aid, Accounting for and Auditing of Digital Assets, providing accounting and auditing professionals with new guidance addressing emerging developments in the digital asset ecosystem, including accounting for stablecoin issuers, auditing mining revenue arrangements, and updates for recently effective auditing standards. The August 2026 update includes several significant enhancements:

  • New guidance for stablecoin issuers
  • New auditing guidance for mining revenue
  • Updated for current auditing standards
  • Additional enhancements

Game, Set, Second Life: Where U.S. Open Tennis Balls Go Next

After a fun few weeks, the U.S Open has officially ended. For those of you who were tuned in, did you ever wonder how many tennis balls are used during the tournament? The answer: 70,000! Where do they go? According to Reader’s Digest, match-used balls can become souvenirs, some are donated to schools, community organizations, and youth tennis programs, and others are recycled into court surfaces and rubber products. A lucky few become autograph balls or collectibles with one championship-point ball from the 2025 men’s final reportedly selling for $88,900.

And if you found yourself struggling to understand tennis, we also found some tennis history facts to help you out. A few things we learned are that the exact origin of “love” for zero is still uncertain, while “deuce” comes from the French word for two. A 6–0 set is called a “bagel,” and a 6–1 set can be a “breadstick”.


Questions and comments about Audit Committee Insights can be addressed to Vanessa Teitelbaum, Senior Director, Professional Practice (vteitelbaum@thecaq.org).

This newsletter is intended as general information and should not be relied upon as being definitive or all-inclusive. The CAQ encourages readers to refer to applicable rules, standards, guidance, and other resources in their entirety. All entities should carefully evaluate which requirements apply to their respective organizations.

About the Center for Audit Quality

The CAQ champions the public interest in the capital markets by:
  • Elevating the quality, credibility, and transparency of public company audits;
  • Advancing critical issues affecting public company audits;
  • Driving innovation in assurance; and
  • Providing a collaborative forum for capital market stakeholders to address evolving needs and challenges.
As the voice of the public company audit profession, we work to instill trust in corporate reporting and the integrity of the auditing process, ultimately empowering investors, companies, and society as a whole. For more information, visit www.thecaq.org.