Audit Committee Pre-Approval Requirements: SEC & PCAOB Rules

Every service a registered public accounting firm provides to its public company audit client must be approved by the company’s audit committee before the work starts. That is the core of the audit committee pre-approval requirements set by the Sarbanes-Oxley Act and enforced through SEC Regulation S-X and PCAOB standards. There is no materiality threshold, no small-engagement carve-out, and almost no ability to ratify work after the fact. If a service was not properly pre-approved, the auditor was not independent for that period, and the financial statements filed during that period may not comply with SEC rules.

The statutory source is Section 202 of Sarbanes-Oxley, codified at 15 U.S.C. § 78j-1(i), which requires audit committee pre-approval of all auditing services and all permissible non-audit services provided to an issuer by its auditor.1Office of the Law Revision Counsel. 15 USC 78j-1 Audit Requirements The SEC operationalizes that mandate in Rule 2-01 of Regulation S-X: an accountant is not independent unless the audit committee approved the engagement before work began.2eCFR. 17 CFR 210.2-01 Qualifications of Accountants PCAOB Rules 3521 through 3524 add further conditions, particularly for tax work.3Public Company Accounting Oversight Board. Section 3 Auditing and Related Professional Practice Standards

Services the Committee Cannot Approve at All

Before the committee thinks about approving anything, it has to know what falls outside its authority entirely. Section 201 of Sarbanes-Oxley lists nine categories of non-audit services that an independent auditor may not perform for its audit client under any circumstances:1Office of the Law Revision Counsel. 15 USC 78j-1 Audit Requirements

  • Bookkeeping or other services related to the client’s accounting records or financial statements.
  • Financial information systems design and implementation.
  • Appraisal or valuation services, fairness opinions, and contribution-in-kind reports.
  • Actuarial services.
  • Internal audit outsourcing.
  • Management functions or human resources work, including acting as a director, officer, or employee, or performing recruiting.
  • Broker, dealer, investment adviser, or investment banking services.
  • Legal services and expert services unrelated to the audit.
  • Any other service the PCAOB determines by regulation to be impermissible.

The common thread is self-review. An auditor who builds an accounting system, runs an internal audit function, or values an asset ends up auditing its own work later. The statute treats these conflicts as unfixable, so no vote by the audit committee, and no fee cap, can bring them inside the rules.

Services That Can Be Pre-Approved

Anything outside the nine prohibited categories is permissible in principle, but still requires pre-approval before the auditor begins. Tax services are the largest permissible category and carry the most specific conditions.

Tax Services

Three PCAOB rules govern tax work. Rule 3521 bars any tax service provided on a contingent-fee basis; if the auditor’s pay depends on a particular tax outcome, independence is broken.3Public Company Accounting Oversight Board. Section 3 Auditing and Related Professional Practice Standards Rule 3523 prohibits the auditor from providing personal tax services to individuals in financial reporting oversight roles at the audit client, including the CEO, CFO, chief accounting officer, controller, and their immediate family members. Narrow exceptions apply to board members whose oversight role exists only through board service, and to engagements already underway when someone moves into an oversight role, as long as the work wraps up within 180 days.

Rule 3524 sets the procedural requirement. Before the committee can approve a tax engagement, the auditor must provide a written description of the scope, the fee structure, any side letters, and any compensation arrangements with third parties tied to the service. The auditor and the committee must discuss the potential effects on independence, and the substance of that discussion must be documented.

Audit-Related and Other Permissible Work

Due diligence for acquisitions, benefit plan audits, and consultations on new accounting standards are typical audit-related services. They generally raise a lower independence risk than tax work, but the committee still has to look past the label and confirm the actual work does not slip into a prohibited category or put the auditor in a management position.

How the Committee Grants Pre-Approval

Rule 2-01 gives the audit committee two procedural paths, plus a limited ability to delegate.2eCFR. 17 CFR 210.2-01 Qualifications of Accountants

Specific Pre-Approval

The committee votes on each engagement individually. The auditor or management presents the scope, estimated fees, and rationale for using the independent auditor instead of another firm, and the committee acts before any work begins. This method fits large, unusual, or one-off projects where the committee needs to weigh the independence implications directly.

Policy-Based Pre-Approval

For recurring, predictable services, the committee can adopt standing pre-approval policies. Under the SEC rule, those policies must be “detailed as to the particular service.” A category as broad as “tax services” does not satisfy the requirement. A compliant policy identifies specific service types, sets fee limits per engagement or category, defines the conditions under which the service can proceed without a separate vote, and is reviewed by the full committee at least annually. The policies cannot hand the committee’s decision authority to management. If management is picking which services get approved, the policy is invalid no matter how detailed it looks on paper.

Delegation to Individual Members

The statute allows the committee to delegate pre-approval authority to one or more of its independent members, which solves the practical problem of engagements arising between scheduled meetings.1Office of the Law Revision Counsel. 15 USC 78j-1 Audit Requirements Any decision by a delegated member must be reported to the full committee at its next scheduled meeting, and the delegation itself must be documented in the committee charter or a formal resolution. Delegating to management is never permitted.

The De Minimis Exception

A narrow safety valve exists for non-audit services that were not pre-approved. All three conditions must be satisfied at once:1Office of the Law Revision Counsel. 15 USC 78j-1 Audit Requirements

  • Total fees for all non-pre-approved non-audit services do not exceed 5% of the total fees paid to the auditor during that fiscal year.
  • The services were not recognized as non-audit services at the time of the engagement, which is a factual determination that gets harder to defend the more often a company relies on the exception.
  • The services are promptly brought to the audit committee and approved before the audit is completed.

The SEC’s rule mirrors these conditions.2eCFR. 17 CFR 210.2-01 Qualifications of Accountants The exception was written for genuinely ambiguous situations, not as a backup approval mechanism. Companies that know they are engaging their auditor for non-audit work cannot rely on it.

What a Pre-Approval Failure Costs

There is no general cure for a missed pre-approval. If a service was not pre-approved and does not qualify for the de minimis exception, the auditor was not independent for the affected period, which can force a restatement or a re-audit by a different firm.

The SEC has brought enforcement actions on these points. In 2019, PricewaterhouseCoopers agreed to pay more than $7.9 million in disgorgement, interest, and penalties after the SEC found that the firm had provided non-audit services to 15 audit clients without meeting PCAOB requirements for written descriptions of the engagement and documented independence discussions with the audit committee.4U.S. Securities and Exchange Commission. SEC Charges PwC LLP With Violating Auditor Independence Rules The failures were procedural rather than exotic.

Fee Disclosures After the Fact

Approval leads to disclosure. Schedule 14A requires companies to report the fees billed by their independent auditor for the last two fiscal years in four categories:5eCFR. 17 CFR 240.14a-101 Schedule 14A Information Required in Proxy Statement

  • Audit Fees, for the annual audit, quarterly reviews, and services normally provided in connection with statutory or regulatory filings.
  • Audit-Related Fees, for assurance and related services reasonably related to the audit but not counted as audit fees, with a description of the services.
  • Tax Fees, for tax compliance, advice, and planning, with a description.
  • All Other Fees, for anything else, with a description.

Companies that use policy-based pre-approval must also disclose the policies themselves and explain how the committee concluded that the approved non-audit services were compatible with the auditor’s independence. That disclosure lets investors see how much the auditor earns from non-audit work relative to the audit itself, which remains the clearest independence signal available to shareholders from public filings.