Article icon
Article

The Data-Centric Revolution: Audit Discounts for Safe Drivers

Yellow TDAN logo on a blue background

A financial audit is an expensive undertaking. In 2024, the average cost of an audit for a publicly traded company was $3.3 million [1]. Smaller, and/or privately held companies spend less for their audits, but they are still expensive. One-tenth of 1% of revenue is a typical benchmark for privately held firms [2], which suggests a $100,000 audit fee for a privately held $100 million revenue company. This expense has led borrowers to push back, and banks to capitulate, on the requirement for audited financial statements. The percent of bank loans substantiated by attested financial statements has fallen from 57% to 33% over the first two decades of this century [3].

The advent of data-centric accounting [4] has the potential to change the economics of the audit function. Before we get into the nature of the change, let’s review the economics of the current best practices in auditing.

The Purpose of a Financial Audit

Investors (and creditors) rely on a company’s published financial statements as a key input into their decision-making. There are two issues that investors and creditors need to deal with on these published financial statements: meaning and credibility.

On the meaning side is the question: Just what did they mean by “revenue” or “cost of goods sold” or any of the dozens of line items in the financial statements? Not only what did they mean, but what was included and excluded, and what were the timing implications (one issue of revenue and expense “recognition” is when should it hit the profit and loss statement)? In order to compare two companies, the investor/creditor needs to know if the figures in two statements are even comparable. For instance, Coca-Cola sells syrup to bottlers, so its revenue is the proceeds from those sales.  Pepsi bottles much of its own, and therefore its revenue is the wholesale price of the bottled product (which presumably is a higher number for the same amount of final product, as it involves more added value).

Because the financial reports are generated by the company there is the possibility, and the temptation, to embellish a bit. This is the credibility bit. Are these financial figures credible reflections of the activity of the enterprise? Misstatements could easily be intentional or unintentional.

It is the job of the external auditor to attest to the validity and the consistency of the reported numbers.

Why Is an Audit Expensive?

There are three main reasons that financial audits are expensive to conduct:

  • The SEC and other agencies have added considerable additional regulatory requirements, including Sarbanes-Oxley (SOX), which add to the work required to complete an audit
  • Each audit is a risk to the auditing firm. Materially misrepresentative financial statements may result in lawsuits or regulatory fines. There are many documented cases of tens of millions and hundreds of millions in damages.
  • Clients’ financial ecosystems are complex. The financial statement is the end product of a long and complex set of processes any of which could be intentionally or unintentionally compromised.

We’re going to focus on the latter item, but it turns out it drives the other two.

The typical publicly traded company has hundreds of systems that contribute to their financial reports. A SOX audit is primarily about evaluating the adequacy of internal controls. In order to conduct one, one of the first tasks is finding all the systems that contribute to the financial report. This often results in wallpapering a “war room” with flow charts for all the systems that contribute to the financial reports.

Not only are there typically dozens of financial systems and financial warehouses, but there are also hundreds of feeder systems. These are systems that capture business events that eventually make their way to the accounting department where they are costed and classified.

In additional to all that, almost all publicly traded firms use a reporting and disclosure system such as Workiva, to combine all the information from the financial systems with hundreds of spreadsheets and word documents to compile the finished product.

This complexity essentially ensures the impossibility of a definitive attestation. The audit is a statistical estimate on top of a subjective controls evaluation of the validity of the result.

It doesn’t need to be like that.

What Is Now Possible

We’re going to describe what is now possible. We are going to describe it in terms of a medium sized privately held firm. We believe that no publicly traded firm will adopt these methods until they have seen them implemented in hundreds of private firms. Even then, the primacy of “Earnings Management” (the analyst industry that deals in predicting company earnings, and the internal practice of income smoothing) means that this will encounter resistance for the next several decades.

A medium sized (say $100 million revenue) privately held firm, has many of the same issues as a larger firm but scaled down. They many have only dozens of systems contributing to their financials. But they have all the issues in miniature. Events occur throughout the enterprise, are captured in various “source systems” and eventually get transformed into financial records and make their way to the financial statements.

Data-Centric Accounting

In The Future of Accounting, we describe a future without data silos. Instead of information flowing and being transformed, it is captured at its source, and automatically and consistently classified, valued and when appropriate recognized.

The financial reports are generated directly from the annotated business events. The opportunity for misrepresentation (intentional or otherwise) is drastically reduced. All data is recoded immutably. Each item on the financial statement has full provenance, as does each business event and its annotations.

By itself this should massively reduce an auditor’s risk. But it opens up another opportunity that isn’t feasible in the traditional information architecture.

The Telematic Device

The “Telematic Device” is the piece of hardware (or software on a phone now) that insurance companies install in cars to evaluate driving habits. The idea is that there are patterns of behavior that lead to safer driving, and therefore fewer accidents, and therefore fewer claims’ payouts and therefore lower premiums.

The auditor of a data-centric company could offer to install the equivalent of a telematic device in the software infrastructure of the firm and monitor financial activity on an ongoing basis. Rather than showing up at the end of the year and assessing random samples of what occurred over the last 12 months (focusing mostly on the more recent items that have the greatest impact on the materiality of the balance sheet) the auditor has had a ring side seat to 100% of what occurred over the entire year. A simple script, or AI agent could watch for suspicious patterns.

An audit firm could charge considerably less per-client, deliver more reliable assurances and still potentially earn higher total revenues, as the trend of declining financial audits amongst privately held firms, described in the introduction, might be reversed. Especially with the added banker incentive.

Lower Borrower Rates

A bank, lending to a data-centric firm, could offer to install a telematic device on a borrower’s system in exchange for a reduced rate. Bankers worry about credit worthiness of their clients. How much would it lower their credit risk if they had a live monitor.

There would have to be transparency on what sort of information was disclosed, but it seems like a small amount of key information would be all a bank would need if it were guaranteed to be accurate and complete. Perhaps just the ongoing cash balance and the ratio of Accounts Receivable to Loan Balance. The bank gets an immediate early warning signal.  When you consider the reduction in credit risk, it may be enough for banks to offer a half or even a full percent reduction in interest rate in exchange for this kind of active monitoring.

Or they may opt for the external attest function, now considerably less expensive than the current variety.

Regulators

How about regulators, including the IRS. They currently rely on detecting patterns in self-reported numbers and occasionally performing expensive audits themselves. What if they could replace a lot of their cumbersome regulatory reporting with a passive telemetric-like device. The high cost of regulatory compliance could begin to come down.

Summary

Reducing the cost of audits, compliance and even obtaining more favorable loans are not the primary motivation for firms adopting data-centric principles. We cover the main motivations in the book.  But as we describe here there are many fortuitous side benefits that come along as a by-product.

[1] thecorporatecounsel.net/blog/2025/10/audit-fees-20-years-of-trend-data.html

[2] proformative.com/questions/benchmark-audit-fees/

[3] mpra.ub.uni-muenchen.de/117472/1/MSV%203-31-2023.pdf

[4] The Future of Accounting, Dave McComb and Cheryl Dunn

Data Architecture Bootcamp

Learn how to design and evolve a modern data architecture – September 15, 22 & 29, 2026.