Skip to content
US Securities and Exchange Commission

SEC proposes removing PCAOB requirement from adviser custody rule audits, examinations

Soyoung Ho, Checkpoint News  Senior Editor

· 8 minute read

Soyoung Ho, Checkpoint News  Senior Editor

· 8 minute read

The Securities and Exchange Commission (SEC) on October 1, 2026, issued a proposal that would eliminate a requirement that certain accountants and auditors engaged under the investment adviser custody rule be registered with and subject to regular audit inspection by the Public Company Accounting Oversight Board (PCAOB).

The 760-page proposal, in Release No. IA-7023, Adviser and Regulated Fund Custody Rules; Crypto Custody Rules, is part of a broader package of rule changes addressing custody of crypto assets by investment advisers and regulated funds and modernizing existing custody requirements under the Investment Advisers Act of 1940 and the Investment Company Act of 1940.

Comments are due 60 days following publication in the Federal Register.

PCAOB registration and inspection provision

Under the custody rule today, a PCAOB-registered firm is required in several circumstances:

  • when an adviser or related person acts as a qualified custodian and an accountant performs the required surprise examination;
  • when an accountant prepares the internal control report required for an adviser or related person acting as a qualified custodian; and
  • when an adviser relies on the custody rule’s audit provision for a pooled investment vehicle.

The SEC proposal would remove the PCAOB registration and inspection conditions in those circumstances. Accountants would continue to be required to qualify as independent public accountants under the custody rule.

The proposed rule would retain the definition of “independent public accountant” as a public accountant meeting the independence standards in Rule 2-01(b) and (c) of Regulation S-X.

The Sarbanes-Oxley Act of 2002 established the PCAOB to oversee audits of public companies and help protect investors.

The requirement for accountants to be registered with the PCAOB was added to the custody rule in 2009. At the time, the commission said that the PCAOB requirements could provide indirect benefits in the quality of the auditor’s other engagements.

“In light of the Commission’s experience since the 2009 amendments, we now believe that any indirect benefits of the Advisers Act custody rule’s PCAOB registration requirements may not justify the incremental cost of engaging a PCAOB-registered firm,” the SEC’s proposing release says.

The commission said PCAOB inspection is focused on public company audits and that the PCAOB does not inspect engagements required solely under the Advisers Act custody rule.

“Because the PCAOB does not currently examine or inspect accountants with respect to the services required under the Advisers Act custody rule, the PCAOB registration and inspection requirements are not an appropriate proxy for the quality of the audit and examination services required under the rule,” the release states.

The PCAOB requirement also raises costs of audits and exams. Firms must pay annual registration fees, and those firms that market themselves as PCAOB-registered have generally been found to have charged higher fees after registration.

Removing the PCAOB requirement could expand the pool of eligible accountants, increase competition, and lower advisers’ compliance costs, the SEC said.

Under the proposal, an accountant performing a surprise examination, preparing an internal control report, or auditing a pooled investment vehicle under the custody rule would no longer have to be registered with or subject to regular PCAOB inspection.

Updated internal control report language

The proposal would revise the wording of the internal control report requirement to align it with updated attestation terminology. Under the proposed redesignated Rule 223-1, an internal control report would need to include an independent public accountant’s opinion on whether controls:

  • were “suitably designed and implemented” and
  • “operating effectively throughout” the period to achieve control objectives related to custodial services, including the safeguarding of client funds and securities.

The existing rule refers to controls that have been placed in operation as of a specific date and are suitably designed and operating effectively. The SEC stated that the revised language is not intended to change the substance of the internal control report requirement.

The proposal also states that the SEC expects to update its 2009 guidance for accountants to reflect current AICPA attestation standards. It identifies three reports that would satisfy the internal control report requirement:

A SOC 1 Type 1 report, which evaluates design and implementation as of a specified date but does not test operating effectiveness throughout a period, would not meet the proposed requirement.

Crypto self-custody internal control reports

A central component of the SEC proposal would allow registered investment advisers to self-custody client crypto assets in limited circumstances. An adviser would first have to determine in writing, before taking self-custody and at least quarterly afterward, that no qualified custodian is available to maintain the particular crypto asset.

An adviser relying on the proposed self-custody exception would be required to obtain an internal control report prepared by an independent public accountant within six months of taking self-custody of a client crypto asset and at least annually thereafter, as long as the adviser holds client crypto assets in self-custody.

The report would need to address whether the adviser’s controls were suitably designed and implemented and operating effectively throughout the relevant period to achieve custodial-service control objectives, including safeguarding crypto assets held for advisory clients.

The proposal would require the accountant to verify that client crypto assets are reconciled to the relevant crypto network. The SEC described the crypto network as the analogous unaffiliated source for verifying ownership and transaction records because crypto asset transactions and ownership are recorded on those networks.

Specific crypto objectives would include safeguarding, generating, storing, distributing and managing private keys throughout their lifecycle; processing onchain events completely, accurately and timely; reconciling crypto asset positions to crypto networks; and providing account statements reflecting crypto asset positions.

As part of testing the reconciliation objective, the accountant would be expected to observe, inspect, or reperform a sample of reconciliations to verify that the data used was obtained from crypto networks and was unaltered.

The proposal states that one internal control report could cover both crypto assets and non-crypto client funds and securities when the same party is responsible for relevant controls and the report addresses all applicable objectives. Where different parties are responsible for the two types of assets, the proposal states that there should be separate internal control reports.

Changes to pooled investment vehicle audit provision

The SEC also proposed several changes to the custody rule’s audit provision for pooled investment vehicles.

Under the current rule, an adviser may be excepted from certain custody rule requirements, including the surprise examination requirement, when a pooled investment vehicle undergoes an annual financial statement audit and distributes audited financial statements to investors.

The proposal would specify that audited financial statements must be prepared in accordance with U.S. GAAP. For pooled investment vehicles organized under non-U.S. law or managed from outside the United States, the proposal would permit accounting principles other than U.S. GAAP if the financial statements contain information substantially similar to U.S. GAAP financial statements, including a reconciliation to U.S. GAAP for material differences. That reconciliation would have to be delivered to U.S. investors.

The SEC also proposed to extend the delivery period for audited financial statements:

  • from 120 days to 180 days after fiscal year-end for a fund of funds; and
  • from 120 days to 260 days after fiscal year-end for a fund of funds of funds.

For a pooled investment vehicle formed within the final 90 days of its first fiscal year, the proposal would permit financial statements for that abbreviated first year to be unaudited if they are distributed within 90 days after fiscal year-end. Audited financial statements covering both the first fiscal year and the following full fiscal year would then be distributed after the second fiscal year.

Estimated audit-related effects

The SEC’s economic analysis estimates that an adviser self-custodying client crypto assets would incur an average annual cost of $376,000 for an internal control report, in addition to other recurring compliance costs.

 

Take your tax and accounting research to the next level with Checkpoint Edge and CoCounsel. Get instant access to AI-assisted research, expert-approved answers, and cutting-edge tools like Advisory Maps and State Charts. Try it today and transform the way you work! Subscribe now and discover a smarter way to find answers.

More answers

Practical Ways to Gear Up for Tax Season

To mentally prepare the upcoming 2025 tax season, practitioners must move beyond survival mode and embrace the complexities of the …