07/15/2026
What do Enron, WorldCom, Parmalat, Sunbeam, Freddie Mac, Fannie Mae, General Electric, Nortel Networks, Waste Management, AIG, Lehman Brothers, Bear Stearns, Mattel, Washington Mutual, Homestore.com, Duke Energy, Tyco International, HealthSouth, Horizon/CMS Healthcare, Satyam Computer Services, Credit Suisse, Morgan Stanley, First Republic Bank, Silicon Valley Bank, Signature Bank, Alameda Research, Future FinTech, USA Technologies—now Cantaloupe—Celadon Group, Austal USA, Roadrunner Transportation Systems, Iconix Brand Group, CHS, Granite Construction, BT Group, Kraft Heinz, Sequential Brands, SAExploration, Manitex International, Hertz, NMC Health, Hill International, ITT Educational Services, Colonial Bank, Obsidian Energy, Alere, Penn West Petroleum, Archer-Daniels-Midland and Datapoint Corporation have in common?
Add Adelphia Communications, Qwest Communications, Royal Ahold, Xerox, Cendant, Computer Associates, Global Crossing, Peregrine Systems, Bristol-Myers Squibb, Computer Sciences Corporation, Comverse Technology, Dell, Diamond Foods, Autonomy, Olympus, Tesco, Toshiba, Valeant Pharmaceuticals, Steinhoff International, Carillion, MiMedx, Wirecard, Luckin Coffee, Americanas and China Evergrande to the list.
Each became associated with significant accounting, financial-reporting, disclosure, internal-control, audit or corporate-governance failures.
The common denominator is not that every company committed the same offense or that every collapse was technically an accounting fraud. The common denominator is that the risk-based audit model repeatedly failed to detect—or timely expose—material misstatements, fabricated transactions, concealed liabilities, manipulated estimates, fictitious revenue, nonexistent cash and management override of internal controls.
The profession’s response is invariably another standard, another risk assessment, another checklist and another representation letter. Yet the failures continue.
Risk-based auditing may be efficient for the audit firm, but efficiency is not the same as effectiveness. An audit methodology that repeatedly produces clean opinions shortly before enormous financial-reporting failures deserves scrutiny, not reflexive defense.
The AICPA’s risk-based auditing standards are not fit for purpose, and the PCAOB’s version of the same basic model has not solved the problem.
There is no right way to do the wrong thing.