Under the Sarbanes-Oxley Act, an accounting firm that audits a public company cannot provide nine categories of non-audit services to that same client, and the PCAOB layers on additional restrictions covering contingent fees, aggressive tax strategies, and personal tax work for senior financial officers. The prohibited non-audit services are set out in Section 201 of Sarbanes-Oxley, codified at 15 U.S.C. ยง 78j-1(g), with implementing detail in SEC Rule 2-01 of Regulation S-X and PCAOB Rules 3520 through 3526.1Office of the Law Revision Counsel. 15 USC 78j-1 – Audit Requirements2eCFR. 17 CFR 210.2-01 – Qualifications of Accountants3PCAOB. Section 3 – Auditing and Related Professional Practice Standards
One scope point up front: these prohibitions apply to public companies registered with the SEC. Private companies fall under AICPA independence standards, which are generally less restrictive and permit some services that are flatly off-limits for public audit clients.
The Nine Statutory Categories
The SEC’s implementing rules give each category specific examples. For the first five, a narrow exception applies when it is reasonable to conclude the results of the service will not be subject to audit procedures. For the last four, no such exception exists.4Securities and Exchange Commission. Strengthening the Commissions Requirements Regarding Auditor Independence
Bookkeeping and Accounting Records
The firm cannot maintain or prepare the client’s accounting records, prepare the financial statements filed with the SEC, or originate the source data behind those statements. You cannot compile the books and then audit them.
Financial Information Systems Design and Implementation
The firm cannot design or implement hardware or software that aggregates source data feeding the financial statements, and it cannot operate or supervise the client’s information system or network. Audits test the controls built into those systems, so the firm cannot audit engineering choices it made itself.
Appraisal and Valuation Services
Valuations, fairness opinions, and contribution-in-kind reports are prohibited when the results could be subject to audit procedures.1Office of the Law Revision Counsel. 15 USC 78j-1 – Audit Requirements A firm that estimated the value of an acquisition target or an intangible asset cannot independently evaluate that estimate during the audit.
Actuarial Services
Any actuarial advisory service that determines amounts recorded in the financial statements is barred. That covers pension obligations, insurance reserves, and post-retirement benefit liabilities. The firm may explain actuarial methods, models, and assumptions, but it cannot perform the calculations that produce the recorded numbers.
Internal Audit Outsourcing
The firm cannot take over the client’s internal audit function for any work related to internal accounting controls, financial systems, or financial statements. External auditors have to evaluate the effectiveness of internal controls, and running those controls and then judging them is a textbook self-review conflict.
Management Functions and Human Resources
The firm cannot act as management or perform management functions, including hiring and firing decisions, supervising employees, or directing operations. An auditor who has been making operational calls cannot then step back and objectively evaluate them.
Broker-Dealer, Investment Adviser, or Investment Banking Services
Acting as a broker, dealer, investment adviser, or investment banker for the client is prohibited. Those roles create a financial stake in the client’s transactions that is incompatible with objective auditing.
Legal Services
Providing legal services to the audit client is barred. Litigation work in particular puts the auditor in an advocacy role that conflicts with the neutral, skeptical posture an audit requires.4Securities and Exchange Commission. Strengthening the Commissions Requirements Regarding Auditor Independence
Expert Services Unrelated to the Audit
The firm cannot provide expert opinions or serve as an expert witness for the client in litigation, regulatory proceedings, or administrative hearings. The line is advocacy. Factual testimony is different: the firm can give factual accounts of work it performed, explain positions it took, or describe conclusions it reached during audit work without losing independence. The audit committee can also engage the firm for internal investigations and fact-finding, and if litigation later arises from that work, the engagement is not retroactively treated as prohibited expert services, as long as the auditor stays in control of the work and it does not become directed by the client’s legal counsel.
Catch-All Category
The ninth category is any other service the PCAOB determines by regulation to be impermissible.1Office of the Law Revision Counsel. 15 USC 78j-1 – Audit Requirements The Board has used that authority to add the restrictions below.
Additional PCAOB Prohibitions
Contingent Fees and Commissions
Under PCAOB Rule 3521, the firm is not independent if it provides any service or product to the audit client for a contingent fee or commission, or receives a contingent fee or commission from the client, during the audit and professional engagement period.3PCAOB. Section 3 – Auditing and Related Professional Practice Standards A contingent fee is any arrangement where the amount depends on a specific outcome, such as a fee tied to the size of a tax refund obtained. The only exception is fees fixed by courts or public authorities rather than tied to results.
Confidential and Aggressive Tax Transactions
PCAOB Rule 3522 covers two tax scenarios. First, the firm cannot provide services related to any transaction offered under conditions of confidentiality for which the client paid an adviser a fee. Second, the firm cannot market, plan, or opine in favor of a tax strategy it recommended (directly or through an affiliate) if a significant purpose is tax avoidance, unless the proposed treatment is at least more likely than not to be allowable under tax law. The PCAOB has stated that listed transactions under IRS regulations fall within this prohibition.
Personal Tax Services for Financial Reporting Officers
PCAOB Rule 3523 prohibits the firm from providing any tax services, personal or otherwise, to individuals at the audit client who serve in a financial reporting oversight role.5Securities and Exchange Commission. PCAOB Release No. 34-54938 – Notice of Filing and Immediate Effectiveness of Proposed Rule Change Adjusting Implementation Schedule of Rule 3523 That typically includes the CEO, CFO, chief accounting officer, controller, and their immediate family members.
What the Firm Can Still Do
Services outside the nine categories are permitted if they do not otherwise impair independence. The most common permissible engagement is tax compliance and general tax planning, including preparing corporate tax returns, advising on the tax implications of a business structure, or providing guidance on a proposed transaction.1Office of the Law Revision Counsel. 15 USC 78j-1 – Audit Requirements The PCAOB restrictions on aggressive tax strategies, confidential transactions, and services to financial reporting officers still apply on top.
Other commonly permissible services include due diligence reviews of historical financial information in connection with mergers and acquisitions (so long as the firm does not participate in negotiating or structuring the deal), comfort letters for securities offerings, agreed-upon procedures engagements, and services required by local or foreign law such as statutory audits in non-U.S. jurisdictions.
The critical guardrail on any allowed service is that the auditor cannot cross into a management role. The client’s management must make all decisions, use the results, and take responsibility for the outcome. If the auditor starts directing strategy or making judgment calls that belong to management, even an otherwise permissible service becomes an independence problem. The firm also must be able to demonstrate that the service is sufficiently removed from the financial reporting process or is ministerial in nature.
Audit Committee Pre-Approval
Every permissible non-audit service must be approved by the audit client’s audit committee before the work begins.1Office of the Law Revision Counsel. 15 USC 78j-1 – Audit Requirements The requirement applies to audit and non-audit services alike. The committee can approve engagements individually, reviewing the scope, fees, and independence implications of each, or it can adopt detailed pre-approval policies that describe acceptable service types and set fee limits by category. One or more independent directors can be authorized to grant pre-approvals under a delegation, but their decisions must be reported to the full committee at each scheduled meeting.
The statute includes a narrow de minimis exception. All three of the following conditions must be met simultaneously:
- The total fees for all non-audit services covered by the exception do not exceed 5 percent of total revenues the company paid to its auditor during the fiscal year.
- The company did not recognize the services as non-audit services when it engaged the firm.
- The services are promptly brought to the audit committee’s attention and approved before the audit is completed.
This is not a blanket 5-percent safe harbor. It covers only services that genuinely slipped through at the time, not work that everyone knew was a non-audit service but that nobody bothered to pre-approve.
Consequences of Getting It Wrong
Independence violations hit both the audit firm and the company. If the SEC determines that an auditor lacked independence, the company’s financial statements may be deemed noncompliant with federal securities laws. In the worst case, the company has to hire a new, fully independent auditor to re-audit its financial statements, an expensive process that can delay SEC filings and trigger additional regulatory scrutiny.
The 2019 PwC enforcement action shows the scale. The SEC found that PwC violated independence rules by providing prohibited non-audit services and caused one audit client to violate its obligation to have financial statements audited by an independent firm. PwC agreed to pay over $4.4 million in disgorgement and prejudgment interest plus a $3.5 million civil penalty, and consented to a censure. The responsible partner was suspended from practicing before the SEC for four years and paid a separate $25,000 penalty.6Securities and Exchange Commission. SEC Charges PwC LLP With Violating Auditor Independence Rules PwC was also required to review its quality controls for independence compliance.
The PCAOB can independently impose sanctions, including censures, monetary penalties, and restrictions on a firm’s or individual’s ability to audit public companies.7PCAOB. Enforcement For individual accountants, a PCAOB bar or SEC suspension can end a career in public company auditing. A single independence lapse can draw consequences from both regulators at once.