Site icon The Raisina Hills

Big Four Audit Deficiencies Fall Sharply in US — But Should Regulators Celebrate Yet?

PCAOB audit of Big Four.

PCAOB audit of Big Four (Image X.com)

Spread love

By P. Sesh Kumar

PCAOB data show a dramatic decline in audit deficiencies at America’s Big Four firms, but risk-based sampling, regulatory changes and a shift toward firm-level inspections make the headline numbers harder to interpret.

New Delhi, August 19, 2026 — On 13 August 2026 the Public Company Accounting Oversight Board (PCAOB)–the counterpart of our National Financial Reporting Authority (NFRA)–published its annual inspection reports on America’s six largest audit firms, and the headline was a regulator’s dream: the Big Four’s aggregate Part I.A deficiency rate had fallen to 8 per cent from 20 per cent a year earlier and 26 per cent two years before, with Deloitte and EY at 5 per cent each, PwC at 9 and KPMG at 13, while BDO and Grant Thornton remained stranded at 34 and 33.

Regulators rarely get to announce good news, so when they do it is worth reading the fine print before joining the applause.

On 13 August 2026 the Public Company Accounting Oversight Board (PCAOB) released its 2025 inspection reports on the six largest American audit firms, and the numbers were startling.  Deloitte & Touche and Ernst & Young (EY) each recorded a Part I.A deficiency rate of 5 per cent. PricewaterhouseCoopers (PwC) came in at 9 per cent, KPMG at 13. Together the Big Four managed an aggregate 8 per cent, against 20 per cent in 2024 and 26 per cent in 2023.  EY’s fall–from 37 per cent in 2023 to 28 in 2024 to 5 in 2025–is the steepest improvement any large firm has recorded in the inspection regime’s history, and the firm attributes it, in terms, to a billion dollars spent on technology and people.

Two firms did not share in the celebration. BDO USA was inspected on 29 audits and found deficient on 10, a rate of 34 per cent–an improvement, certainly, on 60 per cent in 2024 and a barely believable 86 per cent in 2023, but still nearly seven times Deloitte’s rate. Grant Thornton, inspected on 27 audits, was deficient on 9, a rate of 33 per cent, down from 48 and 54 in the two preceding years.

Behind the percentages sit small absolute numbers, and they are worth stating plainly because percentages flatter. Each of the Big Four had 64 audits reviewed. An 8 per cent aggregate across 256 audits means roughly 20 engagements in which, in the inspectors’ judgment, the firm signed an opinion without having obtained sufficient appropriate evidence to support it.

Erica Williams, when she chaired the board, described what such findings can look like: performing no procedures at all to test revenue or the cost of inventory.  Twenty unsupported opinions, at firms that audit some four-fifths of the market capitalisation of American public companies, is not a triumph. It is a smaller catastrophe than last year’s.

What a deficiency rate is, and four things it is not

Before diagnosis, definition–because almost every misreading of these reports comes from treating the rate as something it is not.

Part I.A of a PCAOB inspection report lists engagements where the inspectors concluded the firm did not obtain sufficient appropriate audit evidence to support its opinion on the financial statements or on internal control over financial reporting.  It is a judgment about the audit, not about the company. It does not assert that the financial statements were wrong, that a restatement is due, or that fraud occurred. An audit can be deficient and the accounts perfectly true; the point of the finding is that the auditor did not know, and said he did.

The first thing the rate is not, therefore, is an error rate in reported accounts. The second is a sample of all audits. The board does not inspect everything; it selects engagements largely on risk, with some randomly chosen.  The denominator is picked by the regulator. That single fact carries more analytical weight than any number in the reports, and I will return to it.

The third is a comparable series. Sample sizes shift–56 Deloitte audits in 2023, 63 in 2024, 64 in 2025–and at BDO and Grant Thornton, where only 29 and 27 audits were reviewed, a single engagement moves the published rate by three and a half percentage points. Anyone treating a five-point movement at a mid-tier firm as a signal is reading noise.

The fourth, and most important, is that the rate is not the whole report. A PCAOB inspection report has a Part I.B, covering instances where the firm did not comply with standards or rules in ways that do not necessarily go to the sufficiency of evidence, and a Part II, which addresses the firm’s system of quality control–its governance, its incentives, its monitoring, its acceptance decisions.

Part II is not published unless the firm fails to remediate to the board’s satisfaction within twelve months. So the number the world quotes measures individual engagements, while the diagnosis of why those engagements failed sits in a sealed chapter that becomes public only on failure. It is as though a hospital published its mortality rate but sealed the infection-control audit unless it declined to act on it.

Can Judges Keep Tax-Free Perquisites Under the New Tax Regime? The Legal Battle Explained

What the inspectors actually found, and why it is always the same thing

When we strip the six reports down, the findings are monotonously familiar to anyone who has read an inspection report in any jurisdiction in the last fifteen years.

Revenue was the most frequently reviewed area at every one of the six firms–51 audits at Deloitte, 49 at PwC, 43 at KPMG, 42 at EY, 21 each at BDO and Grant Thornton–and it remains where the findings cluster at the mid-tier, with four deficiencies each at BDO and Grant Thornton against three at PwC, three at Deloitte and one each at EY and KPMG.  Beyond revenue the recurring subjects are inventory, goodwill and intangibles, long-lived assets and business combinations (mergers): in other words, the places where an auditor must either test an estimate or test somebody else’s data.

That is precisely how the PCAOB characterised the two commonest failings at both mid-tier firms –deficiencies in testing an estimate, and deficiencies in testing the data or reports used in substantive testing.  Those two phrases deserve to be nailed above every audit room door, because between them they describe the structural fault line of the modern audit.

Testing an estimate means confronting management’s assumptions–the discount rate, the growth forecast, the useful life, the credit-loss model–and forming an independent view of whether the range is defensible. It is the hardest, most senior, least automatable work in an audit, and it is the work most easily reduced to a memorandum recording that the assumption was “discussed with management and found reasonable”.

Testing the data or reports used in substantive testing is subtler and, in my view, the more dangerous of the two. A modern audit runs on reports extracted from the client’s systems: aging schedules, revenue listings, inventory movements, contract registers. The auditor tests the population in that report exhaustively and elegantly–and never establishes that the report is complete and accurate in the first place.

The arithmetic of a beautifully executed test on an unverified population is worth nothing, and it looks, in the file, exactly like good work. This is the deficiency that automation and analytics have made more common rather than less: the more sophisticated the tool applied to the extract, the greater the temptation to skip the dull question of where the extract came from.

The diagnosis, then, is not ignorance. Nobody at BDO is unaware that data used in substantive testing must be tested. The diagnosis is that audit failure is an engineering failure–of staffing, sequencing, review depth and time–in which the corners cut are invisible to the client, invisible to the audit committee, invisible in the signed opinion, and visible only to an inspector reading the working papers eighteen months later.

A defect with no natural detection mechanism except the regulator will recur until the regulator’s arrival becomes probable enough to price into behaviour. That, and not any deficiency in professional literature, is why the same three findings have appeared in inspection reports on three continents for fifteen years.

Why it recurs, in five layers

The recurrence has layers, and it is worth separating them because each calls for a different remedy.

The first is economics. An audit is priced in a competitive market, delivered largely by staff in their twenties, concentrated into a season that ends on a statutory date, and reviewed by a partner whose bonus is not paid for the third re-performance of an inventory test. Nothing in that structure rewards the marginal hour spent proving that a system-generated report is complete.

The second is the remediation cycle. In the American regime a firm has twelve months to satisfy the board on quality control criticisms before they become public.  A firm optimising rationally will fix the inspected engagements, document the fix, and satisfy the criticism–which is not the same as changing the system that produced the engagement.

The PCAOB’s own answer to this is the reason its new chairman has announced a shift from engagement-level to firm-level inspection: “we are evaluating whether the system–the governance, culture, risk assessment, monitoring, and remediation–is functioning in a way that consistently produces high-quality audits,” Demetrios Logothetis said at a recent open meeting.

He is right, and the shift is overdue. It will also, incidentally, break the comparability of the very series whose improvement is being celebrated–a point to which nobody in the celebration seems to have attended.

The third is the mid-tier gap, and it is a scale problem masquerading as a culture problem. BDO and Grant Thornton are held to identical standards on a fraction of the Big Four’s methodology infrastructure, training budget, national office capacity and technology spend.

A 34 per cent deficiency rate against 5 is not evidence that BDO’s partners care less; it is evidence that quality at this level of complexity has become a capital-intensive product. Any regulator that responds to that arithmetic purely with censure will end by concentrating the market further, which is a peculiar way to serve investors.

The fourth is the measurement problem itself–the risk-based denominator. If the inspectors get better at choosing risky engagements, the rate rises without quality falling. If they relax, it falls without quality rising. The published rate is therefore a joint product of audit quality and inspection posture, and nothing in the public reports lets an outsider separate the two.

The fifth is that nobody is measuring the thing anyone actually cares about, which is whether investors were misled. The deficiency rate is an input measure–the auditor’s process–dressed as an outcome. The outcome measures are restatements, enforcement findings, and the small number of catastrophic failures that destroy value. Correlating the deficiency rate with those outcomes is a piece of research the PCAOB has never published and could.

CAG’s Big Reset: AI Audits, Scrutiny and a Push for Accountability

The elephant: the numbers fell as the referee changed

Here is where an auditor’s instinct, rather than a journalist’s, has to be applied–and where I want to be careful to argue fairly rather than cheaply.

The twelve months in which the Big Four’s deficiency rate fell from 20 per cent to 8 were also the twelve months in which the American audit regulator was taken apart and reassembled. In July 2025 the Securities and Exchange Commission’s (SEC) new chairman, Paul Atkins, secured the resignation of PCAOB chair Erica Williams; reporting at the time indicated she had no intention of leaving until asked.  George Botic served as acting chair. On 30 January 2026 the SEC announced four new board members, including as chairman Demetrios Logothetis, a forty-year veteran of EY, who was sworn in on 10 February.

Law-firm commentary on the appointments–and this is analysis rather than fact, so I flag it–read the new composition as portending looser enforcement, streamlined inspections, fewer new standards and a less adversarial relationship with the firms.  All of this followed a failed attempt in 2025 to abolish the PCAOB outright by folding it into the SEC through budget reconciliation, a provision struck down by the Senate Parliamentarian, and a House bill to abolish it within a year of enactment.

The enforcement numbers moved in the opposite direction to the quality numbers. The SEC and PCAOB together brought 39 enforcement actions against auditors in 2025, a third fewer than the 58 of 2024, with total monetary sanctions of  USD 17.9 million, down 66 per cent. The PCAOB accounted for 37 of the 39 actions; 84 per cent of its actions and 98 per cent of its penalties were initiated before Williams left on 22 July. The SEC brought two.  Since then the board’s enforcement staff has dropped the routine requirement that respondents neither admit nor deny findings, narrowed the circumstances in which issuers are named in settled orders, and gone months without a single enforcement order.

Now the steel-man, because it is strong and it matters.

The 2025 inspection field work was performed largely in 2025 by career inspection staff under the programme Williams built, well before the new board was seated; the reports themselves were drafted by that staff. The improvement did not begin in 2026–it began with the 2024 cycle, under Williams, and she predicted it publicly. It is broad-based, appearing at all six firms and at the triennially inspected smaller firms too, which is not the signature of a manipulated number.

Sample sizes were unchanged at 64 per Big Four firm. And there is a plausible causal story with money behind it: EY’s billion-dollar programme, KPMG’s steady multi-year climb down from 26 per cent, and the industry-wide reaction to the humiliating 2023 cycle in which BDO failed 86 per cent of the audits inspected and two United States senators wrote to the board demanding to know what it intended to do about it.  Firms do respond to public shaming, and the 2023 shaming was severe.

I accept all of that. The deficiency rates are probably measuring something real.

But two objections survive, and neither is a conspiracy theory.

The first is that a risk-based denominator plus a change of regulatory posture is an unfalsifiable combination. The published rate depends on which engagements inspectors select and on where they set the threshold between a Part I.A finding and a lesser comment. Both are professional judgments exercised inside an institution whose leadership was replaced by people who came to office believing the previous leadership had been too aggressive.

Nothing in the public record allows an outsider to test whether the threshold drifted. That is not an accusation; it is a gap in the accountability architecture, and the honest response to it is disclosure rather than reassurance.

The second is that the series is about to be discontinued. If inspection moves to the firm-wide quality control system, the engagement-level Part I.A rate either disappears or ceases to be comparable.

A regulator that changes its metric immediately after the metric produces its best-ever reading has an obligation to publish a bridge–old basis and new, side by side, for at least two cycles–or the improvement becomes unauditable at exactly the moment it becomes historic.

(This is first of the two-part series. Views expressed in the article are author’s own.)

India’s Biggest Insider Trading and Market Manipulation Explained

Follow The Raisina Hills on WhatsApp, Instagram, YouTube, Facebook, and LinkedIn

Exit mobile version