top of page
Search

PCAOB Audit Tradecraft for Broker-Dealer Auditors: Specialized Work Demands Specialized Skills

A broker-dealer audit is not an ordinary financial-statement audit with a different client name.


Broker-dealers operate under specialized SEC financial-responsibility, customer-protection, net-capital and reporting requirements. Their auditors must understand both PCAOB auditing standards and the regulatory framework governing the client’s operations.


A technically weak broker-dealer audit can expose the accounting firm to PCAOB inspection findings, regulatory enforcement, reputational damage and potential loss of the practice.


Corporate Compliance Seminars’ two-day PCAOB Audit Tradecraft for the Broker-Dealer External Auditor webinar helps external auditors develop the specialized knowledge, professional judgment and documentation discipline these engagements require.


Why Broker-Dealer Audits Are Different

Broker-dealers registered with the SEC generally must file annual financial reports audited by an independent public accounting firm registered with the PCAOB.


They also generally file either:

  • A compliance report accompanied by the auditor’s examination report; or

  • An exemption report accompanied by the auditor’s review report.


These audits, examinations and reviews must be performed under PCAOB standards. The PCAOB’s broker-dealer auditor resources make clear that the financial-statement audit and related attestation work are interconnected.


The auditor must understand which regulatory requirements apply, how the broker-dealer claims compliance or exemption and whether sufficient appropriate evidence supports management’s assertions.


Compliance Report or Exemption Report?

One of the first critical issues is determining which reporting framework applies.


Compliance Report

A carrying broker-dealer generally files a compliance report addressing its compliance with specified SEC financial-responsibility rules.


The auditor performs an examination under PCAOB Attestation Standard No. 1 and obtains reasonable assurance concerning specified assertions in the compliance report.


The work may address:

  • Net capital

  • Reserve requirements

  • Possession or control of customer securities

  • Account statements

  • Internal control over compliance

  • Material weaknesses

  • Instances of noncompliance


An examination requires substantially more than asking management whether the firm complied. The auditor must obtain sufficient appropriate evidence supporting the opinion.


Exemption Report

A broker-dealer relying on an exemption from SEC Rule 15c3-3 generally prepares an exemption report identifying the applicable exemption provisions and any exceptions.

The auditor performs a review under PCAOB Attestation Standard No. 2. The objective is to determine whether the auditor is aware of material modifications needed for management’s assertions to be fairly stated.


The review provides a lower level of assurance than an examination, but it is not a casual inquiry. The auditor must understand the exemption provisions, evaluate management’s assertions, perform required inquiries and other procedures, and coordinate the work with the financial-statement audit.


Audit Planning Must Start With the Business

Auditors cannot properly assess risk without understanding how the broker-dealer makes money and handles transactions.


Planning should address:

  • Types of securities transactions

  • Customer relationships

  • Clearing and carrying arrangements

  • Introducing-broker activities

  • Proprietary trading

  • Commission and fee structures

  • Custody of customer assets

  • Regulatory capital requirements

  • Related parties

  • Service organizations

  • Information systems

  • Regulatory examinations

  • Prior audit and inspection findings

  • Changes in products, personnel or operations


A checklist cannot replace an understanding of the client’s actual business model.


Net Capital Is a Core Audit Risk

SEC Rule 15c3-1 establishes minimum net-capital requirements intended to help broker-dealers maintain sufficient liquid assets.


Auditors should understand:

  • The applicable minimum requirement

  • Allowable and nonallowable assets

  • Required haircuts

  • Aggregate indebtedness

  • Operational charges

  • Subordinated borrowings

  • Tentative net capital

  • Withdrawal restrictions

  • Early-warning levels

  • Required regulatory notifications


Errors in classification or valuation can produce an inaccurate net-capital computation and conceal a serious financial condition.


The auditor should not simply agree the final number to management’s schedule. The components, assumptions, classifications and supporting data must be tested.


Customer Protection and Possession or Control

Broker-dealers that hold customer funds or securities are subject to SEC Rule 15c3-3.


The rule creates risks involving:

  • Customer reserve computations

  • Special reserve bank accounts

  • Possession or control of securities

  • Unresolved differences

  • Customer account statements

  • Segregation of customer assets

  • Timely regulatory notifications


Testing should address whether the broker-dealer’s controls and computations operated throughout the applicable period—not merely on the last day of the year.


A year-end snapshot may miss recurring exceptions or temporary noncompliance.


Internal Control Over Compliance

Internal control over compliance is central to the examination of a compliance report.


Auditors should evaluate controls governing:

  • Regulatory computations

  • Data completeness and accuracy

  • Approval and review

  • System interfaces

  • Exception monitoring

  • Regulatory reporting

  • Customer statements

  • Possession or control

  • Reserve accounts

  • Escalation of deficiencies

  • Regulatory notifications


The auditor must understand whether controls are properly designed and whether they operated effectively.


A signed management certification does not substitute for evidence.


Revenue Recognition and Fraud Risks

Broker-dealer revenue may include:

  • Commissions

  • Trading gains and losses

  • Underwriting revenue

  • Advisory fees

  • Interest income

  • Asset-based fees

  • Placement fees

  • Clearing income


Each revenue stream may have different recognition criteria, systems and data sources.


Auditors should consider risks involving:

  • Cutoff

  • Completeness

  • Unauthorized transactions

  • Side agreements

  • Related parties

  • Manipulated valuations

  • Improper fee calculations

  • Manual journal entries

  • Management override

  • Revenue recorded without adequate support


Professional skepticism is particularly important when compensation, regulatory capital or business survival depends on reported results.


Fair Value and Securities Valuation

Securities positions can create significant valuation and disclosure risks.


The auditor should evaluate:

  • The source of pricing information

  • Market activity

  • Valuation methods

  • Observable and unobservable inputs

  • Pricing-service controls

  • Independent price verification

  • Stale prices

  • Valuation adjustments

  • Classification within the fair-value hierarchy

  • Management bias


Simply obtaining a price from a third party does not resolve the audit risk. The auditor must evaluate the relevance and reliability of the pricing evidence.


Information Technology and Service Organizations

Broker-dealers depend heavily on technology, clearing firms, custodians, pricing services and other third parties.


The audit should consider:

  • User-access controls

  • Privileged accounts

  • Program changes

  • System interfaces

  • Automated calculations

  • Cybersecurity incidents

  • Data feeds

  • Reconciliations

  • Service-auditor reports

  • Complementary user-entity controls

  • Subservice organizations

  • Business continuity


A SOC report does not eliminate the auditor’s responsibility. The auditor must determine whether the report covers the relevant period, systems, control objectives and risks.


Auditor Independence

Independence failures remain a major danger for firms auditing broker-dealers.


A firm may impair its independence if it assumes management responsibilities or performs prohibited services. Risk areas include:

  • Preparing accounting records

  • Making management decisions

  • Designing controls and then auditing them

  • Hosting financial information

  • Valuation services

  • Financial interests

  • Employment relationships

  • Business relationships

  • Excessive reliance on one client


The auditor should evaluate independence before accepting the engagement and continue monitoring it throughout the engagement.


A disclosure after the fact does not repair an independence violation.


Audit Documentation Must Stand on Its Own

PCAOB inspections focus heavily on whether the audit documentation demonstrates that required procedures were performed and sufficient appropriate evidence was obtained.


Workpapers should clearly document:

  • The risk assessed

  • The procedure performed

  • The population and sample selected

  • The evidence examined

  • The results obtained

  • Exceptions identified

  • Follow-up procedures

  • Significant judgments

  • Consultations

  • The auditor’s conclusion


“Per discussion with management” is rarely persuasive evidence for a significant audit assertion.


If experienced auditors with no previous connection to the engagement cannot understand what was tested and why the conclusion was reached, the documentation is inadequate.


Common Inspection Problems

Broker-dealer audit deficiencies may involve:

  • Inadequate risk assessment

  • Insufficient testing of revenue

  • Weak journal-entry testing

  • Failure to test information produced by the entity

  • Inadequate net-capital procedures

  • Incomplete exemption-report procedures

  • Weak fair-value testing

  • Failure to evaluate service-organization controls

  • Unsupported sampling

  • Deficient engagement quality reviews

  • Independence violations

  • Inadequate documentation

  • Failure to obtain sufficient appropriate evidence


Passing a checklist through the file does not make the engagement inspection-ready. The workpapers must demonstrate sound audit reasoning.


Electronic Filing on EDGAR

Effective June 30, 2025, broker-dealers generally must file Form X-17A-5 Part III audited annual reports electronically through EDGAR. The SEC provides current filing guidance in its electronic submission FAQs.


Auditors should coordinate with clients concerning:

  • Required reports

  • Filing deadlines

  • Confidential and public portions

  • Report dating

  • Electronic formatting

  • Consistency among submitted documents

  • Correction of filing errors


The client is responsible for filing, but the auditor should understand how its reports will be used and submitted.


What Participants Will Learn

The PCAOB Audit Tradecraft for the Broker-Dealer External Auditor program addresses:

  • The PCAOB broker-dealer oversight program

  • Current PCAOB auditing standards

  • SEC Rule 17a-5 reporting

  • Compliance and exemption reports

  • PCAOB Attestation Standards Nos. 1 and 2

  • Audit planning and risk assessment

  • Entity-level and business-process controls

  • COSO and internal control

  • Internal control over compliance

  • Net-capital and customer-protection risks

  • Revenue, valuation and fraud risks

  • Audit evidence and testing

  • Workpaper documentation

  • Independence and ethics

  • Engagement quality review

  • PCAOB inspection readiness

  • Essential auditor tradecraft


Attend the Two-Day Webinar

PCAOB Audit Tradecraft for the Broker-Dealer External Auditor


Available dates:

  • Wednesday–Thursday, September 16–17, 2026

  • Wednesday–Thursday, November 11–12, 2026


Time: 9:00 a.m.–3:00 p.m. Central Time each day


Private training may also be scheduled for groups of two or more attendees.



Broker-dealer auditing is specialized work. Firms that treat it as routine financial-statement auditing are inviting deficiencies. Successful engagements require regulatory knowledge, disciplined planning, professional skepticism, sufficient appropriate evidence and workpapers capable of surviving PCAOB inspection.

 
 
 

Recent Posts

See All
What the CIA Taught Me About Audit Tradecraft

I learned the real meaning of tradecraft while designing a training-tracking system for new intelligence officers at the Central Intelligence Agency. The system had to track more than completed course

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page