4 ms·
That's not really how auditors work. Auditors either give the client a letter saying what the client wants it to say[0] or decline to provide the client with th
by scott00 4y ago
That's not really how auditors work. Auditors either give the client a letter saying what the client wants it to say[0] or decline to provide the client with that letter. They do not go public with their reasons.
[0] Companies want the letter to say whatever their regulators and/or contractual obligations demand that it say.
- AtlasBarfed 4y agoIf a public company gets an accounting audited and they find irregularities it is not subject to public disclosure requirements? Twitter is a publicly held company. I'm sure there are conflicts of interest and some degree of confidentiality for auditors and clients, but there is a fundamental public interest of disclosure, at a minimum to the government, in the event of irregularities. From the SEC: "In addition, we will continue to focus on auditors. As the Supreme Court noted nearly 30 years ago in U.S. v. Arthur Young & Co., 465 U.S. 805 (1984), auditors play a crucial role in the financial reporting process by serving as the “public watchdog.” So, it is important that we carefully monitor their work and ensure that they fully comply with their professional obligations. If there is a significant restatement or if we learn about improper accounting from a whistleblower, our proactive efforts, or the media, then you can expect that we will scrutinize not only the CEO, CFO and Controller, but also the engagement partner, engagement quality reviewer, and the auditing firm as a whole. We are going to probe the quality of the audit and determine whether the auditors missed or ignored red flags, whether they have proper documentation, and whether they followed professional standards. And it is important to remember that our ability to bring Rule 102(e) bars against auditors extends beyond instances where there are accounting irregularities at a public company. Our Rule 102(e) program is remedial in nature and meant to protect the integrity of the Commission’s processes. As a result, we can and have investigated auditors when their audits fail to meet the most basic standards, regardless of whether there was an actual problem with the auditing client. By pursuing actions over these bad audits, we can fully leverage the Division’s resources and close off access to those who shirk their responsibilities as gatekeepers to the securities markets." ------- From there you can see legal and institutional gravitas, ethics, and expectations of accountants and auditors of public companies. That's kind of what I'm getting at re: elevating security and certain IT roles to higher responsibility and codification. Now, is this a smear attempt by Jack Dorsey in relation to the Elon Musk lawsuit? Eh, maybe.
- scott00 4y agoIf a public company's auditors find irregularities they work with the company's management to resolve them. If, eventually, the auditors decide there are irreconcilable differences, they will resign, and provide reasons for their resignation in the resignation letter to the company. At that point, it is up to the company to decide whether or not those findings are significant enough that they need to be released to the public. The SEC will consider any auditor resignation for cause to be significant enough that it has to be disclosed, but that doesn't mean that companies will actually do it, as you can see by a bunch of enforcement actions relating to exactly that: https://www.investor.gov/introduction-investing/general-resources/news-alerts/alerts-bulletins/investor-bulletins/reverse https://www.investor.gov/introduction-investing/general-reso... (search for "resign") The SEC quote is about requiring auditors to meet their professional standards. Those standards require them to follow certain processes, things like needing to see evidence for certain things, and not both preparing the books and auditing them, and require that they not issue letters they don't actually agree with. Those standards do not require informing the public or regulators about problems they find. There's certainly something to be said for having some codified professional standards for infosec professionals, but if public or regulator notice is something you think is important to be in those standards you shouldn't model them off of the standards for auditors, because auditors have no such professional responsibility.