CPA AUDITING & ATTESTATION (AUD) • ETHICS, PROFESSIONAL RESPONSIBILITIES AND GENERAL PRINCIPLES

SEC And PCAOB Independence Rules — Apply SEC And PCAOB Independence Rules

How auditor independence safeguards the integrity of public company financial reporting.

Historical Context & Motivation

The concept of auditor independence lies at the very heart of the audit function. Without independence, an auditor's opinion on a company's financial statements carries no more credibility than the company's own assertions, and the entire architecture of investor protection collapses. Independence requirements evolved over roughly a century of legislative responses to financial scandals, each wave of regulation tightening the boundary between auditors and their clients. Understanding this historical trajectory is essential for grasping why the Securities and Exchange Commission (SEC) and the Public Company Accounting Oversight Board (PCAOB) impose the specific restrictions they do today.

1933–34
Securities Acts Enacted
In the aftermath of the 1929 market crash, Congress enacted the Securities Act of 1933 and the Securities Exchange Act of 1934, creating the SEC and requiring independent audits of public companies for the first time.
1977
SEC Codification of Independence Rules
The SEC formalized auditor independence requirements in Regulation S-X, Rule 2-01, establishing a comprehensive framework that addressed financial interests, employment relationships, and non-audit services.
2000
SEC Rule Modernization
The SEC adopted sweeping revisions to its independence rules through a final rule titled 'Revision of the Commission's Auditor Independence Requirements,' addressing technology-driven conflicts and expanding the scope of prohibited non-audit services.
2002
Sarbanes-Oxley Act & PCAOB Creation
The collapse of Enron and WorldCom prompted the Sarbanes-Oxley Act (SOX), which created the PCAOB to oversee public company audits. SOX Section 201 enumerated specific prohibited non-audit services and required audit committee pre-approval for all remaining permissible services.
2003–Present
PCAOB Rulemaking
The PCAOB adopted Rule 3520 (auditor independence) and Rule 3526 (communication with audit committees about independence), building an enforcement-backed layer of independence regulation on top of existing SEC rules and AICPA standards.

The central question that these historical developments address is deceptively simple: How do we ensure that auditors remain truly objective when they are paid by the very entities they audit? The SEC and PCAOB answer this question through overlapping but distinct regulatory frameworks, and CPA candidates must understand both the letter and spirit of each body's requirements.

Core Principles & Definitions

SEC and PCAOB independence rules rest on a dual standard. The SEC requires that an auditor be independent both in fact (the auditor actually possesses an unbiased mindset) and in appearance (a reasonable investor, knowing all the facts, would conclude the auditor is objective). This two-pronged test is broader than the AICPA's conceptual framework approach, because the SEC frequently adopts bright-line prohibitions that deem certain relationships to impair independence regardless of the auditor's subjective state of mind. The SEC framework is codified primarily in Regulation S-X, Rule 2-01, while the PCAOB's standards appear in PCAOB Rule 3520 and the interim independence standards adopted from the AICPA's pre-SOX framework.

1

Financial Interest Prohibitions

Covered persons in the firm may not hold direct financial interests in an audit client (regardless of materiality) or material indirect financial interests. A direct interest includes stock, bonds, or options; an indirect interest arises through mutual funds or trusts.
2

Employment & Business Relationships

Independence is impaired if a covered person has been employed by the audit client or serves in any decision-making capacity. The SEC's cooling-off period (typically one year) applies to former client employees who join the audit team.
3

Non-Audit Services Restrictions

SOX Section 201 and SEC Rule 2-01(c)(4) list nine categories of prohibited non-audit services, including bookkeeping, financial information system design, appraisal or valuation services, actuarial services, internal audit outsourcing, management functions, human resources, broker-dealer services, and legal services.
4

Partner Rotation Requirements

The lead audit partner and the concurring review partner must rotate off after five consecutive years and observe a five-year cooling-off period before returning to that engagement.
5

Audit Committee Pre-Approval

All audit and permissible non-audit services must be pre-approved by the audit committee of the issuer. A de minimis exception exists for non-audit services constituting no more than 5% of total fees, provided they are promptly brought to the committee's attention and approved before the audit is completed.
KEY TAKEAWAY
Think of auditor independence like the structural integrity of a bridge. The bridge (the audit opinion) is only useful if investors can trust it to bear the weight of their decisions. A financial interest, a prohibited service, or an undisclosed relationship is like a hidden crack in the steel — even if the bridge happens to stand today, the risk of collapse is unacceptable. The SEC and PCAOB do not wait for the bridge to fail; they inspect for cracks (bright-line rules) and remove compromised beams (mandatory partner rotation) before any weight is placed on them.

Visual Explanation — The SEC Independence Framework

This diagram illustrates the hierarchical structure of SEC Rule 2-01, which branches into three primary areas of independence concern: financial interests, employment/business relationships, and non-audit services. The PCAOB layer at the bottom reflects how PCAOB Rule 3520 incorporates the SEC framework while adding its own communication and enforcement requirements.

The diagram reveals a critical structural point: the SEC and PCAOB do not operate as separate, parallel regimes. Instead, the PCAOB's independence framework is built on top of the SEC's foundational rules. PCAOB Rule 3520 explicitly requires that registered public accounting firms and their associated persons be independent of the firm's audit clients 'in accordance with the Commission's rules on auditor independence' as well as applicable PCAOB standards. This layered approach means that an auditor of a public company (an issuer) must comply simultaneously with SEC Regulation S-X, SOX statutory provisions, and PCAOB rules and interpretations. Where a conflict arises, the more restrictive standard governs — a principle that CPA candidates should internalize.

How the Rules Work — Key Mechanisms

Covered Persons and the Scope of Prohibition

A fundamental mechanism in the SEC's independence rules is the concept of the covered person. Under Rule 2-01(f)(11), covered persons include: (i) the audit engagement team, (ii) the chain of command — those who supervise or direct the audit, or evaluate the performance or recommend the compensation of the lead audit partner — (iii) any partner or manager who provides 10 or more hours of non-audit services to the audit client during the audit or professional engagement period, and (iv) any partner in the same office as the lead audit partner. Different independence restrictions apply with varying stringency depending on the covered person's role. For instance, a direct financial interest of any amount is prohibited for all covered persons, while the same-office partner's restrictions apply primarily to financial interests rather than employment relationships.

Financial Interest Classification

The SEC draws a sharp distinction between direct financial interests and indirect financial interests. A direct interest exists when the covered person (or their immediate family member) owns securities of the audit client outright. Independence is automatically impaired — there is no materiality threshold. An indirect interest arises when the covered person's financial interest in the audit client runs through an intermediary vehicle, such as a mutual fund, retirement plan, or trust. For indirect interests, independence is impaired only if the interest is material to the covered person. However, an important exception exists: a diversified mutual fund holding audit client stock generally does not create an indirect financial interest because the investor does not control the fund's portfolio decisions.

The Prohibited Non-Audit Services Framework

SOX Section 201 and SEC Rule 2-01(c)(4) enumerate nine categories of services that an auditor may not provide to a public company audit client. The underlying logic is that these services either place the auditor in the position of auditing his or her own work (the self-review threat) or place the auditor in a management or advocacy role (the management participation threat). It is important to note that tax services are not categorically prohibited, but the PCAOB adopted Rule 3522 and Rule 3523 imposing specific limitations — for example, a registered firm may not provide tax services to persons in a financial reporting oversight role (FROR) at the audit client or market aggressive tax positions on a contingent-fee basis.

⚠️ PCAOB Rules 3522 & 3523 — Tax Services
Rule 3522 prohibits marketing, planning, or opining in favor of a confidential transaction or aggressive tax position for an audit client. Rule 3523 prohibits providing any tax service to persons in a FROR at the audit client, including executives such as the CEO, CFO, controller, and chief accounting officer, as well as members of the board of directors.

Detailed Breakdown — Covered Persons & Prohibited Services

The hierarchy of covered persons shows decreasing breadth of restrictions from the audit engagement team (most restrictive) to same-office partners (limited to financial interest rules). Immediate family members of each covered person inherit the same financial interest prohibitions, creating an extended web of regulated relationships.
Nine categories of prohibited non-audit services under SOX Section 201 and SEC Rule 2-01(c)(4)
Prohibited Service (SOX §201)Threat CategoryExample
BookkeepingSelf-reviewPreparing journal entries and maintaining the general ledger for the audit client
Financial information system designSelf-reviewDesigning or implementing a new ERP system that generates financial reporting data
Appraisal / valuation servicesSelf-reviewPerforming a fair value appraisal of a material asset that appears in audited statements
Actuarial servicesSelf-reviewComputing pension obligations or insurance reserves recorded by the client
Internal audit outsourcingSelf-review / management participationPerforming operational audits and reporting results to client management
Management functionsManagement participationServing as a temporary CFO or making hiring decisions for the client
Human resourcesManagement participationExecutive recruiting, including searching for and recommending candidates
Broker-dealer / investment advisoryAdvocacyProviding securities brokerage or investment banking services to the audit client
Legal servicesAdvocacyProviding legal opinions or representing the client in litigation or regulatory matters

Worked Example — Independence Analysis

Consider the following fact pattern. Anderson & Co., a registered public accounting firm, audits TechCorp, an SEC registrant. During the current audit, several situations arise that require an independence analysis under SEC and PCAOB rules.

Independence Threat Analysis — Anderson & Co. / TechCorp
1
Step 1 — Identify the FactsSituation A: Sarah Chen, the engagement manager on the TechCorp audit, purchased 50 shares of TechCorp stock valued at $1,200. Situation B: The firm is asked by TechCorp's CFO to provide bookkeeping services for a newly acquired subsidiary. Situation C: David Park, a partner in the same office as the lead audit partner, has a $5,000 investment in a diversified mutual fund that holds 2% of its portfolio in TechCorp stock. Situation D: The lead audit partner, Maria Lopez, has served on the TechCorp engagement for six consecutive years.
2
Step 2 — Classify Each Person's StatusSarah Chen is a member of the audit engagement team — the most restricted category of covered person. David Park is a same-office partner — covered person subject to financial interest restrictions. Maria Lopez is both on the engagement team and in the chain of command as lead audit partner.
All three individuals are covered persons under Rule 2-01(f)(11).
3
Step 3 — Apply Financial Interest Rules (Situations A & C)Situation A: Sarah's 50 shares represent a direct financial interest in TechCorp. Under Rule 2-01(c)(1), any direct financial interest by a covered person — regardless of materiality — automatically impairs independence. The fact that the shares are worth only $1,200 is irrelevant. Situation C: David's mutual fund investment constitutes an indirect financial interest. Because the fund is diversified and David does not control its investment decisions, the SEC staff generally does not treat a diversified fund holding as creating an independence-impairing financial interest, even for covered persons. If the fund were a non-diversified sector fund, further materiality analysis would be required.
Situation A: Independence IMPAIRED. Situation C: Independence NOT impaired (diversified fund exception).
4
Step 4 — Apply Non-Audit Services Rules (Situation B)Bookkeeping is one of the nine specifically prohibited non-audit services under SOX Section 201 and Rule 2-01(c)(4)(i). It does not matter that the bookkeeping would be for a newly acquired subsidiary rather than TechCorp's core operations — the prohibition applies to the audit client and its consolidated subsidiaries. The audit committee cannot approve this service, and there is no exception for immateriality.
Situation B: Independence IMPAIRED — the service is categorically prohibited.
5
Step 5 — Apply Partner Rotation Rules (Situation D)Under SEC rules and PCAOB standards, the lead audit partner must rotate off the engagement after five consecutive years. Maria Lopez has served for six years, exceeding the maximum. She must be replaced immediately and is subject to a five-year cooling-off period before she may return to the TechCorp engagement in any capacity subject to rotation requirements.
Situation D: Independence IMPAIRED — mandatory rotation violated.

SEC/PCAOB vs. AICPA Independence Rules — Key Differences

One of the most tested concepts on the AUD section of the CPA exam is distinguishing between SEC/PCAOB independence requirements (which apply to audits of issuers — public companies registered with the SEC) and AICPA independence requirements (which apply to audits of non-issuers — private companies, nonprofits, and governmental entities). While both frameworks share the foundational concept of independence in fact and appearance, the SEC/PCAOB framework is generally more prescriptive and employs bright-line rules rather than the AICPA's conceptual-framework-with-safeguards approach.

Comparison of SEC/PCAOB and AICPA independence frameworks
DimensionSEC / PCAOB (Issuers)AICPA (Non-Issuers)
Regulatory approachBright-line prohibitions; specific enumerated rulesConceptual framework; threats and safeguards model
Direct financial interestsProhibited for all covered persons regardless of materialityProhibited for covered members regardless of materiality (similar)
Non-audit servicesNine specifically prohibited categories; no exception for management oversightPermissible if client's management assumes responsibility and auditor does not make management decisions
Partner rotationMandatory: 5 years on, 5 years off for lead and concurring partnersNot required by AICPA Code; may be required by state boards or peer review
Audit committee pre-approvalRequired for all audit and permissible non-audit servicesNot applicable (non-issuers may not have audit committees)
Bookkeeping for clientCategorically prohibitedPermitted if management takes responsibility and the auditor does not make management decisions
Tax servicesPermitted with limits; prohibited for FROR persons and aggressive/contingent positionsGenerally permitted; apply threats and safeguards
EnforcementSEC enforcement actions; PCAOB inspections and disciplinary proceedingsAICPA Professional Ethics Division; state boards of accountancy
KEY TAKEAWAY
Think of the difference like driving regulations in a school zone versus a residential street. Both have speed limits, but the school zone (SEC/PCAOB rules for issuers) has fixed, non-negotiable restrictions — 20 mph, period. The residential street (AICPA rules for non-issuers) may let you exercise judgment: 25 mph normally, but slow down further if children are present (a 'safeguard' applied to a 'threat'). On the CPA exam, always identify whether the audit client is an issuer first, because this single determination dictates which rulebook applies.

Connection to Advanced Theory — Global & Evolving Standards

The SEC and PCAOB independence frameworks do not exist in isolation. Globally, the International Ethics Standards Board for Accountants (IESBA) promulgates the International Code of Ethics for Professional Accountants, which employs a threats-and-safeguards conceptual framework broadly similar to the AICPA model but with some provisions that are more restrictive than U.S. standards. Understanding how U.S. rules map against international standards is increasingly important as accounting firms operate across borders and multinational companies may be subject to multiple regulatory regimes simultaneously.

U.S. versus International independence standards
FeatureSEC / PCAOB (U.S.)IESBA (International)
General approachRules-based with bright-line prohibitionsPrinciples-based with threats and safeguards
Firm rotationNot required; only partner rotation mandatedRecommended for public interest entities in some jurisdictions (EU mandatory)
Non-audit servicesNine categorically prohibited services for issuersProhibited for PIEs if creating self-review threat and materiality threshold met; broader services permissible with safeguards for non-PIEs
Fee dependenceNo explicit cap but SEC reviews fee ratiosAddresses significant fee dependence as a self-interest threat; 15% threshold for PIEs
Long association5-year rotation for lead and concurring partners7-year rotation for key audit partners; 5-year cooling-off for PIEs

Looking forward, several evolving areas deserve attention. The PCAOB has signaled interest in expanding the definition of audit-related activities that trigger independence concerns, particularly in the realm of ESG assurance and cryptocurrency audit services. As these emerging service lines grow, expect future rulemaking to clarify which activities constitute prohibited non-audit services and whether new safeguards are needed. Additionally, the SEC's ongoing consideration of mandatory firm rotation — requiring a complete change of audit firm rather than merely rotating partners — remains a live policy debate that has been adopted in the European Union but not yet in the United States.

Practice Problems

PROBLEM 1CONCEPTUAL
Explain why the SEC requires auditor independence both 'in fact' and 'in appearance.' Why isn't independence in fact alone sufficient to protect investors?
PROBLEM 2BASIC CALCULATION
A registered firm charged an SEC-registrant audit client $400,000 in audit fees for the current year. During the audit, the client also engaged the firm for $18,000 in permissible non-audit services that were not pre-approved by the audit committee. The services were brought to the audit committee's attention and ratified before the audit report was issued. Does the de minimis exception under Rule 2-01 apply? Show the calculation.
PROBLEM 3INTERMEDIATE
Kim Patel is a senior manager at a Big Four firm who provided 12 hours of tax consulting to an SEC-registrant audit client during the current audit period. Kim is not on the audit engagement team and does not work in the same office as the lead audit partner. Under SEC rules, is Kim a 'covered person'? If so, what independence restrictions apply to her and her spouse?
PROBLEM 4APPLIED
GreenTech Inc. (an SEC registrant) has just acquired SolarBright Corp. The audit firm that audits GreenTech previously provided internal audit outsourcing services to SolarBright when SolarBright was a private company. GreenTech's management wants the audit firm to continue providing internal audit services to SolarBright for a transition period of six months after the acquisition closes. Analyze whether this arrangement is permissible under SEC/PCAOB rules.
PROBLEM 5CRITICAL THINKING
Some scholars argue that the SEC's bright-line approach to independence regulation is both over-inclusive (prohibiting arrangements that pose no real threat to objectivity) and under-inclusive (failing to capture more subtle forms of bias such as long-standing personal friendships or cultural affinities between auditors and management). Evaluate this critique, drawing on both the SEC/PCAOB rules and the AICPA/IESBA conceptual framework approach. Under what circumstances, if any, might a principles-based approach better serve investor protection than a rules-based approach?

Summary & Review

SEC and PCAOB independence rules serve as the regulatory backbone ensuring that auditors of public companies (issuers) maintain both independence in fact and independence in appearance. The SEC's framework under Regulation S-X, Rule 2-01 establishes bright-line prohibitions organized around three pillars: financial interest restrictions (direct interests always prohibited, indirect interests prohibited if material), employment and business relationship rules (including cooling-off periods and partner rotation of five years on, five years off), and nine prohibited non-audit services codified under SOX Section 201.

The PCAOB's Rule 3520 incorporates the SEC rules and adds requirements for written communication with audit committees (Rule 3526) and specific restrictions on tax services (Rules 3522 and 3523). The concept of covered persons — from the engagement team to same-office partners — determines the scope of restrictions, and audit committee pre-approval is required for all services. The most restrictive standard always governs when rules overlap, and distinguishing between issuer (SEC/PCAOB) and non-issuer (AICPA) engagements is the essential first step in any independence analysis on the CPA exam.

Varsity Tutors • CPA Auditing & Attestation (AUD) • SEC And PCAOB Independence Rules