Professional Skepticism Is Not a Personality Trait
How the accounting profession stopped trusting its own judgment — and built a maintenance schedule instead
Close your eyes and picture a professional skeptic. Someone constitutionally unable to take your word for it. Immune to charm. Unmoved by your explanation of why this particular quarter was unusual.
You pictured an accountant.
It is a decent joke and a terrible assumption, and the profession itself is the party that figured that out. Every significant safeguard in accounting over the last twenty-five years was built on the premise that the person you just imagined does not reliably exist — and each one was added after somebody proved it.
That is the part I find worth writing about. Not the rules. The posture. This is a profession whose entire product is objectivity, and which concluded, in writing, that objectivity cannot be left to the objective.
The Assumption the Profession Gave Up On
For most of its history the profession treated skepticism as a character trait. You hired careful people, credentialed them, held them to a code, and trusted the code to hold.
The problem with that model is not that accountants turned out to be dishonest. It is that character is not auditable. You cannot test it, you cannot document it in a workpaper, and you cannot tell from the outside whether a judgment was independent or merely comfortable. The judgment looks identical either way.
So the profession moved skepticism out of the person and into the structure. Not all at once, and never preemptively. In layers, each one added after a failure that made the previous layer look naive.
There are four of those layers, and they do four completely different jobs. They get lumped together as “accounting rules,” which is how most business owners come to believe the whole apparatus is one undifferentiated mass of compliance. It is not. Understanding which layer does what is the difference between reading your own financial statements and merely receiving them.
Layer One: Fix the Yardstick
The first layer is the one everyone knows by name and almost nobody understands the purpose of. GAAP. The Accounting Standards Codification, which in 2009 collapsed decades of scattered pronouncements into a single referenced structure of authoritative standards for nongovernmental entities. International Accounting Standards and IFRS abroad. And for private companies, the IFRS for SMEs standard — now in its third edition, issued in February 2025 and effective for periods beginning on or after January 1, 2027, currently permitted or required in 85 jurisdictions.
None of these standards say a word about ethics. That is not their job.
Their job is to remove discretion from the preparer, and the reason that matters is subtler than it sounds. A shared yardstick does not make anyone more honest. It makes disagreement possible. When both parties are measuring the same way, “we just look at it differently” stops being an available answer, and the conversation is forced onto the facts.
That is what standardization actually buys. Not accuracy — comparability. The ability to be challenged. A business that keeps its books on a framework nobody else uses has not gained flexibility. It has purchased immunity from being questioned, and it usually does not realize that was the transaction.
Note also what the SME standard represents. The profession did not tell smaller entities to comply with the full framework or go without one. It built a scaled version. Simplification is not the same as dilution, and a safeguard that only works at enterprise scale is not a safeguard, it is a moat.
Layer Two: Label the Confidence
The second layer answers a question the first one cannot: how hard did anyone actually look?
This is what the Statements on Standards for Accounting and Review Services do, and SSARS No. 21 in 2014 drew the line unusually clearly. Three services, three different levels of work, three different reports.
A preparation engagement produces financial statements with no assurance at all. As a rule each page carries a statement saying so. There is no report, and the accountant is not even required to determine whether he is independent, because he is not attesting to anything.
A compilation adds a report. Still no assurance — but independence must now be assessed, and if the accountant is not independent, the report has to say so.
A review provides limited assurance and requires independence outright.
Here is why an owner should care. “My accountant does my financials” describes all three of those, and they are not remotely the same product. I have watched businesses hand a preparation-level statement to a lender and speak about it as though it had been examined. Nobody lied. The disclaimer was on every page. It simply was not read, because the owner did not know there was a distinction to look for.
That layer is not a safeguard against the accountant. It is a safeguard against the reader — against the natural human tendency to assume that a document which looks authoritative was produced by someone who checked.
Layer Three: Remove the Incentive
The third layer is where the profession stopped being polite about itself.
The AICPA’s independence framework does not ask whether a practitioner feels objective. It catalogs the conditions under which objectivity predictably degrades and names them: self-review, advocacy, adverse interest, familiarity, undue influence, financial self-interest, management participation. Seven threats. You evaluate your situation against them, and if a threat is not at an acceptable level, you apply a safeguard or you decline the work.
Read that list again with your own business in mind. Every one of those threats exists in any organization where the person reviewing the work knows the person who did it.
Sarbanes-Oxley took the same logic and made it statutory for public company audits. Section 201 flatly prohibited nine categories of non-audit services for audit clients — bookkeeping and work on the accounting records, financial information systems design and implementation, appraisal and valuation and fairness opinions, actuarial services, internal audit outsourcing, management functions or human resources, broker-dealer and investment adviser and investment banking services, legal and expert services unrelated to the audit, and anything else the oversight board later deems impermissible. Not restricted. Prohibited, because no disclosure regime fixes a firm auditing its own work.
Section 203 addressed familiarity through rotation: the lead partner and the engagement quality reviewer rotate after five years and sit out five, and other audit partners rotate after seven with a two-year time-out. Section 206 closed the revolving door — a firm loses independence if a client’s financial reporting oversight is staffed by someone who was on the audit engagement team during the year preceding the start of audit procedures.
None of that touches private company work. Rotation, the prohibited-services list, the cooling-off rule — those are issuer rules, enforced by the SEC and the oversight board it created. Private engagements run on the AICPA code instead. But the logic migrated, and the newest AICPA additions go directly at the two pressures you feel in any practice: client mix and fee concentration.
Under the fee interpretations effective January 1, 2025, a firm may not let the provision of other services influence what it charges for attest work — only genuine cost savings from experience already gained on those services may be considered. And where total fees from one attest client represent a large proportion of the firm’s total fees for five consecutive years, independence is impaired unless a safeguard is applied: an appropriate reviewer who is not a member of the firm issuing the report reviews that fifth year’s attest engagement, and does so again each year the dependency continues.
Sit with what that rule concedes. It is not aimed at corruption. It assumes an entirely honest practitioner and a client who has done nothing wrong, and it says the arrangement is unsound anyway. The profession decided that objectivity is not a virtue you carry into a room. It is a condition of the room.
Layer Four: Supervise the Firm, Not the Engagement
The first three layers govern work. The fourth governs the shop that produces it, and this is the layer that behaves most like preventive maintenance.
Peer review has been the backbone for decades — firms performing accounting and auditing work are generally reviewed every three years, as a condition of AICPA membership and, in most states, of licensure. An outside firm examines whether your quality system actually operates.
What changed recently is the standard being reviewed against. Statement on Quality Management Standards No. 1 took effect December 15, 2025, replacing a checklist regime with a risk-based one. A firm no longer demonstrates quality by showing it followed prescribed procedures. It has to identify its own quality objectives, identify the specific risks to those objectives given its own clients and staffing and practice mix, design responses to those risks, and then evaluate whether the whole system worked — formally, by December 15, 2026, and annually after that.
That is the same discipline auditors have been imposing on clients for years, finally turned inward. And the annual evaluation requirement is the entire point. It concedes that a control which was correct three years ago may be worthless today, because the firm changed shape and the control did not.
There is no equivalent of that in most private businesses. Controls get installed at a moment of pain — someone stole, someone quit, a lender asked — and then they are never re-examined, even as the company triples in size and the assumptions underneath them quietly expire.
The Complication I Am Not Going to Skip
Four layers. Roughly a century of accumulated correction. And the profession publishes, in the standard itself, exactly where it all fails.
AU-C 240 governs the consideration of fraud in a financial statement audit. It states that fraud may involve sophisticated and carefully organized schemes designed to conceal it, and that attempts at concealment may be even more difficult to detect when accompanied by collusion — because collusion may cause the auditor to believe that audit evidence is persuasive when it is, in fact, false. It states that the risk of not detecting management fraud is greater than for employee fraud, because management is frequently positioned to manipulate records or override controls directly. And it acknowledges an unavoidable risk that some material misstatements will go undetected even in a properly planned and performed audit.
Everything above — the yardstick, the labeling, the rotation, the fee rules, the annual evaluation — is defeated by two people who agree to lie to you, or by one person with enough authority to step around the control entirely.
I do not read that as a weakness in the apparatus. I read it as the most credible thing in it. A system that claimed to have solved fraud would be advertising, and every safeguard listed here would have to be taken on faith. Instead the profession wrote down its own failure mode and left it where any reader can find it.
That is what makes the rest of the structure trustworthy. Not the promise. The disclosed limit.
What This Is Actually a Model Of
I did not write this to explain accounting standards. I wrote it because the profession did something most organizations never manage, and did it in public.
It treated its own integrity as infrastructure. Something with a design, a failure history, a maintenance schedule, and a documented tolerance. Not a value posted on a wall. A system that gets inspected on a cycle by someone who does not work there, revised when the environment shifts, and honestly described where it does not hold.
Three questions come out of that, and they apply to any business with people, money, and a reporting process.
What does each of my controls assume about the people it governs? If the answer is that it assumes good intentions, it is not a control. It is a hope with a procedure attached. Every rule described above assumes an honest practitioner and constrains him anyway.
When did I last change one? Not enforce — change. A safeguard designed for a nine-person company still running unmodified at forty people is not protecting the company that exists. It is protecting the one that used to.
And which of them survives two people deciding to work around it? Answer that honestly and you will find, as the profession did, that the number is small, and that the correct response is not to pretend otherwise. It is to know which ones, and to say so out loud.
Which brings the joke back around.
Asked to picture an unbiased professional skeptic, you pictured a person. So did the profession, for a very long time. Then it spent a century building the structure that person turned out to need — and the last thing it did was write down what the structure still cannot do.
The accountant in your mind’s eye was never the safeguard. He is who the safeguards were built for.