
NYSE Wants Five Years Before Internal Audit. That’s Too Long!
August 28, 2026A few weeks ago, I wrote about the New York Stock Exchange’s proposal to give newly listed companies five years, instead of one, to stand up an internal audit function. I made the same case in Accounting Today: five years is too long to leave a young public company without independent assurance over its riskiest period of growth. But the exchange’s proposal exposed something bigger than a rulemaking dispute. It exposed a truth our profession does not like to say out loud. After decades of progress, internal audit still has to fight to exist in some companies. That should trouble every one of us.
A coalition speaks up
On September 8, the day the SEC’s comment period closed, a coalition of nine organizations wrote to the Commission urging it to reject the proposal. The IIA signed the letter. So did Better Markets, the Association of Certified Fraud Examiners, RIMS, Public Citizen, the Interfaith Center on Corporate Responsibility, the National Whistleblower Center, and the Americans for Financial Reform Education Fund. The letter raised a fact worth noting. Most newly listed companies already qualify for up to five years of exemption from external auditor attestation over internal controls under Sarbanes-Oxley. Add a five-year exemption from internal audit on top of that, and a newly public company could go five years with no internal audit function and no independent attestation of any kind over its controls. The coalition also pointed out that the NYSE’s own filing offers no data on how many companies the rule would affect, no estimate of the burden it would remove, and no quantified savings. It asked the SEC to disapprove the rule outright or open formal proceedings to weigh disapproval.
It is encouraging that eight other organizations, representing investors, fraud examiners, risk managers, and whistleblowers, joined the IIA on this letter. But that is exactly my point. It took a nine-organization coalition to make an argument our profession should win on its own merits. If internal audit delivered indispensable value everywhere it operated, we would not need investor advocates and fraud examiners defending our reason to exist to a stock exchange.
Our fate should never rest with regulators
It would be easy to blame the NYSE, the SEC, or regulators generally, for not requiring internal audit outright. Nasdaq has never required it at all. At the same time, there are other regulators and listing exchanges around the world who have explicitly required internal audit for years. But our legitimacy should never rest on what a regulator mandates. A profession that exists only because a rule says so has not earned its place. A rule assigned that place, and a rule can take it away.
So, who’s to blame for internal audit’s plight?
It would also be easy to blame corporate management. Plenty of executives see internal audit as a cost center, a compliance obligation, or worse, an obstacle to speed. A company that skips internal audit loses an independent set of eyes on risk, culture, and control, and history shows that companies that skip it are often the ones that later implode. I made that case directly in a blog urging investors to shy away from companies without internal audit. Management resistance is real, and it does not serve its company or its investors well.
But if I am honest, and I intend to be, our profession shares some of the blame for our own struggle. If we delivered extraordinary value everywhere we operated, no management team would want to do without us. No board would tolerate a company without us. Yet the IIA’s own Vision 2035 research found that 48% of internal auditors believe we are seen as “the police” inside our own organizations. Not as trusted advisors. Not as partners in risk management. As enforcers. That number demands attention from every chief audit executive. You cannot build indispensable value while half the profession admits it is viewed as adversarial.
A perception problem this widespread does not come from a handful of laggards. It comes from a profession that has not yet proven, broadly and consistently, that it belongs in the room. Regulators will not fix that for us, and neither will management. We have to fix it ourselves, one engagement and one relationship at a time.
The elephant in the room: audit committees
Still, as I survey this landscape of disappointment, I keep coming back to an obvious question nobody seems to be asking. Where are corporate boards and their audit committees in this debate?
Think about who benefits most from a well-resourced, independent internal audit function. It is not the regulator. It is not even management, however much value internal audit delivers to the business. It is the audit committee. No one else in the governance is more accountable to the shareholders for the risks that actually threaten a company. I made this case in a blog on the important role internal audit plays for audit committees and again in an open letter to audit committees. The most dangerous risks to shareholder value are rarely financial reporting risks. They are strategic, operational, and cultural risks, and internal audit is often the only function in the enterprise built to assess them independently and report the results straight to the board.
So why do audit committees stay quiet when a newly listed company proposes waiting five years to build that capability? Why do they stay quiet at companies that have never had an internal audit function at all? The coalition letter made a point that applies no matter how the SEC rules. A director’s fiduciary duty does not pause because a stock exchange grants a grace period. Without independent assurance, an audit committee ends up relying more heavily on the same management representations it exists to scrutinize. An audit committee that understands its own risk exposure should not need a regulator to tell it to insist on internal audit. It should insist on its own, because its members are the ones who will answer for the risks nobody caught.
A call to action for audit committees
This is where I want to draw the line for every audit committee member reading this. If your company does not have an internal audit function, ask why. If your company has one that is underfunded, understaffed, or kept away from the risks that matter, ask why. If your company is newly public and leaning on a five-year grace period, ask whether you are willing to operate that long without independent assurance over the risks that could define your company’s future. These are not rhetorical questions. They are governance questions, and audit committees have both the authority and the obligation to answer them.
Regulators set floors, not ceilings. Management teams respond to incentives, not always to good governance. Internal auditors have real work to do to prove our value beyond question. But audit committees hold the one lever that can change this equation immediately. They can insist on a strong, independent, well-resourced internal audit function as a condition of good governance, regardless of what any exchange requires.
There’s still work to do
Internal audit has come a long way as a profession. We should be proud of that progress. But progress is not the same as arrival, and a profession that still has to fight for its existence in some companies has more work ahead than behind. Regulators, management, and internal auditors all own a piece of that work. Audit committees own the piece that matters most: the decision to demand what their companies need, whether or not anyone makes them.






I welcome your comments via LinkedIn or Twitter (@rfchambers).