Common Financial Statement Audit Findings

When the PCAOB reported that 39% of inspected engagements in 2024 contained at least one significant deficiency, down from 46% in 2023, the instinct is to call it progress. It is progress. But two in five reviewed audits still falling short of professional standards is not a number that warrants much satisfaction, and the more instructive question is what actually moved the number, and why the same categories fail year after year, across firm sizes, across client types, across economic cycles.
The 2024 cycle covered 171 firms and portions of more than 800 public company audits. The PCAOB attributed improvement to four operational changes at the firm level: more in-person collaboration, more targeted training for less experienced staff, stronger national office resources, and more rigorous supervision. What that attribution reveals, quietly, is what was absent before those changes were made.
The deficiency rate fractures sharply by firm tier. The Big Four reached 20% in 2024, down from 26% in each of the two prior years. Six global network firms came in at 26%, down from 34% in 2023. Eight annually inspected non-affiliated U.S. firms sat at 52%, essentially flat from 53% the prior year. Triennially inspected non-affiliated firms registered 61%, the highest of any tier, despite improving from 67%.
That 41-percentage-point spread between the Big Four and the smallest tier is not primarily a competence gap. It is an infrastructure gap: the training programs, the national office specialists, the quality control reviewers who see a file before an opinion is issued, all components of a functioning quality control system. The PCAOB's own language is pointed: "While the progress made in 2024 is significant, overall deficiency rates are still high, and firms must continue to improve." From a regulator, that sentence is not boilerplate. It is an acknowledgment that structural conditions remain unresolved, and that aggregate improvement can coexist with persistent failure in the segments that need the most help. But what if the improvement we are measuring is itself misleading — a signal that the easiest gains have already been captured, and that what remains is structurally harder to fix?
Internal Control Over Financial Reporting: The Most Technically Demanding Audit Area
An ICFR audit asks something categorically different from a financial statement audit, and the distinction is chronically underappreciated, even among experienced practitioners. Testing an account balance is bounded work: does this figure represent what management says it represents? ICFR requires the auditor to evaluate whether the controls designed to prevent or detect misstatements in that balance are both well-designed and actually operating. That requires understanding the organization's risk landscape, the controls mapped to each significant account and assertion, the people executing those controls, and the technology generating the underlying data. Every element is a potential failure point, and auditor judgment is exposed at each one.
PCAOB inspection findings cluster around a recognizable set of ICFR failures. Auditors misidentify the risks that controls need to address. They select controls that do not test the relevant financial reporting assertions. They verify that a control exists rather than that it can prevent or detect a misstatement, conflating existence with both design effectiveness and operating effectiveness. Management review controls, which are high-level and judgmental rather than transactional, receive insufficient scrutiny. IT general controls, which determine whether system-generated reports are reliable, are frequently under-evaluated. Controls tested at interim are not extended through year-end with adequate procedures. When auditors rely on internal audit or other external auditors, they often do not perform sufficient procedures to validate that reliance.
KPMG's 2024 inspection report illustrates how these failures cluster in practice: the most common findings involved testing design or operating effectiveness of selected controls, evaluating the completeness and accuracy of data used within those controls, and identifying which controls were actually tied to significant accounts or assertions.
A narrower example clarifies what these lapses mean operationally. A 2024 PCAOB inspection of PwC Belgium found that the firm, directed to test two controls over manual journal entries, failed to test attributes related to a controller's additional review and the attachment of supporting documentation to journal entry vouchers. That sounds procedurally minor until you consider that manual journal entries are a primary vehicle for fraudulent financial reporting. The two attributes the firm omitted are precisely the ones designed to surface unauthorized or unsupported entries. Testing whether a journal entry review occurred is not the same as testing what that review actually examined. In that gap lives most of the risk.
ICFR is where auditor judgment is most exposed and least amenable to checklist compliance. That is precisely why preparation here has to be more rigorous, not less, and why firms that treat it as an extension of substantive testing keep producing the same findings. One might argue that the recurring nature of these findings reflects a training problem rather than a judgment problem — but that distinction may be less meaningful than it appears, since inadequate training produces inadequate judgment, and the outcome in the workpaper is the same either way.
Revenue Recognition: The Account That Generates the Most Persistent Deficiencies
Revenue has appeared on the PCAOB's top deficiency list with a consistency that eventually stops being surprising and starts raising a different question: if ASC 606 has been in effect long enough that firms have had years to build competency around it, why does this area keep producing findings? There are two distinct failure modes at work, and remediation that addresses only one of them will not hold.
The first is complexity-driven. ASC 606 requires significant judgment about identifying performance obligations, estimating variable consideration, and accounting for contract modifications. In multi-element arrangements, particularly in software and subscription businesses, those judgments multiply. The 2024 PCAOB inspection cycle placed particular emphasis on information technology sector companies with complex revenue arrangements, reflecting that adoption-period risk has simply become ongoing operational risk for this client type, much as it did with lease accounting under ASC 842.
The second failure mode requires no complexity to materialize. A 2024 PwC Canada inspection finding illustrates it plainly: the firm tested a control over an issuer's review of new and modified customer contracts but never tested or evaluated controls over the completeness of the issuer-prepared report from which it made its selections. The sampling methodology was sound, assuming the population was complete, but population completeness was never tested as a separate audit objective. The population was never verified. That is a failure of basic sampling logic, and it could occur on the simplest revenue stream in the simplest industry.
Fraud risk compounds both failure modes. Auditing standards presume that revenue recognition carries a risk of material misstatement due to fraud on nearly every engagement. The AICPA Auditing Standards Board has identified identifying and assessing fraud-related risks as among the most challenging aspects of current auditing practice. When revenue is simultaneously a complex accounting area and a presumed fraud risk, the margin for procedural shortcuts is effectively zero. That margin is nonetheless being exceeded regularly. That raises an important question: at what point does a pattern this persistent indicate that the standards themselves need to be reconsidered, versus that the profession's implementation of them does?
Accounting Estimates: The Category Where Auditor Judgment Is Most Exposed
Estimates concentrate in a handful of high-stakes accounts and generate a disproportionate share of inspection findings. The reason is structural: estimates require auditors to evaluate reasonableness, not accuracy, and reasonableness is irreducibly judgmental. There is no external market price to confirm or contradict. The auditor has to form an independent view, and forming that view is harder than it sounds when the model is management's and the inputs are management's and the auditor arrived after everything was already built.
Goodwill and intangible asset impairment testing rests on discounted cash flow models populated with management assumptions about future revenue growth, operating margins, discount rates, weighted average cost of capital, long-term growth rates, and comparable transaction multiples. Small changes in those inputs compound. An auditor who accepts management's model and reviews the arithmetic without independently stress-testing the assumptions has not audited the estimate. The question is whether the assumptions are reasonable, and answering that requires independent analysis, not verification of someone else's work. Why exactly does this matter? Because an auditor who validates the math without challenging the inputs has performed the easier half of the work and left the riskier half untouched.
Allowance for credit losses ranked among the top three financial statement areas by PCAOB comment forms in 2024 and in the two prior years. The current expected credit loss methodology, CECL, requires auditors to evaluate forward-looking assumptions embedded in loss projections, including probability of default and loss given default estimates. Many audit teams have not kept pace with that model complexity, which is a resource and training problem as much as a judgment one.
Other investments, including Level 3 fair value measurements, topped PCAOB comment forms in each of 2022, 2023, and 2024. Level 3 instruments have no observable market price; fair value is derived entirely from internal models and unobservable inputs. Inspection findings suggest that independent analysis is frequently insufficient to bear that weight.
Business combinations present a related problem. Purchase price allocations require fair valuation of acquired assets and liabilities, often with the assistance of valuation specialists. Deficiencies arise both in the underlying measurements and in the auditor's evaluation of the specialist's work. Engaging a specialist does not transfer the auditor's responsibility; it creates an additional obligation to evaluate whether the specialist's methods and conclusions are reasonable given the auditor's own understanding of the business.
Research published in Contemporary Accounting Research in 2025 found that PCAOB-identified audit deficiencies are positively associated with future misstatements across a firm's client portfolio, and that the most detrimental deficiency type is an auditor's failure to understand the client's accounting procedures or policies. In estimation-heavy accounts, that failure is not incidental. Understanding the model is a prerequisite to testing it.
Risk Assessment and Fraud Consideration: Findings That Precede Everything Else
Risk assessment is the foundation on which every other audit decision rests. Deficiencies here are more consequential than deficiencies anywhere else, because if the risk assessment does not correctly identify where material misstatement is most likely to occur, the audit plan will address those areas with insufficient rigor. No quality of execution downstream repairs a planning failure upstream.
At the PCAOB level, fraud risk consideration ranked among the most common Part I.B deficiencies in 2024, alongside audit committee communications. At smaller firms, AICPA peer reviewers consistently find that risk assessment procedures omit required elements under professional standards. These two findings are connected in a way that deserves more attention: when risk assessment is thin, there is less of substance to communicate to the audit committee, and that absence becomes a separate deficiency. The upstream failure produces a downstream finding, and both get counted.
The AICPA Auditing Standards Board has cited post-pandemic economic volatility, labor shortages, remote work arrangements, and supply chain disruptions as conditions that simultaneously elevate fraud risk and complicate its evaluation. Those conditions have not fully resolved. An organization operating with strained staffing or materially changed processes presents a different control environment, including a changed tone at the top, than it did several years ago, and an audit plan that fails to reflect those changes is stale before fieldwork begins.
The most consequential gap is not between identifying a fraud risk and disclosing it. It is between identifying a fraud risk and designing procedures that actually respond to it. Workpapers frequently acknowledge fraud risk in planning documentation and then proceed with a largely unmodified audit approach. That is the deficiency, and it is a hard one to catch in a planning review, because the failure is not in what is documented but in what is absent. It is also worth considering whether this pattern — acknowledged risk, unchanged response — reflects a resourcing constraint as much as a judgment failure, since designing truly responsive procedures for every identified fraud risk requires time and expertise that smaller engagements often cannot absorb.
Going Concern Evaluation: A Required Procedure That Is Frequently Under-Documented
Every audit requires a going concern evaluation. This is not conditional on whether the auditor suspects a problem. It applies to every engagement, every year, and it requires documented analysis rather than a tacit assumption that everything is fine because nothing obvious has surfaced.
The deficiency pattern is consistent across firm sizes: going concern is treated as a procedural checkbox when conditions appear normal, and the problem surfaces when conditions deteriorate and the workpaper reveals no substantive evaluation was ever performed. In nonprofit audits, this became acute when pandemic-related disruptions reduced donations and canceled revenue-generating events. Auditors encountered real uncertainty and found that prior-year documentation gave them nothing to build from. The evaluation was absent precisely when it was most needed.
This area connects directly to the estimates discussion. A going concern evaluation typically depends on the same forward-looking projections that appear in impairment testing and credit loss assessments: cash flow forecasts, debt covenant compliance projections, assessments of whether planned financing will materialize. An auditor who has not rigorously tested a management cash flow forecast has not meaningfully evaluated a going concern conclusion that rests on it. These weaknesses reinforce each other. It is not a separate problem; it is the same problem appearing in an adjacent column.
Recurring Material Weaknesses in Federal Government Financial Reporting
The federal government is an extreme case, but a clarifying one that practitioners outside government auditing underuse as a reference point.
The GAO has been unable to render an opinion on the federal government's consolidated financial statements for decades. As of the FY 2025 audit, the same three fundamental obstacles persist: serious financial management problems at the Department of Defense, which has not achieved a clean audit opinion given its scale and operational complexity; an inability to adequately account for intragovernmental activity and balances between federal entities, where intragovernmental transactions that should cancel at consolidation are recorded inconsistently across agencies; and weaknesses in the process for preparing the consolidated financial statements themselves.
Two additional continuing material weaknesses compound this picture. Reported improper payment estimates for FY 2025 totaled $186 billion, up from $162 billion in FY 2024, and the government acknowledges it cannot determine the full extent to which those payments include fraud. Thirteen of the 24 CFO Act agencies reported material weaknesses or significant deficiencies in information system controls as of FY 2025.
The federal situation is not a government-specific anomaly. It is a scaled illustration of the same dynamics that produce deficiencies in private-sector audits: complexity that resists clean measurement, interconnected systems where one weakness propagates through others, and estimates that cannot be independently verified with precision. The difference is one of magnitude and institutional inertia, not of kind. Anyone who treats government auditing as a domain entirely separate from their own practice is probably missing something about their own. But how does this affect our original premise that deficiency patterns are primarily a firm-infrastructure problem? The federal case suggests that even when resources are not the binding constraint, structural complexity and interconnected weaknesses can overwhelm any level of audit investment.
What Smaller Firms and Nonprofits Face That Large-Firm Findings Don't Capture
The 61% deficiency rate among triennially inspected non-affiliated firms in 2024 is striking partly because of its magnitude and partly because of what it implies about the engagements below the PCAOB's registration threshold, where AICPA peer review findings suggest comparable patterns without the same level of regulatory visibility.
The most common peer review findings are inadequate planning, insufficient risk assessment, and inadequate documentation. These are upstream failures, the same upstream failures that drive deficiencies at larger firms, but without the national office specialists, training programs, or technical reviewers who see a file before it is finalized. When a small firm's engagement partner makes a judgment call about the sufficiency of evidence, that judgment is often the only review it will receive before the opinion is issued.
New quality management standards, including SQMS No. 1, effective as of December 15, 2025, require firms to identify their individual quality risks and implement appropriate responses, a meaningful shift from compliance-based to risk-based quality management. Smaller firms are still absorbing this change. The analytical work it demands is something many of these firms have not been expected to perform at this level of rigor before, and the transition is not frictionless.
Independence deficiencies follow a similar gradient: potential violations of SEC independence requirements occurred primarily at smaller, triennially inspected firms in 2024. For nonprofit clients specifically, the most frequently flagged peer review areas include going concern documentation, revenue recognition tied to grants and contributions, and related-party transactions. These are not obscure technical areas; they are the core of most nonprofit financial statements. Persistent findings there suggest the problem is more about bandwidth and infrastructure than awareness.
The practical implication for organizations audited by smaller firms is this: management's own preparation, documentation, and internal accounting rigor become more consequential when the auditing firm's infrastructure is thin. Where the second line of defense is unavailable, the burden of quality shifts upstream, whether management recognizes that or not.
How Organizations Can Use Audit Finding Patterns to Reduce Their Own Exposure
The standard advice is to clean up before the auditors arrive. That advice is sound but understates what the deficiency patterns actually reveal.
The recurrence of findings in the same categories across years, firm sizes, and entity types points to something structural: certain accounts and procedures are inherently more difficult to audit well, and that difficulty is predictable. An organization that understands which accounts generate the most persistent findings can invest in documentation, process design, and internal review that makes those accounts more auditable before fieldwork begins. That is a different exercise than pre-audit cleanup. It changes what auditors encounter at the start of fieldwork, rather than what gets reconciled under pressure while they are already in the building.
For ICFR, this means mapping controls not just to accounts but to specific financial reporting assertions, and maintaining evidence that each control actually operated as designed, not merely that it exists. Journal entry controls deserve particular attention: the population of entries subject to review, and the specific attributes verified in that review, should be documented with enough specificity that an auditor can evaluate them without reconstructing what the process was supposed to look like.
For revenue recognition, the completeness of the population from which audit selections are made is as important as the testing of individual items. An organization that can provide a complete, reconciled schedule of new and modified contracts tied to the underlying ledger addresses the failure mode that recurs in inspection findings, including the PwC Canada finding described earlier, before it becomes a fieldwork problem.
For estimates, the most defensible position is a documented rationale for each significant assumption, written before the audit begins and capable of withstanding independent scrutiny. The discipline of committing assumptions to paper before auditors arrive is not about producing a document for them; it is about forcing internal rigor. Auditors who find that management has already stress-tested its own assumptions tend to probe those assumptions differently than auditors who encounter a model without supporting rationale.
For risk assessment, the useful question to ask before audit planning begins is what has changed in the organization's operations, personnel, systems, or external environment since the last audit. Changes to staffing in key financial reporting roles, new accounting systems, new lines of business, shifts in the economic environment: these are precisely the conditions that should trigger a revised risk assessment. Presenting that analysis at the start of engagement anchors the planning conversation rather than leaving it entirely in the auditor's hands.
Going concern documentation is simpler than it often seems. Has someone in the organization prepared and retained an analysis of the entity's ability to continue operating for the next twelve months? If the answer is no, the auditor is being asked to evaluate something the organization itself has left unexamined. That tends to surface as a finding in the years when conditions were ambiguous enough that a thorough analysis was most warranted.
The deficiency patterns documented by the PCAOB, AICPA peer reviewers, and the GAO are not random. They reflect where accounting is hard, where judgment is irreducible, and where procedural discipline is most likely to lapse. Understanding that landscape does not guarantee a clean audit. It does change what auditors walk into, and how prepared an organization is to support, rather than scramble through, the process.


