When Auditor Independence Fails — Where Was the Board?

The above is an AI-generated image of a Board room.

EY is in the headlines for breaching auditor independence standards in its external financial audit of Shell. The commentary so far has centred, understandably, on EY. However, in this article I ask one simple question:

Should the firm be taking all the blame?


Auditor Independence

Auditor independence is fundamental and sits at the core of financial reporting integrity. It is not a technical footnote. Having previously worked in external financial audit – at EY – I know the emphasis that is placed on independence from day 1 as a graduate. And it’s not a ‘one and done’ exercise, either – it’s something you formally need to attest to every year.

Independence standards are not new. They’ve been embedded in professional codes and regulatory frameworks for decades. The introduction of the Sarbanes-Oxley Act had a major impact on independence requirements in the US and Australia in 2003, with changes to corporations laws imposing stricter rotation requirements on audit partners. Prior to this change, the AICPA had independence rules in place as early as 1978.

Similarly in the UK, while independence rules were strengthened in 2016, they had been in place since at least 2009.

Why? Because when independence is compromised, it matters.

But the responsibility for independence does not sit solely within the walls of the audit firm.


The Client’s Role

In large corporations, it is typically the CFO that signs off on external auditor engagement arrangements, following approval of those arrangements by the Audit Committee. The Audit Committee is also typically responsible for approving any non-audit services provided by the same firm. The Board is responsible for overall oversight of financial reporting and the integrity of the external audit relationship – not to mention governance and integrity of the organisation as a whole.

Those roles aren’t ceremonial. They exist precisely because independence risk is foreseeable.

Independence breaches don’t arise from obscure, emerging risks that no one could reasonably anticipate. They arise in an area that has been scrutinised repeatedly across jurisdictions and through regulatory reviews for decades.

So it’s reasonable to ask:

What governance structures were in place on the client side to monitor this risk?

Was independence treated as a standing agenda item, or an assumed compliance box? Was there clear visibility over non-audit services being provided by the auditor?

Or, more concerningly, did senior management and the Board know and understand the boundaries that needed to be applied with their service providers?


Shared Accountability

Good governance is not passive. It does not rely solely on the service provider to manage conflicts that ultimately affect the company. Effective oversight means understanding where independence could erode and putting structures in place to prevent it.

This is not about not trusting the auditor. It is about effective governance structures appreciating that controls are necessary even when relationships are long-standing and professional. And as I have said time and again, trust is not a control.

When something like this hits the headlines, it is easy to frame it as an audit firm failure. And yes, audit firms must answer for breaches of professional standards. But if independence rules have been in place for decades, and if boards and audit committees are charged with oversight of those exact risks, then this cannot be viewed as a one-sided issue.

Governance is shared, and accountability must be shared also.

If you sit on an Audit Committee or in a CFO role, this story shouldn’t feel like commentary about someone else’s problem. It should prompt a proactive review of your own structures and processes. Independence risk is not theoretical. It’s well understood. And when it fails, confidence in the entire reporting framework is impacted.

EY will deal with the consequences on its side. The more interesting question is whether boards everywhere are asking themselves whether their own oversight of auditor independence would withstand the same scrutiny.

Because if they’re not – they should be. Auditor independence isn’t just the auditor’s problem.


Claire Berry (CA, CFE, CPRM, AMIIA) is the Founder and Director of Green Pen Consulting, providing tailored risk management and internal audit support to risk and audit teams.

With nearly 20 years’ experience across audit, risk and governance roles, prior to establishing Green Pen Consulting Claire was Group General Manager – Risk & Internal Audit for an ASX100 entity in the chemical manufacturing industry.

Claire also authors the monthly Green Pen Digest newsletter, keeping readers up to date on the latest news and events across the accounting and auditing industries and is the host of The Green Pen Pep Talk podcast – your daily mindset companion for the modern audit world.

Leave a Reply

Discover more from Green Pen Consulting

Subscribe now to keep reading and get access to the full archive.

Continue reading