Audit challenges in accounting get written up as staffing and technology, but the oversight record says something narrower. Across all the firms it inspected in 2024, the Public Company Accounting Oversight Board, the PCAOB, put the aggregate Part I.A deficiency rate at an estimated 39%, and a Part I.A deficiency says one thing: when the report went out, the file did not hold enough evidence to support the opinion. The standards are specific about where that evidence tends to go missing. Risk assessment, accounting estimates and documentation carry most of it, and each one has a requirement you can read and a date you can put in a calendar.
Audit Challenges in Accounting Show Up as an Evidence Problem
Two national oversight records track US audit quality, and both land in the same place.
In 2024 the PCAOB inspected 171 registered public accounting firms and reviewed portions of over 800 public company audits. The aggregate Part I.A deficiency rate across all inspected firms fell to an estimated 39% from 46% in 2023, while results at the eight annually inspected US non-affiliated firms held roughly steady, at an estimated 52% against 53%. Staff flagged the 2024 figures as estimates, because some inspection results had not been finalized and the corresponding inspection reports had not been published when the report went out (PCAOB staff, Staff Update on 2024 Inspection Activities). Part I.A is the section of an inspection report that records deficiencies where the firm had not obtained sufficient appropriate audit evidence to support its opinion, which is worth reading next to what a finished file is expected to contain.
The same report is blunt about internal control work. Deficiencies in auditing internal control over financial reporting, or ICFR, were related to the sufficiency and appropriateness of audit evidence supporting an audit firm's ICFR opinion, staff wrote.
The private company side has a smaller record and a sharper one. In the AICPA Peer Review Program's enhanced oversight for 2024, subject matter experts re-reviewed 75 engagements that had already been through peer review and judged 20 of them, or 27%, to be nonconforming, meaning not performed or reported on in accordance with applicable professional standards in all material respects. Peer reviewers had identified 12 of those 20, or 60% (AICPA Peer Review Board, Annual Report on Oversight, issued April 2025).
Read that number with its limits attached. Enhanced oversights look only at must-select engagements, meaning engagements that have to be included in the sample selected for a peer review, and most are performed on employee benefit plan, single audit and Government Auditing Standards work, which are the most common must-select categories; the plan audits in that group have their own trigger rules. The 2024 overall sample was also 77% complete when the report was issued (AICPA Peer Review Board).
Risk Assessment Under SAS 145, Including the IT Layer
The first place evidence goes missing is before any testing happens.
AU-C 315, Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement, comes from SAS No. 145 and is effective for audits of financial statements for periods ending on or after December 15, 2023 (AICPA, AU-C sections). It asks at .19 for an understanding of the entity's organizational structure, ownership and governance, and its business model, including the extent to which the business model integrates the use of IT.
Then it narrows to controls. Paragraph .27 requires the auditor to identify controls that address a risk determined to be a significant risk, controls over journal entries and other adjustments, controls whose operating effectiveness the auditor plans to test, and other controls the auditor judges appropriate to meet the objectives of the risk assessment (AU-C 315).
The IT layer is where small engagements find unbudgeted work. Based on the controls identified, .28 requires the auditor to identify the IT applications and the other aspects of the entity's IT environment that are subject to risks arising from the use of IT, and .29 requires identifying both those risks and the entity's general IT controls that address them (AU-C 315). Risks arising from the use of IT is a defined term, meaning the susceptibility of information-processing controls to ineffective design or operation, or risks to the integrity of information in the entity's information system, due to ineffective design or operation of controls in the entity's IT processes. General IT controls are the controls over those IT processes that support the continued proper operation of the IT environment.
Inquiry alone does not finish the job. For each control identified, .30 requires the auditor to evaluate whether it is designed effectively and to determine whether it has been implemented by performing procedures in addition to inquiry of the entity's personnel (AU-C 315).
That chain is precisely what the peer review record says breaks. Among the example material departures the experts found in the 2023 and 2024 samples that the peer reviewers had missed, the single audit and Government Auditing Standards list opens with failure to appropriately document or perform a risk assessment, including not assessing risk at the assertion level, not supporting inherent risk assessments, not properly linking audit procedures performed to the risk assessment, and not documenting understanding of controls including IT (AICPA Peer Review Board).
One amendment on the calendar is smaller than it sounds. SAS No. 149 amends this section for periods ending on or after December 15, 2026, but the changes land only in application material, at .A17, .A53 and .A247, and only to point at group audits. The requirements above do not change (AU-C 315).
Accounting Estimates, and the Two Rulebooks Behind Them
Estimates are where management judgment meets the evidence standard, and they are hard on both sides of the profession.
AU-C 540, Auditing Accounting Estimates and Related Disclosures, is effective for audits of financial statements for periods ending on or after December 15, 2023. It defines an accounting estimate as a monetary amount whose measurement is subject to estimation uncertainty, and estimation uncertainty as susceptibility to an inherent lack of precision in measurement (AICPA, AU-C sections).
Last year's estimate is evidence about this year's. Paragraph .13 requires the auditor to review the outcome of previous accounting estimates, or their subsequent re-estimation, to assist in identifying and assessing the risks of material misstatement in the current period, and it says the review is not intended to call into question judgments that were appropriate on the information available at the time they were made (AU-C 540).
Then the response has to be picked deliberately. Under .17 the further audit procedures include one or more of three approaches: obtaining audit evidence from events occurring up to the date of the auditor's report, testing how management made the estimate, or developing an auditor's point estimate or range. Where an estimate carries a significant risk and the approach consists only of substantive procedures, .19 requires those procedures to include tests of details (AU-C 540).
Public company work reaches the same shape in its own words. AS 2501, Auditing Accounting Estimates, Including Fair Value Measurements, requires at .07 that the auditor test an estimate using one or a combination of testing the company's process used to develop it, developing an independent expectation for comparison, and evaluating audit evidence from events or transactions occurring after the measurement date. The first of those three carries its own definition: .09 says testing the company's process involves performing procedures to test and evaluate the methods, data and significant assumptions used in developing the estimate. Paragraph .31 adds that evaluating potential bias in accounting estimates includes evaluating bias in estimates individually and in aggregate, and whether bias results from the cumulative effect of changes in estimates (PCAOB, AS 2501).
Documentation, and the Deadline That Moved
Documentation fails on a date more often than on judgment.
On a public company audit, AS 1215 requires at .15 that a complete and final set of audit documentation be assembled for retention, that is archived, as of a date not more than 14 days after the report release date, and that date is the documentation completion date. The report release date is defined at .14 as the date the auditor grants permission to use the auditor's report in connection with the issuance of the company's financial statements. Paragraph .14 also requires the auditor to retain audit documentation for seven years from that date, unless a longer period is required by law (PCAOB, AS 1215).
Until the phase-in reaches a firm, the window is the old 45 days. In connection with adopting AS 1000, the Board accelerated the period in AS 1215 to assemble a complete and final set of audit documentation for retention from 45 days to 14 days, with a two-year phase-in, which gives inspections staff earlier access and reduces the window of opportunity for improper alteration before the documentation completion date (PCAOB staff, Staff Update on 2024 Inspection Activities).
The phase-in reaches firms on a schedule. Registered firms that issued audit reports with respect to more than 100 issuers during the calendar year ending Dec. 31, 2024 are in for audits of financial statements for fiscal years beginning on or after December 15, 2024, and all other registered firms for fiscal years beginning on or after December 15, 2025 (PCAOB, AS 1215).
Additions after that point are allowed, and they are visible. Paragraph .16 bars deleting or discarding audit documentation after the documentation completion date, and requires any documentation added to indicate the date the information was added, the name of the person who prepared it, and the reason for adding it (AS 1215).
Private company audits run on the AICPA's own assembly and retention numbers, and those sit with the question of which audit work can move to an outside team at all rather than here.
The failure this produces is not exotic. On employee benefit plan engagements, one example departure listed from the 2023 and 2024 samples was failure to appropriately include sufficient documentation such that an experienced auditor can understand the nature, timing and extent of procedures performed, the results of those procedures, the audit evidence obtained, the conclusions reached and any professional judgments used (AICPA Peer Review Board).
Why Audit Capacity Does Not Behave Like Tax Capacity
Audit hours are harder to move than tax hours, and the reason is structural rather than cultural.
A tax return usually has an extension available to it. Fieldwork does not, because its timing is set by the client's year end and by the date a lender, a board or a plan administrator expects the report. That fixes the work to a window your firm did not choose and cannot slide.
The second constraint sits inside your own file. Preparation work spreads across more hands well, but the judgments do not: the risk assessment, the choice of approach on an estimate, and the conclusion recorded in the workpaper belong to reviewers who are already the narrow point during filing season.
So the honest sequence for a firm carrying audits is to separate the preparation from the judgment, protect reviewer hours for the second, and size the gap before the season rather than during it, which is what a capacity plan is for. The work that has to be finished before fieldwork opens is a sequence of its own.
Questions Firms Ask About Audit Challenges
What Are the Main Challenges Faced in Auditing?
A risk assessment that is documented but never linked to the procedures that followed. An estimate whose methods, data and significant assumptions were never described in the file. Evidence that does not carry the conclusion written above it. And an archive date that arrives after the team has moved on to the next engagement. Each has a written requirement behind it, which is what makes each one auditable in advance.
What Counts as a Significant Risk?
AU-C 315 defines a significant risk at .12 as an identified risk of material misstatement for which the assessment of inherent risk is close to the upper end of the spectrum of inherent risk, because of the degree to which inherent risk factors affect the combination of the likelihood of a misstatement occurring and the magnitude of the potential misstatement, or that another AU-C section requires to be treated as a significant risk (AU-C 315).
Start With the File You Already Issued
Pull the last audit file your firm released and read three things in it. How the risk assessment connects to the procedures that came after it. How the methods, data and significant assumptions behind the largest estimate are described. And the date the file was archived against the date the report went out.
Those three answers point at where your next deficiency is most likely to come from, and they are far cheaper to read now than in the middle of an engagement.
If the constraint underneath all of it is that the same two people carry the year-round accounting behind every client file, don't trust us, test us. Accountably places trained offshore accountants and tax preparers inside US CPA, EA and accounting firms, working on the firm's software and SOPs, with the signature and the final judgment staying with the firm. The scope is accounting and tax work rather than audit fieldwork. Since 2022 that has meant 20+ US firms and 30+ placements.
The way in is small on purpose. A Free 40-Hour Proof Pilot puts a fixed block of your own representative work through the offshore team and your review chain, so your reviewer grades real output before a client file depends on it. If a placement is not the right fit in the first 30 days, the 30-Day Fit Guarantee replaces them free.
