Audit - a screen for the problems of large companies

George Marinescu
English Section / 3 august

Audit - a screen for the problems of large companies

Versiunea în limba română

The auditor enters a company with the authority of the doctor who reads the analyzes and with the prestige of the institution that transforms suspicion into trust. His signature reassures investors, convinces banks, protects management and gives the market the impression that someone independent has verified the reality behind the numbers. But what happens when the doctor is financially dependent on the patient, when the company being audited pays his fee, can terminate his contract and offer him other, more profitable services? Who controls the one paid to control?

The KPMG Australia scandal brings this contradiction to the fore. The Australian Financial Review reported that the company is preparing to eliminate approximately 1,000 positions, about 10% of its staff, amid the effects of a scandal regarding the audit activity. KPMG, one of the companies that are part of the so-called Big Four, stated, according to the cited source, that it is analyzing its operating model, costs and personnel needs, but that it has not yet made a decision on layoffs. But the crisis is real: the firm is under investigation after a whistleblower alleged that confidential information from clients such as Lendlease and Optus was used to win audit contracts at Westpac, Dexus and Telstra. There have been top-level departures and KPMG is temporarily barred from bidding for new Australian federal government contracts.

The case does not just highlight possible individual misconduct, it exposes a fundamental contradiction in the industry: firms tasked with safeguarding the independence and integrity of the market are commercial organisations with a duty to win clients and make a profit. The audit partner must be sceptical of the management of the company being audited, but their firm must keep the company in its portfolio. They must ask uncomfortable questions, but not so uncomfortable that the client chooses another auditor.

The auditor is not paid by the investor they are protecting, the employee who may lose his or her job or the taxpayer who may end up bearing the consequences of a bankruptcy. He is selected and remunerated by the company he audits. His independence exists legally and professionally, but economic dependence does not disappear by invoking a code of ethics. The auditor must "bite the hand that feeds him”, but elegantly enough to be invited back the following year.

The Big Four companies do not only sell auditing, but also tax advice, valuations, strategy, technology, restructuring and transaction assistance. Moreover, auditing can become the gateway to much more profitable contracts, and the information obtained during the audit has enormous commercial value. In theory, there are internal walls and rules on conflicts of interest. In practice, the Australian scandal shows how fragile the wall can become when confidential information can help the company win new clients.

Wirecard, a case where the auditor made a serious mistake

The European Union has introduced auditor rotation, bans on certain services and a cap on non-audit services allowed to public interest entities. These rules limit risks but do not eliminate the economic model that generates them. The market is concentrated, and large banks, energy companies, listed companies and international groups usually choose from a small circle of suppliers. The auditor changes, but the game often continues with the same few players. History shows that an unqualified audit report does not guarantee the survival of a company. Wirecard, the German technology star, went into insolvency in 2020 after discovering a 1.9 billion euro hole. EY had been auditing its financial statements for years. The German supervisory authority fined the firm 500,000 euros and banned it from taking on new audits of public interest entities for two years, according to Reuters. In the UK, Carillion went into liquidation in 2018 after years of unqualified opinions from KPMG. According to the BBC and The Guardian, the parliamentary inquiry described the audits as superficial and the long-standing relationship between KPMG and the company as one marked by complacency, symptomatic of a market that works for the benefit of the oligopoly, but not the economy.

The industry's defense is technically correct: an audit does not guarantee the health of the company, does not certify the future and cannot detect all fraud. The auditor only provides "reasonable assurance” that the financial statements do not contain material misstatements. The problem is that the market reads the report as a seal of health. Banks grant loans, investors buy shares, suppliers accept payment on time, and authorities maintain licenses based partly on audited information. The company pays for the trust, but finds out after bankruptcy that it had only received limited insurance.

City Ins urance - another case with a sanctioned auditor

Romania has its own examples. City Insurance, the former leader of the RCA market, collapsed, leaving behind hundreds of thousands of victims and obligations transferred to the Insurance Guarantee Fund. BDO Audit, the company's main auditor during its expansion, was sanctioned by the Authority for the Public Supervision of Statutory Audit Activity with a warning and a fine representing 0.6% of turnover, according to information published at the time. In 2025, however, BDO Audit obtained in court the annulment of a separate decision of the ASF from 2021, by which its approval for auditing insurance companies had been withdrawn. The case shows how complicated it becomes to establish liability after the collapse of a company: the management invokes the audited situations, the auditor the information received from the management, and the supervisor the reports provided by the company.

However, the vulnerability of the audit does not only appear in bankruptcy. It can exist when a large professional services firm evaluates a transaction or participates in the resolution of a dispute, and then ends up auditing one of the companies at the center of that economic construction. The Comvex-Davira case, presented by the newspaper BURSA, raises precisely this issue.

Following a capital increase in Comvex, Solidmet SRL's stake decreased from 63.24% to 30.68%. Solidmet was fully owned by Bulk Project SRL, controlled by Befstras Holding Limited of Cyprus and Octogon Shipping & Services SRL. Befstras was owned by Davira AG of Zurich, whose shareholders were Dan Drăgoi, Viorel Panait and Raimondo de Rubeis. Davira thus had an indirect economic stake in Comvex, even though, according to the position transmitted by Comvex to the newspaper BURSA, the Swiss company was not directly listed in the Romanian company's shareholders register.

Complete lack of transparency in the Pwc-Comvex-Davira case

Documents consulted by BURSA show that, in December 2017, a Swiss law firm warned that the federal tax administration could consider the subscription of preferential rights by people close to shareholders as a hidden distribution of profits to the detriment of Davira. The amount in question was approximately 5.8 million Swiss francs, and the potential tax burden for Davira would have amounted to approximately 3.15 million francs.

On December 22, 2017, after a meeting attended by Viorel Panait, representatives of Davira and a representative of PricewaterhouseCoopers, a memorandum was signed by which the economic consequence borne by Davira was reduced from approximately 5.8 million to 211,000 Swiss francs. The Swiss lawyers cited in the BURSA documentation claimed that the reduction was unfounded. Davira executives had stated that PwC was to assess the dilution of the indirect stake in Comvex.

Approximately one month later, Comvex shareholders were called upon to appoint PricewaterhouseCoopers Audit SRL as the financial auditor for the next three years. The relationship continued, with Comvex's 2025 annual report showing that the company's financial statements were also audited by PricewaterhouseCoopers Audit SRL.

The chronology alone does not demonstrate a breach of independence, nor does it demonstrate that the representative involved in the discussions in Switzerland and PricewaterhouseCoopers Audit SRL belonged to the same legal entity or team. However, it does raise a legitimate question: if an entity or individuals from the PwC network contributed to an assessment related to the dilution of the stake in Comvex, and a firm from the same network immediately afterwards became Comvex's auditor, who verified the existence of a self-review threat and what measures were taken to protect independence?

The questions returned after Davira recorded a loss of approximately 7.67 million Swiss francs at the end of 2022. Raimondo de Rubeis claimed for BURSA that a PwC Romania report would have described Comvex's activity as declining and would have taken into account the possibility that the company would not distribute dividends. According to him, subsequent developments contradicted the scenario, as Comvex granted consistent dividends for the years 2021-2023, and for 2024 a new important distribution was emerging.

A forecast refuted by subsequent developments does not automatically prove the negligence of the valuer. For a conclusion, the full report, the information available at the time of preparation and the assumptions used should be known. But the report becomes relevant if it contributed to the depreciation of Davira's stake, the recapitalization of the company or the change in the shareholder structure.

Asked by BURSA to provide information about the report and memorandum, PwC Romania responded that its policy is not to comment on client-related issues. Confidentiality is a professional obligation, but creates an opaque zone when the reports have effects on the shareholders of a listed company. The firm cannot disclose the client information, and the public cannot verify the independence and assumptions used. The only institution that can examine the documents without violating commercial secrecy remains the supervisory authority.

Delayed sanctions, assumed as a cost of activity by the Big Four companies

The Comvex-Davira case should not be compared to Wirecard or City Insurance, nor presented as the case of a company on the verge of bankruptcy. Its relevance is different: it shows that the problem of auditor independence can also exist in a profitable company that distributes dividends. The question is whether the firm called upon to certify the financial statements previously had a role as a consultant or evaluator in a situation whose economic effects were connected to the audited company.

The same risk arises in state-owned companies, where auditor independence encounters political influence. Losses can be hidden in bad debts, overvalued assets, insufficient provisions, onerous contracts or overly optimistic assumptions about the continuation of the activity. The auditor can formulate reservations and warnings, but these often remain buried in voluminous reports, while management presents only the turnover and accounting profit to the public.

In Romania, the supervision of the statutory audit is the responsibility of ASPAAS, based on Law no. 162/2017. For public interest entities, audit committees, ASF, the National Bank and other control bodies also intervene. However, the problem is not the number of institutions, but the speed and depth of the checks, the transparency of the findings and the severity of the sanctions. A bearable fine, applied years after the problem occurred, risks becoming a simple cost of the activity.

Audit fees and those for additional services should be presented transparently. Where an entity in a global network has previously provided valuation or advisory services to a company to be audited, the independence statement should explain the general nature of the relationship and the steps taken to eliminate the risk of self-review. In cases of major insolvency, unexplained losses or disputes over valuations with a significant effect, an independent review of the auditor's work should be automatically triggered.

KPMG Australia, Wirecard, Carillion, City Insurance and Comvex-Davira are not identical cases and should not be forced into a single legal conclusion. But they point to the same flaw: the organization called upon to defend independence is dependent on contracts, relationships and profit, and the public sees the result of its work without always being able to see the business relationships behind it.

If the auditor controls the company, the regulator must control the auditor and the public must be able to control the regulator. Otherwise, after the next bankruptcy, the next loss transferred to shareholders or the next valuation convenient to the one who ordered it, we will receive the same impeccably formulated explanation: all institutions fulfilled their duties, all procedures were respected, only the company, the money and the trust disappeared.

Enron and Greece, the great frauds that passed the auditors' filters

Two of the cases that revealed the serious limits of financial auditing, although the responsibilities are not identical, are Enron and Goldman Sachs-Greece. In the case of Enron, the failure was direct and devastating. Enron, once considered one of the most innovative American companies, went bankrupt on December 2, 2001, after the discovery of systematic accounting fraud. The group's management had hidden debts and losses through specially created companies and had presented financial results to investors that did not reflect the real situation. Enron shares collapsed from over $90 to less than a dollar, and shareholders lost approximately $60 billion. Thousands of employees lost their jobs and lost a significant part of their retirement savings. Arthur Andersen LLP, Enron's auditor, validated financial statements that concealed huge debts and losses, and the firm's employees destroyed audit-related documents. For its work at Enron, Arthur Andersen LLP received $25 million for the audit in 2000 and another $27 million for consulting services. The destruction of Enron-related documents permanently damaged the auditor's reputation. Although the firm's criminal conviction was later overturned in 2005 by the U.S. Supreme Court due to faulty jury instructions, Arthur Andersen LLP had already lost clients and virtually disappeared from the market. The scandal led to the adoption of the Sarbanes-Oxley Act, which tightened controls over financial reporting and auditors' work. In the case of Greece, the mechanism was more complicated. Goldman Sachs brokered derivative transactions in 2001 that reduced the country's external debt by euro2.367 billion and temporarily lowered the debt-to-GDP ratio from 105.3% to 103.7%. That year, Goldman Sachs' financial statements were audited by PricewaterhouseCoopers. The transactions were reported by Goldman Sachs, a bank audited by PwC, while Greek institutions provided unreliable fiscal data, as Eurostat did not have sufficient audit powers to directly verify the state's accounts at the time.

In conclusion, Enron shows a demonstrated failure of a company's auditor, while the Greek case shows the failure of an entire system of auditing, reporting and supervision. In both cases, the guarantees offered to the public proved insufficient when the accounting and financial engineering exceeded the institutions' capacity or willingness to question it.

Reader's Opinion

Accord

By writing your opinion here you confirm that you have read the rules below and that you consent to them.

www.agerpres.ro
www.dreptonline.ro
www.hipo.ro

adb