top of page
Search

PCAOB Broker-Dealer Inspections: Where External Auditors Are Still Getting It Wrong

The Latest PCAOB Inspection Results Should Get the Attention of Every Broker-Dealer Auditor

The latest PCAOB broker-dealer inspection results contain both good news and a serious warning.


Audit quality improved.


But the deficiency rates remain far too high.


In its 2026 Annual Report on the Interim Inspection Program Related to Audits of Brokers and Dealers, reporting on 2025 inspections, the PCAOB reported that it reviewed 103 broker-dealer audits and identified deficiencies in 68—approximately 66% of the audits inspected.


Even more significant, 58 of the 103 audits—56%—contained deficiencies involving insufficient or inappropriate audit evidence supporting the audit opinion.


That should concern:

  • External auditors

  • Audit partners

  • Broker-dealer CFOs and controllers

  • Compliance professionals

  • Audit committees

  • Quality-control personnel


The PCAOB is not merely finding documentation problems.


It continues to find situations where auditors did not obtain sufficient appropriate audit evidence to support their conclusions.


And that raises a much bigger question:

Why are experienced auditors still getting fundamental elements of broker-dealer auditing wrong?

The answer frequently comes down to audit tradecraft.


The 2025 Inspection Results: Improvement, But Still a Serious Problem

The trend deserves some context.

Engagement Type

2023

2024

2025

Broker-dealer audits with deficiencies

70%

76%

66%

Examination engagements with deficiencies

66%

59%

40%

Exemption-report review engagements with deficiencies

40%

42%

41%

The improvement in broker-dealer financial statement audits is encouraging.


The improvement in examination engagements—from 59% to 40%—is particularly notable.


But let's put the numbers into plain English.


Approximately two out of every three broker-dealer audits inspected still contained a deficiency.


And approximately four out of every ten exemption-report review engagements inspected contained deficiencies.


Those are not insignificant failure rates.


The Three Biggest Financial Statement Audit Problems

The PCAOB's latest inspection results identify three particularly important areas:

  • Revenue

  • Evaluating Audit Results

  • Journal Entries


These should be on the radar of every engagement partner and manager responsible for broker-dealer audits.


Let's examine why.

1. Revenue: Did the Auditor Understand How the Broker-Dealer Actually Makes Money?

Revenue continues to cause problems.


Broker-dealer revenue can arise from numerous activities, depending on the firm's business model.


The audit team first needs to understand:

  • What revenue streams exist?

  • How are transactions initiated?

  • What systems process them?

  • What contractual arrangements apply?

  • When has the performance obligation been satisfied?

  • What assertions create the greatest risk?

  • What evidence supports the recorded revenue?


The PCAOB identified deficiencies involving auditors who did not perform sufficient procedures over revenue, including its accuracy and whether relevant performance obligations had been satisfied.


This is where audit tradecraft matters.


The auditor should not begin with:

"What procedure did we perform last year?"

Start with:

"How does this broker-dealer make money, and what could cause that revenue to be materially misstated?"

The audit procedure should follow the risk.


2. Journal Entries: Fraud Testing Requires More Than Running a Report

Journal-entry testing continues to present problems.


The PCAOB found auditors who selected journal entries without sufficiently considering fraud-risk characteristics.


It also identified situations where auditors excluded certain journal entries from testing without an appropriate basis.


That is particularly concerning because journal-entry testing is an important response to the risk of management override.


A strong auditor should think about:

  • Who can post journal entries?

  • Who can approve them?

  • Who can post directly to the general ledger?

  • Can senior management override normal approval processes?

  • Are entries posted late at night?

  • Are entries posted on weekends?

  • Are unusual accounts involved?

  • Are entries just below review thresholds?

  • Are entries posted near period-end?

  • Are unusual users making entries?

  • Are entries reversed immediately after period-end?


The auditor should also ask:

If I were trying to manipulate these financial statements, what type of journal entry would I make?

That is tradecraft.


The purpose of journal-entry testing is not to prove that the auditor ran an analytics program.


The purpose is to identify and appropriately test journal entries that could indicate fraud or material misstatement.


3. Evaluating Audit Results: Step Back and Look at the Whole Audit


This may be one of the most interesting findings.


The PCAOB identified deficiencies involving auditors' evaluation of audit results, including whether financial statements were presented fairly under the applicable accounting framework.


Auditors can become so focused on completing individual workpapers that they lose sight of the overall engagement.

  • Revenue testing—complete.

  • Cash—complete.

  • Journal entries—complete.

  • Expenses—complete.

  • Financial statements—complete.


But somebody needs to step back and ask:

Does all of this make sense together?

Consider:

  • What did we learn during the audit?

  • Were there contradictory explanations?

  • Did management estimates consistently favor one direction?

  • Were there unexpected relationships?

  • Did identified misstatements reveal broader problems?

  • Are financial statement disclosures consistent with what we learned?

  • Did the audit results change our original risk assessment?

  • Have we really obtained enough evidence?


Checking every box does not necessarily produce a high-quality audit.


4. Related-Party Transactions Have the PCAOB's Attention

In February 2026, the PCAOB issued a specific Broker-Dealer Audit Focus on Related Party Transactions.


That tells auditors something important.


Pay attention.


The PCAOB noted continuing deficiencies involving transactions between broker-dealers and related parties, including parents and affiliates, particularly involving revenue and expenses.


Related-party transactions deserve additional skepticism because they may not occur under the same economic conditions as transactions between independent parties.


Auditors should understand:

  • Who are the related parties?

  • What services move between organizations?

  • How are expenses allocated?

  • How are revenues allocated?

  • Are intercompany balances reconciled?

  • Are agreements documented?

  • Are transactions properly disclosed?

  • Does the economic substance agree with the accounting?


The auditor needs to understand the relationship—not simply inspect the invoice.


5. Net Capital: Recalculation Is Not Enough

Broker-dealer auditors operate within a specialized regulatory environment.


One of the most important areas is compliance with the SEC's net capital requirements.

PCAOB inspectors identified problems involving testing the completeness and accuracy of information used in net capital computations and failures involving reconciliation between net capital computations and FOCUS reporting.


This illustrates an important auditing principle.


Suppose management gives the auditor a spreadsheet.


The spreadsheet calculates perfectly.


That does not establish that the result is correct.


The auditor still needs to ask:

Where did the information in the spreadsheet come from?

And:

Is it complete and accurate?

Recalculating an unreliable spreadsheet only proves that the spreadsheet performs arithmetic correctly.


6. Customer Protection Rule Testing Remains Difficult

The PCAOB also continues to identify deficiencies involving the Customer Protection Rule.


Problems included insufficient testing of information underlying customer and PAB reserve computations and issues involving information originating from service organizations.


This again illustrates a recurring PCAOB theme:

Do not assume information is reliable simply because management gave it to you.

The auditor needs evidence supporting:

  • Completeness

  • Accuracy

  • Classification

  • Regulatory treatment


The auditor must understand the regulatory calculation well enough to determine whether management performed it correctly.


7. Possession or Control: Understand What the Requirement Is Trying to Accomplish

Possession-or-control requirements are designed to protect customer securities.


The PCAOB identified deficiencies involving auditors who did not sufficiently test information supporting compliance with possession-or-control requirements, including information generated by service organizations.


This should remind auditors of a basic principle: Understand the objective before designing the audit procedure.


If you do not understand why a regulatory control exists, it becomes difficult to determine whether your audit procedure actually tests it.


8. Exemption Reports Continue to Produce High Deficiency Rates

The PCAOB inspected 66 exemption-report review engagements and found deficiencies in 27—approximately 41%.


Among the problems were failures to sufficiently understand activities relevant to the broker-dealer's claimed exemption and failures to perform required inquiries concerning controls and monitoring.


This raises a fundamental question:

Does the auditor really understand why the broker-dealer qualifies for the exemption?

The engagement should not begin with management's assertion and work backward toward supporting it.


The auditor needs to understand the business activities sufficiently to evaluate the assertion independently.


9. Internal Control Over Compliance: Did the Auditor Actually Test the Important Controls?

The PCAOB's examination-engagement findings also deserve serious attention.

Inspectors continued to identify problems involving Internal Control Over Compliance (ICOC).


The PCAOB identified issues involving:

  • Controls containing review elements

  • Controls over information used by the broker-dealer

  • IT General Controls

  • Testing important controls


Most concerning, the PCAOB observed an increase in instances where firms did not test any important controls over one or more financial responsibility rules.


Think about that.


The auditor is performing an examination of compliance controls and fails to test important controls addressing a relevant regulatory requirement.


That is not a formatting problem.


That goes directly to the substance of the engagement.


10. Service Organizations and System-Generated Information Require Better Audit Evidence

Modern broker-dealers rely heavily on:

  • Clearing firms

  • Custodians

  • Technology providers

  • Third-party processors

  • Service organizations


That means important audit information may originate outside the broker-dealer.


The PCAOB identified deficiencies involving auditors' use and testing of information produced by service organizations, including information used in customer-reserve and possession-or-control testing.


An auditor cannot simply say:

"The clearing firm produced the report."

The auditor still needs to determine whether the information provides reliable audit evidence for the intended purpose.


There Is Another Number Audit Firms Should Study

The PCAOB's supplementary inspection information shows a striking difference between the largest audit firms and the overall population.


For 2025:

  • Broker-dealer audit deficiencies

    • Largest firms: 35%

    • All inspected firms: 66%

  • Examination engagement deficiencies

    • Largest firms: 13%

    • All inspected firms: 40%

  • Exemption-report review deficiencies

    • Largest firms: 7%

    • All inspected firms: 41%.


These numbers should not automatically be interpreted to mean that firm size itself causes audit quality.


Inspection selection is risk-based, and populations can differ.


But the disparity raises an important question for smaller firms:

Do we have enough broker-dealer-specific expertise, methodology, supervision and quality control to perform these engagements properly?

That question deserves a serious answer.


Broker-Dealer Experience Matters

Broker-dealer auditing is specialized.


The PCAOB itself considers the experience of the audit firm and engagement personnel when selecting engagements for risk-based inspection.


That makes sense.


A broker-dealer auditor needs to understand more than GAAP and traditional financial statement auditing.


The auditor may need competence involving:

  • SEC financial responsibility rules

  • Net capital

  • Customer protection

  • Possession or control

  • Exemption reports

  • Compliance reports

  • FOCUS reporting

  • Related parties

  • Service organizations

  • Broker-dealer operations


An auditor cannot effectively audit what the auditor does not understand.


The Real Issue Is Audit Tradecraft

When I look across these PCAOB findings, I see a pattern.


The individual technical requirements differ.


But many of the underlying failures come back to fundamental audit skills.


Understand the Business

How does this broker-dealer actually operate?

Understand the Risk

What could go materially wrong?

Understand the Control

What is supposed to prevent or detect it?

Understand the Evidence

What proves that the assertion is correct?

Challenge the Evidence

Is the information complete, accurate and reliable?

Follow Contradictory Information

What doesn't make sense?

Document the Judgment

Can another experienced auditor understand what we did and why?


Those are the fundamentals of good auditing.


They are also the fundamentals of audit tradecraft.


AI Can Help Broker-Dealer Auditors—but It Cannot Replace Tradecraft

Artificial intelligence will increasingly become part of broker-dealer auditing.


Auditors can use AI to help:

  • Research regulatory requirements

  • Prepare walkthrough questions

  • Analyze transaction populations

  • Identify unusual journal entries

  • Compare agreements

  • Summarize documentation

  • Identify inconsistencies

  • Review workpapers

  • Challenge preliminary conclusions


But AI creates a dangerous possibility.


It can make weak audit work look extremely professional.


A beautifully written AI-generated workpaper does not compensate for inadequate evidence.


The engagement team must still determine:

  • Whether the procedure addressed the risk

  • Whether the evidence was reliable

  • Whether contradictory information was resolved

  • Whether the conclusion was reasonable


AI can enhance auditor tradecraft. It cannot substitute for it.


A PCAOB Inspection-Readiness Test

Before completing a broker-dealer engagement, engagement teams should consider asking these ten questions:

  1. Do we understand how the broker-dealer actually makes money?

  2. Did our procedures respond to the identified risks?

  3. Did journal-entry testing incorporate fraud-risk characteristics?

  4. Did we appropriately identify and test related-party transactions?

  5. Did we test the completeness and accuracy of information underlying regulatory calculations?

  6. Do we understand the broker-dealer's exemption or compliance assertions?

  7. Did we test important controls over applicable financial responsibility rules?

  8. Did we appropriately evaluate information from service organizations?

  9. Did we resolve contradictory evidence?

  10. If a PCAOB inspector selected this workpaper tomorrow, could we defend our conclusion?


If the answer to number ten is no, the engagement probably is not finished.


The Bottom Line

The PCAOB's latest broker-dealer inspection results demonstrate progress.

But they do not demonstrate that the profession has solved the problem.


A 66% deficiency rate for inspected broker-dealer audits remains a significant warning.


The recurring problems involve some of the most fundamental elements of auditing:

  • Revenue.

  • Fraud and journal entries.

  • Audit evidence.

  • Related parties.

  • Net capital.

  • Customer protection.

  • Regulatory compliance.

  • Internal controls.

  • Service organizations.

  • Evaluation of audit results.


The lesson for audit firms is straightforward:

Broker-dealer auditing requires specialized knowledge, rigorous methodology, professional skepticism and strong audit tradecraft.

Standards tell auditors what they are required to accomplish.


Methodology provides structure.


Technology and AI can make the auditor more efficient.


But ultimately, audit quality still depends upon an auditor who understands the business, recognizes the risk, asks the right questions, obtains persuasive evidence and has the professional judgment to know when something does not make sense.


That is the tradecraft of the external auditor.

 
 
 

Recent Posts

See All
The History of Maturity Models

Why Auditors Should Understand Where Maturity Models Came From Auditors traditionally ask questions such as: Does the control exist? Is the control properly designed? Is the control operating effectiv

 
 
 
What Should TUSD's Objectives Be?

COSO divides objectives into three broad categories: Operations — Reporting — Compliance For TUSD, I would establish 12 enterprise-level objectives beneath those categories. The key principle is: Obje

 
 
 

Comments


Subscribe Form

Thanks for submitting!

479-200-4373

  • Facebook
  • Twitter
  • LinkedIn
  • Twitter
  • LinkedIn
  • Facebook

©2026 by The Accountware Group. Proudly created with Wix.com

bottom of page