Audit and assurance for financial services
Meeting stakeholder and regulatory expectations requires more than accurate reporting. Discover how audit and assurance can help improve operations, manage risk and support long-term success.
How we help you
Assurance is more crucial than ever as financial services organizations seek to build greater confidence with customers, members and regulators.
Leverage sector-specific services for custody, internal and single audits.
Access customized, risk-based financial statement audits and reviews.
Strengthen stakeholder confidence with experienced compliance support.
Address assurance needs beyond financial reporting.
Gain insight from your assurance
Wipfli leverages our strong CPA foundation and financial services industry experience to take assurance further, giving you valuable insight into performance, processes and your organization’s overall health.
Explore our services
Wipfli has nearly 20 years of experience in performing custody audits in the broker dealer and wealth and asset management industries. Our custody audit process provides all the right components for you to satisfy your obligations, and our proven tools help us perform testing in an efficient manner, limiting disruption.
Wipfli keeps the focus of our review or audit on the critical issues facing your organization. We take a customized, risk-based approach that incorporates our experience in the financial services industry and business practicality so that we use your time and resources efficiently.
Wipfli uses our extensive experience and known frameworks to provide you with SOC 1, SOC 2 and SOC 3 services. Our team can also help evaluate your preparedness and controls against the Cloud Controls Matrix with a SOC 2+ audit.
Wipfli brings practicality and objectivity to every PCAOB audit. As a registered auditor with the Public Company Accounting Oversight Board, we’re ready to help SEC issuers and broker dealers manage their compliance challenges.
Wipfli’s internal audit services provide more than just a list of items that need fixes. We guide you in practical solutions and industry best practices based on the latest regulatory guidance. With our help, you can focus your resources on your management and board’s highest priorities.
Experience a smooth single audit process with Wipfli. Our professionals help meet your needs for accountability and transparency with dedicated services, including support for Uniform Guidance, that go beyond financial statements to help ensure your processes and systems stay in compliance.
Wipfli’s team brings experience in conducting over 700 employee benefits plan audits to help your organization better adhere to fiduciary responsibilities and maintain compliance.
Wipfli can meet your assurance needs beyond financial statements with attest services, including third-party validation and agreed-upon procedures. We’re ready to help remove doubt and bring clarity and efficiency to processes such as SEC custody exams, contract compliance and director exams.
Insights and resources
Learn MoreARTICLE
Avoiding adjustable-rate mortgage loan compliance challenges
Adjustable-rate mortgage (ARM) loans can present compliance challenges throughout the entire loan life cycle. From application disclosures to rate adjustment notices, even minor errors can result in regulatory violations, customer confusion and operational risk. Keep reading to learn about several common ARM compliance errors and for guidance on avoiding them. Timing of early disclosures A common mistake is the timing of early ARM disclosures, including the Consumer Handbook on Adjustable-Rate Mortgages or a suitable substitute and a loan program disclosure for each variable-rate program in which the consumer expresses an interest. These do not always allow you three business days from the application date to provide the disclosures, like other early disclosures. Regulation Z states that these disclosures must be provided at the time an application form is provided or before the consumer pays a non-refundable fee, whichever is earlier (except that the disclosures may be delivered or placed in the mail not later than three business days following receipt of a consumer’s application when the application reaches the creditor by telephone, or through an intermediary agent or broker). Based on that requirement, an in-person application request requires the disclosures to be provided on the date of application and cannot be mailed later. Common mistakes with loan program disclosures Other common issues include incorrect information in the ARM loan program disclosure. If the initial interest rate is a discounted or premium rate (not based on the index and margin in effect), this fact must be disclosed in the early disclosure, but it is often missing. If using the optional 15-year historical example, make sure the disclosure identifies the month and day being used for each year in the table, verify the indexes disclosed are correct, and the margin used was one in effect within the prior six months. Often, the table is not updated properly or quickly enough. When disclosing the initial interest rate and payment example for a $10,000 loan, make sure a current rate is being used. Also, when updating the index and margin, make sure the example payment reflects the newly disclosed rate. Avoiding violations with ARM rate changes ARM rate changes and notification requirements probably cause the most errors. Using the wrong index is a common mistake. For example, an index that specifies a weekly average may be inaccurately disclosed with the daily version of the index. The weekly average is calculated on Friday and is generally published the following Monday, but the daily index is often used instead of the weekly average, resulting in errors and incorrect interest rates being assigned to borrowers. Make sure the index is pulled from the correct source and matches what was disclosed in the promissory note. Another common issue involves periodic caps. Institutions should verify that the caps disclosed in the promissory note match those being used to calculate rate adjustments. It is common to have different caps for the first-rate change than for subsequent rate changes. The system might be set up for those initial caps, but not updated for the caps that will follow for any subsequent rate changes. Errors in rate change notices are common Rate change notices present additional challenges. An example of an error is failing to provide sufficient detail when describing the index used to determine the new rate. Some systems limit the number of characters, so it takes a bit of creativity to fit the required details, especially when trying to spell out the “X”-year weekly average constant maturity U.S. treasury securities index, which is quite lengthy. The weekly average part is often omitted when truncating, but it is an important distinction in the index used and should be included. Also, the estimated balance and projected new payment must be based on the projected balance and number of remaining payments due at the time the rate will be changed. But some notices include the current balance at the time the notice is generated rather than a projected balance, which also results in the new payment being inaccurately calculated on the notice. In addition, the requirement to disclose rate limits and foregone interest rate increases can be confusing, as the disclosures required by § 1026.20(c)(2)(iv) regarding foregone interest rate increases apply only to transactions permitting interest rate carryover. Usually, a promissory note does not include such a provision, yet the foregone interest disclosure is being included anyway. Even though the interest rate was not increased fully due to a limit or cap percentage, there is no foregone interest when the note does not allow for such carryover of interest. Another issue is the required timing of the ARM adjustment notices. An initial notice must be sent at least 210 days, but no more than 240 days, before the new payment at the adjusted rate is due. The subsequent notices must be sent at least 60 days, but no more than 120 days, before the new payment at the adjusted rate is due. Occasionally, the credit agreement for an ARM originated AFTER January 1, 2015 (the date Regulation Z ARM notice requirements were effective) does not have an adequate lookback period for selecting the index prior to the change date (at least 45 days), resulting in issues with meeting the timing requirements for the ARM adjustment notices. For example, if the credit agreement does not contain a lookback period and requires the index to be selected on the change date, it is not possible to send an ARM adjustment notice at least 60 days before the new payment at the new rate is due, because the index will not yet have been published. Remaining compliant While ARM loans present numerous compliance challenges, many of the most common errors can be prevented through strong procedures, staff training and periodic quality-control reviews. Regular validation of disclosures, rate calculations and notice content can help institutions remain compliant while providing accurate information to borrowers. Read more FDICIA requirements: How banks approaching $1 billion should prepare for FDICIA compliance Tips for mastering accurate CECL regulatory reporting 6 steps to strengthen your financial institution’s call report preparation process
Learn MoreARTICLE
Repos and foreclosures are trending up. How should financial institutions prepare?
Both repossessions and foreclosures have been rising over the past year. The uptick creates additional risk for lenders, especially community financial institutions that have made issuing auto and home loans a core part of their business model. Are those institutions prepared to deal with this trend, which, for now, seems likely to continue? From an accounting, customer service and risk management perspective, there are key actions you should be taking today to shore up your processes and ready your team. Keep reading to learn more. Rising repossessions and foreclosures create risks for financial institutions With consumer debt recently rising to a record high of almost $19 trillion , Americans are feeling mounting financial pressure. This is starting to show up in repossession and foreclosure rates, the latter of which are higher than at any point in the last 6 years . Consumers are also increasingly underwater on vehicle loans, many of which reflect inflated COVID-era pricing for even used cars. For financial institutions, this environment comes with risks. Institutions may face increased risk to their actual loan portfolios, as well as related challenges like incorrectly accounting for repossessions in their books. Consider factors like: Portfolio risks: Your institution is at risk of a spike in repossessions or foreclosures on the loans you’ve issued directly to customers or members. However, the bigger risk may fall on institutions that participated in loan pools or indirect lending, especially involving auto loans. In these situations, the borrowers may not be your customers or members and lack a relationship with your institution, resulting in less loyalty to repay their loans than borrowers who bank with you. There is also a risk with the reliance on the lead lender’s collection and reporting practices in a participation situation. Liquidity dangers: Are you ready to handle a major jump in defaults from a liquidity perspective? For community financial institutions that lack the resources of their giant national competitors, a notable drop in borrowers meeting their repayment obligations could pose a genuine liquidity risk you should weigh with your risk management team. Team inexperience: Foreclosure rates are significantly higher than in previous years, so your team may not be fully prepared to navigate an uptick from a process or compliance perspective. This could materialize as inexperience in collection efforts or workouts — with shortfalls in the latter area leading to foreclosures that could otherwise have been avoided had your team been ready to offer restructured payment terms. Incorrect accounting: Many financial institutions make GAAP accounting errors with vehicle repossessions. For example, if your institution takes ownership of a vehicle during the repossession process, you are supposed to immediately write down the value of that vehicle. However, institutions often wait until the vehicle is sold before writing it down, which can lead to delayed recognition of losses and regulatory findings. So what should you do to address these risks? Here’s where to start. How should financial institution CFOs adapt to meet the current repossession and foreclosure uptick? To meet the heightened repossession and foreclosure environment, financial institution CFOs and finance leaders should take action to manage risks, improve processes and maintain compliance. Watch for warning signs and make sure you know what to do if more of your loans start going into default, including from both a process and accounting perspective. Key action steps include: 1. Double-check your accounting processes Don’t make avoidable accounting mistakes. Double-check your accounting processes to make sure you are accounting for repossessions and foreclosures correctly. Under GAAP, you should be basing your accounting of either asset type on fair value minus costs to sell, so work with your team to ensure that you’re doing so and consider bringing in additional advisory support if you need further guidance. 2. Get in touch with your borrowers when you notice warning signs You have a great deal of information about your borrowers, so watch that data and look for warning signs for both individual borrowers and in broader trends. Do you see signs that your customers or members are taking on more credit card debt, perhaps to cover living expenses? This is a red flag that they may be at risk of falling behind on loan payments. If you notice a borrower is headed for trouble, don’t wait for them to default. Instead, be proactive: Approach the borrower to go after a workout or a refinance that will allow them to continue meeting their loan obligations. Also, make sure your team understands how to take this type of action and why it matters. 3. Keep an eye on your participations If you’re involved in a group of pooled loans with other financial institutions, carefully assess your risks there. Do your due diligence: Get all the documents and reports you can from the lead lender and make sure you know what your options are if the loans in the participation start to go bad. (If you’re the lead lender, make sure you’re sharing all relevant information with the other participants.) 4. Inform your borrowers about last-ditch options Beyond workouts or refinancing, make sure your borrowers also know about last-ditch options like a voluntary repossession or a deed in lieu. These are obviously far from ideal, but may be less damaging to a borrower’s credit than a standard default and can also allow your institution to complete an inevitable repossession or a foreclosure more quickly. 5. Brush up on compliance rules Different states have their own rules around repossessions, foreclosures and collections. Make sure you and your team are aware of and in compliance with the appropriate compliance standards for any states you operate in, and that you have access to resources to stay on top of regulatory changes. 6. Decide how to handle collections Do you handle collections internally or outsource to a collections agency? There’s no right or wrong answer, but think about yours. 7. Reassess your allowance for credit losses As delinquencies, repossessions and foreclosures increase, make sure your allowance methodology is keeping pace with changing portfolio risk. Review whether your reserves reflect current performance, emerging loss trends and relevant qualitative factors, including economic conditions, collateral values, borrower behavior, underwriting practices and collection experience. Waiting until a loss is realized or collateral is sold can delay recognition of credit deterioration and leave reserves short of the portfolio’s actual risk. 8. Look to advisory support A third-party advisory and accounting firm can help you better navigate the current consumer debt climate. Look to advisory support to help assess your risks, review your current loan portfolio, double-check your accounting, review your controls and strengthen your regulatory compliance. Read more Financial institutions need proactive general ledger certification How to mitigate ransomware attacks on financial institutions Can traditional banking avoid losing Gen Z to fintech?
Learn MoreARTICLE
FDICIA requirements: How banks approaching $1 billion should prepare for FDICIA compliance
As your bank approaches $1 billion in total assets, the Federal Deposit Insurance Corporation Improvement Act (FDICIA) introduces a new level of rigor around financial reporting, audit oversight and governance structure. These requirements are designed to enhance transparency and accountability, but they also require advance planning to implement effectively. What does FDICIA compliance require, and how should your institution prepare as you approach the $1 billion and $5 billion thresholds? Keep reading to find out. Why FDICIA compliance matters FDICIA establishes enhanced audit, reporting and governance requirements for insured depository institutions. These requirements begin at the $1 billion asset threshold and expand significantly at $5 billion, particularly regarding internal control over financial reporting (ICFR). While FDICIA requirements are mandatory under 12 CFR Part 363, they also serve as a critical framework for strengthening financial reporting discipline, governance oversight and overall risk management. A common misstep is delaying preparation until a threshold is imminent. In practice, achieving FDICIA readiness at $1 billion — including establishing audit capabilities, governance structures and sustainable reporting processes — requires advance planning and disciplined execution. Institutions approaching $5 billion must take a further step, developing a mature and well-documented ICFR framework, supported by formal risk assessment, control testing and remediation processes. Institutions approaching either threshold should plan proactively to avoid compressed timelines, operational strain and heightened supervisory scrutiny at the point of applicability. Key FDICIA requirements FDICIA Part 363 establishes graduated reporting, audit and governance requirements for institutions based on asset size. These requirements take effect at two key thresholds: $1 billion in assets and $5 billion. Institutions with $1B or more in assets are generally subject to annual audited comparative financial statements, Part 363 management reporting and board-level audit committee requirements. Institutions with $5 billion or more in assets are also subject to management assessment and independent auditor attestation requirements related to ICFR audits. At $5 billion, additional internal control and audit committee expectations also kick in. FDICIA reporting requirements Banks with at least $1 billion in assets must provide independently audited comparative financial statements annually. These audited financial statements provide regulators, directors and other stakeholders with independent assurance regarding the accuracy of the institution’s financial reporting. FDICIA audit requirements The audit of your financial statements must be completed by an independent auditor who complies with SEC/PCAOB independence standards. This means your auditor cannot perform non-attest services that could impair their independence with respect to financial reporting oversight, including: Preparing financial statements Performing appraisal, valuation or internal audit services Providing tax services FDICIA internal control expectations Management — principally, your CEO and CFO — is responsible for the preparation and fair presentation of your institution’s financial statements and for establishing and maintaining an effective system of ICFR. For banks that reach $5 billion in total assets, Part 363 requires management to perform a formal assessment of ICFR and to support an independent auditor’s attestation on the effectiveness of those controls. This entails conducting a comprehensive risk assessment, implementing and documenting key controls at the process level and maintaining sufficient evidence to support both management’s conclusions and the auditor’s opinion on ICFR. Governance and audit committee responsibilities Banks with $1 billion or more in assets must maintain a board-level audit committee composed entirely of outside directors, with a majority independent of management. At $5 billion and above, all members must be independent of management and meet enhanced governance expectations. Your audit committee is responsible for the appointment, compensation and oversight of your independent auditor, including evaluating the auditor’s independence and performance. It also provides oversight of your bank’s financial reporting process, ICFR and compliance with Part 363 requirements. In performing these duties, your committee reviews audited financial statements, monitors significant control issues and remediation efforts and ensures appropriate coordination among management, internal audit and your external auditor. FDICIA threshold changes explained Effective January 1, 2026, the FDIC revised 12 CFR Part 363 (FDICIA) to adjust key asset thresholds for inflation, materially reducing the scope of institutions subject to audit and internal control requirements. The applicability threshold for annual independent audits and reporting increased from $500 million to $1 billion, while the threshold for management’s assessment and auditor attestation of ICFR increased from $1 billion to $5 billion, along with corresponding increases to audit committee governance requirements. These changes shift FDICIA toward a more risk-based framework, providing immediate compliance relief for many community and mid-sized banks, but still requiring institutions approaching $1 billion to proactively establish audit, governance and control structures ahead of becoming subject to Part 363. In other words, don’t overlook FDICIA compliance if you haven’t yet reached $1 billion. You’ll need time to prepare, and your bank still faces other regulatory compliance and risk management challenges that remain in place regardless of the FDICIA threshold change. How to prepare for FDICIA compliance Bringing your bank into FDICIA compliance requires phased preparation aligned to the $1 billion and $5 billion thresholds, as expectations increase significantly at each level. Banks approaching $1 billion in assets should focus on foundational readiness, including establishing an appropriately independent audit committee, engaging a qualified external auditor and enhancing financial reporting processes; many institutions already perform an independent financial statement audit. In contrast, institutions approaching $5 billion should shift to a more robust control environment by formalizing ICFR, performing a comprehensive risk assessment, strengthening control documentation and testing processes and preparing for management’s ICFR assessment and external auditor attestation. At both stages, a structured readiness assessment and clear alignment of responsibilities across management, internal audit and the board are critical to ensuring timely and effective compliance. Here are specific keys to success as you approach an FDICIA threshold: Start planning early As you approach $750 million in assets, you should start getting serious about FDICIA compliance. Establishing a board audit committee, finding an independent auditor (if you do not already have one) and establishing an effective internal control environment will take time. On the off chance you’re not already doing so, it’s a good idea to conduct an independent audit of your financial statements the year before you expect to reach $1 billion, as this will help you prepare for the FDICIA-required audit process once you reach $1 billion. Conduct an FDICIA readiness assessment Assess your overall level of FDICIA readiness. Unless your internal team has significant experience in FDICIA compliance, you’ll typically benefit from working with a third-party advisory firm to do this. This firm can help you identify gaps in your existing controls, processes and compliance structures and help ensure you are properly in compliance by the time you reach $1 billion. Define responsibilities across management, internal audit and the board Your CEO and CFO, independent auditor and board audit committee each have specific responsibilities under FDICIA. Ensure each stakeholder understands their specific areas of responsibility and also has sufficient resources to implement FDICIA requirements within that area. Strengthen internal controls and documentation Management — particularly your CEO and CFO — is responsible for establishing and maintaining an effective system of ICFR, including identifying key controls, evaluating design and operating effectiveness and maintaining sufficient documentation to support those conclusions. If your bank is approaching $1 billion, your focus should be on establishing a well-documented control framework and consistent testing discipline. For institutions approaching $5 billion, expectations expand significantly to include a more formalized ICFR structure, anchored by a comprehensive risk assessment, enhanced control documentation at the process level, and systematic testing and remediation of control deficiencies. These institutions must be prepared to support management’s ICFR assessment and the external auditor’s attestation, requiring a higher degree of rigor, consistency, and evidentiary support across the control environment. Common FDICIA compliance challenges Top FDICIA compliance challenges include: Underestimating time and resource needs FDICIA compliance requires significant coordination across management, finance, internal audit, your board and external auditors. This often takes longer to implement than anticipated. Institutions approaching $1 billion should begin preparation 12 to 24 months in advance, as establishing an audit committee structure, completing a first-time external audit, if applicable and implementing consistent reporting processes can be time-intensive. For institutions approaching $5 billion, the effort increases substantially due to the need to formalize ICFR, testing and documentation, often requiring dedicated resources, tooling, and enhanced internal audit capabilities. In both cases, balance sheet growth —particularly through acquisitions — can accelerate applicability timelines and compress readiness efforts. Incomplete documentation and control testing A common challenge is failing to establish sufficient documentation and evidence to support control design and operating effectiveness. While this is important for institutions approaching $1 billion, expectations become significantly more rigorous at $5 billion, where management must support a formal ICFR assessment and external auditor attestation. Inadequate documentation, inconsistent control execution or insufficient testing discipline can result in control deficiencies, delayed reporting or adverse audit outcomes, in addition to heightened regulatory scrutiny. Preparing too late for threshold requirements Banks that delay FDICIA readiness may reach the $1 billion threshold without the necessary audit, governance and reporting infrastructure in place, increasing the risk of supervisory criticism and operational strain. This risk becomes more pronounced as institutions approach $5 billion, where the transition to a fully supportable ICFR framework requires well-established processes, documentation standards and remediation protocols. Early, phased preparation aligned to both thresholds is critical to avoiding compressed implementation timelines and ensuring a controlled transition into Part 363 compliance. FDICIA compliance FAQs Here are some common FAQs about FDICIA compliance: How long does it take to prepare for FDICIA compliance? Banks should generally plan for a 12 to 24-month FDICIA preparation period as they approach the $1 billion threshold, depending on complexity and existing governance structures. This preparation typically begins with a readiness assessment to evaluate financial reporting processes as well as governance and audit requirements, and should allow sufficient time to establish an independent audit committee. Institutions approaching $5 billion should allow for additional lead time to design, implement and validate a fully supportable ICFR framework in advance of management assessment and auditor attestation requirements. We recommend an 18-month lead time for preparation. Who is responsible for FDICIA compliance within a bank? Responsibility for FDICIA compliance rests with management, led by your CEO and CFO, who are accountable for the accuracy of financial reporting and the effectiveness of internal controls. These responsibilities are executed in coordination with finance, internal audit and compliance functions, with oversight provided by your board of directors and audit committee. Your independent external auditor also plays a critical role in providing assurance on financial statements — and for institutions above $5 billion, on the effectiveness of ICFR. What happens if a bank is not prepared for FDICIA requirements? Institutions that are not adequately prepared for FDICIA compliance may face heightened supervisory scrutiny, including potential enforcement actions, reporting delays or adverse audit outcomes. Beyond regulatory risk, insufficient readiness can strain internal resources, disrupt financial reporting processes and negatively impact board confidence, investor perception and overall governance effectiveness. Read more FDICIA threshold changes: Next steps you can’t overlook How lenders should comply with new SBA lending rules How to mitigate ransomware attacks on financial institutions
Perspective changes everything.
Receive timely industry developments, regulatory changes and other news impacting your success.
Reach out to our team
See how we move beyond compliance to help you uncover insights that strengthen operations, controls and organizational health.


LET'S CONNECT
See how Wipfli’s collaborative approach can help your organization turn regulatory, operational and technology challenges into opportunities for growth and resilience.


