The Sarbanes Oxley Privilege For Public Company Accounting Oversight Board Materials: Its Implications For SEC Enforcement Proceedings

Andrew J. Morris*

I.         Introduction

In 2002, a wave of high-profile accounting scandals led Congress to pass the Sarbanes-Oxley Act—“SOX.”[1] In SOX, Congress created the Public Company Accounting Oversight Board—the “PCAOB”—and charged it to oversee the auditors of public companies.[2] The PCAOB soon began inspecting accounting firms. According to knowledgeable commentators, these inspections have significantly improved the audits of public-company financial statements.[3]

Recent developments, however, threaten to undermine one of the critical foundations of the PCAOB oversight program: the “SOX privilege.” This statutory privilege ensures that the details of PCAOB inspections and investigations remain confidential.[4] The threat to this privilege arises when the PCAOB shares information with other regulators, including the Securities and Exchange Commission (“SEC” or the “Commission”). SOX permits this sharing, but only on the express condition that the receiving regulator must preserve the SOX privilege.[5] SOX makes this condition quite plain, stating that regulators who accept privileged information from the PCAOB “shall maintain such information as confidential and privileged.”[6]

The problem is that some private litigants, some SEC staff, and at least one court do not read this simple mandate to mean what it says. They find it counterintuitive—and therefore hard to accept—that a statute would restrict the SEC’s use of information it obtains from the PCAOB. This resistance to the statutory language is apparent in Securities & Exchange Commission v. Goldstone, 301 F.R.D. 593 (D.N.M. 2014), the first judicial opinion on the issue. In Goldstone, the United States District Court for the District of New Mexico concluded that when the SEC brings enforcement actions, it can disclose privileged information received from the PCAOB.[7]

This article explains how Goldstone misreads SOX. Part I briefly outlines why the privilege is critical to the success of the PCAOB’s inspection regime, and Part II sketches its statutory basis. Part III explains how Goldstone undermines the SOX privilege and, in turn, threatens to weaken the entire PCAOB oversight regime. Part III then shows that Goldstone creates practical problems for the PCAOB, for the auditing profession it oversees, and paradoxically, for the SEC itself. Finally, Part IV suggests that, in order to resolve these issues, the SEC should adopt a formal policy relating to PCAOB materials that acknowledges the full force of the SOX privilege and establishes internal procedures for working with materials covered by the privilege.

II.         The SOX Privilege Provides Confidentiality That Is Critical to the PCAOB’s Successful Inspection Regime

A.          The Effectiveness of the PCAOB’s Predecessor Was Hampered by the Absence of a Privilege Protecting Its Inspections

During the hearings that led Congress to pass SOX, several prominent witnesses criticized the audit regulator at the time (the predecessor to the PCAOB) as “ineffective.”[8] One reason for this ineffectiveness, according to the regulator itself, was its inability to shield its oversight process from private litigants who wanted information for lawsuits against accounting firms.[9]

The SEC, after conducting its own study of audit regulation, also concluded that confidentiality was important to effective oversight. It wrote at the time that auditing firms “may be less forthcoming in responding to [an auditing regulator] inquiry if they believe that the information they provide will be made public or made available to private litigants.”[10] It also warned that a failure to ensure confidentiality could harm audit quality, injure accounting firms unfairly, and harm the shareholders of the companies involved.[11]

B.          The Privilege Created by SOX Enables the PCAOB to Conduct Inspections That Are Effective Because They Are Cooperative Rather Than Adversarial

Congress provided this confidentiality when it passed SOX and established an improved oversight regime. The cornerstone of this regime is the PCAOB’s inspection program,[12] which examines accounting firms responsible for auditing 98 percent of U.S. market capitalization.[13] This program relies on a process that is cooperative rather than adversarial, and the SOX privilege is critical to maintaining a cooperative, frank exchange of information between the regulator, and the regulated.

Each inspection involves extensive dialog between the PCAOB and the inspected firm.[14] In a typical inspection, the PCAOB inspectors select a sample of the firm’s audit engagements, review audit workpapers and other materials, talk to auditors and other firm representatives, and then provide criticisms and suggestions.[15] The inspectors and the firm then exchange oral and written comments, typically in several informal rounds.[16] Often the firm agrees to make auditing changes proposed by the inspectors.[17] Ultimately the PCAOB issues a final inspection report, which the firm can ask the SEC to review.[18]

Congress specifically chose this interactive and constructive process.[19] As the PCAOB has explained, SOX “reflects a legislative policy choice favoring the correction of quality control problems over the exposure of them.”[20] For this reason, it “generally seeks, in its inspection program, to encourage constructive engagement, rather than to put firms in a position where they will perceive that their self-interest is better served by an adversarial and confrontational posture.”[21]

Accounting firms can safely participate in this “constructive engagement” only if they know that their compromises with the PCAOB will remain confidential and, therefore, will not be cited against them as evidence that audit work was inadequate.[22] The SOX privilege provides the necessary confidentiality by shielding PCAOB inspection and enforcement details from disclosure to third parties (with a narrow exception that is described below).[23]

The privilege thus gives auditors an incentive to accept the PCAOB’s comments and adjust audit procedures to address them. Because the SOX privilege permits auditors to agree with PCAOB inspectors without fear of incurring liability, it is a linchpin of the cooperative regulatory scheme.

According to the PCAOB, this guarantee of confidentiality has contributed to the effectiveness of the inspection program.[24] By 2007, the PCAOB reported that it was increasingly able to “foster improvement in audit quality through the on-site dialogue the inspection process allows for, in addition to more formal findings in inspection reports and other oversight actions.”[25] The PCAOB also reported that firms have routinely agreed to “perform[] missed or additional auditing procedures” on specific audits, and to make changes “to the firm’s internal quality control processes and systems.”[26] It concluded that “the effectiveness and the efficiency of the Board’s programs are enhanced when firms opt for constructive engagement rather than an adversarial approach.”[27]

III.        SOX Expressly Requires the SEC to Preserve the Privilege When It Receives Privileged Material from the PCAOB

A.          Subparagraph (A) Of Section 105(b)(5) Establishes The SOX Privilege

Congress established the SOX privilege in SOX Section 105(b)(5).[28] Subparagraph 105(b)(5)(A), titled “Confidentiality,” sets out the privilege’s basic elements.[29] Subparagraph (A) begins with a carve-out (“Except as provided in subparagraphs (B) and (C) . . . .”),[30] which excludes material that the PCAOB passes along to other regulators. This material is governed by Subparagraphs (B) and (C), which are discussed in Part II.B below. [31]

Subparagraph (A) then identifies the broad range of material it does govern: “all documents and information prepared or received by or specifically for the Board, and deliberations of the Board and its employees and agents, in connection with an inspection . . . or with an investigation.”[32]

The subparagraph next describes the protection provided by the privilege: The SOX privilege shields the governed material from “civil discovery or other legal process” and from introduction into evidence.[33] It then identifies the broad range of forums where the privilege applies: “any proceeding in any Federal or State court or administrative agency.”[34]

Finally, Subparagraph (A) says how the privilege can be terminated.[35] It states that information remains privileged “unless and until presented in connection with a public proceeding or released in accordance with [SOX Section 105(c)].”[36] That subsection, titled “Disciplinary procedures,” addresses disciplinary PCAOB proceedings against auditors.[37]

B.          Subparagraph (B) Permits the PCAOB to Share Privileged Information with Other Regulators—But Only on the Express Condition That Those Regulators Preserve the Privilege

Next in SOX Section 105(b)(5), subparagraphs (B) and (C) govern the material carved out of subparagraph (A). They permit the PCAOB to share information with regulators in the United States (Subparagraph (B)) and elsewhere (Subparagraph (C)).[38]

Subparagraph (B), titled “Availability to Government agencies,” authorizes the PCAOB to share privileged material with “(i) [T]he Commission; [and] (ii) [other enumerated regulators, including] the Attorney General of the United States[,] State attorneys general, . . . state regulatory authorit[ies]; and [certain] self-regulatory organization[s] . . . .”[39] Crucially, however, it requires that those entities “maintain such information as confidential and privileged.[40] This is the provision that binds the SEC to preserve the privilege for material it receives from the PCAOB.

IV.         The Court in SEC v. Goldstone Erred When It Held that the SEC Can Disclose Privileged Material Received from the PCAOB

In sum, SOX Section 105 permits the PCAOB to share privileged material with other regulators, but only on the condition that those regulators “maintain such information as confidential and privileged.”[41] The statutory language and structure are simple. Yet the one judicial opinion on the issue, SEC v. Goldstone, declines to enforce the statute as written.

A.          The Court Overrode SOX’s Plain Language to Create an Exception to the Mandate that the SEC “Shall Maintain” the Privilege

1.          The Goldstone Court’s Reading of the Statute

Goldstone was an SEC enforcement action against several officers of a registrant.[42] During the litigation’s discovery phase, the officers demanded that the SEC produce documents it had previously received from the PCAOB.[43] The PCAOB had generated these documents when it had investigated the registrant’s auditor.[44] Then, under the authority granted to it under Subparagraph (B) of SOX Section 105(b)(5), the PCAOB had transmitted the documents to the SEC during the SEC’s investigation of the registrant’s management.[45] When these documents were created, they were covered by the SOX privilege—a point not disputed by any party in Goldstone.[46]

The Goldstone defendants moved to compel the SEC to produce this material, arguing that it no longer was privileged.[47] They contended that the SEC had relied on the material when it drafted its complaint;[48] the defendants then pointed to the clause at the end of SOX Section 105(b)(5)(A) providing that the privilege is terminated if material is “presented in connection with a public proceeding.”[49] The defendants argued that the SEC had “presented” the material “in connection with a public proceeding” by relying on it to draft the complaint in the enforcement case. [50] The SEC opposed the defendants’ motion, in particular contending that it had not relied on the documents when it drafted the complaint in this case.[51]

The registrant’s auditor intervened in the litigation.[52] Like the SEC, the accounting firm opposed the defendants’ motion to compel.[53] But unlike the SEC,[54] the firm disputed the very first step in the defendants’ argument: The firm contended that SOX prohibited the SEC from disclosing the PCAOB documents whether or not the SEC had relied on them to draft the complaint.[55] In support, the firm cited Subparagraph (B)’s mandate that the SEC “shall maintain” SOX-privileged “information as confidential and privileged.”[56] It also pointed out that this mandate contains no exceptions.[57]

The court disagreed with the accounting firm and concluded that, despite this mandate, the SEC had the authority to disclose the material.[58] The court ultimately did not order the SEC to produce the documents, though only because it found that, as a factual matter, the SEC had not actually relied on them in the litigation.[59] But the damage to the SOX privilege was done, because the court had already concluded that the SEC has the authority to terminate the privilege.[60]

To reach this conclusion, the court first turned to the SOX clause stating that covered information remains privileged “unless and until presented in connection with a public proceeding or released in accordance with subsection (c).”[61] This clause is contained in Subparagraph (A), not Subparagraph (B), and is the only clause in the statute that addresses termination of the privilege. The court construed the word “proceeding” to refer, not only to PCAOB disciplinary proceedings, but also to SEC litigation. In other words, the court reasoned, this clause indicated that the SEC has the authority to terminate the SOX privilege by “presenting” privileged material in its own litigation.[62]

The court’s reading of this Subparagraph (A) clause to include SEC litigation was clear error, as explained below. But even in light of its reading of Subparagraph (A), the court still was confronted with Subparagraph (B)’s explicit mandate that the SEC “shall maintain” the privilege.[63] This mandate contains no written exceptions.[64]

The court proceeded to infer an exception that is unwritten. The court reasoned that it makes no sense to permit the SEC to receive privileged information from the PCAOB—as the first part of Subparagraph (B) permits—while also requiring the SEC to keep that information confidential—as the latter part of Subparagraph (B) requires.[65] The court explained its reasoning: “If the Attorney General or the SEC could never bring an action and present the information, there would be no useful reason to share the information.”[66]

Although the court also reasoned that “the ‘until presented’ language [in Subparagraph (A)] would not mean anything” if the SEC were not permitted to “present” PCAOB information in SEC litigation, the court reiterated that the decisive factor was the Subparagraph (B) provision permitting the PCAOB to share information with the SEC.[67] The court thus summed up: “The Court is not sure what benefit it would be for the PCAOB to share documents and information from its investigations or inspections,” as Subparagraph (B) permits, “if the SEC or other government agencies may not then use the information.”[68]

2.          Flaws in the Court’s Reasoning

The court’s discussion makes a hash of the statute. To begin, Subparagraph (A)’s “unless and until presented” clause does not apply to material that the PCAOB discloses to the SEC. That material is covered by Subparagraph (B), and Subparagraph (A) begins with the simple carve-out clause, “Except as provided in Subparagraph[] (B).” The court thus erred by even considering the “unless and until presented” clause.[69]

In any event, although the court cited this clause, the decisive factor for the court was Subparagraph (B)’s provision permitting the PCAOB to share privileged information with the SEC.[70] Based on the court’s view of the purpose of this sharing provision, the court overrode the plain text of the privilege requirement contained later in the same subparagraph—in fact, later in the same sentence. It did so based on its belief that a more sensible statute would permit the SEC to use PCAOB information in its own litigation. The court apparently concluded that, if Congress had thought about it, Congress would have created an exception permitting the SEC to use this information in enforcement matters.

This reasoning has no basis in the statute’s words or structure; it overrides both in pursuit of a better policy. And that pursuit rests on another error: the assumption that, unless the SEC can use PCAOB material in enforcement actions, it cannot use the material at all. But SOX does permit the SEC to use PCAOB materials for other purposes—purposes that are quite important. In particular, the SEC can use this information to inform its oversight of the PCAOB as well as to support its responsibility for rulemaking relating to financial-statement audits.[71] These uses do not require the Commission to break the SOX privilege. On the other hand, SOX itself shows that Congress was aware of the possible use for which the Goldstone court created an exception: litigation relating to the audits at issue.[72] Yet, Congress did not create an exception permitting use of PCAOB material in litigation outside the PCAOB.

Congress also knew that the SOX privilege does what every legal privilege does: It forbids the discovery and use of evidence that may be relevant in litigation.[73] Yet Congress chose to require regulators, specifically including the SEC, to preserve the SOX privilege.

The court’s reasoning suffers from one more flaw. Not only did the court override clear text based on a policy goal, it chose a policy goal that conflicts with the one that motivated the statute at issue. The court’s policy goal was to increase the SEC’s authority in enforcement cases, but the statute’s policy goal was to improve the oversight regime for financial-statement audits—and to do so by ensuring that PCAOB oversight activities remain confidential.[74] The Goldstone court’s conclusion works against that goal by opening a hole in the shield of confidentiality—thus working against Congress’s purpose in creating the SOX privilege in the first place.

B.          The Goldstone Holding Upsets the Information-Sharing Scheme Established by SOX and Works Against SOX’s Statutory Purpose

Applied to other cases, the Goldstone holding can lead to the disclosure of reams of PCAOB-related documents that, to date, have been shielded by the SOX privilege. When Subparagraphs (A) and (B) are read correctly—with no inferred exceptions—SOX-privileged information can be disclosed only by the PCAOB, and only in a specific, narrow context. This context is limited to final orders in PCAOB disciplinary actions that result in sanctions against an auditor or firm.[75] These orders disclose a limited amount of privileged information, because an order describes only the facts that are relevant to the final decision.[76] The PCAOB does not disclose any privileged documents at all.[77]

By contrast, the Goldstone reading of SOX permits the SEC to produce extensive amounts of privileged information. By producing PCAOB material in discovery, the SEC can disclose extensive documentary records otherwise covered by the SOX privilege: for example, entire histories of firm inspections, files of correspondence with auditors, and volumes of the extensive testimony that the PCAOB takes during its investigations. Once these documents are disclosed, they are available to any third party with access to a subpoena—indeed, once the documents have been disclosed, third parties could subpoena them directly from the SEC. Goldstone thus creates a glaring anomaly: It gives the SEC, and through it these unknown third parties, far broader authority to disclose PCAOB oversight materials than the statute gives the PCAOB itself.[78]

In sum, Goldstone re-creates the same problems that led SOX’s drafters to create the privilege in the first place, because it weakens the protection the privilege provides to accounting firms. This result works against Congress’ purpose in adopting the SOX privilege.[79]

C.         The Court’s Opinion Conflicts with the Stated Position of the PCAOB

Goldstone also presents the PCAOB itself with significant compliance and ethical issues, as well as complications in its relationship with the SEC. The PCAOB has stated that it reads SOX to prohibit agencies from disclosing privileged information that the PCAOB shares with them.[80] For this reason, the PCAOB already has warned that, if an agency did disclose privileged information, the PCAOB could exercise its discretion to decline to provide requested information or could “require appropriate assurances of confidentiality.”[81] Against this background, Goldstone puts the PCAOB in an uncomfortable bind.

V.         The SEC Should Adopt a Policy Stating That It Will Comply with Its Statutory Duty to Preserve the SOX Privilege

A.         The SEC Staff Has Taken Inconsistent Positions in Litigation

These problems are further complicated by the SEC’s own inconsistent positions on the SOX privilege. In Goldstone the SEC did not dispute that it has the authority to disclose material covered by the SOX privilege.[82] In another enforcement action, the Enforcement Division actually produced privileged information it had received from the PCAOB.[83] In yet another case, however, the SEC properly asserted that SOX Section 105(b)(5)(A) and (B) “expressly prohibit the Commission from turning [materials received from the PCAOB] over in discovery to anyone.”[84] This inconsistency creates various risks for the SEC. Among other problems, it could invite arguments that the Commission’s positions are arbitrary and capricious—arguments that conceivably could lead to reversal of a judgment in the SEC’s favor.[85]

B.         An Express SEC Policy Could Ensure Compliance with SOX and Restore Certainty to the Privilege Protection that Is Critical to the PCAOB’s Oversight Regime

Without waiting for the courts to correct Goldstone, the SEC can and should restore certainty to the SOX privilege by adopting a written policy that governs information it receives from the PCAOB. The policy should acknowledge the SEC’s statutory obligation to “maintain” covered information as “confidential and privileged.”[86] It should include a process through which senior staff evaluates the risks in each case before the SEC even requests privileged material from the PCAOB.

The policy also should include procedures to ensure that, once the SEC does take possession of privileged material, it can show that it did not waive the privilege. (Although the proper reading of SOX indicates that the SEC cannot waive the privilege, even inadvertently, litigating that point in multiple enforcement proceedings would be costly and wasteful.)[87] A policy should establish that SEC Staff will oppose any discovery demands for privileged material. The policy also should require the Staff to notify the PCAOB and the relevant accounting firm about any such demands.

Such a policy would not hinder the SEC’s enforcement efforts. Preserving the SOX privilege does not reduce access to the types of evidence the Enforcement Division routinely obtains in accounting cases, such as audit workpapers and auditor testimony.[88] And PCAOB-inspection materials have no real evidentiary value anyway; inspection reports are non-adjudicated statements that, as the PCAOB has warned, “are not intended to result in conclusive findings.”[89]

Nor would a policy preserving the SOX privilege cause any prejudice to the defense in SEC enforcement actions. Like the SEC, respondents would still have the rights to use the usual discovery tools.[90] And Section 105’s statement that privileged information is inadmissible as evidence protects respondents in administrative proceedings and defendants in civil litigation from use of this information against them.[91]

While such an SEC policy would not hinder either side in enforcement actions, its benefits would be substantial. It would ensure that SEC Staff take an informed, uniform position on the SOX privilege. It would give the Staff guidance about appropriate practices for working with PCAOB materials. And it could help avoid the substantial collateral litigation, as seen in Goldstone, that can flare up when the SEC possesses privileged information.

A written policy also would guide the proper development of the law. Most judges have no experience with the PCAOB, and they would give considerable weight to the view of the agency that exercise oversight over it.

An SEC policy also would guide other regulators to which the PCAOB may provide SOX-privileged information, including the Department of Justice, state attorneys general, and other regulatory bodies.[92] SOX Section 105(b)(5)(B) requires these regulators to preserve the privilege.[93] When these regulators analyze their privilege obligations under SOX, they are likely to give considerable weight to the views of the SEC, which is the agency with the most expertise on the issue.

Most importantly, by removing much of the uncertainty created by Goldstone and the SEC’s litigation positions, a policy would strengthen the PCAOB inspection system. It would assure the PCAOB that information it provides to the SEC will remain confidential. This assurance would, in turn, preserve the ability of auditing firms to cooperate fully and freely with the PCAOB without fear that their cooperation could be used against them. All of these developments would contribute to improved audit quality, which is the goal established by Congress and shared by the PCAOB and the SEC.[94]


Preferred citation: Andrew J. Morris, The Sarbanes Oxley Privilege For Public Company Accounting Oversight Board Materials: Its Implications For SEC Enforcement Proceedings, 5 Harv. Bus. L. Rev. Online 87 (2015),

* Andrew J. Morris is a partner in Morvillo LLP.

