PCAOB 3.0: The Evolving Role of Investor Protection at the PCAOB

I. Introduction

Thank you Michael [Alles] for that kind introduction.[1]

First, my thanks to Rutgers Business School for the opportunity to speak at the 50th World Continuous Auditing & Reporting Symposium. It is a great privilege to be here today (virtually).

Before I begin, I need to remind you that the views I am expressing today are my own and do not necessarily reflect the views of my fellow Board members or the staff of the PCAOB.

The concept of continuous auditing is critical to the future of the audit profession. The issue goes to the heart of the relevancy of the audit. I have, in the past, talked about audit relevancy and the risks that, without changes, the profession may confront extinction.[2]

My view was, and still is, that the role of the auditor in providing assurance for information outside of the financial statements should be modernized. This type of disclosure is increasingly used by investors and other participants in the capital markets. Investors rely on non-GAAP measures, key performance indicators, and environmental, social, and governance (ESG) metrics to make investment and voting decisions.

I believe that the PCAOB is in a good position to lead the discussions on the role, if any, of auditors, in providing assurance on these metrics.

Today though I want to talk not about extinction but evolution. The PCAOB is an almost two decades experiment in the oversight of the audit profession by an independent regulatory organization. Before 2003, the audit profession was subject to self-regulation, a time when standards were written by practicing auditors without adequate public input[3] and inspections were conducted by peer audit firms, a practice subject to extensive criticism.[4]

The creation of the PCAOB ended the era of self-regulation. Perhaps the most far reaching change made by Congress in setting up the PCAOB was to include in the statute an explicit mission to act in the interests of investors and the public.[5] In setting standards, conducting inspections, and imposing disciplinary sanctions, the explicit objective was and is to act in the public interest.

The change had the potential to profoundly affect the approach to auditor oversight. While all stakeholders presumably wanted to improve audit quality, investors and the public often had very different ideas about how to accomplish this goal.[6]

Seventeen years after the creation of the PCAOB, implementation of this mission warrants reexamination. While the PCAOB has taken some useful steps, much more needs to be done. The policies designed to promote investor input should be clearly specified and added to the PCAOB's bylaws and rules, making them a requirement not a choice.[7] In doing so, these avenues should be structured in a manner consistent with congressional initiatives.

So today I want to talk about the evolution of the investor protection mission of the PCAOB and ways to ensure that this evolution strengthens the role played by investors and the public in the oversight of the audit profession.

II. The Mission of the PCAOB

Until 2003, firms auditing public companies regulated themselves. Self-regulation meant that audit firms wrote their own rules and standards, inspected each other, and conducted investigations of potential violations of their requirements.[8] Investors and the public did not play a significant role in the process.[9]

Enron and Worldcom effectively put an end to the system of self-regulation.[10] The profession would no longer write the standards or engage in peer reviews, at least with respect to audits of public companies and, eventually, SEC-registered broker-dealers. Instead, audit oversight would fall to an independent regulator.[11]

In Congress's decision to create an independent regulator, investors and the public were top of mind and perhaps the most significant driver for the Sarbanes-Oxley Act (SOX).[12] This could be seen most clearly in the audit space through the mission given to the PCAOB. Audit oversight would focus on, and reflect, the interests of investors and the public.[13] The approach was strengthened by the requirement that the SEC appoint to the Board only individuals who had a history of "demonstrated commitment to the interests of investors and the public."[14]

This mission significantly reoriented audit oversight.[15] Investors and the public were given a seat at the standard-setting table. They could be expected to, and did, have some very different ideas about the structure and content of standards and other aspects of audit oversight.[16]

The public protection mission was not, however, self-executing.

The PCAOB from the outset took steps designed to obtain input and advice from investors. The PCAOB sometimes engaged in outreach with respect to specific matters.[17] Investors and the public were given an opportunity to comment whenever standards were changed.[18] Advisory groups that included investors were formed. [19]

These policies and approaches were, however, precarious. They were for the most part not enshrined in the rules of the PCAOB or its bylaws and could be set aside at the discretion of the Board. Even with respect to advisory groups, which had some statutory and regulatory basis, the Board retained significant discretion, including control over the agenda and the frequency of the meetings.[20]

Over time, the discretionary nature of these policies became increasingly apparent. Advisory groups at the PCAOB were not convened after November of 2018.[21] When the PCAOB recently revised the standard setting and research agendas, there was no meaningful discussion of outreach to, or input from, investors.[22] The concept release on quality control issued in December 2019 did not include a section on, or otherwise discuss, outreach to investors.[23]

All of this suggests that changes are necessary for the PCAOB to more effectively achieve the public interest mission. This requires increased transparency, including the addition of mechanisms designed to increase awareness of the operations and activities of the PCAOB. Transparency also should include improvements in the information provided to investors and the public for use in assessing audit quality and in making investment and voting decisions.

In addition to transparency, the PCAOB needs to increase and make permanent the avenues of investor and public input. These mechanisms should be inserted into the rules or bylaws of the PCAOB, making clear to the public that they are a requirement not a choice.

III. Accountability and Transparency

Transparency is essential to accountability. Investors and the public can't provide input and advice on what they don't know.

The PCAOB has struggled with transparency, having been described as "completely opaque."[24] SOX did not make mandatory the suite of laws designed to ensure transparency by government agencies.[25] Unlike the U.S. Securities and Exchange Commission (SEC or Commission), therefore, the PCAOB is not subject to the Sunshine Act,[26] the Freedom of Information Act (FOIA),[27] or the Administrative Procedure Act (APA).[28]

The failure to make these laws mandatory was not the same as a prohibition. Nothing prevented the PCAOB from implementing the principles embodied in these laws. Nonetheless, the PCAOB has, for the most part, chosen not to do so.

This approach should be reconsidered. Although not a government agency, the PCAOB remains accountable to the public. And while the budget is approved by the SEC, it is ultimately paid by the public in the form of an accounting support fee assessed on issuers and SEC-registered broker-dealers.[29] Investors and the public are, therefore, entitled to a level of transparency comparable to government agencies.

Similarly, while Congress imposed some limitations on the PCAOB's ability to disclose information to the public learned during the inspection process and enforcement proceedings, these should not, given the mission of the PCAOB, be extended.[30] Yet they have been.

Public inspection reports have excluded the identity of the companies where the audit deficiencies occurred, sharply reducing the usefulness of the reports to investors and the public.[31] With respect to enforcement settlements, the PCAOB typically identified the company where the allegedly deficient audit occurred, an approach consistent with practices at the SEC.[32] In 2019, however, the instances of issuer disclosure were significantly reduced, limiting the usefulness of enforcement settlements to investors, audit committees, and the public.[33] These decisions bear reexamination.[34]

Changes that would improve transparency at the PCAOB should include:

A. Organizational Transparency

With respect to organizational transparency, the PCAOB should implement and observe the fundamental principles of the FOIA, APA and Sunshine Act. Here are a few examples of how this might be done.

The PCAOB should disclose meetings by the Board with outside parties and the agendas of these meetings.[35] The Board often meets with large audit firms and rarely with investors. Making this information public would presumably act as a catalyst for more investor interaction.[36]

Correspondence and other materials received by the PCAOB could be posted along with any responses on the PCAOB website, at least to the extent discussing policy issues and matters of interest to investors and the public.[37] Letters to the PCAOB can come from anyone, including investors, industry trade associations, audit firms and public companies.[38]

As is done at the SEC[39] and required by the APA,[40] the PCAOB should, where permitted by statute, publish the voting records of Board members. The public would presumably benefit from understanding any significant and clear divisions within the Board.

With respect to Board meetings, the PCAOB should look to the Sunshine Act[41] and hold public meetings whenever the Board discusses matters of public importance. [42] In the early days of the PCAOB, public meetings were held monthly.[43] The public had a front row seat in the creation of a new regulatory organization. The PCAOB's bylaws, however, only require public meetings on a quarterly basis.[44]

B. Transparency and Public Disclosure

The PCAOB should provide information more useful in assessing audit quality and making investment and voting decisions. Doing so will encourage investors and the public to allocate scarce resources to the oversight of the PCAOB.

The PCAOB can do so with respect to public inspection reports. Currently the PCAOB reveals some of the deficiencies uncovered in an inspection but does not disclose the identity of the public company where the purported deficiency occurred.

The identity of the issuer is important information for investors and other stakeholders. Audit committees would presumably want to know that their own financial statements were subject to a potentially deficient audit. Investors might have questions about the company's financial statements or the quality of the audit. The information may be relevant in assessing the oversight of the audit committees.

In addition to disclosure of the identity of the issuer, the PCAOB should look to increase the usefulness of information provided to customers about audits of broker-dealers.[45] Other places where PCAOB disclosure should be made more useful include the reconsideration of the decision to more often withhold the identity of the issuer from enforcement settlements[46] and the policy of withholding opinions by the Board in matters that are appealed to the Commission.[47]

IV. Accountability and Public Input

With respect to the PCAOB's mission, transparency is necessary but not sufficient. Transparency is no guarantee of actual participation. For this to occur, the PCAOB must put in place structures that ensure investors have clear, consistent and recognized avenues for input. In doing so, the PCAOB should ensure that input is sought from underrepresented segments of the investor community.

A. Current Mechanisms

The PCAOB has traditionally sought investor input in three basic ways: notice and comment with respect to proposed standards; direct outreach; and advisory groups.

Advisory groups have been an important source of investor input and views, particularly with the creation of the Investor Advisory Group, an advisory group consisting entirely of investors and those familiar with the investor community.[48] Members of the advisory groups have been given multiple year terms[49] that allowed for the development of an increased understanding of the activities of the PCAOB and the audit process. In addition, the advisory groups relied on open meetings, providing the public with insight into the activities of the PCAOB and the issues raised by investors at those meetings.

These groups were governed by charters adopted by the PCAOB.[50] The charters gave the PCAOB plenary control over the frequency of the meetings, the agenda, and any follow-through. They can be changed without notice to, or input from, the public. The PCAOB could, if it wanted, dispense with meetings in their entirety.

This, in fact, has occurred. Advisory groups have not met since November 2018, a hiatus of two years and counting. Given this dearth of meetings, there was no opportunity for the advisory groups, particularly the investors on these advisory groups, to publicly weigh in on recent changes to the standard setting agenda despite their impact on issues identified by investors as important.[51]

The PCAOB also permits investors to participate by providing an opportunity to comment on proposed standards. Merely allowing for investor participation does not ensure that participation will in fact occur. In the past, the PCAOB has engaged in outreach and taken into account investor input when issuing standards or considering changes to the standard setting agenda. The discretionary nature of these practices means that they can be discontinued at any time.[52]

B. Reforms

After almost two decades of experience, it's clear that the efforts to obtain adequate investor input and advice needs to be strengthened. The PCAOB should enhance existing avenues, add additional ones, and make them mandatory through inclusion in the bylaws and rules. This would transform them into an obligation rather than a choice.

In setting up the relevant structures, the PCAOB should also take cues from Congress. Congress has recognized that agencies charged with protecting investors can sometimes benefit from structural changes designed to enhance that mission. Where Congress has stepped in, the PCAOB should implement these requirements, altered appropriately to address any unique attributes of the PCAOB.

1. Advisory Groups and Investor Advocate

With respect to advisory groups, the PCAOB approach should rely on the model adopted by Congress for use at the SEC.

In the Dodd-Frank Act, Congress instructed the SEC to establish an investor advisory committee.[53] In requiring that the SEC do so, Congress set out a clear structure. The committee was given a broad purpose,[54] a specified size, and mandatory representation for certain important groups or organizations.[55] The statute specified the terms of office and a minimum frequency of meetings.[56] The officers, including the chair, were to be elected by the committee.

Perhaps most significantly, the committee received the authority to issue recommendations and the Commission was obligated to respond.[57] The meetings were held in public with a webcast posted for anyone to review.[58] The investor advisory committee also formed subcommittees to discuss and advance recommendations in between meetings of the entire committee.[59]

Dodd-Frank did more than mandate an investor advisory committee. Congress also created the Office of the Investor Advocate.[60] The Investor Advocate must have experience "in advocating for the interests of investors in securities and investor protection issues, from the perspective of investors."[61] The provision addressed compensation, reporting lines, staffing, and the functions of the office.[62] Some degree of transparency was ensured by a requirement that the office produce an annual report filed with Congress. The PCAOB would benefit from the addition of this Office.[63]

2. Notice and Comment

The PCAOB has, since inception, provided investors and the public with an opportunity to comment on proposed standards. The policy is, however, discretionary and could be set aside at any time by the Board. In addition, while providing opportunities for notice and comment, the PCAOB has never publicly committed to adherence to the requirements of the APA. The APA requires more than public notice and an opportunity for comment.

The PCAOB should do two things with respect to notice and comment.

First, the PCAOB should make it an obligation not a choice.[64] The requirement should, therefore, be included in the PCAOB's bylaws or rules. The PCAOB can provide exceptions but they should be limited to those set out in the APA.[65]

Second, the PCAOB should agree to follow the requirements of the APA with respect to informal rulemaking. This would require the submission of memoranda to the rulemaking file whenever Board members or other staff meet with an outside organization to discuss a proposed standard.[66] Investors and the public would benefit from knowing who met with Board members and/or the staff in connection with a proposed rule or standard.

3. Right to Petition

The PCAOB should take from and adopt other provisions in the APA designed to encourage investor and public participation. In particular, the PCAOB should set up a mechanism that allows for public petitions to change standards or rules and requires the posting of any comment letters received on the petition.

This is a requirement for government agencies.[67] Market participants make extensive use of the authority at the SEC.[68] Recent petitions have addressed topics ranging from changes to require companies to report on the physical location of their significant assets,[69] to ending the Commission's "backdoor" regulation of 12b-1 fees,[70] to the use of electronic signatures.[71] Petitions are made public and sometimes generate a substantial number of comment letters.[72]

Implementing this mechanism would be a substantial change at the PCAOB. Right now if an investor or member of the public writes to us and asks for revisions in our standards, rules, or approach, the PCAOB doesn't make the communication (or any response) public. As a result, other investors and the public may be unaware of these views or concerns.

Implementing a public petitioning mechanism, including the posting of comment letters, would likely increase public participation. Investor views would become more accessible and potentially encourage other participants in the capital markets to submit their own comments to further the discussion.

4. Outreach and Underserved Communities

With respect to outreach, the PCAOB currently has a position devoted to outreach to all stakeholders, including audit committees, preparers, and investors. The operating divisions sometimes conduct outreach to investors in specific cases.[73]

Outreach concerning proposed standards or other policy decisions is, however, discretionary not mandatory.[74] Nor is there structural mechanism designed to ensure that outreach occurs with respect to underrepresented communities or that these communities are adequately considered in connection with the PCAOB's advisory groups.

Congress, however, provided a way forward with respect to this issue. Dodd-Frank required that the SEC put in place an Office of Minority and Women Inclusion.[75] The purpose was to promote diversity and inclusion in the financial services industry.[76] As a regulator in the financial services industry, the PCAOB would benefit from a similar office. The office would help improve outreach by the PCAOB to underrepresented communities and to promote transparency and awareness of diversity practice within the PCAOB.

V. Conclusion

So let me return to where I started. This is about the evolution of the PCAOB.

Congress inserted into the DNA of the PCAOB a mission to act in the interests of investors and the public. The mission, however, came with few specifics. Execution was left for the PCAOB to determine.

In 2003, the PCAOB, in executing the mission, was writing on whole cloth. Figuring out how to incorporate investor views into the process would necessarily be a learning exercise that would evolve over time.

We've now had 17 years of experience and insight. Investors and the public want, and are entitled to, a level of transparency comparable to what is provided by government agencies. They also want more useful information that can be factored into investment and voting decisions. Avenues for investor input, which means input for all investors, including underrepresented communities, should be guaranteed through structural changes to our bylaws or rules.

We should implement these evolutionary steps because we know from experience that they are necessary. As Congress knew, the capital markets benefit from the public interest mission. Investor and public input increases trust in the actions of the PCAOB, the audit and, ultimately, the financial disclosure process.[77]

