Skip to main content
Accounting

Former IIA CEO has concerns about NYSE proposal

Richard Chambers thinks five years is “too long” for new public companies to go without an internal audit function.

• 3 min read

TOPICS: Accounting / Audit & Assurance / Internal Audit

Spare a thought for the internal auditor. A 2024 global survey by the Internal Audit Foundation found that half of the 6,500 respondents (78% of whom were employed as internal auditors) thought the greatest challenge to the profession was “being misunderstood or undervalued.” And 48% said internal auditors were stereotyped as the corporate “police.”

Now the New York Stock Exchange wants to give its newly listed companies more time to set up an internal audit function.

This summer, the NYSE filed a proposal with the SEC to extend the transition period for newly public companies to establish an internal audit function. The exchange wants to give companies five years to do so, instead of the current one year. The SEC’s comment period for the NYSE proposal ended Sept. 8.

Count Richard Chambers, the former president and CEO of the Institute of Internal Auditors and former national practice leader in internal audit advisory services at PwC, as among those strongly opposing the idea.

Chambers believes a five-year grace period is too long. “Those are the years in which companies don’t have mature controls, mature risk management,” he told CFO Brew. “They’re building and forging the infrastructure to be successful long term. Now suddenly you’re not going to have the internal audit function? That seems like an unnecessary level of risk to take.”

Truth tellers. The internal audit function is essential to the protection of shareholders, and internal audit teams are “going to be there to apprise them of how the overall risk management and internal control structure of the company is working,” Chambers, now a senior advisor at governance platform Optro, said.

While external auditors inform businesses when there are problems with the financial reports, Chambers said, “internal auditors do so much more than that. They look at every risk. They look at operational risks, IT risks, compliance risks,” he said.

headshot, former CEO of IIA, Optro

Richard Chambers

Without them, boards would have to take management’s word about the status of the company. “They’re always going to tell you it’s fine even if it isn’t. I say always, but they almost always will. They’re not going to come and tell on themselves…If you’re accepting investor money, you should have a system of controls in place to ensure that that money is well protected,” he said.

News built for finance pros

CFO Brew helps finance pros navigate their roles with insights into risk management, compliance, and strategy through our newsletter, virtual events, and digital guides.

By subscribing, you accept our Terms & Privacy Policy.

Competing for IPOs. Competition among exchanges for listings could be a factor in the proposal, Chambers wrote in a recent blog. The Nasdaq, which doesn’t require listed companies to have an internal audit function, has snagged some of the biggest IPOs this year, including the $75 billion offering from SpaceX. The $100 billion deal from Anthropic is also listing on the Nasdaq, according to Business Insider.

What worries Chambers, though, are the mid-sized and small companies seeking to go public that will be wondering, “how much regulation do I have to adhere to?” he said.

As of Sept. 22, 97% of the 128 comments the SEC received objected to the NYSE’s rollback of the audit rule, according to an analysis published by Professor Tzachi Zach at Ohio State University and Professor Sarah McVay of the University of Washington.

The SEC has to approve or reject the NYSE proposal. “I’m not optimistic that we’re going to have been heard, but at least we didn’t go down without a fight,” Chambers said.

The SEC declined to comment. The NYSE did not respond by the time of publication.

About the author

Luisa Beltran

CFO Brew

CFO Brew helps finance pros navigate their roles with insights into risk management, compliance, and strategy through our newsletter, virtual events, and digital guides.

By subscribing, you accept our Terms & Privacy Policy.