A beautiful view of a cityscape surrounded by colorful autumn trees in Pittsburgh, Pennsylvania

2026 Q3 Audit committee update

The evolving risk landscape is raising new questions for audit committees about resilience, reporting and readiness.


In brief
  • Geopolitical disruption, macroeconomic conditions, cyber risks, AI, supply chain changes, and other shifts are top of mind for audit committees this quarter.
  • Given today’s threat landscape, connecting emerging risks to strategy and testing resilience will strengthen oversight of AI and cyber.
  • Audit committees are watching evolving FASB, SEC and PCAOB priorities and the related impacts on reporting and disclosure requirements.

Five areas audit committees should watch next

As audit committees prepare for the quarter ahead, they should consider the following themes as they set agendas. Additional context is provided below.

Risk oversight must be more connected and forward-looking

Geopolitical disruption, tariff uncertainty, AI, cyber risk, market volatility and regulatory change are converging across operations, supply chains, technology environments and capital allocation decisions. Audit committees should challenge whether management is assessing these risks collectively (and their interdependencies) and with sufficient visibility into second- and third-order impacts.

Resilience should be tested, not assumed

Companies may be accustomed to disruption, but the current environment requires more rigorous scenario planning, stress testing, liquidity discipline and third-party dependency mapping. Audit committees should understand the triggers, thresholds and contingency actions management would use if conditions deteriorated.

AI governance is entering a more disciplined phase

As AI moves from experimentation to scaled deployment, boards are focusing on cost, return, accountability and control. Audit committees should ask whether management has clear decision rights, reliable cost and value measures, appropriate data and model controls, and cyber defenses that can keep pace with AI-enabled threats.

Financial reporting implications need early attention

Tariffs, supply chain changes, inflation, interest rates, impairment indicators, liquidity pressures, tax developments, cyber incidents and AI-enabled processes may affect judgments, estimates, disclosures and internal controls. Audit committees should confirm that disclosure controls and ICFR remain responsive to the current risk environment.

Regulatory change may create both relief and new oversight demands

FASB, SEC and PCAOB developments could affect disclosure requirements, enforcement expectations and audit quality discussions. Audit committees should monitor rulemaking progress and outcomes, being mindful to consider potential implications for investor communications, audit planning and governance practices.

Risk management

Audit committees enter Q3 with a risk agenda shaped by continued uncertainty, rapid technology changes and increasing interdependence across business ecosystems. The priority is not to monitor more risks, but to understand which developments could materially affect strategy, performance, resilience, reporting and capital allocation. Audit committees should continue to challenge whether management is connecting risks across the enterprise, revisiting key assumptions and defining clear triggers, thresholds and contingency actions as conditions evolve. Key areas for Q3 audit committee attention include:

  • Geopolitical and economic uncertainty continue to test organizational resilience.
  • Emerging technology risks are expanding the board’s oversight agenda beyond AI.
  • AI is accelerating cybersecurity risk and creating new resilience challenges across the enterprise.
  • The economics of AI are driving greater scrutiny of costs, returns and governance.

Download the full report for more details.

Financial reporting and internal controls

Audit committees should continue to assess whether financial reporting judgments, disclosures and internal controls remain responsive to the current operating environment. This includes understanding how macroeconomic volatility, tariff and trade developments, technology changes, cyber risk and evolving regulatory expectations may affect estimates, controls, liquidity, MD&A and investor communications. Download the full report for details on disaggregated income statement expenses and company-specific MD&A disclosures.

SEC rulemaking and other regulatory considerations

The SEC has continued to execute on its ambitious agenda focused on capital formation, compliance burden reduction and the creation of a more welcoming environment for digital assets. In July, the SEC released its 2026 regulatory agenda, which includes 38 rulemaking projects. In remarks on the agenda, SEC Chairman Paul Atkins said that the Commission is “embracing innovation and new technology,” working to revitalize the public markets and to facilitate retail investor participation in private markets. Planned rulemakings could reduce disclosure and reporting obligations and impact capital raising strategies for public companies, including by amending executive compensation disclosure requirements, modernizing custody rules for crypto assets and expanding retail investor access to private markets.

Chairman Atkins has focused on stakeholder engagement in his pursuit to “make IPOs great again.” In a May speech, he also solicited public comment on “broader ideas for modernizing IPOs overall,” emphasizing the need to dismantle “the barriers that drove companies away in the first place.” He added that “overly burdensome SEC rules may not be the sole reason for this decline—but where regulatory frictions are a determinant of it, the agency is moving intently to remove them.” In July, the Commission hosted a discussion with public market practitioners on innovative approaches and regulatory solutions to improve access to public markets.

 

In August, the SEC proposed new rules for crypto assets that would, among other things, provide two exemptions from registration under the Securities Act of 1933 for covered investment contracts. The proposal would create a startup exemption for offerings of up to $5 million over four years and a two-tier fundraising exemption for offerings of up to $20 million under Tier 1 and up to $75 million under Tier 2 in any 12-month period. Comments on this proposal are due on 20 October 2026.

The Commission also issued the highly anticipated “innovation exemption” in September, which provides five-year exemptive relief to certain securities trading venues and liquidity providers to facilitate on chain trading of tokenized National Market System securities.

The Commission took steps to modify the shareholder proposal framework in September, issuing a proposal to rescind SEC Rule 14a-8, which governs when public companies must include non-binding shareholder proposals in their proxy materials. If adopted, only state law would govern the treatment of these proposals.

With comment periods now closed on other rule proposals, including those to allow semiannual reporting, simplify the filer status framework, rescind climate-related disclosure rules and enhance the registered offering reform process, as well as on the request for comment on IPO modernization, the Commission is weighing stakeholder feedback before it finalizes rule amendments. While the proposals reflect priorities supported by the current Commission, the timing and scope of any final amendments remain uncertain.

 

On enforcement, the SEC announced the launch of a new Financial Reporting and Accounting Unit dedicated to pursuing “accounting and financial reporting fraud cases as well as general misconduct in the accounting and auditing areas.” It also has rescinded its “no-admit/no-deny” policy, which had been in place for more than 50 years and required registrants settling with the Commission to agree not to publicly deny the allegations against them. When rescinding the policy, the Commission also stated it will not enforce the policy in settlements already in place. In another Division of Enforcement development, Principal Deputy Director Sam Waldon departed and was succeeded by Osman Nawaz, who previously served in the Division and now also oversees its specialized units.

Audit committees should monitor whether the SEC’s recent action could affect the company’s disclosure roadmap, capital markets strategy and investor communications, including how the company prepares for potential SEC staff comments or questions.

Download the full report for more details including updates on PCAOB developments and questions for audit committees to consider.


Reports from previous quarters

2026 Q2 audit committee update

2026 Q1 audit committee update

2026 audit committee priorities


Summary

Audit committees face an increasingly interconnected agenda spanning geopolitical and economic uncertainty, emerging technology, cyber risk, AI governance, financial reporting and regulatory change. Effective oversight requires more than monitoring developments. By working with management and asking the right questions, audit committees can effectively support readiness, reporting quality and organizational resilience.

About this article

Authors

Related articles

Remaking risk oversight: How boards can support risk-aligned strategy

Boards can strengthen resilience and growth by integrating risk into strategy, defining risk appetite and anticipating emerging threats.

How boards can lead in a world remade by AI

Learn how AI is reshaping business and how effective board oversight of AI can guide companies for what’s next.

Cyber and AI oversight disclosures: what companies shared in 2025

Find out what Fortune 100 companies disclosed in 2025 about cyber and AI oversight.