What Are the Most Common Auditing Issues?

The most common auditing issues cluster in a few predictable places: clients who show up unprepared with weak internal controls, accounting areas that depend on management’s judgment about the future, transactions with related parties, fraud risks the auditor has to actively hunt for, disagreements over what counts as material, and threats to the auditor’s own independence. Some of these slow the engagement down and inflate the bill. Others can change the audit opinion itself. For public companies, the rules come from the Public Company Accounting Oversight Board (PCAOB); for private entities, from the American Institute of Certified Public Accountants (AICPA).1Public Company Accounting Oversight Board. Auditing Standards2AICPA & CIMA. AICPA Auditing Standards Board

Weak Internal Controls and Unprepared Clients

How ready the company is when the audit team arrives is the single biggest factor in how long the work takes and how much it costs. Unprepared clients force auditors to do more hands-on testing to compensate, and that work gets billed by the hour.

Most of these problems trace back to internal controls — the procedures a company uses to keep its financial reporting accurate and its assets safe. When key controls are missing, auditors classify the gap as either a significant deficiency or a material weakness. A material weakness means there is a reasonable possibility that a significant error in the financial statements could slip through undetected. For a public company, that finding triggers an adverse opinion on internal controls.3Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting A significant deficiency is less severe but still needs to reach the audit committee.

Segregation of duties is the classic example. When one employee can authorize a payment, record the transaction, and reconcile the bank account, both error and fraud risk climb. The auditor cannot rely on the company’s own processes to catch mistakes, so the team has to test more individual transactions to build the same level of confidence. IT controls create parallel problems. If former employees still have system access, or if software updates go live without proper testing, the auditor expands testing to rule out data corruption or unauthorized changes.

Unreconciled balance sheet accounts are another expensive one. When year-end bank accounts, receivables, or intercompany balances have not been reconciled, the audit team ends up doing the client’s bookkeeping before the actual audit can start. That is billable time spent on work the client’s accounting staff should have finished weeks earlier.

Missing or disorganized source documents are a direct obstacle to gathering evidence. Auditors need vendor invoices, signed contracts, and bank statements to verify reported balances. When those cannot be located promptly, the engagement stalls. In extreme cases the auditor issues a qualified opinion or disclaims an opinion altogether because of the scope limitation.

External confirmations get held up by the same disorganization. Auditors obtain written responses directly from banks, customers, and other third parties to verify balances like cash, receivables, and debt, because evidence from a knowledgeable outside source is generally more reliable than anything the company provides.4Public Company Accounting Oversight Board. AS 2310 – The Auditor’s Use of Confirmation When client records are messy, confirmation requests go out with wrong information, or responses come back with unexplained differences that need investigating. Low response rates force alternative procedures, adding time and cost.

An underappreciated driver of delay is the client’s own accounting staff. When they cannot explain the accounting behind their numbers or cannot efficiently pull the data the auditors need, the engagement team ends up either educating staff or extracting data themselves. Neither is productive audit time.

Accounting Areas That Rely on Management Judgment

Some financial statement areas are hard to audit because they depend on management’s view of the future rather than on verifiable historical transactions. The auditor’s job in these areas is to evaluate whether the assumptions behind those judgments are reasonable, which usually means challenging projections that management has every incentive to shade optimistically.

Fair Value Measurements

Assets and liabilities carried at fair value are among the most technically demanding areas to audit. Inputs are organized into a three-level hierarchy based on how observable they are. Level 1 inputs come from quoted prices in active markets and are straightforward to verify. Level 2 inputs are indirectly observable, like comparable transaction data. Level 3 inputs are the problem: they are unobservable and rely entirely on the company’s own assumptions, such as internal cash flow models used to value complex financial instruments or illiquid investments.5Public Company Accounting Oversight Board. AS 2501 – Auditing Accounting Estimates, Including Fair Value Measurements

Auditing Level 3 valuations usually pulls in the firm’s own valuation specialists. They independently assess the model, test the key inputs, and run sensitivity analyses to see how much the value changes when assumptions shift. Disagreements erupt when the specialist concludes the reasonable range does not include the number management reported. A company carrying an asset at $50 million when the auditor’s specialist puts the reasonable range at $38 to $46 million faces an uncomfortable conversation and a likely adjustment.

Impairment Testing

Testing whether long-lived assets and goodwill are impaired is saturated with management judgment. The company has to project future cash flows to decide whether an asset’s book value is recoverable, and those projections depend on assumptions about revenue growth, operating margins, discount rates, and market conditions.

The issue is that management can avoid recording an impairment by making slightly more optimistic assumptions. A small change to the discount rate or projected revenue growth can be the difference between a large write-down and no write-down at all. Auditors have to push back on rosy projections, especially when the company is already showing signs of financial stress. Some of the most contentious audit disagreements happen here, because the financial stakes of an impairment charge can be enormous.

Contingencies and Litigation Reserves

Companies facing lawsuits, warranty claims, or environmental cleanup obligations have to decide whether to record a loss. The accounting rule requires accruing a loss when two conditions are met: it is probable that a loss has been incurred, and the amount can be reasonably estimated.6Financial Accounting Standards Board. Summary of Statement No. 5 Evaluating “probable” is fundamentally a legal judgment that accountants are trying to make with imperfect information.

Auditors lean on responses from the company’s external legal counsel to assess litigation risk, sending formal inquiry letters asking lawyers to evaluate the likelihood and potential magnitude of pending claims. Attorneys are naturally reluctant to give definitive assessments that could be used against their own clients, so responses tend to be carefully worded and vague. That gap between what the auditor needs and what the lawyer will say forces greater reliance on management’s own assessment — exactly the kind of self-interested judgment auditors are supposed to be testing.

Going Concern

The auditor has to evaluate whether there is substantial doubt about the company’s ability to continue operating for a reasonable period, meaning up to one year beyond the date of the financial statements.7Public Company Accounting Oversight Board. AS 2415 – Consideration of an Entity’s Ability to Continue as a Going Concern Warning signs include recurring operating losses, negative cash flows, loan defaults, and loss of major customers. When those conditions exist, the auditor obtains and evaluates management’s plans for dealing with them.

Going concern is among the most sensitive areas in auditing. Adding a going concern paragraph to the audit report can become a self-fulfilling prophecy: lenders tighten credit, customers look for alternative suppliers, and the stock price drops. Management pushes back hard, often presenting turnaround plans the auditor has to evaluate for plausibility. If substantial doubt remains after considering those plans, the report must include an explanatory paragraph, and the auditor also has to assess whether the disclosures about the situation are adequate.

Related Party Transactions

Transactions between a company and its related parties, such as deals with the CEO’s family members, subsidiaries, or entities controlled by major shareholders, present a distinct risk. They may not occur at arm’s-length terms, and they can be used to manipulate reported results or funnel assets out of the company. The auditor has to understand the company’s process for identifying related parties and independently test whether the company has accurately and completely identified those relationships.8Public Company Accounting Oversight Board. AS 2410 – Related Parties

For each related party transaction that is either material or identified as a significant risk, the auditor reads the underlying agreements, verifies that the transaction was authorized through the company’s own policies, and evaluates whether the related party actually has the financial capacity to hold up its end of the deal. The practical challenge is that companies sometimes fail to disclose these relationships at all, through oversight or intentionally. Auditors may discover undisclosed related parties mid-audit through bank confirmations, public records, or inconsistencies in transaction terms. That kind of discovery escalates the engagement’s risk assessment and triggers additional procedures.

Fraud Risks the Auditor Has to Hunt For

The auditor’s job is to obtain reasonable assurance that the financial statements are free from material misstatement, whether caused by error or fraud. The standard acknowledges a limitation: even a properly planned and executed audit may not detect a material fraud, because those committing it are actively working to hide the evidence.9Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit

Auditors assess fraud risk around three conditions generally present when fraud occurs: pressure or incentive, opportunity, and the ability to rationalize the behavior. The team designs specific procedures for each.

Management Override of Controls

Management override is the fraud risk that keeps auditors up at night, because it involves the people at the top bypassing the very controls meant to prevent misstatements. A CFO who posts a fabricated journal entry or manipulates an estimate can do enormous damage, and the normal control structure will not catch it because the person committing the fraud has the authority to circumvent it. Auditors have to test non-standard journal entries for proper authorization and supporting documentation, review estimates for signs of bias, and evaluate the business rationale for unusual transactions.

Revenue Recognition

Premature revenue recognition is one of the most common vehicles for fraudulent reporting. Companies under pressure to hit earnings targets record sales before they have delivered on their obligations. The auditor rigorously examines sales recorded near period-end, verifies the underlying contract terms, and confirms that performance obligations have been met. Cutoff testing, which checks that transactions land in the right period, is a core procedure here, and even small timing shifts can materially inflate reported earnings.

Asset Misappropriation

Theft of company assets through fake vendor payments, inflated expense reimbursements, or inventory skimming tends to be smaller in dollar terms than reporting fraud but is far more common. The response focuses on controls over cash disbursements, surprise inventory counts, and more detailed testing of operating expenses. Because these schemes usually involve lower-level employees, they can be easier to detect through control testing than management override schemes.

Professional Skepticism

Underneath all fraud work is professional skepticism, defined as a questioning mind and a critical assessment of audit evidence. The auditor is not supposed to assume management is dishonest, but also cannot accept less-than-persuasive evidence just because management appears trustworthy. Maintaining that stance year after year with the same client is one of the hardest behavioral disciplines in auditing.

Materiality Disputes and Uncorrected Misstatements

Before fieldwork begins, the audit team sets a materiality threshold — the dollar amount below which errors are unlikely to influence a reasonable investor’s decisions. The PCAOB requires materiality to be set “appropriate in light of the particular circumstances” and considering earnings and other relevant factors, but does not prescribe a formula.10Public Company Accounting Oversight Board. AS 2105 – Consideration of Materiality in Planning and Performing an Audit Most firms start with a percentage of pre-tax income, revenue, or total assets and adjust from there.

Materiality drives the scope of everything that follows. A lower threshold means more transactions tested, more accounts scrutinized, and a longer audit. Disagreements with management about where to set it can arise early and color the entire engagement.

As the audit proceeds, the team accumulates every misstatement it finds, except those that are clearly trivial. That includes projected errors extrapolated from sample testing, not just the specific items identified. Management then has the opportunity to correct them.11Public Company Accounting Oversight Board. AS 2810 – Evaluating Audit Results Friction arises when management refuses to correct misstatements it considers immaterial. The auditor then has to evaluate whether the uncorrected errors, individually or together, cross the materiality line. If they do and management still will not adjust, the auditor modifies the opinion.

Threats to Auditor Independence

The entire value of an audit depends on the auditor being independent from the company it is examining. Without independence, the opinion is meaningless regardless of how thorough the work was. Independence has two dimensions: the auditor must actually be free of conflicts, and must also appear free of conflicts to a reasonable observer.

Non-Audit Services for Audit Clients

The Sarbanes-Oxley Act of 2002 prohibits audit firms from providing certain non-audit services to public companies they audit, including bookkeeping, financial information system design, appraisal and valuation, actuarial services, internal audit outsourcing, management functions, broker-dealer or investment advisory services, and legal services unrelated to the audit, along with any other service the PCAOB decides is impermissible.12Public Company Accounting Oversight Board. Public Law 107-204 – Sarbanes-Oxley Act of 2002 The logic is simple: an auditor who designed the client’s accounting system or ran its internal audit would be reviewing its own work.

Financial and Personal Ties

Owning stock in the client, having a direct lending relationship with it, or holding other financial interests that could be affected by the audit outcome are all prohibited. Firms are required to monitor the financial interests of their partners, managers, and other covered professionals to catch these conflicts before they compromise an engagement.13U.S. Securities and Exchange Commission. Commission Adopts Rules Strengthening Auditor Independence

Partner Rotation

Long tenure on one client creates familiarity threats. When the same partner works with the same management team for years, the willingness to push back on aggressive accounting can erode. Sarbanes-Oxley makes it unlawful for the lead partner or the concurring review partner to serve the same public company for more than five consecutive fiscal years, and after rotating off, the partner must sit out for five years before returning to that engagement.13U.S. Securities and Exchange Commission. Commission Adopts Rules Strengthening Auditor Independence

What Happens When Independence Breaks Down

When independence fails, the consequences extend well beyond the individual engagement. The SEC and PCAOB can impose monetary penalties, censure firms, and bar individuals from auditing public companies. Those sanctions target the ethical violation itself, not just any resulting audit failure. The broader damage is to investor confidence: if auditors are not truly independent, the financial statements they certify lose their credibility as a basis for investment decisions.