Who Is Carrying the Risk?
The SEC has decided to stop shouting at companies for their disclosures and start screaming at the auditors instead. This is the most consequential shift this week. For years, the regulatory dance was about whether a company disclosed enough risk in its filings. Now, the regulator is easing up on those disclosure requirements while simultaneously cranking up enforcement against the firms signing off on the books.
It's a simple pivot: they've stopped caring if the client admits they have a problem and started caring why the auditor didn't find it.
When I'm sitting across from a controller, I don't care about their "mature" risk framework. Those are just slide decks. My question is always: what would you show me on a Tuesday? If you can't produce the actual evidence of a control functioning in real-time, you don't have a control; you have a wish list. The SEC is now applying that same skepticism to audit firms. They aren't looking for a tidy workpaper that says "sampled 25 items and all were correct." They're looking for the professional skepticism that should have flagged a red flag before it became a restatement.
This puts auditors in a vice. If you lean too hard on the client, you risk the relationship. If you don't lean hard enough, you're the one paying the fine.
Then there's the AI mess. The Trump administration has blocked mandatory AI audits, but that's a thin victory because a government evaluation just found a flaw in an AI sandbox environment. This is where it gets dangerous for the downstream players. If we stop mandating audits of these systems, who is actually verifying the outputs?
The FRC is already looking into how AI affects audit integrity. I suspect they'll find that many auditors are treating AI like a black box, trusting the output because the tool is "certified." But look at the breach at Unlimited Technology Systems. Nearly 4 million patient records exposed. I guarantee you those systems had some form of certification or a checklist that said they were secure. A certificate on a wall doesn't stop a leak; only a rigorous, suspicious audit does.
The strongest objection here is that auditors can't be expected to find every needle in the haystack, especially when clients hide them. That's true. But the regulator isn't asking for perfection: they're asking for evidence of effort. They want to see where you pushed back and where the client blinked.
The second-order effect is obvious: audit fees are about to skyrocket. As the SEC targets the practitioners, firms will over-compensate by increasing sample sizes and demanding more documentation to cover their own backs. We're moving from "trust but verify" to "verify everything or face a career-ending fine."
Companies bragging about their new ISO 42001 or SOC 2 certifications this week are missing the point. A certification is a snapshot of a single moment in time. It's a trophy. The SEC doesn't care about trophies; they care about who lied to whom and who failed to notice it.
I'll change my mind when I see an enforcement action that actually punishes a C-suite executive for misleading their auditor, rather than punishing the auditor for being misled. Until then, expect your auditors to become significantly more annoying during your next walkthrough.
They've realized they're the ones in the crosshairs.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- Unlimited Technology Systems Data Breach Exposes 3.8 Million Healthcare Patients' Information – 2025 Incident Analysis - Rescana InfoSec Compliance (Google News)
- North Macedonia Transfers Exclusive Online Gambling Rights to Wholly State-Owned Company from 2027 - SCCG Management InfoSec Compliance (Google News)
- Trump Blocks Mandatory AI Audits: Government Evaluation Shares Exploited Sandbox Flaw - Tech Times InfoSec Compliance (Google News)
- SEC Compensation Recovery Rule: Restatements and Related Clawbacks, Quarterly Update # 6 - The National Law Review Compliance Week (Google News)
- The SEC’s Mixed Message- Cracking Down on Auditors While Easing Up on Disclosure - The National Law Review Compliance Week (Google News)
- American Addiction Centers Discloses Another Data Breach - Claim Depot Data Privacy (Google News)
- ACHNET Releases AI Act Documentation for Employers Using High-Risk Hiring AI - The AI Journal InfoSec Compliance (Google News)
- Greater Cincinnati data breach impacts 3.8 million people nationwide - NewsBreak: Local News & Alerts InfoSec Compliance (Google News)