PCAOB New Rules Spark Controversy: Auditors May Be Pushed into 'Compliance Police' Role
Brian Croteau, Chief Auditor of PwC US, writes that the PCAOB's proposed NOCLAR auditing standard would significantly expand auditors' responsibilities, potentially diverting them from their original mission of independently verifying financial reports, reducing them to compliance officer roles, and bringing about soaring costs and independence risks.

Author: Brian Croteau, U.S. Chief Auditor at PwC, and a member of the Public Company Accounting Oversight Board (PCAOB) Standards and Emerging Issues Advisory Group. This article reflects the author's personal views only.
Background: The Evolution of the SOX Act and Audit Responsibilities
Twenty-two years ago, the U.S. Congress enacted the Sarbanes-Oxley Act—a landmark piece of legislation that laid the foundation for the modern corporate financial reporting and audit landscape and gave rise to the Public Company Accounting Oversight Board (PCAOB), established to oversee audits of U.S. public companies. Since then, the business environment has changed profoundly, and the audit profession has had to respond to the evolving needs and expectations of a wide range of stakeholders.
At its core, auditors play a vital role—building trust in the financial information provided by public companies, which in turn underpins the functioning of capital markets. As auditors, we understand the weight of this responsibility. That is why, since the implementation of the SOX Act, we have continued to take proactive steps to enhance confidence, address emerging and evolving risks, and clarify the boundaries of the auditor's role.
The NOCLAR Proposal: A Dramatic Expansion of Responsibilities
For these reasons, meaningful but appropriately calibrated changes to audit standards and regulatory rules are essential to the strength of capital markets and the investor community. This is precisely why a new audit standard proposed by the PCAOB in June 2023 warrants close attention.
In June 2023, the PCAOB issued a proposed audit standard on "Noncompliance with Laws and Regulations" (NOCLAR) that would significantly reshape the audit landscape. On March 6 of this year, I participated in a PCAOB roundtable aimed at gathering further stakeholder feedback on the proposed standard.
As discussed at the roundtable, the NOCLAR audit standard would substantially expand the scope of the auditor's work: under the proposal, auditors would be assigned responsibilities far beyond current requirements to identify—and even prevent—noncompliance with an extremely broad range of laws and regulations applicable to the company.
Comparing the Current Standard with the Proposal
This stands in sharp contrast to the current standard. Under the existing framework, auditors focus on laws and regulations that have a direct and material effect on the company's financial statements—such as those related to income taxes and pensions. When instances of noncompliance with other types of laws and regulations come to our attention, we perform further procedures on the identified matters, because such noncompliance could indirectly affect the financial statements through fines or other penalties.
Auditors also closely evaluate matters related to the accounting for loss contingencies and related disclosures. To illustrate how the current standard operates, consider a hypothetical electronics manufacturer. Today, the manufacturer's financial statements and disclosures are subject to procedures designed to provide reasonable assurance of detecting illegal acts that would have a direct and material effect on the determination of financial statement amounts—such as laws imposing federal corporate income taxes.
The Line Between Reasonable Expansion and Overreach
It would be reasonable for the PCAOB to expand the auditor's role by adopting a rule requiring auditors to perform additional risk-based procedures with respect to laws and regulations that are critical or essential to a company's operations. In the electronics manufacturer example above, relevant laws might involve compliance with standards for raw material sourcing or waste disposal—both of which could have a material impact on its financial reporting.
But would it be equally reasonable for the PCAOB to adopt a rule requiring the electronics manufacturer's auditor to assess whether the company complies with foreign regulations concerning permits for office renovations? Although this may seem like an extreme example, given that any company is subject to thousands of laws and regulations, it is crucial to clearly define the auditor's role and keep it closely tied to reliable financial reporting.
The Potential Risks of NOCLAR: Impaired Independence and Role Confusion
The NOCLAR standard has the potential to shift the independent auditor's role—expressing an opinion on whether financial statements are fairly presented based on reasonable assurance—into that of a compliance officer. Since compliance responsibilities should rest entirely with company management, the proposal could jeopardize auditor independence.
For chief financial officers (CFOs) of public companies, the NOCLAR standard as proposed would lead to significantly increased costs, likely far exceeding its benefits, while also introducing unintended consequences such as added complexity around privilege considerations and greater difficulty in managing interactions with internal and external legal counsel. Such issues could ultimately complicate—and in some respects blur—the responsibilities of CFOs, audit committees, and external auditors.
Balance and the Way Forward: Revision, Not Rejection
We understand that the goal of the PCAOB's proposed rule is to address concerns about risks to investors arising from corporate noncompliance, and we see the potential benefits of updating the standards to continuously improve quality and foster a better understanding of the auditor's role.
However, as currently drafted, the PCAOB's NOCLAR proposal still requires revision, because its proposed approach would likely—albeit unintentionally—exacerbate misunderstandings about the auditor's role in situations of corporate noncompliance. We have already shared alternative approaches better suited to the role auditors play in enhancing the reliability of financial information and the functioning of capital markets.
As the PCAOB deliberates on changes, we must all keep investor needs at the forefront, designing standards for audit services such that the benefits of those services are commensurate with the costs borne by investors. If regulators issue rules without securing broad recognition of their value across market participants, they risk creating conflicting expectations that could undermine trust—trust that is a defining strength of our financial reporting system.
Conclusion: Proceeding Prudently to Safeguard Trust
The PCAOB's focus on investor protection is essential—for market stakeholders, for the health of capital markets, and for the future of independent auditing. However, a major regulatory change requiring auditors to perform compliance audits over a broad range of laws and regulations that do not directly affect a company's financial statements would increase the cost, complexity, and time required for audits, without necessarily delivering commensurate, meaningful improvements in investor protection.
Auditors understand that our work is part of the bond of trust that sustains the functioning of U.S. capital markets. Our ability to contribute to that trust depends on our focus on relevant risks, our independence, and our objectivity. I welcome prudent, incremental initiatives that are carefully balanced between costs and benefits and are scalable to audits of companies of all sizes and complexities.