PCAOB Broker-Dealer Inspections: Where External Auditors Are Still Getting It Wrong
- John Blackshire
- Aug 11
- 8 min read
The Latest PCAOB Inspection Results Should Get the Attention of Every Broker-Dealer Auditor
The latest PCAOB broker-dealer inspection results contain both good news and a serious warning.
Audit quality improved.
But the deficiency rates remain far too high.
In its 2026 Annual Report on the Interim Inspection Program Related to Audits of Brokers and Dealers, reporting on 2025 inspections, the PCAOB reported that it reviewed 103 broker-dealer audits and identified deficiencies in 68—approximately 66% of the audits inspected.
Even more significant, 58 of the 103 audits—56%—contained deficiencies involving insufficient or inappropriate audit evidence supporting the audit opinion.
That should concern:
External auditors
Audit partners
Broker-dealer CFOs and controllers
Compliance professionals
Audit committees
Quality-control personnel
The PCAOB is not merely finding documentation problems.
It continues to find situations where auditors did not obtain sufficient appropriate audit evidence to support their conclusions.
And that raises a much bigger question:
Why are experienced auditors still getting fundamental elements of broker-dealer auditing wrong?
The answer frequently comes down to audit tradecraft.
The 2025 Inspection Results: Improvement, But Still a Serious Problem
The trend deserves some context.
Engagement Type | 2023 | 2024 | 2025 |
Broker-dealer audits with deficiencies | 70% | 76% | 66% |
Examination engagements with deficiencies | 66% | 59% | 40% |
Exemption-report review engagements with deficiencies | 40% | 42% | 41% |
The improvement in broker-dealer financial statement audits is encouraging.
The improvement in examination engagements—from 59% to 40%—is particularly notable.
But let's put the numbers into plain English.
Approximately two out of every three broker-dealer audits inspected still contained a deficiency.
And approximately four out of every ten exemption-report review engagements inspected contained deficiencies.
Those are not insignificant failure rates.
The Three Biggest Financial Statement Audit Problems
The PCAOB's latest inspection results identify three particularly important areas:
Revenue
Evaluating Audit Results
Journal Entries
These should be on the radar of every engagement partner and manager responsible for broker-dealer audits.
Let's examine why.
1. Revenue: Did the Auditor Understand How the Broker-Dealer Actually Makes Money?
Revenue continues to cause problems.
Broker-dealer revenue can arise from numerous activities, depending on the firm's business model.
The audit team first needs to understand:
What revenue streams exist?
How are transactions initiated?
What systems process them?
What contractual arrangements apply?
When has the performance obligation been satisfied?
What assertions create the greatest risk?
What evidence supports the recorded revenue?
The PCAOB identified deficiencies involving auditors who did not perform sufficient procedures over revenue, including its accuracy and whether relevant performance obligations had been satisfied.
This is where audit tradecraft matters.
The auditor should not begin with:
"What procedure did we perform last year?"
Start with:
"How does this broker-dealer make money, and what could cause that revenue to be materially misstated?"
The audit procedure should follow the risk.
2. Journal Entries: Fraud Testing Requires More Than Running a Report
Journal-entry testing continues to present problems.
The PCAOB found auditors who selected journal entries without sufficiently considering fraud-risk characteristics.
It also identified situations where auditors excluded certain journal entries from testing without an appropriate basis.
That is particularly concerning because journal-entry testing is an important response to the risk of management override.
A strong auditor should think about:
Who can post journal entries?
Who can approve them?
Who can post directly to the general ledger?
Can senior management override normal approval processes?
Are entries posted late at night?
Are entries posted on weekends?
Are unusual accounts involved?
Are entries just below review thresholds?
Are entries posted near period-end?
Are unusual users making entries?
Are entries reversed immediately after period-end?
The auditor should also ask:
If I were trying to manipulate these financial statements, what type of journal entry would I make?
That is tradecraft.
The purpose of journal-entry testing is not to prove that the auditor ran an analytics program.
The purpose is to identify and appropriately test journal entries that could indicate fraud or material misstatement.
3. Evaluating Audit Results: Step Back and Look at the Whole Audit
This may be one of the most interesting findings.
The PCAOB identified deficiencies involving auditors' evaluation of audit results, including whether financial statements were presented fairly under the applicable accounting framework.
Auditors can become so focused on completing individual workpapers that they lose sight of the overall engagement.
Revenue testing—complete.
Cash—complete.
Journal entries—complete.
Expenses—complete.
Financial statements—complete.
But somebody needs to step back and ask:
Does all of this make sense together?
Consider:
What did we learn during the audit?
Were there contradictory explanations?
Did management estimates consistently favor one direction?
Were there unexpected relationships?
Did identified misstatements reveal broader problems?
Are financial statement disclosures consistent with what we learned?
Did the audit results change our original risk assessment?
Have we really obtained enough evidence?
Checking every box does not necessarily produce a high-quality audit.
4. Related-Party Transactions Have the PCAOB's Attention
In February 2026, the PCAOB issued a specific Broker-Dealer Audit Focus on Related Party Transactions.
That tells auditors something important.
Pay attention.
The PCAOB noted continuing deficiencies involving transactions between broker-dealers and related parties, including parents and affiliates, particularly involving revenue and expenses.
Related-party transactions deserve additional skepticism because they may not occur under the same economic conditions as transactions between independent parties.
Auditors should understand:
Who are the related parties?
What services move between organizations?
How are expenses allocated?
How are revenues allocated?
Are intercompany balances reconciled?
Are agreements documented?
Are transactions properly disclosed?
Does the economic substance agree with the accounting?
The auditor needs to understand the relationship—not simply inspect the invoice.
5. Net Capital: Recalculation Is Not Enough
Broker-dealer auditors operate within a specialized regulatory environment.
One of the most important areas is compliance with the SEC's net capital requirements.
PCAOB inspectors identified problems involving testing the completeness and accuracy of information used in net capital computations and failures involving reconciliation between net capital computations and FOCUS reporting.
This illustrates an important auditing principle.
Suppose management gives the auditor a spreadsheet.
The spreadsheet calculates perfectly.
That does not establish that the result is correct.
The auditor still needs to ask:
Where did the information in the spreadsheet come from?
And:
Is it complete and accurate?
Recalculating an unreliable spreadsheet only proves that the spreadsheet performs arithmetic correctly.
6. Customer Protection Rule Testing Remains Difficult
The PCAOB also continues to identify deficiencies involving the Customer Protection Rule.
Problems included insufficient testing of information underlying customer and PAB reserve computations and issues involving information originating from service organizations.
This again illustrates a recurring PCAOB theme:
Do not assume information is reliable simply because management gave it to you.
The auditor needs evidence supporting:
Completeness
Accuracy
Classification
Regulatory treatment
The auditor must understand the regulatory calculation well enough to determine whether management performed it correctly.
7. Possession or Control: Understand What the Requirement Is Trying to Accomplish
Possession-or-control requirements are designed to protect customer securities.
The PCAOB identified deficiencies involving auditors who did not sufficiently test information supporting compliance with possession-or-control requirements, including information generated by service organizations.
This should remind auditors of a basic principle: Understand the objective before designing the audit procedure.
If you do not understand why a regulatory control exists, it becomes difficult to determine whether your audit procedure actually tests it.
8. Exemption Reports Continue to Produce High Deficiency Rates
The PCAOB inspected 66 exemption-report review engagements and found deficiencies in 27—approximately 41%.
Among the problems were failures to sufficiently understand activities relevant to the broker-dealer's claimed exemption and failures to perform required inquiries concerning controls and monitoring.
This raises a fundamental question:
Does the auditor really understand why the broker-dealer qualifies for the exemption?
The engagement should not begin with management's assertion and work backward toward supporting it.
The auditor needs to understand the business activities sufficiently to evaluate the assertion independently.
9. Internal Control Over Compliance: Did the Auditor Actually Test the Important Controls?
The PCAOB's examination-engagement findings also deserve serious attention.
Inspectors continued to identify problems involving Internal Control Over Compliance (ICOC).
The PCAOB identified issues involving:
Controls containing review elements
Controls over information used by the broker-dealer
IT General Controls
Testing important controls
Most concerning, the PCAOB observed an increase in instances where firms did not test any important controls over one or more financial responsibility rules.
Think about that.
The auditor is performing an examination of compliance controls and fails to test important controls addressing a relevant regulatory requirement.
That is not a formatting problem.
That goes directly to the substance of the engagement.
10. Service Organizations and System-Generated Information Require Better Audit Evidence
Modern broker-dealers rely heavily on:
Clearing firms
Custodians
Technology providers
Third-party processors
Service organizations
That means important audit information may originate outside the broker-dealer.
The PCAOB identified deficiencies involving auditors' use and testing of information produced by service organizations, including information used in customer-reserve and possession-or-control testing.
An auditor cannot simply say:
"The clearing firm produced the report."
The auditor still needs to determine whether the information provides reliable audit evidence for the intended purpose.
There Is Another Number Audit Firms Should Study
The PCAOB's supplementary inspection information shows a striking difference between the largest audit firms and the overall population.
For 2025:
Broker-dealer audit deficiencies
Largest firms: 35%
All inspected firms: 66%
Examination engagement deficiencies
Largest firms: 13%
All inspected firms: 40%
Exemption-report review deficiencies
Largest firms: 7%
All inspected firms: 41%.
These numbers should not automatically be interpreted to mean that firm size itself causes audit quality.
Inspection selection is risk-based, and populations can differ.
But the disparity raises an important question for smaller firms:
Do we have enough broker-dealer-specific expertise, methodology, supervision and quality control to perform these engagements properly?
That question deserves a serious answer.
Broker-Dealer Experience Matters
Broker-dealer auditing is specialized.
The PCAOB itself considers the experience of the audit firm and engagement personnel when selecting engagements for risk-based inspection.
That makes sense.
A broker-dealer auditor needs to understand more than GAAP and traditional financial statement auditing.
The auditor may need competence involving:
SEC financial responsibility rules
Net capital
Customer protection
Possession or control
Exemption reports
Compliance reports
FOCUS reporting
Related parties
Service organizations
Broker-dealer operations
An auditor cannot effectively audit what the auditor does not understand.
The Real Issue Is Audit Tradecraft
When I look across these PCAOB findings, I see a pattern.
The individual technical requirements differ.
But many of the underlying failures come back to fundamental audit skills.
Understand the Business
How does this broker-dealer actually operate?
Understand the Risk
What could go materially wrong?
Understand the Control
What is supposed to prevent or detect it?
Understand the Evidence
What proves that the assertion is correct?
Challenge the Evidence
Is the information complete, accurate and reliable?
Follow Contradictory Information
What doesn't make sense?
Document the Judgment
Can another experienced auditor understand what we did and why?
Those are the fundamentals of good auditing.
They are also the fundamentals of audit tradecraft.
AI Can Help Broker-Dealer Auditors—but It Cannot Replace Tradecraft
Artificial intelligence will increasingly become part of broker-dealer auditing.
Auditors can use AI to help:
Research regulatory requirements
Prepare walkthrough questions
Analyze transaction populations
Identify unusual journal entries
Compare agreements
Summarize documentation
Identify inconsistencies
Review workpapers
Challenge preliminary conclusions
But AI creates a dangerous possibility.
It can make weak audit work look extremely professional.
A beautifully written AI-generated workpaper does not compensate for inadequate evidence.
The engagement team must still determine:
Whether the procedure addressed the risk
Whether the evidence was reliable
Whether contradictory information was resolved
Whether the conclusion was reasonable
AI can enhance auditor tradecraft. It cannot substitute for it.
A PCAOB Inspection-Readiness Test
Before completing a broker-dealer engagement, engagement teams should consider asking these ten questions:
Do we understand how the broker-dealer actually makes money?
Did our procedures respond to the identified risks?
Did journal-entry testing incorporate fraud-risk characteristics?
Did we appropriately identify and test related-party transactions?
Did we test the completeness and accuracy of information underlying regulatory calculations?
Do we understand the broker-dealer's exemption or compliance assertions?
Did we test important controls over applicable financial responsibility rules?
Did we appropriately evaluate information from service organizations?
Did we resolve contradictory evidence?
If a PCAOB inspector selected this workpaper tomorrow, could we defend our conclusion?
If the answer to number ten is no, the engagement probably is not finished.
The Bottom Line
The PCAOB's latest broker-dealer inspection results demonstrate progress.
But they do not demonstrate that the profession has solved the problem.
A 66% deficiency rate for inspected broker-dealer audits remains a significant warning.
The recurring problems involve some of the most fundamental elements of auditing:
Revenue.
Fraud and journal entries.
Audit evidence.
Related parties.
Net capital.
Customer protection.
Regulatory compliance.
Internal controls.
Service organizations.
Evaluation of audit results.
The lesson for audit firms is straightforward:
Broker-dealer auditing requires specialized knowledge, rigorous methodology, professional skepticism and strong audit tradecraft.
Standards tell auditors what they are required to accomplish.
Methodology provides structure.
Technology and AI can make the auditor more efficient.
But ultimately, audit quality still depends upon an auditor who understands the business, recognizes the risk, asks the right questions, obtains persuasive evidence and has the professional judgment to know when something does not make sense.
That is the tradecraft of the external auditor.
Comments