The SEC’s proposed changes to filer status requirements could significantly change the oversight landscape for many public companies. If adopted, the proposal would raise the threshold for large-accelerated filer status from $700 million to $2 billion in public float and could eliminate the requirement for an independent auditor attestation of internal control over financial reporting (ICFR) under Section 404(b) of the Sarbanes-Oxley Act for many registrants.
As written, the proposal would exempt approximately 60 percent of companies that currently receive ICFR attestation from being required to obtain it in the future. However, management would remain responsible for establishing, maintaining and assessing the effectiveness of internal controls. The SEC designed the proposal to simplify regulatory requirements, reduce burdensome compliance costs and encourage more companies to access the public markets.
For audit committees, this could change how they obtain assurance regarding the effectiveness of internal controls and carry out their existing oversight responsibilities. Audit committees may want to evaluate whether existing oversight, reporting and assurance mechanisms provide sufficient visibility into the effectiveness of internal controls.
Internal Controls Remain a Board and Audit Committee Priority
The SEC’s proposal would replace the current multi-category filer framework with two primary classifications: large-accelerated filers and non-accelerated filers. Audit committees should assess whether their company’s filer status could change, and if so, may wish to revisit how they oversee and receive information about the company’s internal control environment.
Questions audit committees may consider include:
- How would the committee gain additional visibility into management’s control assessment processes?
- What would the communication process look like for significant deficiencies or remediation activities?
- How would internal audit responsibilities and reporting change?
- What information would investors expect the committee to understand and oversee regarding internal controls?
For many audit committee members, the independent auditor’s work on ICFR provides an additional perspective on the strength of the company’s internal controls. While auditor attestation is often viewed as a compliance requirement, audit committees also view it as a source of insight into control deficiencies, financial reporting risks and management’s overall control framework. If the requirement no longer applies, audit committees may need to consider if additional reporting or oversight mechanisms are necessary.
ICFR in Today’s Advanced Technology Landscape
The SEC’s proposal arrives at a time when strong internal controls may be more important than ever. Organizations increasingly rely on AI, automation, advanced analytics and other technology-driven systems throughout their financial reporting processes. While these can improve efficiency and assist in more informed decision-making, they can also introduce new risks related to data integrity, cybersecurity and more.
Audit committees are becoming more responsible for AI and cybersecurity oversight and audit partners observe these areas as key challenges facing the committees they work with. Audit committees should understand how technology is changing the control landscape, whether existing governance structures are well established to address emerging risks, and consider increasing the frequency of technology-related discussions.
Additional questions could include:
- How is AI currently incorporated into the financial reporting process?
- What controls exist around AI-generated outputs and automated decision-making?
- How are management and internal audit evaluating technology-related risks?
- How does the current ICFR attestation process provide insight into technology-related controls, and how might that visibility change in the future?
- How would the mechanisms for committees to receive AI and technology-related information change?
Potential Impacts on Audit Committee Agendas
Because filer status influences several reporting and compliance requirements, the proposal could affect many topics commonly addressed by audit committees.
Areas of discussion may include:
- Filer status assessments and monitoring
- Reporting calendar implications
- Internal control oversight processes
- External audit scope and planning
- Disclosure practices and investor communications
Audit committees may also benefit from engaging management, internal auditors and external auditors to discuss potential implementation scenarios. The proposal remains subject to the rulemaking process, but understanding different outcomes and engaging with stakeholders may help committees identify areas requiring additional attention and be prepared for potential changes.
What Comes Next?
The comment letter period closed in July 2026, and the SEC is evaluating the public’s input. The Commission may revise the proposal further before considering and voting on a final rule.
The filer status proposal raises broader questions about balancing regulatory efficiency and investor protections. The Center for Audit Quality (CAQ) supports the SEC’s objectives to reduce compliance costs but encourages the SEC to consider if the scope is appropriate for today’s markets and investor needs.
While the proposal may lead to reduced compliance requirements for some registrants, it also provides an opportunity for audit committees to reassess reporting processes, internal control oversight and disclosure practices for continued confidence in financial reporting. By understanding the proposal and its potential implications now, audit committees position themselves to navigate regulatory changes while continuing to support transparency and accountability in U.S. capital markets.
Subscribe to the CAQ for the latest regulatory news and impacts for audit committees


