PCAOB Audit Quality Problems Often Begin at the Staff Level: Why External Auditors Need Better Training
Audit Evidence, Professional Skepticism, Internal Controls, Fraud Risk and Workpaper Quality Are Skills That Must Be Developed
When the PCAOB identifies an audit deficiency, the problem may appear in a technical area such as audit evidence, risk assessment, internal control over financial reporting, accounting estimates, fraud, or the auditor's response to identified risks.
But underneath many audit-quality problems is a more fundamental question:
Did the people performing the audit understand what they were doing, why they were doing it, and what evidence was necessary to support their conclusion?
That is why staff development matters so much for accounting firms performing PCAOB-regulated audits of public companies and broker-dealers.
Corporate Compliance Seminars' Audit & Assurance: Staff Two program, presented Wednesday–Thursday, September 2–3, 2026, is designed to strengthen the practical audit competencies that developing financial auditors need as they assume greater engagement responsibilities.
This is not simply another accounting CPE program.
It addresses the foundation underneath audit quality:
Risk → Controls → Procedures → Evidence → Documentation → Conclusion
PCAOB Audit Deficiencies Should Matter to Every Staff Auditor
It is easy for a junior auditor to think PCAOB inspection findings are a partner or engagement-quality problem.
They aren't.
PCAOB standards place substantial importance on obtaining sufficient appropriate audit evidence, responding appropriately to risks of material misstatement, exercising professional skepticism, evaluating internal controls when applicable, and properly documenting the work performed.
The staff auditor frequently performs the procedures that generate that evidence.
Consider what happens during an actual engagement.
A staff auditor may:
Perform a walkthrough.
Select samples.
Inspect invoices.
Examine contracts.
Test controls.
Perform analytical procedures.
Investigate exceptions.
Analyze accounts.
Document conversations with management.
Prepare workpapers.
If that work is poorly conceived or inadequately documented, review by a senior or manager can identify the problem.
But review cannot magically transform inadequate audit evidence into sufficient appropriate audit evidence.
That is why firms need to develop competence before the problem reaches the engagement file.
PCAOB AS 1105: Audit Evidence Is Where Everything Comes Together
One of the most important concepts for a developing financial auditor is sufficient appropriate audit evidence.
PCAOB AS 1105 addresses the evidence necessary to support the auditor's opinion.
The concept sounds simple until the auditor encounters a real engagement.
Suppose management provides a spreadsheet supporting a significant account.
The inexperienced auditor may think:
“I received the schedule. I have my evidence.”
The experienced auditor starts asking questions:
Who created the report?
Where did the information come from?
Is the population complete?
Is the information accurate?
What assertion am I testing?
Does this evidence actually address that assertion?
Is there contradictory evidence elsewhere?
That difference in thinking is enormous.
The objective isn't collecting documents.
It is obtaining persuasive evidence.
PCAOB AS 2301: Connect the Risk to the Audit Procedure
Another critical skill is understanding the auditor's response to the risks of material misstatement.
Weak auditing can become procedural:
“Last year we tested 25, so this year we'll test 25.”
That is backwards.
The auditor should understand:
What is the risk?
↓
Which financial statement assertion is affected?
↓
What could cause a material misstatement?
↓
Which procedure responds to that risk?
↓
What evidence would be persuasive?
↓
What did the procedure actually tell us?
That is the logic behind a defensible audit procedure.
Staff auditors need to understand that the audit program isn't the objective.
The objective is responding appropriately to risk.
PCAOB AS 2201: Internal Controls Require More Than Looking for a Signature
Auditors working on integrated audits of internal control over financial reporting (ICFR) need another level of competency.
A control may appear to have operated because somebody initialed a document.
That proves very little by itself.
The auditor needs to understand the control.
Suppose a controller reviews a monthly account reconciliation.
The staff auditor sees the controller's initials.
Testing should not automatically stop there.
The auditor should ask:
What exactly was reviewed?
What information was available to the reviewer?
What constitutes an exception?
What happens when an exception is identified?
How precise is the review?
Could this control actually prevent or detect a material misstatement?
This brings the auditor to the distinction between design effectiveness and operating effectiveness.
A control can be performed exactly as designed and still be a bad control.
ITGCs Matter to Financial Auditors
One of the subjects covered in the Staff Two program is Information Technology General Controls (ITGCs).
That belongs in financial-auditor training because modern financial statements are produced through technology.
Auditors increasingly rely upon:
ERP systems
Automated controls
System-generated reports
Electronic approvals
Interfaces
Databases
Financial reporting applications
If an auditor intends to rely upon information generated by a system, the reliability of the underlying technology environment may matter.
Financial auditors therefore need enough IT knowledge to understand issues involving:
Access
Change Management
Computer Operations
Information Security
System-Generated Information
The answer cannot always be:
“The IT auditors handle that.”
Financial auditors need to understand how technology affects their audit evidence.
PCAOB AS 2401: Fraud Requires a Different Mindset
Fraud risk is another area where developing auditors need more than procedures.
They need a mindset.
An error-oriented auditor asks:
“Could something have gone wrong?”
A fraud-oriented auditor adds:
“Could someone have intentionally made this look right when it wasn't?”
That changes the analysis.
Consider a journal entry.
Instead of merely determining whether documentation exists, ask:
Who initiated it?
Who approved it?
Was the approver truly independent?
Is the business purpose reasonable?
Was it posted near period end?
Is the supporting documentation authentic?
Does the transaction make economic sense?
Could management override normal controls?
That is professional skepticism in practice.
Professional Skepticism Doesn't Mean Accusing Management of Lying
New auditors sometimes misunderstand professional skepticism.
They either trust management too readily or believe skepticism means treating everyone as dishonest.
Neither approach is appropriate.
Professional skepticism means maintaining a questioning mind and critically assessing evidence.
Management says:
“That exception isn't significant.”
The auditor asks:
Why?
Management says:
“It only happened once.”
The auditor asks:
How was that determined?
Management says:
“The system won't allow that.”
The auditor asks:
Can we test that assertion?
Management says:
“We fixed the problem.”
The auditor asks:
What evidence demonstrates the corrective action is operating?
That is not hostility.
That is auditing.
Analytical Procedures Need Analysis
The same problem appears with analytical procedures.
A staff auditor compares current-year expenses with the prior year and calculates the percentage change.
That is arithmetic.
It is not necessarily analysis.
The audit question is:
What relationship did we expect?
Then:
What happened?
Then:
Why is there a difference?
And finally:
What evidence supports management's explanation?
AI and data analytics can make this process considerably more powerful by allowing auditors to examine larger populations and identify unusual relationships.
But technology does not eliminate the need for judgment.
It makes judgment more important.
Sampling Is Not “Pick 25”
Sampling provides another example of why methodology matters.
The auditor should understand:
Population → Risk → Sampling Objective → Selection → Testing → Exceptions → Evaluation → Conclusion
The number of items selected is only one part of the methodology.
Staff auditors need to understand why the sample exists and what conclusions can—and cannot—be drawn from the results.
Otherwise, sampling becomes another mechanical procedure.
Audit Workpapers Need to Survive Review
One of the best tests of a workpaper is simple:
Can an experienced auditor who did not perform the work understand what was done, what evidence was obtained, what was found, and why the auditor reached the conclusion?
A strong workpaper tells a coherent audit story:
Objective
↓
Risk
↓
Procedure
↓
Evidence
↓
Results
↓
Exceptions
↓
Conclusion
A workpaper should not merely prove that the staff auditor spent time on the engagement.
It should demonstrate the basis for the audit conclusion.
Stop Teaching Staff to SALY
There is another dangerous habit in financial auditing:
SALY — Same As Last Year.
Prior-year workpapers are useful.
They provide history.
They should not become substitutes for thinking.
The current year may involve:
New personnel
New systems
New products
New estimates
New controls
New fraud risks
New economic conditions
New cybersecurity risks
New transactions
The staff auditor should therefore ask:
What changed?
and
How should that change affect our audit?
That is how auditors develop professional judgment.
AI Makes Staff Development Even More Important
Artificial intelligence is rapidly entering financial auditing.
That increases rather than decreases the importance of fundamental audit knowledge.
AI can help auditors:
Develop walkthrough questions.
Summarize documents.
Analyze contracts.
Brainstorm fraud risks.
Identify unusual transactions.
Develop analytical expectations.
Summarize testing results.
Improve workpaper narratives.
Draft findings.
But an auditor who doesn't understand audit evidence cannot reliably determine whether an AI-generated conclusion is supportable.
An auditor who doesn't understand risk assessment cannot determine whether an AI-generated audit procedure addresses the risk.
And an auditor who doesn't understand professional skepticism may simply replace:
“Management said it, therefore it must be true.”
with:
“AI said it, therefore it must be true.”
Neither is acceptable.
AI makes competent auditors more productive. It does not make an untrained auditor competent.
The Progression From Staff Auditor to Audit Professional
There is a major difference between someone who can complete assigned procedures and someone who understands the audit.
The developmental progression should look something like this:
Follow the Procedure
↓
Understand the Procedure
↓
Understand the Risk
↓
Evaluate the Evidence
↓
Recognize the Exception
↓
Determine What Additional Work Is Necessary
↓
Reach and Defend the Conclusion
That progression is how professional judgment develops.
It also explains why second-level staff training matters.
The auditor is moving beyond simply learning what to do.
The auditor needs to understand why it is being done.
Why Audit Firms Should Invest in Staff Two Training
For firms performing PCAOB-regulated audits, the business case is straightforward.
Better-trained staff can contribute to:
Better walkthroughs
Better risk identification
Better control testing
Better fraud awareness
Better evidence evaluation
Better workpapers
Better escalation of exceptions
Better supervision efficiency
Better audit quality
There is also a leverage effect.
When a staff auditor produces weak work, the senior spends additional time correcting it.
Then the manager reviews the correction.
Potentially, the partner becomes involved.
Poor staff performance therefore consumes resources throughout the engagement hierarchy.
Developing the auditor earlier can improve both audit quality and engagement efficiency.
Who Should Attend Audit & Assurance: Staff Two?
This CCS program should be particularly relevant for financial auditors who have completed their initial introduction to external auditing and are beginning to assume greater responsibility.
That includes auditors working on:
Public-company audits
PCAOB issuer audits
Broker-dealer audits
Financial statement audits
Integrated audits of ICFR
Audit engagements involving complex internal controls
Engagements requiring greater professional judgment
It can also be useful for accounting firms seeking a structured training program for their developing assurance staff.
Build Better PCAOB Auditors Before the Inspection
PCAOB inspection findings are ultimately discovered after audit work has already been performed.
Training needs to happen before that.
The objective should be to develop staff auditors who understand:
PCAOB Audit Evidence
Risk of Material Misstatement
Internal Control Over Financial Reporting
Professional Skepticism
Fraud Risk
ITGCs
Data Analytics
Financial Audit Procedures
Audit Documentation
Those aren't isolated subjects.
Together, they form the foundation of audit quality.
Join Corporate Compliance Seminars September 2–3, 2026
Corporate Compliance Seminars will present Audit & Assurance: Staff Two on Wednesday–Thursday, September 2–3, 2026.
For financial auditors performing PCAOB-regulated work, this program provides an opportunity to strengthen the practical competencies that increasingly determine whether audit procedures produce meaningful, defensible evidence.
The goal isn't to teach auditors how to fill out more workpapers.
It is to teach them how to become better financial auditors.
And for accounting firms performing PCAOB-regulated audits, that distinction matters.

Comments