PCAOB Audit Tradecraft for Broker-Dealer Auditors: Specialized Work Demands Specialized Skills
- John C. Blackshire, Jr.

- 2 hours ago
- 6 min read
A broker-dealer audit is not an ordinary financial-statement audit with a different client name.
Broker-dealers operate under specialized SEC financial-responsibility, customer-protection, net-capital and reporting requirements. Their auditors must understand both PCAOB auditing standards and the regulatory framework governing the client’s operations.
A technically weak broker-dealer audit can expose the accounting firm to PCAOB inspection findings, regulatory enforcement, reputational damage and potential loss of the practice.
Corporate Compliance Seminars’ two-day PCAOB Audit Tradecraft for the Broker-Dealer External Auditor webinar helps external auditors develop the specialized knowledge, professional judgment and documentation discipline these engagements require.
Why Broker-Dealer Audits Are Different
Broker-dealers registered with the SEC generally must file annual financial reports audited by an independent public accounting firm registered with the PCAOB.
They also generally file either:
A compliance report accompanied by the auditor’s examination report; or
An exemption report accompanied by the auditor’s review report.
These audits, examinations and reviews must be performed under PCAOB standards. The PCAOB’s broker-dealer auditor resources make clear that the financial-statement audit and related attestation work are interconnected.
The auditor must understand which regulatory requirements apply, how the broker-dealer claims compliance or exemption and whether sufficient appropriate evidence supports management’s assertions.
Compliance Report or Exemption Report?
One of the first critical issues is determining which reporting framework applies.
Compliance Report
A carrying broker-dealer generally files a compliance report addressing its compliance with specified SEC financial-responsibility rules.
The auditor performs an examination under PCAOB Attestation Standard No. 1 and obtains reasonable assurance concerning specified assertions in the compliance report.
The work may address:
Net capital
Reserve requirements
Possession or control of customer securities
Account statements
Internal control over compliance
Material weaknesses
Instances of noncompliance
An examination requires substantially more than asking management whether the firm complied. The auditor must obtain sufficient appropriate evidence supporting the opinion.
Exemption Report
A broker-dealer relying on an exemption from SEC Rule 15c3-3 generally prepares an exemption report identifying the applicable exemption provisions and any exceptions.
The auditor performs a review under PCAOB Attestation Standard No. 2. The objective is to determine whether the auditor is aware of material modifications needed for management’s assertions to be fairly stated.
The review provides a lower level of assurance than an examination, but it is not a casual inquiry. The auditor must understand the exemption provisions, evaluate management’s assertions, perform required inquiries and other procedures, and coordinate the work with the financial-statement audit.
Audit Planning Must Start With the Business
Auditors cannot properly assess risk without understanding how the broker-dealer makes money and handles transactions.
Planning should address:
Types of securities transactions
Customer relationships
Clearing and carrying arrangements
Introducing-broker activities
Proprietary trading
Commission and fee structures
Custody of customer assets
Regulatory capital requirements
Related parties
Service organizations
Information systems
Regulatory examinations
Prior audit and inspection findings
Changes in products, personnel or operations
A checklist cannot replace an understanding of the client’s actual business model.
Net Capital Is a Core Audit Risk
SEC Rule 15c3-1 establishes minimum net-capital requirements intended to help broker-dealers maintain sufficient liquid assets.
Auditors should understand:
The applicable minimum requirement
Allowable and nonallowable assets
Required haircuts
Aggregate indebtedness
Operational charges
Subordinated borrowings
Tentative net capital
Withdrawal restrictions
Early-warning levels
Required regulatory notifications
Errors in classification or valuation can produce an inaccurate net-capital computation and conceal a serious financial condition.
The auditor should not simply agree the final number to management’s schedule. The components, assumptions, classifications and supporting data must be tested.
Customer Protection and Possession or Control
Broker-dealers that hold customer funds or securities are subject to SEC Rule 15c3-3.
The rule creates risks involving:
Customer reserve computations
Special reserve bank accounts
Possession or control of securities
Unresolved differences
Customer account statements
Segregation of customer assets
Timely regulatory notifications
Testing should address whether the broker-dealer’s controls and computations operated throughout the applicable period—not merely on the last day of the year.
A year-end snapshot may miss recurring exceptions or temporary noncompliance.
Internal Control Over Compliance
Internal control over compliance is central to the examination of a compliance report.
Auditors should evaluate controls governing:
Regulatory computations
Data completeness and accuracy
Approval and review
System interfaces
Exception monitoring
Regulatory reporting
Customer statements
Possession or control
Reserve accounts
Escalation of deficiencies
Regulatory notifications
The auditor must understand whether controls are properly designed and whether they operated effectively.
A signed management certification does not substitute for evidence.
Revenue Recognition and Fraud Risks
Broker-dealer revenue may include:
Commissions
Trading gains and losses
Underwriting revenue
Advisory fees
Interest income
Asset-based fees
Placement fees
Clearing income
Each revenue stream may have different recognition criteria, systems and data sources.
Auditors should consider risks involving:
Cutoff
Completeness
Unauthorized transactions
Side agreements
Related parties
Manipulated valuations
Improper fee calculations
Manual journal entries
Management override
Revenue recorded without adequate support
Professional skepticism is particularly important when compensation, regulatory capital or business survival depends on reported results.
Fair Value and Securities Valuation
Securities positions can create significant valuation and disclosure risks.
The auditor should evaluate:
The source of pricing information
Market activity
Valuation methods
Observable and unobservable inputs
Pricing-service controls
Independent price verification
Stale prices
Valuation adjustments
Classification within the fair-value hierarchy
Management bias
Simply obtaining a price from a third party does not resolve the audit risk. The auditor must evaluate the relevance and reliability of the pricing evidence.
Information Technology and Service Organizations
Broker-dealers depend heavily on technology, clearing firms, custodians, pricing services and other third parties.
The audit should consider:
User-access controls
Privileged accounts
Program changes
System interfaces
Automated calculations
Cybersecurity incidents
Data feeds
Reconciliations
Service-auditor reports
Complementary user-entity controls
Subservice organizations
Business continuity
A SOC report does not eliminate the auditor’s responsibility. The auditor must determine whether the report covers the relevant period, systems, control objectives and risks.
Auditor Independence
Independence failures remain a major danger for firms auditing broker-dealers.
A firm may impair its independence if it assumes management responsibilities or performs prohibited services. Risk areas include:
Preparing accounting records
Making management decisions
Designing controls and then auditing them
Hosting financial information
Valuation services
Financial interests
Employment relationships
Business relationships
Excessive reliance on one client
The auditor should evaluate independence before accepting the engagement and continue monitoring it throughout the engagement.
A disclosure after the fact does not repair an independence violation.
Audit Documentation Must Stand on Its Own
PCAOB inspections focus heavily on whether the audit documentation demonstrates that required procedures were performed and sufficient appropriate evidence was obtained.
Workpapers should clearly document:
The risk assessed
The procedure performed
The population and sample selected
The evidence examined
The results obtained
Exceptions identified
Follow-up procedures
Significant judgments
Consultations
The auditor’s conclusion
“Per discussion with management” is rarely persuasive evidence for a significant audit assertion.
If experienced auditors with no previous connection to the engagement cannot understand what was tested and why the conclusion was reached, the documentation is inadequate.
Common Inspection Problems
Broker-dealer audit deficiencies may involve:
Inadequate risk assessment
Insufficient testing of revenue
Weak journal-entry testing
Failure to test information produced by the entity
Inadequate net-capital procedures
Incomplete exemption-report procedures
Weak fair-value testing
Failure to evaluate service-organization controls
Unsupported sampling
Deficient engagement quality reviews
Independence violations
Inadequate documentation
Failure to obtain sufficient appropriate evidence
Passing a checklist through the file does not make the engagement inspection-ready. The workpapers must demonstrate sound audit reasoning.
Electronic Filing on EDGAR
Effective June 30, 2025, broker-dealers generally must file Form X-17A-5 Part III audited annual reports electronically through EDGAR. The SEC provides current filing guidance in its electronic submission FAQs.
Auditors should coordinate with clients concerning:
Required reports
Filing deadlines
Confidential and public portions
Report dating
Electronic formatting
Consistency among submitted documents
Correction of filing errors
The client is responsible for filing, but the auditor should understand how its reports will be used and submitted.
What Participants Will Learn
The PCAOB Audit Tradecraft for the Broker-Dealer External Auditor program addresses:
The PCAOB broker-dealer oversight program
Current PCAOB auditing standards
SEC Rule 17a-5 reporting
Compliance and exemption reports
PCAOB Attestation Standards Nos. 1 and 2
Audit planning and risk assessment
Entity-level and business-process controls
COSO and internal control
Internal control over compliance
Net-capital and customer-protection risks
Revenue, valuation and fraud risks
Audit evidence and testing
Workpaper documentation
Independence and ethics
Engagement quality review
PCAOB inspection readiness
Essential auditor tradecraft
Attend the Two-Day Webinar
PCAOB Audit Tradecraft for the Broker-Dealer External Auditor
Available dates:
Wednesday–Thursday, September 16–17, 2026
Wednesday–Thursday, November 11–12, 2026
Time: 9:00 a.m.–3:00 p.m. Central Time each day
Private training may also be scheduled for groups of two or more attendees.
Broker-dealer auditing is specialized work. Firms that treat it as routine financial-statement auditing are inviting deficiencies. Successful engagements require regulatory knowledge, disciplined planning, professional skepticism, sufficient appropriate evidence and workpapers capable of surviving PCAOB inspection.
Comments