Statement in Support of the Adoption of Final Amendments to QC 1000, A Firm’s System of Quality Control

Remarks as prepared for delivery

This is my first open Board meeting and my first public statement as a member of the PCAOB. I was sworn in on August 10, and I want to thank SEC Chairman Atkins and Commissioners Peirce and Uyeda for the confidence they’ve placed in me, as well as my fellow Board Members Chairman Logothetis, George, Steve, and Mark for the welcome they have given me.

Let me say a little about the perspective I bring to this work. 

I began my career trading bonds and derivatives at Lehman Brothers, working in New York and Tokyo, and had a front-row seat when the firm collapsed in 2008. So I’m no stranger to the consequences of excessive risk-taking by management or to how the political system, rightly or wrongly, responds to financial disasters. The financial crisis that led to the Dodd-Frank Act is, in some ways, an echo of the accounting scandals that ultimately gave us Sarbanes-Oxley and the PCAOB.  Different problems, same theme: when investors lose confidence in the information and institutions they rely on, the public suffers. Our job isn’t eliminating risk or preventing business failures, goals that would be both impossible and counterproductive, but rather strengthening confidence in the information that investors use to evaluate companies and their management.

After leaving the financial industry, I've had something of a liberal arts degree in financial policy. I served as economic policy advisor to Senator Tom Cotton, as Staff Director of the Senate Banking Committee’s Subcommittee on Economic Policy. Prior to that, I served as a member of the SEC’s Advisory Committee on Small and Emerging Companies. That was mostly about the pre-IPO companies, and as you might imagine, part of their decision-making about whether to go public or list in the US involved the new compliance and reporting requirements they’d encounter. Most recently, I served on the Board of the National Credit Union Administration from December 2020 until joining the PCAOB, including about the last year and a half as Chairman. Each of those jobs taught me the same lesson: As the expression goes, there are no solutions, only tradeoffs.

One thing I’ve always been known for is being accessible. I was the only Senate staffer that I’m aware of that had my mobile number on my business card and email signature. I intend to bring that same approach to this role. At this job, my email is [email protected] and my work cell is 202-826-5343.

In terms of focus areas, one theme I have, and will always, come back to is ending the unethical, un-American practice of “regulation by enforcement.” Included in that concern is “regulation by inspection”, where firms begin making decisions based not on standards or rules, but on what they believe regulators prefer or expect. When that occurs, it can concentrate risk, increasing the likelihood of widespread problems. A useful example from outside the accounting world is the July 2024 problems caused by a faulty update from the cybersecurity firm CrowdStrike. As was noted at the time, the biggest problems were in regulated industries: banking, airlines, and healthcare. In part because many firms in highly regulated industries gravitated toward the same widely accepted vendor, concentrating operational risk.

That brings me to QC 1000 and the amendments before us today. Investors benefit when firms maintain robust systems of quality control, and I strongly support that objective. Independent audits play a critical role in our markets, and strong quality control systems help support audit quality across an entire firm, not just on individual engagements. At the same time, regulatory requirements should be designed to improve audit quality, not simply add process.

As firms have worked to implement QC 1000, we have learned more about where certain requirements may be unnecessarily prescriptive, impose costs that are disproportionate to their benefits, or create complexity that does not directly contribute to audit quality. I view this proposal as a good example of a regulator being willing to learn, listen, and adjust where appropriate. The amendments preserve the core framework and objectives of QC 1000 while providing additional flexibility in areas where a more tailored approach can achieve comparable investor protection outcomes.

I am also mindful that regulatory costs do not affect every firm equally. Large firms may be able to absorb additional requirements relatively easily. Smaller firms, and firms considering entering or expanding in the issuer audit market, often face a different reality. Requirements that create substantial fixed costs can become barriers to entry, reduce competition, and ultimately limit options available to issuers and investors. Many of the amendments before us today address that concern by making QC 1000 more scalable and more flexible. They allow firms greater discretion in how they organize their quality control systems, eliminate requirements that may provide limited incremental benefit relative to their cost, and better align the standard with frameworks that many firms already use.

Several of the amendments illustrate this approach:

  • Eliminating the design-only requirement avoids imposing costs on firms that have no current engagement responsibilities.
  • Providing greater flexibility in assigning quality control roles recognizes that firms differ in size, structure, and access to expertise while preserving accountability for results.
  • Allowing firms to select their own evaluation date and simplifying certain communication requirements reduces administrative burden without weakening accountability.
  • Likewise, focusing the analysis of similar deficiencies on issues that could materially affect audit quality helps direct resources toward risks that are most important to investors.

Ultimately, I support these amendments because they preserve what is most important about QC 1000 while making the standard more practical, more scalable, and more focused on the outcomes that matter.

With that, I would like to recognize and thank all the staff from across the PCAOB’s Divisions and Offices who have contributed to today’s proposal, especially Dominika Taraszkiewicz, Jessica Watts, Karen Wiedemann, Ekaterina Dizna, Linnette Klinedinst, Schyler Simms, Carla Del Monico, and Kevin Lombardi in the Office of the Chief Auditor; Ying Compton, Erik Durbin, Nick Galunic, and Zoey Xie in the Office of Economic and Risk Analysis. They worked through the comment letters, analyzed the issues, engaged with stakeholders, and carefully considered how the requirements would operate in practice. That kind of work often goes unseen, but it’s exactly what made these amendments possible. I also want to thank the Chairman and my fellow Board members for their commitment to public outreach and engagement throughout this process, and the staff from SEC’s Office of the Chief Accountant for their input. Finally, I want to thank the commenters who took the time to share their views. Their feedback helped shape these amendments, and I look forward to continued engagement with the public as the Board considers future issues.