October 8, 2026
 

Audit Insider | September 2026

Welcome back, Audit Insiders! Summer has given way to back-to-school traffic and the first signs of football season here in Washington. Can you believe we are already looking at the fourth quarter?

As we wrap up Q3, the profession continues to move at full speed. This month, the PCAOB adopted targeted amendments to QC 1000 at its open meeting and hosted two forums for auditors of small businesses and broker-dealers in Denver and San Francisco. Elsewhere, EY released new survey data on AI governance, and the AICPA updated its digital assets practice aid. At the CAQ, my colleagues and I have been just as busy, from submitting our comment letter on the PCAOB’s draft strategic goals, releasing the fifth edition of the Audit Committee Practices Report with Deloitte’s Center for Board Effectiveness, to convening leaders across finance, business, and technology with Axios for a conversation on trust and innovation in the capital markets.

Read on for what I’m tracking.

Please note that these perspectives are my own. If this email was forwarded to you, subscribe here so that you never miss a public company auditing update.

What's new in public company audit

PCAOB Adopts Targeted Amendments to QC 1000

At an open meeting on September 9, the PCAOB adopted targeted amendments to QC 1000, A Firm’s System of Quality Control. The standard and the amendments take effect December 15, 2026, subject to SEC approval.

The Board adopted nine amendments. Among those most relevant to implementation planning, the PCAOB rescinded the design-only requirement and the External QC Function requirement, removed the prescribed annual evaluation date of September 30, and reduced the documentation retention period from seven years to five.

The CAQ welcomes these changes. They reflect what firms have learned during implementation and bring QC 1000 into closer alignment with other quality management standards, including ISQM 1 and SQMS 1, reducing the friction of operating under multiple frameworks without weakening the standard’s objectives. Firms should revisit their implementation plans against the final text now, particularly where evaluation timing or documentation retention was already built out.

The CAQ Comments on the PCAOB’s Draft Strategic Goals

On September 4, the CAQ submitted a comment letter on the PCAOB’s draft 2026-2030 goals and objectives. We emphasized that culture and expertise are foundational to every other priority and encouraged the Board to broaden its access to outside expertise through fellowships, advisory committees, and task forces. We expressed strong support for a quality control-focused inspection model, recommended clearer communication about what inspection reports can and cannot tell a reader, and encouraged the Board to empower the Office of the Chief Auditor as the authoritative source for standard setting, implementation guidance, and interpretive positions. Thirty-two letters were submitted in all, and I’d encourage you to read and unpack what other stakeholders are sharing.

unpack what other stakeholders are sharing.

PCAOB Forums for Auditors of Small Businesses and Broker-Dealers  

Board Member Steven D. Laughton hosted one forum in Denver on September 18, and Board Member George R. Botic hosted another in San Francisco on September 22. The forums cover broker-dealer and issuer inspections, a standard-setting update from the Office of the Chief Auditor, an enforcement update, and updates from SEC and FINRA staff. Recordings will be available on the event pages.

The Audit Effect: The Role of the Auditor

2026 Audit Committee Practices Report

On September 22, the CAQ released the fifth edition of the Audit Committee Practices Report, produced with Deloitte’s Center for Board Effectiveness and drawing on nearly 250 responses from audit committee chairs and members. For the first time since the survey began, enterprise risk management ranked as the top priority, a sign that committees are increasingly treating risk as a single connected picture rather than a set of separate agenda items.

The finding that stayed with me is that a large majority of committees now call AI governance a top priority, while an even larger share describe their own oversight of it as still emerging. Committees are stepping into a governance role for a risk area most are still building the expertise to oversee, and getting that oversight right is where the real work is now. Dive into the report now.

Tech Corner

EY Survey Finds Autonomous AI Outpacing Oversight

This month, EY released its AI Governance and Risk Survey, and the findings are worth paying a closer look. Nearly every respondent, 98%, reported having a formal AI governance policy in place, yet 47% said their organization has bypassed those processes for urgent deployments and 36% reported an AI incident or failure that caused material impact.

The agentic AI findings are the ones I’d put in front of an engagement team. Among organizations using agentic AI, 85% report those systems execute actions without real-time human oversight, 49% say their governance frameworks have not been updated for agentic AI risks, and 26% say they cannot detect unauthorized AI agents operating internally. The survey reflects 202 senior AI decision-makers publicly traded companies with at least $1 billion in annual revenue.

FEI’s AI Framework for Internal Control Over Financial Reporting

Financial Executives International and its Committee on Corporate Reporting released the AI Framework: Internal Control Over Financial Reporting, which sets out four control approaches for AI used in the financial reporting process: human-in-the-loop validation, performance testing against known results, multi-model validation, and data analytics to monitor for anomalies and drift.

AICPA Updates Its Digital Assets Practice Aid

On August 25, the AICPA released an updated version of its practice aid, Accounting for and Auditing of Digital Assets. The update adds a chapter on stablecoin issuer accounting, covering both the issuer’s obligations and the reserve assets behind them, and new auditing guidance for mining revenue arrangements. It also revises the chapter on existence, rights, and obligations of digital assets and conforms the guidance to auditing standards through SAS No. 148. If you have clients with digital asset exposure, the stablecoin and mining revenue material is the place to start.

Fighting Fraud

Fraud Risk Considerations in 2026

The Anti-Fraud Collaboration published Fraud Risk Considerations in 2026, drawing on the AFC Executive Workshop at this summer’s ACFE Global Fraud Conference. My colleague Desiré Carroll, our Senior Director of Professional Practice, lays out where the fraud risk landscape is heading, including why a shifting regulatory environment does not justify reduced vigilance, why MD&A, non-GAAP measures, and investor communications remain high-risk areas, and how poorly governed AI can erode critical thinking and accountability.

We’ll be expanding on this conversation at the upcoming Fraud Forum in November, so keep an eye out for my key takeaways after the event for even further insights.

From the CAQ

Where Trust Goes Next

As a guest feature on our Substack newsletter, Sara Krople, Audit Partner at Crowe, shares what happens as the information investors rely on expands beyond the financial statements. AI and digital assets have moved from novelty to the boardroom, and with the FASB requiring crypto assets to be measured at fair value through earnings, investors want confidence that appropriate controls exist, that assets are held securely, and that the underlying data is complete and accurate. Sara’s argument is that meeting that demand takes deliberate investment in talent, pairing traditional audit skills in risk assessment, control testing, and evaluating evidence with specialists who understand distributed ledgers, model governance, and encryption. Her closing point is what I would also echo here: other providers can advise, but auditors are accountable.

This month's Audit Insider

What role does assurance play in fostering trust in the capital markets? In the latest installment of our Audit Effect video series, Frank Milano, Managing Partner – Assurance at Deloitte shares his perspective on how independent audits help strengthen confidence in company-reported information and support informed decision-making.

His insights reinforce a core message of the Audit Effect campaign: when investors and other stakeholders can rely on credible, transparent information, capital markets can function more effectively and efficiently.

Watch the video: The Audit Effect | Frank Milano, Deloitte & Touche LLP – YouTube

Additional Resources & Events

Webinar on PCAOB Developments and Priorities

On October 15, my colleague, Vanessa Teitelbaum, our Senior Director of Professional Practice, will host a webinar on PCAOB developments and priorities and what they mean for audit committees. The conversation covers the Board’s modernization initiatives, inspection program updates, audit committee communications, and emerging risks, including artificial intelligence. It is built for audit committee members and the people who support them. Attendees are eligible for one CPE credit. 

Register here.

AICPA & CIMA Conference on Current SEC and PCAOB Developments

Registration is open for the AICPA & CIMA Conference on Current SEC and PCAOB Developments (December 7 – 9). The program brings standard setters and regulators together to cover the latest accounting, auditing, and regulatory developments directly from the SEC, PCAOB, and FASB, with up to 21.5 CPE credits available. I hope to see you there!

An Evening with Axios: Trust and Innovation in Capital Markets

On September 16, the CAQ co-hosted Trust and Innovation in Capital Markets, with Axios at our nation’s capital. We convened finance, business, and technology leaders on how U.S. capital markets can modernize without compromising trust. Our Interim CEO, Mark Koziel, PCAOB Chairman Demetrios (Jim) Logothetis, and Dennis Kelleher, Co-Founder, President and CEO of Better Markets, discussed oversight, market integrity, and the role of independent assurance as companies adopt AI and new business models. My biggest takeaway is that the fundamentals of audit quality do not change even as the tools evolve. We as auditors know that independence, professional skepticism, and rigorous evaluation of evidence remain the foundation for investor confidence.

—

Dennis McGowan
Vice President, Professional Practice, CAQ
​​​​​​
—