NYSE proposes to amend Sections 303A.00 and 303A.07 of the Listed Company Manual to extend the period in which a newly listed company must establish an internal audit function from one year to five years. This tracker classifies the comment letters filed on that proposal.
One entry per coded letter, showing every call the scheme makes about it, the rater agreement behind that call, and the evidence it rests on. Where the three raters did not agree the split is marked beside the call.
Each row is followed by the exact words in the letter that earned it, copied out of the letter body character for character. The position, each procedural ask and each argument code carry their own quote, so the words a writer uses to state an ask are never pooled with the words used to argue the merits. Where a letter argues a case but never states an ask, the position row says so instead of showing a stand-in quote. Where a code was assigned by two raters rather than three, the vote is shown beside it. All 127 coded letters appear below.
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | No position split | primary No positionliteralist Opposecharitable Support The letter states no ask. The position is read from what it argues. The IIA asks the Commission to extend the comment period by at least thirty days, citing the filing's absent evidentiary record and the Exchange's failure to solicit feedback, and reserves substantive comment for later. |
| Entity | Professional body / trade association unanimous | primary Professional body / trade associationself-described Professional body / trade associationletterhead Professional body / trade association |
| Remedy | No modification requested | — |
| Procedural | PROC_EXTEND | The IIA requests that the Commission extend the comment period by at least thirty days, to October 8, 2026. |
| NOEV | No evidentiary record | the Proposal itself contains no supporting data or analysis: it identifies no population |
| INVPROT | Investor protection standard | investors whose protection Section 6(b)(5) of the Exchange Act makes the touchstone of the |
| IMPETUS 2 of 3 | No occasion for the change | No urgency attends this filing: the current one-year requirement has been in place for more than a decade, and the Exchange identifies no extenuating circumstance requiring resolution on a compressed schedule. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to reject the proposed rule change or, at a minimum, conduct additional review before approving a reduction in protections that have served investors and public companies well for more than twenty years. A CIA with over twenty years in internal audit strongly opposes the five-year extension, arguing risk is highest right after an IPO, that SOX attestation exemptions would compound the gap, and that scaled or outsourced functions make one year workable. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | retain the existing one-year requirement; at a minimum, additional review before approving |
| HIRISK | Peak risk window | organizations need independent assurance most during periods of significant change and growth. The first years after an IPO are exactly that. |
| NONSUB | Not substitutes | Internal audit provides boards and audit committees with an independent perspective that neither management nor external auditors are designed to provide. |
| 404B | Attestation gap | many newly public companies are already exempt from SOX auditor attestation requirements for several years after their IPO. |
| FEAS | The one-year rule is workable | companies have successfully implemented appropriately scaled internal audit functions through in-house, co-sourced, or outsourced models. |
| NOEV | No evidentiary record | I am also not persuaded that the proposal presents sufficient evidence to justify such a significant change. |
| INVPROT 2 of 3 | Investor protection standard | That is not a strengthening of investor protection; it is a reduction of it. |
| FOUNDATION | Built at the foundation | Effective governance should begin when a company enters the public markets, not five years later. |
| LEGACY | Why the rule exists, and how it got here | a reduction in protections that have served investors and public companies well for more than twenty years |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | No position split | primary No positionliteralist Opposecharitable Support The letter states no ask. The position is read from what it argues. The creator of the ISR Standard and founder of BUDAPROTOCOL expressly declines to oppose the five-year period and instead offers his decision-reliability framework for the Commission's technical review as an evidence-based alternative to measuring maturity by elapsed time. |
| Entity | Consultant / advisory firm unanimous | primary Consultant / advisory firmself-described Consultant / advisory firmletterhead Consultant / advisory firm |
| Remedy | No modification requested | — |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the Commission to reconsider the proposed extension and maintain a shorter transition period that ensures internal audit is implemented early in a company’s public journey. A chief audit executive and CPA calls the five-year extension a step backward for investor protection, rejects the Nasdaq comparison as a race to the bottom, and urges a shorter tiered transition with interim third-party assurance and reported milestones. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Internal audit professionalletterhead Consultant / advisory firm sub-role: Chief audit executive / head of function |
| Remedy | Scaled / risk-based phase-in or milestones | tiered by size and complexity - one year for large accelerated filers, two years for smaller issuers; mandatory interim third-party assurance; transparent milestones reported to audit committees and disclosed to investors |
| HIRISK | Peak risk window | it needs it most at the formative stage when systems, controls, and governance practices are still being built |
| FEAS | The one-year rule is workable | A tiered transition period based on company size and complexity (e.g., one year for large accelerated filers, two years for smaller issuers). |
| NASDAQ | Nasdaq benchmark contested | this comparison should not be used to justify weaker standards |
| INVPROT 2 of 3 | Investor protection standard | a significant step backward for investor protection and market integrity |
| FOUNDATION | Built at the foundation | Embedding internal audit into the governance framework from the outset of public life is essential to upholding the principles of accountability, transparency, and investor protection |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeThis is why it is important that the rule of the 1 year requirement should remain unchanged. A Northwest Ohio chief audit executive says newly public companies undergo rapid change that requires independent assurance and concludes the one-year requirement should remain unchanged. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Chief audit executive / head of function |
| Remedy | Keep one year | one year, unchanged |
| HIRISK | Peak risk window | Organizations during their first years of public offering are usually going through rapid changes which require independent assurance that internal controls are in place and effective. |
| FOUNDATION 2 of 3 | Built at the foundation | By delaying for even a few years, the value that internal auditors can have at the onset would be greatly reduced. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. IIA Orange County Chapter letter whose stated ask is a comment-period extension to December 31, 2026, but which objects in the body to delaying internal audit for five years, citing the absent evidentiary record, cyber/AI risk and Section 6(b)(5). |
| Entity | Professional body / trade association unanimous | primary Professional body / trade associationself-described Professional body / trade associationletterhead Professional body / trade association |
| Remedy | No modification requested | No change to the rule text requested; asks that the comment period be extended to December 31, 2026 |
| Procedural | PROC_EXTEND | we respectfully request that the Securities and Exchange Commission extend the public comment period for the proposed rule change to December 31, 2026. |
| HIRISK | Peak risk window | runs counter to the SEC’s own emphasis on early, effective governance in high-risk environments |
| FEAS | The one-year rule is workable | The current one-year requirement has been functioning |
| NOEV | No evidentiary record | the Proposal is flying blind. It contains no supporting data |
| INVPROT | Investor protection standard | Commission is obligated to protect under Section 6(b)(5) of the Exchange Act |
| FOUNDATION | Built at the foundation | not delaying the standing up of the function, or making them smaller. |
| SCOPE 2 of 3 | Widened domain | where technology accelerates risk at an unprecedented pace |
| LEGACY | Why the rule exists, and how it got here | like Enron, which severely hurt investors and the public at large |
| IMPETUS 2 of 3 | No occasion for the change | The current one-year requirement has been functioning for over a decade, and there is absolutely no emergency demanding a compressed resolution. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the Commission not to approve the proposed extension from one year to five years. An internal audit and risk professional urges the Commission not to approve the five-year extension, arguing proportionality rather than postponement answers cost concerns, and offers a more limited or phased accommodation only as a fallback. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Fallback / compromise | primary ask is the existing one year period; if additional flexibility is warranted, a significantly more limited or phased accommodation rather than five years |
| HIRISK | Peak risk window | The first several years following a public listing can involve rapid organizational change, increased financial and regulatory scrutiny, new reporting obligations |
| NONSUB | Not substitutes | Internal audit also serves a fundamentally different purpose from external audit |
| FEAS | The one-year rule is workable | Companies can adopt risk based approaches, use appropriately scaled internal resources, or supplement their capabilities through qualified third party providers. |
| INVPROT 2 of 3 | Investor protection standard | preserving an important safeguard for investors and the integrity of the public markets |
| FOUNDATION | Built at the foundation | five years is not a temporary accommodation in any meaningful sense |
| COST | Burden on new issuers | I recognize that newly listed companies face substantial costs and competing demands as they transition into the public markets. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully encourage the Commission to disapprove of the proposed amendment and retain the existing one-year transition period. Individual commenter asks the Commission to disapprove the five-year extension and retain the one-year transition, arguing the filing offers no empirical evidence, that EGC 404(b) exemptions would compound the assurance gap, and that outsourced providers can stand up a scaled function within months. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Keep one year | retain the existing one-year transition period; notes a 'more limited or targeted accommodation' was never justified |
| HIRISK | Peak risk window | support of the proposal—rapid growth, changing systems and controls, additional personnel, and competing regulatory demands—increase execution, reporting, compliance, and control risk. |
| NONSUB | Not substitutes | are not effective substitutes for internal audit. Internal audit complements these |
| 404B | Attestation gap | be exempt from the external-auditor attestation requirement under Section 404(b) for up |
| FEAS | The one-year rule is workable | risk-based internal audit function within months, allowing the function to mature and |
| NOEV | No evidentiary record | implementation challenges, it presents no empirical evidence that the existing one-year |
| NASDAQ | Nasdaq benchmark contested | The fact that Nasdaq does not impose a comparable internal audit requirement does not establish that weakening |
| INVPROT | Investor protection standard | protect investors or advance the public interest under Section 6(b)(5) of the Exchange |
| 5YRS | Five years is unexplained | It also does not explain why a five-year period—as opposed to a more limited or targeted accommodation—is necessary. |
| COST | Burden on new issuers | Although the filing cites issuer concerns regarding competing obligations and implementation challenges, |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Support majority | primary Supportliteralist Opposecharitable SupportWith regard to this proposed change, I am in favor of the change. Career internal audit and risk advisory senior manager at an advisory firm favors the change on cost grounds, calling internal audit a check-the-box exercise, while noting five years may be excessive and one year fast. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Outsourced / co-sourced provider |
| Remedy | Shorter extension | no specific period named; writer states '5 years may be excessive, but 1 year is fast' |
| COST | Burden on new issuers | new companies should be extended time to have to take on that cost |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the SEC to disapprove NYSE’s proposed rule change in File No. SR-NYSE-2026-37, which would extend the deadline for newly listed companies to establish an internal audit function from one year to five years. IIA San Jose chapter president, writing in a stated personal capacity but citing the chapter's 723 members, urges disapproval or at minimum proceedings, arguing the earliest public years are when independent assurance matters most and that the function can be co-sourced rather than postponed. |
| Entity | Professional body / trade association majority | primary Professional body / trade associationself-described Internal audit professionalletterhead Professional body / trade association |
| Remedy | Keep one year | asks for disapproval, which leaves the existing one-year deadline in place; no alternative period named |
| Procedural | PROC_PROCEEDINGS | I respectfully ask the Commission to disapprove it, or at minimum institute proceedings to examine the proposal more fully. |
| HIRISK | Peak risk window | The earliest years of a newly public company are precisely when independent assurance is most important. |
| NONSUB | Not substitutes | This work complements, rather than replaces, the work of external auditors and management. |
| FEAS | The one-year rule is workable | A function can also be scaled to a company’s size and risk profile, including through co-sourcing or outsourcing arrangements, rather than postponed for five years. |
| INVPROT | Investor protection standard | I believe the proposal is not consistent with investor protection and the public interest. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully request that the Commission not approve SR-NYSE-2026-37 as proposed. Senior manager of internal audit, writing individually, opposes the five-year extension and asks the Commission not to approve it, arguing weaknesses are cheaper to catch during design than years later, and offering a more limited or phased accommodation only as a fallback. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Manager |
| Remedy | Fallback / compromise | primary ask is that the Commission not approve the proposal; only if additional flexibility is found warranted, 'a more limited or phased accommodation' rather than five years |
| HIRISK | Peak risk window | Significant organizational and technology changes create new risks |
| NONSUB | Not substitutes | but they are not substitutes for an internal audit function |
| FEAS | The one-year rule is workable | the internal audit function may be outsourced to a qualified third party, reducing the need for a newly listed company to immediately build a complete department internally |
| INVPROT 2 of 3 | Investor protection standard | Public-company governance requirements should be strongest where they meaningfully protect investors, not simply where they are easiest for issuers to implement. |
| FOUNDATION | Built at the foundation | identifying weaknesses after processes and systems have been in place for several years is generally more difficult and costly than identifying them as they are being designed and implemented |
| COST | Burden on new issuers | I recognize that establishing an effective internal audit function requires planning and resources. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully encourage the Commission to reject the proposed five-year transition period and retain a substantially shorter timeframe for newly listed companies to establish an effective internal audit function. Internal audit professional asks the Commission to reject the five-year transition and retain a substantially shorter timeframe, distinguishing flexibility in how internal audit is sourced from postponing the function altogether; letter's Re: line misstates the file number as SR-NYSE-2025-43 but the subject and body address SR-NYSE-2026-37. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Shorter extension | internal audit required 'substantially earlier than five years after listing'; no specific period named; suggests a scalable or risk-based requirement to preserve flexibility |
| HIRISK | Peak risk window | Newly listed companies may experience rapid expansion, significant increases in transaction volume, new systems and processes, changes in leadership and staffing |
| NONSUB | Not substitutes | nor does it replace the role of the independent external auditor |
| FEAS | The one-year rule is workable | an organization may initially use a lean internal audit team, co-source specialized expertise, or outsource portions of the function |
| INVPROT | Investor protection standard | From an investor-protection perspective, the potential consequences of a five-year delay deserve particular consideration. |
| FOUNDATION | Built at the foundation | establishing an effective internal audit capability early can help an organization mature its governance and control environment as it grows rather than attempting to remediate deficiencies |
| COST | Burden on new issuers | I recognize the importance of reducing unnecessary regulatory burdens and allowing newly public companies reasonable flexibility as they transition to the public markets. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Credentialed internal audit professional (CIA, CFE, CHIAP) writing personally urges disapproval, arguing assurance matters most while systems and controls are being built and that the one-year requirement is attainable through co-sourcing or outsourcing. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | urges disapproval and states the current one-year requirement can be met by companies of different sizes |
| HIRISK | Peak risk window | significant change, risks and control gaps can emerge quickly because responsibilities, workflows, data, |
| FEAS | The one-year rule is workable | be appropriately scaled and supported through co-sourcing or outsourcing. |
| FOUNDATION | Built at the foundation | control environments are developing, rather than waiting until practices and weaknesses have become |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the Commission to reject the proposed rule change and preserve the existing requirement that newly listed companies establish an internal audit function within one year of listing. CPA/CIA urges the Commission to reject the five-year extension and preserve the one-year requirement, arguing early-years risk, the 404(b) attestation gap, COSO monitoring principles and Section 6(b)(5) investor protection. |
| Entity | Accountant / external auditor (CPA) unanimous | primary Accountant / external auditor (CPA)self-described Accountant / external auditor (CPA)letterhead Accountant / external auditor (CPA) |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | The first years following an initial public offering are often characterized by rapid |
| NONSUB | Not substitutes | The internal audit function also provides audit committees with an independent |
| 404B | Attestation gap | exempt from auditor attestation requirements under Section 404(b) of the Sarbanes- |
| NOEV | No evidentiary record | change or, at a minimum, require a substantially greater evidentiary basis demonstrating |
| INVPROT | Investor protection standard | of Section 6(b)(5) of the Securities Exchange Act of 1934. The proposal would weaken a |
| FOUNDATION | Built at the foundation | Good governance begins when a company enters the public markets, not five years later. |
| SCOPE | Widened domain | evaluates governance, risk management, cybersecurity, operational resilience, third-party |
| COST | Burden on new issuers | an internal audit function because they are simultaneously managing growth, governance |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. IIA Lansing Chapter secretary raises four objections: the fivefold extension is disproportionate and unjustified, SOX 404 is not a substitute for internal audit, the early post-listing period is the highest-risk one, and the Nasdaq comparison is competitive positioning rather than investor protection. |
| Entity | Professional body / trade association unanimous | primary Professional body / trade associationself-described Professional body / trade associationletterhead Professional body / trade association |
| Remedy | Shorter extension | two or three years |
| HIRISK | Peak risk window | The early post-listing period, marked by rapid growth, leadership transitions, and pressure to meet public-market expectations, is also a period when internal control breakdowns |
| NONSUB | Not substitutes | Sarbanes-Oxley compliance is not an adequate substitute for an internal audit function. |
| NOEV | No evidentiary record | The magnitude of the change deserves more justification than the filing provides. |
| NASDAQ | Nasdaq benchmark contested | The comparison to Nasdaq's listing standards is not a substantive justification. |
| INVPROT 2 of 3 | Investor protection standard | This is a competitive-positioning argument, not an investor-protection argument. |
| 5YRS | Five years is unexplained | If the difficulty is that one year is too short, the Exchange has not explained why five years, rather than two or three, is the appropriate remedy. |
| COST | Burden on new issuers | to build a capable internal audit function amid the demands of becoming a newly public company |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor the reasons outlined above, I respectfully urge the Commission to disapprove SR- NYSE-2026-37. Senior internal audit manager urges the Commission to disapprove the five-year extension, arguing internal audit is complementary to management, external auditors and the audit committee and that the one-year period is workable given outsourced and co-sourced models. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Manager |
| Remedy | Keep one year | retain the existing one-year transition period |
| HIRISK | Peak risk window | companies often face rapid growth, increased regulatory scrutiny, heightened operational |
| NONSUB | Not substitutes | distinct and complementary role that cannot be fully replicated by management, external |
| FEAS | The one-year rule is workable | the current rule already permits companies to satisfy the internal audit |
| FOUNDATION | Built at the foundation | The period immediately following a public listing is critical for establishing a strong culture |
| COST | Burden on new issuers | options for compliance while managing costs and resource constraints. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Internal audit practitioner (7 years, CIA/CPA) writing personally opposes the extension and urges disapproval, arguing assurance matters most while systems are being built and that the one-year deadline is already met because the rule permits outsourced, co-sourced and scaled functions. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | first years as a public company are when its systems and controls are being built, and when objective assurance over that work matters most |
| FEAS | The one-year rule is workable | The current one-year requirement is met every year by companies of every size, precisely because the Exchange’s own rule allows the function to be outsourced or co-sourced |
| FOUNDATION | Built at the foundation | embedding operational discipline into daily workflows before bad habits or vulnerabilities could solidify |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the Commission to reject the proposed rule change and retain the current requirement that newly listed companies establish an internal audit function within one year of their IPO. Chief audit executive writing personally urges rejection of the extension and retention of the one-year requirement, citing early-post-IPO risk, the audit committee's loss of an independent information source, the overlapping SOX attestation exemption, two decades of scalable compliance, and the filing's lack of data. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Chief audit executive / head of function |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | The years immediately following an IPO are often characterized by rapid growth, organizational change, new regulatory requirements, evolving management structures |
| NONSUB | Not substitutes | Audit committees rely on internal audit as an independent source of information and perspective. Without that resource, oversight becomes more dependent on information provided by management |
| 404B | Attestation gap | many newly public companies are already exempt from SOX auditor attestation requirements for a period following their IPO |
| FEAS | The one-year rule is workable | Companies have successfully complied with this requirement for more than two decades through a variety of scalable approaches, including outsourced, co-sourced |
| NOEV | No evidentiary record | The filing itself does not appear to include data demonstrating the magnitude of the alleged burden or the impact on investors. |
| INVPROT 2 of 3 | Investor protection standard | before considering such a significant reduction in investor protections |
| FOUNDATION | Built at the foundation | independent assurance is most valuable when a company is establishing the foundation upon which its future growth and long-term performance will depend |
| SCOPE | Widened domain | Internal auditors evaluate operational risks, cybersecurity and technology risks, third-party relationships, supply chain resilience, compliance programs, fraud risks, data privacy practices |
| COST | Burden on new issuers | the current one-year requirement imposes an undue burden on newly listed companies |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI urge the SEC to reject this proposal and maintain the current one-year requirement to safeguard market integrity and protect public investors. Unaffiliated individual opposes the five-year extension and asks the Commission to reject it and keep the one-year rule, stressing the overlap with the SOX auditor-attestation exemption and the absence of supporting data. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Keep one year | maintain the current one-year requirement |
| HIRISK 2 of 3 | Peak risk window | Newly public companies are in a critical phase of building their governance systems and need independent assurance immediately |
| NONSUB | Not substitutes | delaying this function deprives audit committees of their vital, independent channel of information apart from management. |
| 404B | Attestation gap | Because most of these companies are already exempt from the Sarbanes-Oxley (SOX) auditor attestation |
| NOEV | No evidentiary record | The NYSE has provided no empirical data or cost-benefit analysis to justify weakening investor protections |
| FOUNDATION | Built at the foundation | in a critical phase of building their governance systems |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Risk management professional with six years in internal audit (IIA chapter advocacy liaison) writing personally opposes the extension and urges disapproval, arguing early engagement builds stronger control foundations and the one-year deadline is already met because the rule allows outsourcing and scaling. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Internal audit professionalletterhead Professional body / trade association sub-role: Practitioner |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | first years as a public company are when its systems and controls are being built, and when objective assurance over that work matters most |
| FEAS | The one-year rule is workable | The current one-year requirement is met every year by companies of every size, precisely because the Exchange’s own rule allows the function to be outsourced or co-sourced |
| FOUNDATION | Built at the foundation | By engaging early, internal audit helped build stronger foundations from the outset, reducing the need for costly remediation later |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose(2) not approve the proposed five-year transition period Accounting professor opposes the five-year extension, citing peer-reviewed evidence on internal audit value, the 404(b)/filer-status assurance gap and the filing's lack of record, and recommends a 30-day comment extension, non-approval, and either retaining one year or instituting proceedings. |
| Entity | Academic researcher or academic body majority | primary Academic researcher or academic bodyself-described Individualletterhead Academic researcher or academic body |
| Remedy | Keep one year | retain the existing one-year requirement, or institute proceedings to develop a fuller record; also asks for a 30-day comment-period extension |
| Procedural | PROC_PROCEEDINGS | (3) either retain the existing one-year requirement or institute proceedings to develop a fuller record concerning the costs, benefits, investor-protection consequences, and reasonable alternatives. |
| Procedural | PROC_EXTEND | (1) grant the 30-day extension of the comment period requested by The IIA; |
| HIRISK | Peak risk window | The period immediately before and after an initial public offering is characterized by rapid |
| NONSUB | Not substitutes | SOX, external audit, and audit-committee oversight complement internal audit; they do not |
| 404B | Attestation gap | exempt from the Section 404(b) auditor attestation requirement for up to five years |
| FEAS | The one-year rule is workable | The existing NYSE rule expressly permits the function to be outsourced to a third-party provider |
| NOEV | No evidentiary record | The Exchange also states that no written comments were solicited or received before the proposal |
| INVPROT 2 of 3 | Investor protection standard | I believe a five-year delay would move in the wrong direction for investor protection |
| FOUNDATION | Built at the foundation | Internal audit may be most valuable while a company is building its governance |
| SCOPE 2 of 3 | Widened domain | including operations, compliance, cybersecurity and information technology, fraud |
| CAPMKT | Capital-market consequences | it directly examines how capital-market participants valued an exchange-level requirement |
| IMPETUS | No occasion for the change | However, the NYSE filing does not identify the number or characteristics of affected issuers. |
| COST | Burden on new issuers | address legitimate resource constraints while preserving timely independent assurance. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission not to approve the proposed five-year implementation period. Individual writing in a personal capacity urges the Commission to disapprove the five-year period or at minimum institute proceedings, citing the audit committee information gap, external audit not being a substitute, the overlapping 404(b) attestation exemption, and the absence of quantitative evidence in the filing. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Keep one year | one year |
| Procedural | PROC_PROCEEDINGS | For these reasons, I respectfully urge the Commission to disapprove the proposed five-year implementation period or, at minimum, institute proceedings to more fully evaluate whether such a significant extension is justified. |
| HIRISK | Peak risk window | Newly listed companies are adapting to the responsibilities of being public companies while continuing to develop their systems, internal controls, risk-management processes |
| NONSUB | Not substitutes | The two functions are complementary rather than interchangeable. |
| 404B | Attestation gap | existing exemptions from auditor attestation requirements under Section 404(b) of the Sarbanes-Oxley Act |
| FEAS | The one-year rule is workable | Companies also have flexibility in how they establish the function, including through co-sourcing or outsourcing rather than immediately building a large internal department. |
| NOEV | No evidentiary record | it does not provide quantitative evidence regarding the number of affected issuers, the magnitude of the costs imposed by the existing requirement, expected cost savings |
| INVPROT 2 of 3 | Investor protection standard | such a substantial extension should be supported by evidence demonstrating that the benefits justify the potential reduction in investor protections |
| SCOPE | Widened domain | internal audit can address a broader range of risks on an ongoing basis, including operational, technology, cybersecurity, compliance, and data-privacy risks |
| COST | Burden on new issuers | The proposal reportedly cites burdens associated with the current one-year implementation period |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. Chief audit executive requests a 30-day comment-period extension and also calls the five-year extension a significant rollback in investor protection because risk is highest right after listing. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Chief audit executive / head of function |
| Remedy | No modification requested | — |
| Procedural | PROC_EXTEND | I am asking, as a practicing Chief Audit Executive, for a 30-day extension so that more voices can be heard on this extension to five years. |
| HIRISK | Peak risk window | precisely during the period when governance and controls are typically least mature and risk is highest |
| INVPROT 2 of 3 | Investor protection standard | I believe this proposal is a significant rollback in investor protection |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI hope this never materialises. Brief unaffiliated letter opposing the change as an affront to SEC policy that would undermine standards and create openings for fraud, with no developed argument. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Keep one year | — |
| NR | No substantive rationale | The proposed changes are a direct affront to the very foundational policy framework of the SEC and a diminition of the role and importance of audit. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully encourage the Commission to disapprove of the proposed amendment and retain the existing one-year transition period. Unaffiliated commenter asks the Commission to disapprove and retain the one-year period, arguing the filing lacks evidence, that 404(b) EGC exemptions would overlap the same window, that other safeguards are not substitutes, and that Nasdaq is no benchmark. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Keep one year | one year (retain existing transition period) |
| HIRISK | Peak risk window | rapid growth, changing systems and controls, additional personnel, and competing regulatory demands-increase execution, reporting, compliance, and control risk. |
| NONSUB | Not substitutes | Yet, these measures are not effective substitutes for internal audit. |
| 404B | Attestation gap | Further, many newly public companies that qualify as emerging growth companies may be exempt from the external-auditor attestation requirement under Section 404(b) for up to five fiscal years. |
| FEAS | The one-year rule is workable | audit professionals and third-party providers can assist boards and executive management in establishing an appropriately scaled internal audit function within months, rather than years. |
| NOEV | No evidentiary record | it presents no empirical evidence that the existing one-year period has resulted in ineffective internal audit functions or unreasonable implementation burdens. |
| NASDAQ | Nasdaq benchmark contested | The fact that Nasdaq does not impose a comparable internal audit requirement does not establish that weakening the NYSE's existing standard would protect NYSE investors. |
| INVPROT | Investor protection standard | protect investors or advance the public interest under Section 6(b)(5) of the Exchange Act. |
| FOUNDATION 2 of 3 | Built at the foundation | this is particularly important as a private company transitions to the heightened responsibilities and expectations associated with being publicly traded. |
| IMPETUS 2 of 3 | No occasion for the change | Although the filing cites issuer concerns regarding competing obligations and implementation challenges, it presents no empirical evidence that the existing one-year period has resulted in ineffective internal audit functions |
| 5YRS | Five years is unexplained | It also does not explain why a five-year period-as opposed to a more limited or targeted accommodation-is necessary. |
| COST | Burden on new issuers | Although the filing cites issuer concerns regarding competing obligations and implementation challenges, |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI don't anticipate that you will move the requirement from one to zero years, but at least don't change it to five years. CPA and CIA with 18+ years in public accounting and internal audit strongly opposes, arguing the audit committee, management's SOX 404 assessment and the external auditor cannot substitute for internal audit, rejecting the Nasdaq comparison, and asking for zero years rather than five. |
| Entity | Accountant / external auditor (CPA) majority | primary Accountant / external auditor (CPA)self-described Accountant / external auditor (CPA)letterhead Internal audit professional |
| Remedy | Fallback / compromise | primary ask is zero years - internal audit function required in place before listing; fallback is at least do not change the current requirement to five years |
| NONSUB | Not substitutes | Reliance on the audit committee to provide meaningful governance without a functioning internal audit function is borderline laughable. |
| FEAS 2 of 3 | The one-year rule is workable | Companies have to do myriad things to get ready to go public - establishing an internal audit function should be one of them. |
| NASDAQ | Nasdaq benchmark contested | The proposal letter states that issuers on the Nasdaq are not required to have an internal audit function. |
| INVPROT 2 of 3 | Investor protection standard | Investors have the right to know there is someone on the inside of the company who is independent, objective, and looking out for them. |
| FOUNDATION | Built at the foundation | Part of being a public company is having an internal audit function. That should be required before a company is allowed to go public, not five years later. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose majority | primary Opposeliteralist Opposecharitable Support The letter states no ask. The position is read from what it argues. Internal audit manager and CIA argues newly listed companies most need internal audit to police IPO fund use and set ethical tone while culture is being formed; never names the proposal or a requested outcome, so only the charitable rater reads it as Support. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Manager |
| Remedy | No modification requested | — |
| HIRISK 2 of 3 | Peak risk window | Newly listed companies often receive substantial investment funding for development, making it crucial for internal audit to step in |
| FOUNDATION | Built at the foundation | Compared with already established companies, new corporations are at a critical stage of building their culture. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Senior internal auditor with four years' experience urges disapproval, citing AI-driven expansion of internal audit's remit, the control-building risk of the first public years, and the feasibility of the one-year rule through outsourcing and co-sourcing. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Early career (<5 yrs) |
| Remedy | Keep one year | one year (current requirement) |
| HIRISK | Peak risk window | A company's first years as a public company are when its systems and controls are being built, and when objective assurance over that work matters most. |
| FEAS | The one-year rule is workable | The current one-year requirement is met every year by companies of every size, precisely because the Exchange's own rule allows the function to be outsourced or co-sourced |
| SCOPE | Widened domain | The Internal Audit function is more important now than ever as AI becomes a part of every industry. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose majority | primary Opposeliteralist Opposecharitable Support The letter states no ask. The position is read from what it argues. Certified internal auditor and IIA chapter member argues newly listed companies need an independent internal audit function early to police IPO proceeds and set ethical tone; never names the five-year extension or a requested period. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | No modification requested | — |
| HIRISK | Peak risk window | Newly listed companies often receive significant investment funding, making it essential for internal audit to ensure these resources are used responsibly |
| FOUNDATION | Built at the foundation | New companies are also in the critical phase of shaping their culture. If the tone at the top lacks ethical direction, correcting course later becomes extremely difficult. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. CIA/CFE/CGFM internal auditor says a five-year delay would leave control deficiencies undetected and urges retention of the one-year requirement, without asking the Commission for any procedural step. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | The transition to public ownership brings increased risks, regulatory requirements, and expectations for strong internal controls. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI advise the SEC to reject this proposal and maintain the current one-year requirement to protect public investors and maintain market integrity. Internal audit manager (CPA) states strong opposition, argues delay deprives investors and audit committees of independent insight in formative years, and asks the SEC to reject the proposal and keep the one-year requirement. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Accountant / external auditor (CPA)letterhead Internal audit professional sub-role: Manager |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | The Internal Audit function provides vital, independent assurance at a critical time when newly public companies are building their governance, risk management, and control processes. |
| NONSUB | Not substitutes | Delaying this requirement could leave investors, audit committees, and other stakeholders without an important source of independent insight during their early formative years. |
| FOUNDATION 2 of 3 | Built at the foundation | during their early formative years |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the SEC to reject the proposed rule change and preserve the current requirement for newly listed companies to establish an internal audit function within one year. Internal audit director opposes the five-year extension on early-lifecycle risk, broadened risk scope (third parties, cyber, AI), audit-committee assurance, and the filing's lack of supporting evidence; urges rejection and retention of one year. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Manager |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | The years immediately following an initial public offering are among the most important in a company's lifecycle. |
| NONSUB | Not substitutes | Internal audit serves as an independent source of assurance and insight for boards and audit committees |
| NOEV | No evidentiary record | the proposal appears to weaken investor protections without a corresponding body of evidence demonstrating that the benefits outweigh the risks |
| INVPROT 2 of 3 | Investor protection standard | I am also concerned that the proposal appears to weaken investor protections |
| FOUNDATION 2 of 3 | Built at the foundation | Newly public companies are expected to build and mature governance, risk management, and internal control frameworks |
| SCOPE | Widened domain | Today's risk environment is also significantly more complex than when many existing governance requirements were established. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeBecause of this, I urge the SEC to reject this proposal and maintain the current one-year requirement. Unaffiliated individual acknowledges the setup burden but objects that retail investors could trade for five years without independent oversight; urges rejection and retention of the one-year requirement. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Keep one year | one year |
| CAPMKT 2 of 3 | Capital-market consequences | investors may not have the full picture they need to trade comfortably |
| COST 2 of 3 | Burden on new issuers | I understand that it may take time to formally establish an internal audit team and their procedures |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully recommend that the Commission disapprove SR-NYSE-2026- 37 as currently proposed or institute proceedings to develop a sufficient evidentiary record and consider a risk-based, phased alternative. Internal audit practitioner writing individually opposes the five-year extension, argues the 2013 one-year transition was approved as limited in duration and the filing carries no evidentiary support, and asks the Commission to disapprove or institute proceedings while keeping the one-year deadline with a scaled, risk-based function. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | Retain the one-year deadline while permitting the function to be scaled to the issuer's risks, size, complexity and maturity (outsourcing permitted); asks the Commission to consider a risk-based, phased alternative |
| Procedural | PROC_PROCEEDINGS | For these reasons, I respectfully recommend that the Commission disapprove SR-NYSE-2026- 37 as currently proposed or institute proceedings to develop a sufficient evidentiary record and consider a risk-based, phased alternative. |
| HIRISK | Peak risk window | systems, controls, risk-management practices, and governance structures are undergoing |
| NONSUB | Not substitutes | The other safeguards identified by NYSE are important, but they are not functional substitutes |
| FEAS | The one-year rule is workable | large or fully mature internal audit department within its first year |
| NOEV | No evidentiary record | The present filing states that issuers have expressed concerns, but it does not quantify the |
| INVPROT | Investor protection standard | demonstrate consistency with the Exchange Act and that a mere assertion of consistency is |
| FOUNDATION 2 of 3 | Built at the foundation | governance practices are easier to evaluate and improve while they are being developed than |
| CAPMKT 2 of 3 | Capital-market consequences | may reduce information asymmetry through identification and communication of internal-control issues |
| LEGACY | Why the rule exists, and how it got here | emphasized that the transition was limited in duration |
| IMPETUS | No occasion for the change | The present filing does not adequately explain what has changed to justify increasing that transition period fivefold. |
| COST | Burden on new issuers | I support reasonable efforts to reduce unnecessary compliance burden on newly |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I encourage the Commission to reject the proposed extension and retain the existing one-year requirement. Unaffiliated individual opposes the extension because the post-listing period carries elevated risk, and asks the Commission to reject the extension and retain the one-year requirement. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | The period immediately following a public listing is often characterized by significant growth, change, and increased risk. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully request that the Commission disapprove SR-NYSE-2026-37 or require the NYSE to adopt a substantially shorter, phased transition period Internal auditor and fraud professional opposes the five-year extension, asks the Commission to disapprove, and offers a first-year phased-milestone alternative if flexibility is granted. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Chief audit executive / head of function |
| Remedy | Fallback / compromise | Primary ask is disapproval; if the Commission finds flexibility appropriate, a substantially shorter phased transition with first-year milestones (enterprise-wide risk assessment, designated internal audit leader reporting functionally to the audit committee, internal audit charter, start of risk-based audit coverage) |
| HIRISK | Peak risk window | The period immediately following a public listing can involve rapid growth, evolving systems, new personnel, increased regulatory obligations |
| NONSUB | Not substitutes | Sarbanes-Oxley requirements, management certifications, external-auditor attestations, and audit-committee oversight do not replace an internal audit function. |
| FEAS | The one-year rule is workable | A small internal team, a co-sourced arrangement, or another appropriately resourced model could satisfy the requirement |
| NOEV 2 of 3 | No evidentiary record | The proposal does not establish that existing audit-committee, management-certification, external-audit, and Sarbanes-Oxley requirements provide an adequate substitute for internal audit |
| NASDAQ | Nasdaq benchmark contested | Nor does the fact that another exchange may not require an internal audit function demonstrate that weakening the NYSE requirement is consistent with investor protection. |
| INVPROT | Investor protection standard | a phased approach would better protect investors than a categorical five-year exemption |
| FOUNDATION | Built at the foundation | Waiting five years may allow ineffective controls, unclear responsibilities, weak governance practices, and unidentified risks to become embedded in the organization. |
| COST 2 of 3 | Burden on new issuers | The proposal states that newly public companies often are upgrading their accounting systems, internal controls, and staffing. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI urge you to reconsider this proposal. Sixteen-year audit professional and IIA Houston Chapter officer is firmly opposed, arguing a five-year gap removes oversight when risks are greatest and controls least mature. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | — |
| HIRISK | Peak risk window | at the exact moment when risks are greatest and controls are least mature |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeThe SEC should REJECT this request from the NYSE. Unaffiliated individual asks the SEC to reject the proposal, faulting the NYSE for offering only anecdotes and arguing a company unable to stand up internal audit within a year is not ready to be public. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Keep one year | one year |
| FEAS | The one-year rule is workable | If a company cannot implement an internal audit function within one year of going public, that company IS NOT READY to go public. |
| NOEV | No evidentiary record | the NYSE fails to provide any evidence to support this allegation beyond referencing general anecdotes from some issuers. |
| FOUNDATION 2 of 3 | Built at the foundation | This proposal is a significant step BACKWARD for good governance. |
| IMPETUS | No occasion for the change | However, the NYSE fails to provide any evidence to support this allegation beyond referencing general anecdotes from some issuers. |
| COST | Burden on new issuers | The NYSE alleges that complying with the current one-year implementation timeline creates |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Internal audit manager writing personally urges disapproval, arguing assurance matters most while controls are being built and that the one-year rule is already met because it can be outsourced and scaled. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Manager |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | would leave newly public companies without an important mechanism for identifying and addressing risks during one of the most significant transitions |
| NONSUB 2 of 3 | Not substitutes | Internal audit helps leadership and boards make informed decisions by providing objective assessments of risk management and control activities. |
| FEAS | The one-year rule is workable | The current one-year requirement is met every year by companies of every size |
| INVPROT 2 of 3 | Investor protection standard | Five years without it is not a transition; it is an absence, during the years investors can least afford one. |
| FOUNDATION | Built at the foundation | first years as a public company are when its systems and controls are being built, and when objective assurance over that work matters most |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeThe SEC should reject the proposal on File number SR-NYSE-2026-37, as it is detrimental to investors. Internal audit practitioner asks the SEC to reject the proposal as detrimental to investors, stressing insider incentives to withhold information around an IPO and proposing an insider trading bar as a condition. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Fallback / compromise | Primary ask is rejection; says the proposal should only be considered if employees/owners are barred from trading their shares until at least one year after the internal audit requirement is effective |
| HIRISK | Peak risk window | precisely during the period when governance and controls are typically least mature, the risk is high |
| INVPROT 2 of 3 | Investor protection standard | The SEC should reject the proposal on File number SR-NYSE-2026-37, as it is detrimental to investors. |
| CAPMKT 2 of 3 | Capital-market consequences | the incentives for management to sweep information under the rug (and away from investors) are the highest |
| COST | Burden on new issuers | only really benefits registrants with potential lower costs of not having the function |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor those reasons, I encourage the Commission to reject the proposed rule change and retain the current standard. Unaffiliated commenter opposes the extension and asks the Commission to retain the one-year rule, citing existing SOX attestation exemptions, the absence of burden evidence, and available co-sourcing options. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | Delaying that oversight for five years creates a significant gap during a period when organizations are often experiencing rapid growth and change. |
| NONSUB | Not substitutes | Internal audit is also one of the few functions that provides independent feedback to both management and the audit committee. |
| 404B | Attestation gap | I am also concerned that many newly public companies are already exempt from certain SOX attestation requirements for a period after going public. |
| FEAS | The one-year rule is workable | For more than twenty years, companies have found practical ways to comply, whether through a small internal team, co-sourcing arrangements, or outsourced internal audit services. |
| NOEV | No evidentiary record | The proposal also does not appear to provide meaningful evidence that the current one-year requirement is creating a widespread burden for issuers. |
| INVPROT 2 of 3 | Investor protection standard | maintaining the existing one-year requirement better supports strong governance, effective board oversight, and investor confidence |
| FOUNDATION | Built at the foundation | The first few years after an IPO are when companies are building and refining the processes, controls, and governance structures they will rely on going forward. |
| COST | Burden on new issuers | the current one-year requirement is creating a widespread burden for issuers |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Internal auditor with 23 years' experience opposes the five-year extension and asks the Commission to disapprove, arguing assurance matters most in the first years and that the one-year rule is already workable because the function may be outsourced or co-sourced. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year (existing transition period retained) |
| HIRISK | Peak risk window | A company’s first years as a public company are when its systems and controls are being built, and when objective assurance over that work matters most. |
| FEAS | The one-year rule is workable | The current one-year requirement is met every year by companies of every size |
| FOUNDATION | Built at the foundation | This outside perspective helped organizations build stronger control environments from the outset |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the Commission not to approve the proposed five-year extension and to retain the existing requirement that newly listed companies establish an internal audit function within one year. Senior internal audit leader opposes the five-year extension and asks the Commission to retain the one-year requirement, stressing that internal audit gives the audit committee an independent source of information that management and the external auditor cannot replace. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Chief audit executive / head of function |
| Remedy | Keep one year | one year (asks the Commission to retain the existing one-year requirement) |
| HIRISK | Peak risk window | The years immediately following a public listing are precisely when independent internal audit oversight can be most valuable. |
| NONSUB | Not substitutes | That role cannot simply be replaced by management’s responsibility for internal controls or by the work of the external auditor. |
| FEAS | The one-year rule is workable | The existing one-year transition period already provides companies time to establish that capability. |
| FOUNDATION | Built at the foundation | Strong governance should develop alongside a company’s access to the public capital markets, not years afterward. |
| COST | Burden on new issuers | I recognize that newly public companies face significant demands and that establishing an effective internal audit function requires resources. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to reject the proposed extension and maintain the current requirement that newly listed companies establish an internal audit function within one year of listing. Internal senior auditor opposes the extension and urges the Commission to reject it and maintain the one-year requirement, arguing the change would delay detection of control and governance weaknesses during the highest-risk post-listing years. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year (asks that the current one-year requirement be maintained) |
| HIRISK | Peak risk window | heightened risks associated with growth, governance development, regulatory compliance, and control maturity |
| INVPROT 2 of 3 | Investor protection standard | the benefits of independent assurance and investor protection |
| COST | Burden on new issuers | While newly listed organizations may face competing priorities and resource constraints |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission not to approve the proposed five-year implementation period. IIA member writing in a personal capacity urges disapproval or, at minimum, institution of proceedings, arguing the extension compounds existing 404(b) attestation exemptions and rests on no quantitative evidence. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Individualletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year; asks for disapproval or, at minimum, institution of proceedings to evaluate the extension |
| Procedural | PROC_PROCEEDINGS | For these reasons, I respectfully urge the Commission to disapprove the proposed five-year implementation period or, at minimum, institute proceedings to more fully evaluate whether such a significant extension is justified. |
| HIRISK | Peak risk window | Newly listed companies are adapting to the responsibilities of being public companies while continuing to develop their systems, internal controls, risk-management processes |
| NONSUB | Not substitutes | I also do not believe that external audit should be viewed as an adequate substitute for internal audit. |
| 404B | Attestation gap | I am particularly concerned by the interaction between this proposal and existing exemptions from auditor attestation requirements under Section 404(b) of the Sarbanes-Oxley Act. |
| FEAS | The one-year rule is workable | Companies also have flexibility in how they establish the function, including through co-sourcing or outsourcing rather than immediately building a large internal department. |
| NOEV | No evidentiary record | does not provide quantitative evidence regarding the number of affected issuers, the magnitude of the costs imposed by the existing requirement, expected cost savings |
| INVPROT | Investor protection standard | such a substantial extension should be supported by evidence demonstrating that the benefits justify the potential reduction in investor protections |
| SCOPE | Widened domain | internal audit can address a broader range of risks on an ongoing basis, including operational, technology, cybersecurity, compliance, and data-privacy risks |
| COST 2 of 3 | Burden on new issuers | The proposal reportedly cites burdens associated with the current one-year implementation period |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully ask the Commission to disapprove the Proposal, or to require the Exchange to refile it with the evidentiary support CPA/CIA opposes the extension and asks the Commission to disapprove or require refiling with an evidentiary record, arguing a longer deadline only postpones the obligation, that SOX and the audit committee depend on internal audit's testing, and that the filing offers no data. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Individualletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year; alternatively asks that the Exchange be required to refile with a defined affected population, a quantified burden analysis, and an investor-protection assessment |
| HIRISK | Peak risk window | precisely the period in which its control environment is least mature and most likely to have gaps |
| NONSUB | Not substitutes | it is not a redundant layer sitting alongside SOX compliance, it is frequently the mechanism that makes SOX compliance possible in substance rather than on paper |
| 404B | Attestation gap | many newly public companies qualify for extended exemptions from the auditor attestation requirement |
| FEAS | The one-year rule is workable | An issuer that intends to build a capable function can do so within a year |
| NOEV | No evidentiary record | It identifies no population of affected issuers, quantifies no burden associated with the current one-year requirement |
| INVPROT | Investor protection standard | offers no analysis of the investor-protection consequences of a five-year transition |
| FOUNDATION 2 of 3 | Built at the foundation | the inconvenience of building the oversight functions that public status is supposed to require |
| IMPETUS | No occasion for the change | Absent a real evidentiary basis, the Commission should not treat a bare assertion of unnamed issuer discomfort as sufficient grounds to weaken a governance requirement |
| COST | Burden on new issuers | alongside the accounting-system upgrades and staffing the Exchange cites as competing priorities |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to carefully evaluate the investor protection, governance, and oversight implications of this proposal and to consider disapproving the rule change or undertaking additional review Certified Internal Auditor writing in a personal capacity opposes the extension and asks the Commission to consider disapproving or undertaking further review, citing the overlap with the five-year SOX attestation exemption, the loss of the audit committee's independent channel, and the filing's lack of data. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Individualletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year; asks the Commission to consider disapproving or to undertake additional review before allowing the change to proceed |
| HIRISK | Peak risk window | during the period when independent assurance is arguably needed most |
| NONSUB | Not substitutes | audit committees would lose access to an independent source of information and insight for an extended period, increasing their reliance on management reporting alone |
| 404B | Attestation gap | Most newly listed companies are already exempt from the Sarbanes-Oxley auditor attestation requirements over internal control for up to five years following their initial public offering. |
| NOEV | No evidentiary record | The filing does not include data regarding the number of companies affected, the magnitude of the alleged compliance burden, expected cost savings, or the potential impact on investors. |
| INVPROT | Investor protection standard | carefully evaluate the investor protection, governance, and oversight implications of this proposal |
| FOUNDATION 2 of 3 | Built at the foundation | Newly public companies are establishing the systems, controls, and governance processes that will support them for years to come. |
| LEGACY | Why the rule exists, and how it got here | Before reducing a longstanding governance protection that has been in place for more than two decades |
| COST 2 of 3 | Burden on new issuers | the magnitude of the alleged compliance burden |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. CPA/CIA requests a comment-period extension but also calls the proposal a change for the worse and stresses internal auditors' growing importance in the AI era, so it objects to the substance. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Accountant / external auditor (CPA)letterhead Internal audit professional sub-role: Practitioner |
| Remedy | No modification requested | — |
| Procedural | PROC_EXTEND | I’m writing to respectfully request an extension for the public comment period for the proposed rule change for SR-NYSE-2026-37. |
| SCOPE 2 of 3 | Widened domain | as AI continues to reshape how organizations operate, the need for trust will only grow |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to extend the comment period and disapprove the Proposal. Internal audit professional of 30+ years asks for a one-month comment-period extension and, on the substance, urges disapproval because the one-year rule is met today through outsourcing and scaling. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | — |
| Procedural | PROC_EXTEND | I therefore request that the September 8 deadline be extended by at least one month so affected groups have a meaningful opportunity to review and comment. |
| HIRISK | Peak risk window | A company’s first years in the public markets are precisely when its systems and controls are being built and independent assurance and advice matter most. |
| FEAS | The one-year rule is workable | Companies of every size can meet the current one-year requirement because the rule permits the internal audit function to be outsourced, co-sourced, and scaled appropriately. |
| NOEV | No evidentiary record | the Exchange acknowledges that it did not solicit stakeholder feedback before filing |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeThe Commission should disapprove this proposed rule change. CEO of an internal audit co-sourcing and advisory firm asks the Commission to institute 19(b)(2)(B) proceedings and disapprove, arguing the Exchange fails its Rule 700(b)(3) burden, recycles its 2013 rationale, and relies on 404 protections and a Nasdaq comparison that do not hold. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Internal audit professionalletterhead Consultant / advisory firm sub-role: Outsourced / co-sourced provider |
| Remedy | Keep one year | No alternative period proposed; narrower measures (shorter extension conditioned on affirmative audit committee action, a first-year implementation plan, disclosure of reliance, exclusion of issuers with unremediated material weaknesses) are listed expressly not as a compromise but as evidence of what the filing omits. |
| Procedural | PROC_PROCEEDINGS | I ask the Commission to institute proceedings under Section 19(b)(2)(B) for the purpose of disapproving the filing under Section 19(b)(2)(C)(ii). |
| HIRISK | Peak risk window | The Exchange treats the control immaturity of a newly listed company as the reason to defer assurance. |
| NONSUB | Not substitutes | does not leave a supplement absent. It leaves the position unfilled. |
| 404B | Attestation gap | Emerging growth companies are exempt from the Section 404(b) auditor attestation for up to five |
| FEAS | The one-year rule is workable | Section 303A.07(c) already permits a listed company to source the internal audit function from a third |
| NOEV | No evidentiary record | The Exchange further reports that no written comments were solicited or received |
| NASDAQ | Nasdaq benchmark contested | The filing relies substantially on the observation that Nasdaq imposes no internal audit requirement |
| INVPROT | Investor protection standard | Section 6(b)(5) without analyzing the effect of the change on investors. |
| FOUNDATION | Built at the foundation | Organizations do not develop assurance discipline on a schedule. They develop it under pressure, |
| SCOPE | Widened domain | cybersecurity, third-party and vendor risk, data privacy, regulatory compliance, supply chain |
| CAPMKT | Capital-market consequences | They raise the discount investors apply to comparable issuers. |
| LEGACY | Why the rule exists, and how it got here | In 2013 the Exchange asked the Commission to extend the existing one-year transition period to |
| IMPETUS | No occasion for the change | It does not identify what has changed in the intervening thirteen years. |
| 5YRS | Five years is unexplained | A rationale that supported twelve months in 2013 cannot, without more, support sixty months in 2026. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI strongly support maintaining the requirement for listed companies to establish an Internal Audit function within their first year of listing. Staff assurance analyst with a CIA supports keeping the one-year requirement, citing the filing's thin evidence of burden relief against heightened control risk during early growth. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Early career (<5 yrs) |
| Remedy | Keep one year | — |
| HIRISK | Peak risk window | significantly increasing governance, compliance, and internal control risks during a critical period of growth and change |
| NOEV | No evidentiary record | The proposal provides little evidence that extending the timeline to five years would meaningfully reduce burden |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeCII therefore respectfully requests that the SEC disapprove the Proposed Amendments. Council of Institutional Investors opposes the extension as potentially inconsistent with Section 6(b)(5), arguing the Exchange failed to consider that the SEC's pending filer-status proposal would exempt newly public companies from the 404(b) attestation over the same five years, and asks the Commission to disapprove. |
| Entity | Investor advocacy org majority | primary Investor advocacy orgself-described Investment professional / institutional investorletterhead Investor advocacy org |
| Remedy | Keep one year | Requests disapproval of the proposed amendments; no alternative period or phase-in proposed |
| NONSUB | Not substitutes | the Section 404(b) Requirement, they may have concluded that there would not be sufficient |
| 404B | Attestation gap | Exchange Commission (SEC) has a current proposal that would effectively provide initial public |
| INVPROT | Investor protection standard | language of Section 6(b)(5) of the Securities |
| LEGACY | Why the rule exists, and how it got here | accounting failures of the early 2000s, including Enron and WorldCom |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. CIA-credentialed internal auditor of 20+ years opposes the five-year extension and urges disapproval, arguing early establishment sets tone at the top and the one-year rule is already met by scaling or co-sourcing. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | — |
| HIRISK | Peak risk window | when its systems and controls are being built, and when objective assurance over that work matters most |
| FEAS | The one-year rule is workable | The current one-year requirement is met every year by companies of every size |
| FOUNDATION | Built at the foundation | Striking the right balance between agility and appropriate oversight requires a strong tone at the top. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the Commission to disapprove the proposal, or to institute proceedings to fully examine its consequences for investors before any such change is approved. Technology audit director writing personally urges disapproval or proceedings, citing the post-2003 origin of the rule, historic control failures, the overlapping 404(b) exemption, and the absence of any evidentiary record. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Manager |
| Remedy | Keep one year | — |
| Procedural | PROC_PROCEEDINGS | For these reasons, I respectfully urge the Commission to disapprove the proposal, or to institute proceedings to fully examine its consequences for investors before any such change is approved. |
| HIRISK | Peak risk window | That is exactly the window in which governance is least mature and risk is highest |
| NONSUB | Not substitutes | with no one on the other side of the table for five years, deepening their dependence on the very management they are charged with overseeing |
| 404B | Attestation gap | Most newly public companies are already exempt from the SOX Section 404(b) auditor attestation over internal control for up to five years post-IPO |
| FEAS | The one-year rule is workable | by appointing a chief audit executive with a co-sourced or outsourced provider, or by building a small team scaled to their risks |
| NOEV | No evidentiary record | The filing offers no evidence to justify the rollback. It identifies no population of affected issuers, quantifies no burden or cost savings |
| INVPROT | Investor protection standard | Section 6(b)(5) of the Exchange Act requires that exchange rules protect investors and the public interest |
| FOUNDATION | Built at the foundation | A newly public company spends its first years building the systems, controls, and governance practices it will rely on for decades. |
| SCOPE 2 of 3 | Widened domain | internal audit looks forward and continuously across cyber, technology, operations, supply chain, data privacy, and compliance risk |
| LEGACY | Why the rule exists, and how it got here | weakening it now reverses more than two decades of hard-won investor protection |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeYou have the opportunity to shut down this ability to hide questionable behavior for this extended time. Unaffiliated individual opposes the five-year extension on general transparency grounds and asks the Commission to stop it, offering no substantive analysis of the proposal. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Keep one year | — |
| IMPETUS | No occasion for the change | I would be interested to know why this rule is even being proposed - what lobbyists are pushing for this change? |
| NR 2 of 3 | No substantive rationale | I was very disheartened to hear about NYSE Proposed Rule Filing SR-NYSE-2026-37. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the Commission to disapprove the proposed rule change. CIA-credentialed internal audit professional writing personally opposes the five-year extension, rebuts the burden, Nasdaq-benchmark and maturity rationales, and urges the Commission to disapprove. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | — |
| HIRISK | Peak risk window | These pressures can increase risk to investors and the company's broader stakeholder community, strengthening the need for early, objective assurance. |
| NONSUB | Not substitutes | An independent audit committee provides oversight, but it does not itself generate independent information. |
| 404B | Attestation gap | Section 404(b) does not apply to every newly public company during this period |
| FEAS | The one-year rule is workable | a company can establish a small, risk-based function scaled to its circumstances, including through outsourcing |
| NOEV | No evidentiary record | The proposal provides no meaningful data showing that the current deadline is unworkable |
| NASDAQ | Nasdaq benchmark contested | Nasdaq's lack of a comparable requirement establishes only that the exchanges have different listing standards. |
| FOUNDATION | Built at the foundation | Early attention to these areas can prevent weaknesses from becoming embedded |
| SCOPE | Widened domain | Internal Audit has been critical beyond financial reporting in areas such as non-financial reporting, data integrity, privacy, cybersecurity |
| 5YRS | Five years is unexplained | The proposal provides no meaningful data showing that the current deadline is unworkable, that five years is necessary, or that the asserted burden outweighs the resulting assurance gap. |
| COST | Burden on new issuers | The one-year requirement need not impose an excessive burden. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the SEC to reject the proposed rule change or require further analysis and stakeholder input before taking action. Corporate internal audit manager opposes the extension, arguing it removes independent assurance while new issuers' controls are still maturing, and asks the SEC to reject it or require further analysis. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Manager |
| Remedy | Keep one year | — |
| HIRISK | Peak risk window | Newly public companies often face significant operational, compliance, technology, and financial reporting risks while their governance structures and control environments are still maturing. |
| NONSUB 2 of 3 | Not substitutes | Extending the implementation period to five years could leave investors and boards with less visibility into emerging risks and control weaknesses |
| FOUNDATION 2 of 3 | Built at the foundation | Risks should be identified early and often to prevent major reputational and shareholder loss. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully request that the Commission retain the existing one-year requirement and disapprove the proposed rule change. Chief Internal Auditor opposes the extension, stressing the attestation-exemption overlap, the audit committee's loss of independent assurance and the filing's lack of quantitative evidence, and asks for disapproval or formal proceedings. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Chief audit executive / head of function |
| Remedy | Keep one year | — |
| Procedural | PROC_PROCEEDINGS | At a minimum, the Commission should institute formal proceedings to evaluate the proposal and obtain additional evidence before taking action. |
| HIRISK | Peak risk window | The years immediately following a public listing can present heightened risk. |
| NONSUB | Not substitutes | External audit, management certifications, and audit committee oversight are important protections, but they do not replace internal audit. |
| 404B | Attestation gap | This concern is compounded by the external auditor attestation exemptions available to many newly public companies. |
| FEAS | The one-year rule is workable | Newly listed companies can meet the requirement through a risk-appropriate internal team, a co-sourced arrangement, or an outsourced provider |
| NOEV | No evidentiary record | The NYSE filing does not provide quantitative evidence regarding the number of companies affected |
| FOUNDATION | Built at the foundation | risk professionals are able to recommend building controls into the processes as they are created |
| SCOPE | Widened domain | Internal audit provides broader and ongoing assurance over risks such as cybersecurity, technology, operations, supply chain, data privacy, fraud, regulatory compliance, and governance. |
| COST | Burden on new issuers | The challenges of building an internal audit function do not justify a five-year delay. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. Texas CPA and IIA member lists five objections to the five-year extension - high-risk window, investor-protection gap, ICFR reliability, reduced management accountability and operational readiness - and invokes past corporate failures, without a named procedural request. |
| Entity | Accountant / external auditor (CPA) unanimous | primary Accountant / external auditor (CPA)self-described Accountant / external auditor (CPA)letterhead Accountant / external auditor (CPA) |
| Remedy | Keep one year | — |
| HIRISK | Peak risk window | Newly listed companies typically experience rapid growth, immature processes, and evolving governance structures. |
| NONSUB 2 of 3 | Not substitutes | This creates an environment where issues may be concealed, minimized, or unaddressed, impairing the quality of information available to boards, audit committees, and investors. |
| INVPROT 2 of 3 | Investor protection standard | This gap is inconsistent with the SEC's mandate to safeguard investors. |
| FOUNDATION | Built at the foundation | Requiring internal audit within one year ensures companies build foundational controls early. |
| SCOPE 2 of 3 | Widened domain | exposes investors to heightened risk of misstatement, fraud, cybersecurity vulnerabilities, and operational failures |
| LEGACY 2 of 3 | Why the rule exists, and how it got here | We should not lose sight of market history or the well-documented failures of companies that did not establish, maintain, or evolve their internal control and audit capabilities. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI therefore respectfully urge the Commission to disapprove the proposed rule change Internal audit professional writing personally opposes the extension, citing the formative-years risk window, the attestation-exemption overlap, scalable outsourced options and thin supporting evidence, and asks for disapproval or proceedings. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | — |
| Procedural | PROC_PROCEEDINGS | at minimum, institute proceedings to examine more fully its effects on corporate governance, audit committee effectiveness, investor protection, and the overall assurance environment of newly listed companies. |
| HIRISK | Peak risk window | The first years after a company becomes publicly listed are typically a period of significant institutional development. |
| NONSUB | Not substitutes | Other assurance mechanisms therefore should not be considered substitutes for internal audit. |
| 404B | Attestation gap | many newly public companies may already operate for several years without auditor attestation over internal control pursuant to existing exemptions |
| FEAS | The one-year rule is workable | An effective internal audit function also does not necessarily require a large department. |
| NOEV | No evidentiary record | I am also concerned by the limited evidence presented for such a significant change. |
| FOUNDATION 2 of 3 | Built at the foundation | I see little justification for concluding that such a component should only become necessary five years after a company enters the public markets. |
| SCOPE | Widened domain | Its scope can extend well beyond financial reporting to areas such as cybersecurity, technology, regulatory compliance, operations, third-party risk, data governance |
| 5YRS | Five years is unexplained | I see little justification for concluding that such a component should only become necessary five years after a company enters the public markets. |
| COST | Burden on new issuers | A general assertion that establishing internal audit can be difficult or costly does not, by itself, justify such a substantial reduction in assurance. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI am writing to respectfully express my strong opposition to extending the current one-year requirement for newly listed public companies to establish an internal audit function to five years. Career internal auditor in financial services opposes the five-year extension, arguing independent internal audit is most valuable in the first years after listing, when processes and controls are still being built. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | The first few years as a public company are often when organizations are building new processes, strengthening controls, and adapting to increased regulatory and investor expectations. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I urge the Commission to disapprove the proposed rule change. A CPA opposes the extension and urges the Commission to disapprove, arguing the post-IPO years are when independent assurance is most critical and delay would weaken oversight. |
| Entity | Accountant / external auditor (CPA) unanimous | primary Accountant / external auditor (CPA)self-described Accountant / external auditor (CPA)letterhead Accountant / external auditor (CPA) |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | Newly public companies are establishing governance frameworks, internal controls, and risk management processes while facing heightened regulatory, operational, and reporting risks. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the SEC to reject the proposed rule change and maintain the existing one-year requirement for newly listed companies to establish an internal audit function. An internal audit professional writing personally urges rejection of the extension, citing post-IPO risk, overlapping auditor-attestation exemptions, the absence of supporting evidence in the filing, and the feasibility of scaled or outsourced internal audit. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | The years immediately following an IPO are often characterized by rapid growth, organizational change, evolving processes, and developing control environments. |
| NONSUB | Not substitutes | without both internal audit oversight and other forms of independent assurance would significantly reduce transparency and oversight available to investors and audit committees |
| 404B | Attestation gap | many newly public companies already benefit from exemptions related to auditor attestation of internal controls |
| FEAS | The one-year rule is workable | companies have successfully implemented appropriately scaled internal audit functions through in-house, co-sourced, or outsourced models |
| NOEV | No evidentiary record | the proposal does not appear to provide sufficient evidence demonstrating that the current one-year requirement imposes an unreasonable burden |
| FOUNDATION | Built at the foundation | as these foundational governance structures mature |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to reject the proposed extension and preserve the current one-year requirement. A Certified Internal Auditor urges the Commission to reject the extension and preserve the one-year rule, arguing existing safeguards do not replace internal audit and that a proportionate, risk-based or outsourced function is workable from the start. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | The early years following a public listing are precisely when governance, reporting processes, technology, and internal controls are evolving, while business and regulatory demands are increasing. |
| NONSUB | Not substitutes | The existing requirements cited by the NYSE do not replace internal audit. |
| FEAS | The one-year rule is workable | Internal audit does not need to begin as a large or heavily resourced function. A proportionate, risk-based capability can be established and scaled as the company matures. |
| FOUNDATION | Built at the foundation | Strong governance should be part of a public company’s foundation, not introduced after risks and control weaknesses have had years to develop. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeAs an auditor for more than 20 years I strongly oppose the proposal to extend - from one year to five years - the deadline for newly listed companies to stand up their required internal audit function. An auditor of more than 20 years opposes the five-year extension as a rollback in investor protection covering the period of least mature controls, and separately asks for a 30-day comment-period extension. |
| Entity | Accountant / external auditor (CPA) unanimous | primary Accountant / external auditor (CPA)self-described Accountant / external auditor (CPA)letterhead Accountant / external auditor (CPA) |
| Remedy | Keep one year | one year |
| Procedural | PROC_EXTEND | I also ask the SEC for a 30-day extension so more voices can be heard on this important matter. |
| HIRISK | Peak risk window | precisely during the period when governance and controls are typically least mature and risk is highest |
| INVPROT 2 of 3 | Investor protection standard | I believe that it is a significant rollback in investor protection |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. A corporate internal audit manager writing personally objects that a five-year deferral would remove independent oversight during the period of greatest change, and questions whether the other safeguards the filing cites are sufficient for the audit committee. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Manager |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | Periods of significant organizational transition often carry increased risk. Processes are changing, responsibilities may be shifting, new systems and controls may be implemented |
| NONSUB | Not substitutes | Management oversight and external audit provide important safeguards, but they do not necessarily provide the same ongoing, enterprise-wide independent assessment of risk, governance, and controls |
| FEAS | The one-year rule is workable | An internal audit function does not need to be fully mature on day one to begin providing this value. |
| FOUNDATION 2 of 3 | Built at the foundation | as the company grows into its responsibilities as a public entity |
| SCOPE | Widened domain | This value is not limited to accounting or financial reporting. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the SEC to reconsider the proposed five-year delay and maintain a shorter timeframe for the internal audit requirement. A Certified Internal Auditor objects that a five-year delay is too long, urges a shorter timeframe, and also asks for an extended comment period. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Shorter extension | unspecified shorter timeframe than five years |
| Procedural | PROC_EXTEND | I also support extending the public comment period so that investors, audit professionals, public companies, and other stakeholders have adequate opportunity to evaluate and comment on the proposal. |
| HIRISK | Peak risk window | The first several years following a public listing are a critical period in which companies establish and strengthen their governance, risk management, internal controls |
| FOUNDATION | Built at the foundation | Delaying this requirement for five years could leave investors without an important governance safeguard during a company's formative years as a public company. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. An IIA chapter letter objects that the filing shows no evidence of burden and that a five-year delay would cut independent assurance during the formative post-IPO years, asking the Commission to weigh those implications before acting. |
| Entity | Professional body / trade association unanimous | primary Professional body / trade associationself-described Professional body / trade associationletterhead Professional body / trade association |
| Remedy | No modification requested | — |
| HIRISK | Peak risk window | when risk is often heightened and governance practices have not yet fully matured. |
| NONSUB | Not substitutes | Internal audit provides boards and audit committees with an independent source of |
| FEAS | The one-year rule is workable | For more than two decades, companies have successfully complied with the requirement |
| NOEV | No evidentiary record | We are also concerned that the proposal does not provide supporting evidence |
| FOUNDATION | Built at the foundation | independent assurance is particularly valuable during the early years of a company's life |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the Commission to disapprove the proposal or institute proceedings to examine it more fully. A Certified Internal Auditor urges disapproval or proceedings, arguing the EGC 404(b) exemption leaves five years with no attestation and no internal audit, that the filing offers no evidence, and that Nasdaq is no benchmark. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year |
| Procedural | PROC_PROCEEDINGS | For these reasons, I respectfully urge the Commission to disapprove the proposal or institute proceedings to examine it more fully. |
| HIRISK | Peak risk window | precisely when its systems, controls, and governance are least mature and risk is highest |
| NONSUB | Not substitutes | For five years, no one would sit on the other side of that table, leaving directors dependent on the management they are charged with overseeing. |
| 404B | Attestation gap | most newly listed companies are Emerging Growth Companies, already exempt from 404(b) attestation for up to five years after IPO |
| FEAS | The one-year rule is workable | For more than two decades, issuers have met this requirement through a chief audit executive with a co-sourced or outsourced provider, or a small team scaled to their risks. |
| NOEV | No evidentiary record | The filing offers no evidence. It identifies no population of affected issuers, quantifies no burden, estimates no cost savings, and analyzes no investor consequences. |
| NASDAQ | Nasdaq benchmark contested | That Nasdaq imposes no such requirement is a reason to preserve the NYSE's standard, not to lower it toward a weaker one. |
| FOUNDATION | Built at the foundation | A newly public company is building the control environment it will rely on for decades. |
| SCOPE 2 of 3 | Widened domain | internal audit examines the full risk picture - cyber, technology, operations, data privacy, and compliance - continuously |
| LEGACY | Why the rule exists, and how it got here | A change of this magnitude to a post-Enron governance safeguard warrants an evidentiary record, not assertion. |
| IMPETUS | No occasion for the change | It rests on anecdotes from unnamed issuers, yet proposes a 400% extension of the timeline. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I strongly encourage the Commission to preserve the existing requirement and continue recognizing the vital role internal audit plays in protecting investors and supporting healthy, well-governed public companies. An unaffiliated individual urges the Commission to keep the current requirement and not adopt a five-year delay, arguing post-IPO risk is heightened and internal audit is foundational governance. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Keep one year | maintain the current one-year requirement |
| HIRISK | Peak risk window | Organizations transitioning to the public markets face heightened risks stemming from rapid growth, increased regulatory obligations, evolving business processes, expanding operations |
| FOUNDATION | Built at the foundation | An effective internal audit function is a foundational component of strong corporate governance. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI therefore encourage the SEC and NYSE to reconsider the proposed five-year transition period. Certified Internal Auditor with four years' experience objects that five years is unnecessarily long, argues internal audit is not replaceable by the board or external auditor and can be small or outsourced, and urges a shorter transition of two or three years. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Early career (<5 yrs) |
| Remedy | Shorter extension | two or three years |
| HIRISK | Peak risk window | Newly public companies are adapting to the demands of public-company reporting, governance, internal controls, and increased investor scrutiny. |
| NONSUB | Not substitutes | Internal audit provides a perspective that is fundamentally different from management, the audit committee, and the external auditor. |
| FEAS | The one-year rule is workable | Internal audit functions do not necessarily need to be large or expensive. |
| COST | Burden on new issuers | I recognize that establishing an internal audit function can create costs and administrative challenges for newly public companies. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI urge the SEC to reject the proposal and retain the current one-year requirement. A CPA opposes the rule change and asks the SEC to reject it and retain the one-year requirement, citing the existing SOX attestation exemption, the loss of an audit committee information channel, and the absence of evidence. |
| Entity | Accountant / external auditor (CPA) unanimous | primary Accountant / external auditor (CPA)self-described Accountant / external auditor (CPA)letterhead Accountant / external auditor (CPA) |
| Remedy | Keep one year | one year |
| NONSUB | Not substitutes | deprive audit committees of a key source of information independent of management |
| 404B | Attestation gap | Because most are already exempt from SOX auditor attestation requirements |
| NOEV | No evidentiary record | The NYSE has offered no empirical evidence or cost-benefit analysis to support this reduction in investor protections. |
| FOUNDATION | Built at the foundation | New public companies need independent assurance from the start. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the Commission to disapprove the proposal or open formal proceedings to evaluate its impact on investors and market integrity. An internal audit and analytics professional urges disapproval or formal proceedings, arguing the delay strips audit committees of an independent channel when risk is highest and that no data show the one-year timeline is burdensome. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year |
| Procedural | PROC_PROCEEDINGS | For these reasons, I respectfully urge the Commission to disapprove the proposal or open formal proceedings to evaluate its impact on investors and market integrity. |
| HIRISK | Peak risk window | during the period when risks are highest and controls are least mature |
| NONSUB | Not substitutes | would leave audit committees without an independent channel |
| FEAS | The one-year rule is workable | In practice, companies can meet the requirement through a small internal team |
| NOEV | No evidentiary record | The proposal also provides no data showing that the current one-year timeline is burdensome. |
| FOUNDATION | Built at the foundation | The first year is when systems, controls, and reporting processes are still forming |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. Certified Internal Auditor with public-accounting, gaming and school-board internal audit experience strongly disagrees with the five-year extension, arguing the first five years are the riskiest and the function should be built during IPO preparation. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | function should be built while the company is preparing to go public |
| HIRISK | Peak risk window | The first five years of a company is an extremely risky time period, and adequate controls must be in place. |
| FEAS | The one-year rule is workable | Companies should work on creating their internal audit function during the time in which they are preparing to take their company public. |
| FOUNDATION 2 of 3 | Built at the foundation | Companies should work on creating their internal audit function during the time in which they are preparing to take their company public. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI agree with the NYSE's prior comments that having a robust internal audit function is a key component of sound corporate governance and therefore ask that you reconsider this proposal to change the existing requirement. Chief Internal Auditor at Apple Bank with a 43-year career calls a five-year wait a step backwards for corporate governance and asks the Commission to reconsider the change to the existing requirement. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Chief audit executive / head of function |
| Remedy | Keep one year | — |
| FOUNDATION 2 of 3 | Built at the foundation | Waiting five years for newly listed companies to establish an internal audit function is definitely a step backwards for corporate governance. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeAccordingly, I respectfully suggest that the Commission consider alternatives rather than adopting the full five-year extension. Audit Manager in Apple Bank's internal audit department acknowledges post-IPO resource burdens but argues five years is longer than necessary, urging a two-to-three-year period or a phased, milestone-based implementation with co-sourcing flexibility. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Manager |
| Remedy | Shorter extension | two or three years; alternatively a phased schedule (enterprise risk assessment in year one, audit committee-approved internal audit charter in year two, fully operational function by year three), enhanced audit committee disclosure, and co-sourcing/outsourcing flexibility |
| HIRISK | Peak risk window | The period immediately following an IPO is often when companies experience rapid growth, organizational change, new regulatory obligations, and increased operational complexity. |
| NONSUB | Not substitutes | internal audit provides a unique and important line of assurance that complements management and external audit activities |
| FEAS | The one-year rule is workable | The NYSE already permits the internal audit function to be outsourced to an independent third-party provider. |
| INVPROT 2 of 3 | Investor protection standard | I encourage the Commission to carefully evaluate whether a five-year transition period appropriately balances issuer burden with investor protection objectives |
| FOUNDATION | Built at the foundation | extending the transition period to five years would result in a significant portion of a company's early public-company lifecycle operating without a dedicated internal audit function |
| COST | Burden on new issuers | I appreciate the NYSE's recognition that newly public companies must devote considerable resources to complying with public company reporting obligations |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI am writing to implore you to reconsider extending the required time frame from 1 to 5 years for newly listed NYSE companies. CIA and CFE urges the Commission to reconsider the one-to-five-year extension, invoking Enron and WorldCom, arguing internal audit is inexpensive, and proposing instead that Nasdaq be held to the same one-year requirement. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | retain the one-year requirement and have Nasdaq adopt the same one-year requirement for consistency |
| NASDAQ | Nasdaq benchmark contested | Instead, you should be looking to have Nasdaq have the same 1-year requirement of the NYSE to provide consistency and close this loophole. |
| FOUNDATION | Built at the foundation | Internal Audit matters and having them tied to the organization from the outset of going public is critically important. |
| LEGACY | Why the rule exists, and how it got here | Do you really want another Enron or Worldcom corporate failure? |
| COST | Burden on new issuers | Internal audit functions are not costly overall but provide so much value to their companies and for the investing public. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Internal audit professional with 20-plus years and a CISA, writing in a personal capacity, opposes the extension because the first public years are when assurance matters most and the one-year rule is already met given outsourcing and scaling, and urges disapproval. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | — |
| HIRISK | Peak risk window | A public company's first years are when its systems and controls are being built, and when objective assurance over that work matters most. |
| FEAS | The one-year rule is workable | The current one-year requirement is met every year by companies of all sizes because the Exchange's rule allows the function to be outsourced, co-sourced, and scaled to the company. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission not to approve the proposal as submitted. Anonymous commenter opposes the five-year extension, arguing the post-listing years carry the highest risk and that audit committee, ICFR and external-auditor safeguards do not replace internal audit, and urges the Commission not to approve the proposal as submitted. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Fallback / compromise | if additional flexibility is warranted, a shorter transition period or defined, risk-based implementation milestones instead of a blanket five-year delay |
| HIRISK | Peak risk window | The years immediately following a public listing are often characterized by rapid growth, evolving systems, significant organizational change, and heightened operational and compliance risk. |
| NONSUB | Not substitutes | external-auditor requirements are important safeguards, but they do not replace an internal audit function's broader and continuous evaluation |
| FOUNDATION 2 of 3 | Built at the foundation | during precisely the period when governance and control frameworks may be least mature |
| SCOPE 2 of 3 | Widened domain | broader and continuous evaluation of governance, risk management, operational controls, technology, compliance, and emerging risks |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the Commission to disapprove the proposed rule change Internal audit and IT risk advisory senior manager (CIA, CISA, CISM) opposes the five-year extension, stressing the combined gap with the SOX 404(b) attestation exemption, the audit committee's loss of an independent channel, and the absence of supporting data; asks the Commission to disapprove or institute 19(b)(2)(B) proceedings. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Individualletterhead Internal audit professional sub-role: Outsourced / co-sourced provider |
| Remedy | Keep one year | Retain the existing one-year transition period; scale the function to risk (a chief audit executive plus co-sourced/outsourced support) rather than extend to five years. |
| Procedural | PROC_PROCEEDINGS | or, at minimum, to institute proceedings under Section 19(b)(2)(B) of the Securities Exchange |
| HIRISK | Peak risk window | still building the control environment they will operate under for years to come |
| NONSUB | Not substitutes | because audit committees need a source of information that does not run through management. |
| 404B | Attestation gap | the SOX internal control auditor attestation for up to five years, and a separate pending SEC |
| FEAS | The one-year rule is workable | company's risk profile starting with a chief audit executive and a co-sourced or outsourced |
| NOEV | No evidentiary record | the NYSE's filing does not include any supporting data: no count of how many issuers this would |
| FOUNDATION 2 of 3 | Built at the foundation | it just means the company operates through its most formative period without anyone |
| COST 2 of 3 | Burden on new issuers | no quantification of the burden the current one-year requirement imposes |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI strongly urge the Commission to reject this proposal and maintain the current one-year transition period to ensure newly public companies remain accountable, secure, and transparent from the outset. Retired CPA/CIA/CISA and former PwC internal audit partner and chief audit executive strongly opposes the extension, invoking Enron/WorldCom and SOX, modern cyber and AI risk, and a race to the bottom with exchanges lacking an internal audit mandate; urges rejection and retention of one year. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Accountant / external auditor (CPA)letterhead Internal audit professional sub-role: Retired / former |
| Remedy | Keep one year | Maintain the current one-year transition period |
| HIRISK | Peak risk window | leaves organizations highly exposed during their most vulnerable, high-growth phase |
| NONSUB | Not substitutes | While external auditors focus primarily on historical financial metrics, an internal audit function is uniquely equipped to continuously evaluate these real-time operational risks |
| NASDAQ | Nasdaq benchmark contested | Relaxing these safeguards to compete with exchanges that lack robust internal audit mandates creates a harmful |
| FOUNDATION | Built at the foundation | to ensure newly public companies remain accountable, secure, and transparent from the outset |
| SCOPE | Widened domain | the operational landscape today is vastly more complex and volatile than it was two decades ago |
| LEGACY | Why the rule exists, and how it got here | The devastating financial statement fraud scandals of the early 2000s-most notably Enron and WorldCom-wiped out billions of dollars in investor wealth |
| COST 2 of 3 | Burden on new issuers | While I understand the desire to reduce regulatory burdens for newly public entities |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI urge the SEC to maintain the current one‑year requirement. Short individual letter opposing the five-year extension on the ground that it weakens early-stage investor protection when controls and governance are least mature, and urging retention of the one-year requirement. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Keep one year | Maintain the current one-year requirement |
| HIRISK | Peak risk window | when controls and governance are least mature |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the Commission to disapprove the proposed amendment and retain the existing one-year transition period. Internal audit practitioner opposes the five-year extension in a six-part argument that the audit committee, SOX 404, CEO/CFO certifications and external audit are complements rather than substitutes, that the existing rule already allows outsourcing, and that the filing offers no supporting evidence; asks for disapproval, supports the IIA's comment-period extension request, and offers a narrowly tailored milestone-based alternative. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Fallback / compromise | Primary ask is to disapprove and retain one year; only if the Commission concludes additional flexibility is warranted, a narrowly tailored limited additional transition period conditioned on an initial enterprise risk assessment, an internal audit charter and audit-committee reporting line, an implementation plan, and access to independent internal audit resources. |
| Procedural | PROC_EXTEND | I also support The Institute of Internal Auditors' request for additional time for public comment. |
| HIRISK | Peak risk window | Periods of rapid organizational change are precisely when risks can evolve faster than governance structures and controls. |
| NONSUB | Not substitutes | Internal audit is not redundant with an independent audit committee, Sarbanes-Oxley compliance, external audit, or CEO and CFO certifications. |
| FEAS | The one-year rule is workable | Section 303A.07 permits a company's internal audit function to be outsourced to a third-party service provider other than its independent auditor. |
| NOEV | No evidentiary record | the filing does not quantify the cost or burden imposed by the existing requirement |
| NASDAQ | Nasdaq benchmark contested | The fact that Nasdaq does not require an internal audit function does not demonstrate that the NYSE requirement lacks value |
| INVPROT 2 of 3 | Investor protection standard | evaluate the investor-protection consequences of permitting companies to operate for five years without the function |
| FOUNDATION 2 of 3 | Built at the foundation | help prevent immature practices from becoming institutionalized |
| SCOPE 2 of 3 | Widened domain | Internal audit can assess risks involving operations, regulatory compliance, technology, cybersecurity, third parties, governance, fraud risk, data, business continuity, conduct |
| IMPETUS | No occasion for the change | The filing instead refers generally to concerns raised by issuers, while also stating that no written comments were solicited or received with respect to the proposed rule change. |
| 5YRS 2 of 3 | Five years is unexplained | Before weakening a longstanding corporate governance requirement to this extent, there should be compelling evidence that the existing rule creates a material problem and that a five-year exemption is appropriately tailored to address it. |
| COST | Burden on new issuers | the operational difficulty of building a mature internal audit department does not, by itself, justify |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeKeep 1 year as the requirement. Internal audit trainer with nearly 30 years in the field asks that the one-year requirement be kept, arguing weaknesses are harder to correct once established and that early internal audit helps build control and governance structures and institutional knowledge from Day 1. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | Keep 1 year as the requirement |
| FOUNDATION | Built at the foundation | Internal Audit can provide valuable advisory work to help set up the right internal control and governance structures from Day 1 of the company. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully encourage the Commission to disapprove the proposed five-year extension or consider a more proportionate phased implementation approach. CIA/CRMA writing in a personal capacity opposes the five-year transition, arguing internal audit as the third line of defense is not interchangeable with management assessment, external audit or audit committee oversight and that outsourcing makes the current deadline workable; asks for disapproval or a proportionate phased model with year-one minimums. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Individualletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Scaled / risk-based phase-in or milestones | Retain the existing one-year requirement or adopt a phased model: within the first year, an independent internal audit mandate, reporting to the audit committee, an enterprise-level risk assessment and a risk-based assurance plan, with the size and maturity of the function developing proportionately. |
| HIRISK | Peak risk window | particularly during a period when systems, controls, management structures and regulatory obligations are themselves changing rapidly |
| NONSUB | Not substitutes | Management assessment, external audit, audit committee oversight, all perform different governance roles. |
| FEAS | The one-year rule is workable | the existing ability to outsource or co-source internal audit provides a proportionate alternative |
| COST | Burden on new issuers | If the principal concern is the practical difficulty of building a mature in-house function during the first year after listing |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I urge the Commission to disapprove the proposal, or open formal proceedings under Section 19(b)(2)(B) of the Securities Exchange Act. Internal audit practice leader at a national accounting and advisory firm opposes the five-year extension, urging disapproval or 19(b)(2)(B) proceedings, citing early-listing control fragility, the concurrent SOX attestation exemption, loss of the audit committee's independent channel, and the filing's lack of data. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Accountant / external auditor (CPA)letterhead Internal audit professional sub-role: Outsourced / co-sourced provider |
| Remedy | Keep one year | retain the existing one-year transition period |
| Procedural | PROC_PROCEEDINGS | For these reasons, I urge the Commission to disapprove the proposal, or open formal proceedings under Section 19(b)(2)(B) of the Securities Exchange Act. |
| HIRISK | Peak risk window | a newly public company's control environment is most fragile in its first months as a public issuer |
| NONSUB | Not substitutes | NYSE's own listing standards direct audit committees to meet periodically, and separately, with internal auditors. |
| 404B | Attestation gap | neither an internal audit function nor an external attestation over internal control |
| FEAS | The one-year rule is workable | the current one-year timeline is workable |
| NOEV | No evidentiary record | includes no data on the issuers affected, the costs involved, or the expected impact |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeWe therefore urge the Commission to disapprove the proposed rule change or institute proceedings under Section 19(b)(2)(B) of the Securities Exchange Act to determine whether it should be Eight-organization coalition led by The Institute of Internal Auditors opposes the extension, arguing the 404(b) exemption and the SEC's pending filer-status proposal would leave newly listed companies five years with neither internal audit nor attestation, and urges disapproval or proceedings under Section 19(b)(2)(B). |
| Entity | Professional body / trade association majority | primary Professional body / trade associationself-described Investor advocacy orgletterhead Professional body / trade association |
| Remedy | Keep one year | Urges disapproval or proceedings under Section 19(b)(2)(B); no alternative period proposed, assurance should begin at the foundation of a newly public company |
| Procedural | PROC_PROCEEDINGS | We therefore urge the Commission to disapprove the proposed rule change or institute proceedings under Section 19(b)(2)(B) of the Securities Exchange Act to determine whether it should be |
| HIRISK | Peak risk window | a time when systems, controls, and governance practices are still being built |
| NONSUB | Not substitutes | a purpose no other safeguard duplicates: it gives the board and audit committee an objective, |
| 404B | Attestation gap | Most newly listed companies are exempt from the Sarbanes-Oxley auditor attestation over |
| FEAS | The one-year rule is workable | permits the function to be outsourced, and newly listed companies routinely comply by appointing |
| NOEV | No evidentiary record | the filing identifies no affected population, quantifies no burden |
| INVPROT 2 of 3 | Investor protection standard | so that a change of this consequence receives the scrutiny |
| FOUNDATION | Built at the foundation | Independent assurance should begin at the foundation of a |
| SCOPE | Widened domain | they say nothing about the cybersecurity, emerging technology, |
| LEGACY | Why the rule exists, and how it got here | The internal audit listing requirement is a legacy of hard lessons. |
| COST | Burden on new issuers | audit is a high-value, cost-effective protection |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | No position split | primary No positionliteralist Opposecharitable Support The letter states no ask. The position is read from what it argues. Risk governance and internal audit professional requests a 30-day comment-period extension, citing the 21-day window and the filing's limited supporting data, without asking the Commission to approve or reject the five-year extension. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | No modification requested | — |
| Procedural | PROC_EXTEND | I respectfully request that the SEC extend the public comment period for File No. SR-NYSE-2026-37 by at least 30 days. |
| HIRISK 2 of 3 | Peak risk window | internal audit provides critical independent assurance during the formative years of an organization's governance and control environment |
| NOEV | No evidentiary record | the proposal contains limited supporting data regarding the population of affected issuers |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeIt is requested that the required period for independent internal audit should be kept to one year. Finance director calls the proposal a significant rollback in investor protection, argues risk is highest and governance least mature right after listing and that AI-era growth argues for shorter not longer timelines, and asks that the period be kept to one year. |
| Entity | Issuer / Corporate — current unanimous | primary Issuer / Corporate — currentself-described Issuer / Corporate — currentletterhead Issuer / Corporate — current |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | precisely during the period when governance and controls are typically least mature and risk is highest |
| SCOPE 2 of 3 | Widened domain | With AI, the timelines should rather reduce when nimble organizations would be growing to list. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposePlease do not extend the transition period to longer than one year for public companies to stand up their Internal Audit teams for the sake of the overall health of our financial markets. Tennessee CPA and Certified Internal Auditor asks the Commission to keep the one-year timeline, grounding the request in the Enron collapse and the loss of investor confidence if no one is positioned to flag problems during a company's formative years. |
| Entity | Accountant / external auditor (CPA) majority | primary Accountant / external auditor (CPA)self-described Accountant / external auditor (CPA)letterhead Internal audit professional |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | especially at a time when organizations are in their formative years |
| LEGACY | Why the rule exists, and how it got here | I was in school when Enron fell and it ruined the retirement of a friend of mine's mother |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. Career internal auditor objects to giving newly listed companies five years, invoking the WorldCom/MCI fraud that produced SOX and arguing internal audit validation of controls must come as soon as possible after listing. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | — |
| HIRISK | Peak risk window | Investors need assurance most at the start, not five years later. |
| LEGACY | Why the rule exists, and how it got here | It is not that far in the past that SOX was established due to fraudulent behavior that left millions without jobs |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI believe that maintaining the current requirement, or considering a more limited alternative extension, would better support the interests of investors and the integrity of the public markets. Internal audit manager (CIA, CRMA, IIA member) opposes the five-year extension, arguing the post-IPO years are the most transformative, that the current requirement is already scalable and outsourceable, and asking that the one-year requirement be maintained or at most a more limited extension granted. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Manager |
| Remedy | Fallback / compromise | maintain the current one-year requirement, or a more limited alternative extension (no period named) |
| HIRISK | Peak risk window | During this period of rapid growth and increased stakeholder expectations, independent assurance becomes particularly valuable. |
| FEAS | The one-year rule is workable | Organizations have flexibility to implement scalable internal audit solutions, including the use of qualified third-party providers where appropriate. |
| INVPROT 2 of 3 | Investor protection standard | whether extending the implementation period from one year to five years is consistent with the objectives of sound corporate governance and investor protection |
| FOUNDATION | Built at the foundation | Investors benefit when companies establish strong governance structures early and demonstrate a commitment to effective oversight and accountability. |
| COST | Burden on new issuers | I recognize that newly listed companies face numerous competing priorities and compliance obligations |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI believe that maintaining the current requirement, or considering a more limited alternative extension, would better support the interests of investors and the integrity of the public markets. Risk consultant and CIA opposes the five-year extension, arguing post-IPO years carry the highest control risk and that the one-year rule is already met through scalable or outsourced internal audit; asks the Commission to keep the current requirement or, failing that, a more limited extension. |
| Entity | Consultant / advisory firm unanimous | primary Consultant / advisory firmself-described Consultant / advisory firmletterhead Consultant / advisory firm |
| Remedy | Fallback / compromise | Primary ask is maintaining the current one-year requirement; alternatively a 'more limited alternative extension' with no period named. |
| HIRISK | Peak risk window | During this period of rapid growth and increased stakeholder expectations, independent assurance becomes particularly valuable. |
| FEAS | The one-year rule is workable | Organizations have flexibility to implement scalable internal audit solutions, including the use of qualified third-party providers where appropriate. |
| INVPROT 2 of 3 | Investor protection standard | whether extending the implementation period from one year to five years is consistent with the objectives of sound corporate governance and investor protection |
| FOUNDATION | Built at the foundation | Investors benefit when companies establish strong governance structures early and demonstrate a commitment to effective oversight and accountability. |
| COST | Burden on new issuers | While I recognize that newly listed companies face numerous competing priorities and compliance obligations |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I urge the Commission to disapprove the proposed rule change or undertake further review of its implications for investors and market confidence. Internal auditor (CIA, CRMA) opposes the extension and urges disapproval, stressing post-IPO control risk, the audit committee's loss of an independent assurance source, overlap with SOX attestation exemptions, and the filing's lack of supporting evidence. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | — |
| HIRISK | Peak risk window | The years immediately following an IPO are when companies are developing the governance structures, risk management processes, and internal controls that investors rely upon. |
| NONSUB | Not substitutes | Internal audit also serves as an important independent resource for audit committees. |
| 404B | Attestation gap | many newly public companies are already exempt from certain Sarbanes-Oxley internal control attestation requirements |
| NOEV | No evidentiary record | the proposal does not provide sufficient evidence demonstrating that the benefits of a five-year delay outweigh the reduction in investor protections |
| INVPROT 2 of 3 | Investor protection standard | Before weakening a governance safeguard that has been in place for more than two decades, the SEC should require a stronger factual basis supporting the change. |
| FOUNDATION | Built at the foundation | Independent assurance is most valuable during this formative period, not five years later. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to reconsider the proposed five-year extension and maintain a timeframe that ensures newly listed companies implement an effective internal audit function much earlier in their transition to public ownership. Internal audit professional objects to the five-year extension as weakening governance during a company's formative public years, urges a much earlier requirement, and separately asks the SEC to extend the public comment period. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | Asks the Commission to reconsider and maintain a timeframe requiring internal audit much earlier than five years; no specific period named. |
| Procedural | PROC_EXTEND | I also encourage the SEC to provide additional opportunity for stakeholder feedback by extending the public comment period. |
| HIRISK | Peak risk window | a period when companies are experiencing rapid growth, increasing complexity, and heightened investor scrutiny |
| FOUNDATION | Built at the foundation | discourage organizations from establishing robust governance practices early in their public company lifecycle |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI urge the Commission to disapprove this proposed rule change, or at minimum to require NYSE to justify a substantially shorter extension supported by evidence, rather than an open-ended five-year window with no interim milestones or accountability. Cyber and risk governance consultant urges disapproval, rebutting the filing's reliance on SOX 302/404/906 as substitutes and on Nasdaq as a benchmark, and asking at minimum for a substantially shorter, evidence-supported extension with interim milestones. |
| Entity | Consultant / advisory firm unanimous | primary Consultant / advisory firmself-described Consultant / advisory firmletterhead Consultant / advisory firm |
| Remedy | Fallback / compromise | Primary ask is disapproval; at minimum, a substantially shorter extension supported by evidence, with interim milestones or accountability. No period named. |
| HIRISK | Peak risk window | Five years is also precisely the period in which newly public companies face the greatest pressure: rapid growth, new reporting obligations, leadership turnover |
| NONSUB | Not substitutes | The filing leans heavily on Sarbanes-Oxley Sections 302, 404, and 906 as sufficient substitutes. They are not. |
| NOEV 2 of 3 | No evidentiary record | to require NYSE to justify a substantially shorter extension supported by evidence, rather than an open-ended five-year window with no interim milestones or accountability |
| NASDAQ | Nasdaq benchmark contested | The comparison to Nasdaq's lack of an internal audit requirement is not a reason to weaken NYSE's own standard. |
| FOUNDATION | Built at the foundation | what happens when a company's internal control environment is left to mature informally rather than being built and tested early |
| 5YRS 2 of 3 | Five years is unexplained | or at minimum to require NYSE to justify a substantially shorter extension supported by evidence, rather than an open-ended five-year window with no interim milestones or accountability. |
| COST | Burden on new issuers | A five-year gap does not give a young public company breathing room |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully request that the SEC reject the proposed five-year extension and retain the existing one-year requirement. Global internal audit manager with prior external-audit and outsourced internal audit experience asks the SEC to reject the five-year extension and retain the one-year requirement, arguing audit committee oversight, certifications, SOX 404 and external audit complement rather than replace internal audit. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Manager |
| Remedy | Keep one year | Retain the existing one-year requirement. |
| HIRISK | Peak risk window | Newly public companies are also undergoing significant changes as they adapt to public-company reporting, governance, regulatory, and operational requirements. |
| NONSUB | Not substitutes | These requirements are important, but they do not replace internal audit. |
| FEAS | The one-year rule is workable | The existing one-year transition period already provides companies with reasonable time to establish an appropriate internal audit function |
| INVPROT 2 of 3 | Investor protection standard | Investor protection and effective corporate governance should remain the primary considerations. |
| FOUNDATION | Built at the foundation | A newly public company should have appropriate independent oversight of its risk management and internal control environment from the outset |
| COST | Burden on new issuers | while recognizing the challenges of becoming a public company |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Early-career internal audit professional (CPA) urges disapproval, arguing controls are built in a company's first public years and that the one-year requirement is already met because the Exchange's rule permits outsourced, co-sourced and scaled functions. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Early career (<5 yrs) |
| Remedy | Keep one year | — |
| HIRISK | Peak risk window | Five years without it is not a transition; it is an absence, during the years investors can least afford one. |
| FEAS | The one-year rule is workable | The current one-year requirement is met every year by companies of every size |
| FOUNDATION | Built at the foundation | A company's first years as a public company are when its systems and controls are being built, and when objective assurance over that work matters most. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the SEC to reject the NYSE proposal and maintain the existing requirement that newly listed companies establish an internal audit function within one year of listing. VP of Internal Audit opposes the five-year extension, urges the SEC to reject it and keep the one-year rule, and also asks that stakeholders get sufficient opportunity to comment. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Chief audit executive / head of function |
| Remedy | Keep one year | one year |
| Procedural | PROC_EXTEND | The SEC should ensure that investors, governance professionals, audit practitioners, academics, and other stakeholders have sufficient opportunity to assess and comment on the potential consequences of this change. |
| HIRISK | Peak risk window | These risks do not diminish immediately after an IPO; rather, they are often heightened during the first several years as companies scale rapidly |
| NONSUB | Not substitutes | Without this function, boards and audit committees may have diminished visibility into operational risks, control failures, regulatory compliance issues |
| FEAS | The one-year rule is workable | Establishing an internal audit function within the first year after listing strikes an appropriate balance between implementation challenges and investor protection. |
| NOEV 2 of 3 | No evidentiary record | The NYSE has not demonstrated that the existing one-year requirement imposes an unreasonable burden on newly listed companies. |
| FOUNDATION | Built at the foundation | Public companies are expected to maintain governance structures commensurate with their responsibilities to shareholders and the public markets. |
| IMPETUS | No occasion for the change | The NYSE has not demonstrated that the existing one-year requirement imposes an unreasonable burden on newly listed companies. |
| COST | Burden on new issuers | imposes an unreasonable burden on newly listed companies |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Internal audit and ERM service line leader (CIA), writing personally, opposes the extension and urges the Commission to disapprove, arguing internal audit can be stood up quickly, scaled and co-sourced. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Outsourced / co-sourced provider |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | A company's first years as a public company are when its systems and controls are being built, and when objective assurance over that work matters most. |
| NONSUB | Not substitutes | Internal audit also provides audit committees with an objective view of whether management's control environment is developing at the same pace as the business. |
| FEAS | The one-year rule is workable | Internal audit can be established quickly, scaled to the size and risk profile of the organization, and supported by outside specialists where needed. |
| FOUNDATION | Built at the foundation | a newly public company is building the infrastructure, discipline, and accountability expected of a public company |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeIf the Commission approves this extended transition period, I would urge a tiered approach based on the current filer status framework. CISA/CRISC risk professional objects that the proposal overstates SOX as a substitute and applies uniformly regardless of size, urging a tiered transition keyed to filer status if the Commission proceeds. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Scaled / risk-based phase-in or milestones | tiered by filer status: Large Accelerated Filers keep the one-year period; Accelerated, Non-Accelerated and Emerging Growth Companies get two to five years |
| NONSUB | Not substitutes | The NYSE's rationale relies heavily on the argument that Sarbanes-Oxley Section 404 requirements, CEO/CFO certifications, and independent audit committee oversight |
| 404B | Attestation gap | Large Accelerated Filer threshold to $2 billion and exempt significantly more public companies from Section 404(b) auditor attestations. |
| FOUNDATION | Built at the foundation | proposal risks embedding the perception within newly public companies that internal audit exists solely to support financial reporting and ICFR. |
| SCOPE | Widened domain | enterprise risk, including operational risk, cybersecurity, data privacy, fraud, third-party governance, product safety, regulatory compliance, and artificial |
| COST | Burden on new issuers | small emerging-growth company faces significantly different resource constraints than a large-scale IPO valued at tens or hundreds of billions of dollars. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. IT audit professional opposes the extension and urges the Commission to disapprove, arguing control weaknesses concentrate in the formative post-listing years and the one-year rule already permits outsourced or scaled functions. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | the most consequential control weaknesses often arise when systems, processes, and governance structures are still being designed and implemented |
| NONSUB 2 of 3 | Not substitutes | Independent assurance provides an objective perspective that helps leadership and boards understand whether risks are being appropriately identified and managed. |
| FEAS | The one-year rule is workable | the Exchange's own rule allows the function to be outsourced or co-sourced and scaled to the company |
| FOUNDATION | Built at the foundation | The organizations that established internal audit early were better positioned to identify control gaps, strengthen accountability |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI urge the Commission to reject this proposed extension and to maintain the current one-year requirement for establishing an internal audit function. Internal Audit Director writing personally urges the Commission to reject the extension and keep the one-year requirement, citing heightened post-listing risk and loss of board visibility. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Chief audit executive / head of function |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | Rapid growth, new regulatory obligations, expanding third-party relationships, and the pressure to scale quickly all increase the likelihood of control gaps |
| NONSUB 2 of 3 | Not substitutes | it gives management and the board real-time visibility into where controls are breaking down before those gaps become material weaknesses |
| FEAS 2 of 3 | The one-year rule is workable | An internal audit function established early does not slow a company down |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the SEC to reject the proposed rule change and encourage the SEC to preserve the existing one-year requirement Anonymous audit and internal controls professional urges the SEC to reject the extension and preserve the one-year requirement, stressing the overlap with existing 404(b) attestation exemptions and the absence of empirical support in the filing. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | Newly public companies are navigating increased regulatory requirements, expanding stakeholder expectations, and rapidly evolving operational risks. |
| NONSUB | Not substitutes | investors could face a prolonged period during which newly listed companies operate without either an internal audit function or independent assurance over the effectiveness of key controls |
| 404B | Attestation gap | many newly public companies are already exempt from external auditor attestation over internal control for several years after going public |
| FEAS | The one-year rule is workable | Internal audit can be scaled appropriately based on an organization's size and complexity through in-house, co-sourced, or outsourced models. |
| NOEV | No evidentiary record | the proposal does not appear to provide sufficient empirical evidence demonstrating that the existing one-year requirement imposes an unreasonable burden on issuers |
| FOUNDATION | Built at the foundation | Strong governance practices should begin when a company enters the public markets, not several years later. |
| LEGACY | Why the rule exists, and how it got here | Before reducing a governance requirement that has been in place for more than two decades |
| COST | Burden on new issuers | imposes an unreasonable burden on issuers |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeFor these reasons, I respectfully urge the Commission to disapprove the proposed rule change. Internal audit professional (15+ years, CIA/CISA) writing personally opposes the five-year extension and urges disapproval, arguing early post-listing years carry the highest control risk and that the one-year rule is workable via outsourced or co-sourced arrangements. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | retain the current one-year requirement |
| HIRISK | Peak risk window | A company's first years as a public company are often characterized by accelerated growth, increased regulatory scrutiny, evolving business processes, and heightened investor expectations. |
| FEAS | The one-year rule is workable | The current one-year requirement appropriately recognizes this need while allowing companies flexibility to scale their internal audit function through outsourced or co-sourced arrangements. |
| FOUNDATION | Built at the foundation | internal audit provides the greatest value when organizations are building and evolving rather than after systems, processes, and governance structures are already established |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. CPA/CIA with three decades in internal audit, writing personally, objects that the record does not support a five-year transition and urges a more limited or phased approach, rejecting the audit-committee-substitute and Nasdaq-benchmark rationales. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Accountant / external auditor (CPA)letterhead Internal audit professional sub-role: Practitioner |
| Remedy | Scaled / risk-based phase-in or milestones | a more limited or phased approach; no specific period named |
| HIRISK | Peak risk window | When systems are changing, controls are developing, responsibilities are shifting, and organizations are growing rapidly, risk does not wait for the organization to mature. |
| NONSUB | Not substitutes | I am also concerned by the suggestion that an independent audit committee and other existing requirements can adequately substitute for an internal audit function |
| FEAS | The one-year rule is workable | The existing NYSE rule permits the function to be outsourced to a qualified third party other than the company's independent auditor. |
| NOEV | No evidentiary record | the filing does not quantify the burden of the current one-year period, identify the expected cost savings from a five-year period, or explain why five years represents the appropriate balance. |
| NASDAQ | Nasdaq benchmark contested | I also do not believe the fact that Nasdaq does not require its listed companies to maintain an internal audit function, standing alone, resolves the question |
| INVPROT | Investor protection standard | Investor protection should be evaluated on its merits, rather than solely by reference to whether another marketplace has adopted a less restrictive requirement. |
| FOUNDATION | Built at the foundation | Strong governance is not something that begins only after an organization has finished growing. |
| 5YRS | Five years is unexplained | the filing does not quantify the burden of the current one-year period, identify the expected cost savings from a five-year period, or explain why five years represents the appropriate balance. |
| COST | Burden on new issuers | Establishing an effective internal audit function requires time, resources, and thoughtful planning. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose majority | primary Opposeliteralist Opposecharitable Support The letter states no ask. The position is read from what it argues. Unaffiliated individual expresses generalized concern that the amendments could reduce, delay or weaken audit-committee-related governance obligations and asks that any added flexibility not come at the expense of investor protection; never addresses the five-year internal audit period directly. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | No modification requested | — |
| INVPROT | Investor protection standard | such flexibility should not come at the expense of investor protection, financial reporting reliability, or accountability for board-level oversight. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. One-sentence note asking the Commission to extend the comment period and stating that five years is too long for the internal audit requirement, with no supporting reasoning. |
| Entity | Consultant / advisory firm majority | primary Consultant / advisory firmself-described Individualletterhead Consultant / advisory firm |
| Remedy | Shorter extension | no period named; states only that five years is too long |
| Procedural | PROC_EXTEND | Please extend the commentary period as 5 years is too long for the new internal audit requirement |
| NR | No substantive rationale | Please extend the commentary period as 5 years is too long for the new internal audit requirement |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeThe IIA urges the Commission to disapprove the Proposal and, to that end, to institute proceedings under Section 19(b)(2)(B). The Institute of Internal Auditors urges the Commission to disapprove the five-year extension and institute 19(b)(2)(B) proceedings, arguing the filing has no evidentiary record, that SOX 404(b) and related protections do not cover newly listed issuers, that the change guts audit committee oversight, and that the one-year rule is already proportionate and outsourceable. |
| Entity | Professional body / trade association unanimous | primary Professional body / trade associationself-described Professional body / trade associationletterhead Professional body / trade association |
| Remedy | Fallback / compromise | primary ask is disapproval (keep the one-year rule); if the Exchange believes refinement is warranted, an amended filing supported by evidence providing a materially shorter period with interim safeguards (early appointment of internal audit leadership, audit-committee-approved charter, IPPF conformance) |
| Procedural | PROC_PROCEEDINGS | The IIA urges the Commission to disapprove the Proposal and, to that end, to institute proceedings under Section 19(b)(2)(B). |
| HIRISK | Peak risk window | Newly public issuers, including rapidly scaling technology companies, confront risks that |
| NONSUB | Not substitutes | A retrospective annual examination of financial controls cannot substitute for |
| 404B | Attestation gap | First, most newly listed companies are not subject to the Section 404(b) auditor attestation |
| FEAS | The one-year rule is workable | The current rule requires presence, not scale. It does not oblige a newly listed company to |
| NOEV | No evidentiary record | filing contains no data of any kind: it identifies no population of affected issuers, quantifies |
| NASDAQ | Nasdaq benchmark contested | Nor is the absence of a comparable requirement at the Nasdaq Stock Market a reason to |
| INVPROT | Investor protection standard | II. The Exchange Has Not Carried Its Burden Under the Exchange Act |
| FOUNDATION | Built at the foundation | Internal audit belongs at the foundation of a newly public company |
| LEGACY | Why the rule exists, and how it got here | The requirement has been relaxed once already; it should not be relaxed again. |
| IMPETUS | No occasion for the change | Its entire factual predicate is a statement that unnamed issuers “have expressed concern,” and the Exchange acknowledges that it neither solicited nor received any written comments before filing. |
| 5YRS | Five years is unexplained | and provides no explanation of why five years—rather than any shorter period—is the appropriate term. |
The letter refers back to the extension request The IIA filed separately (letter #1) and submits without prejudice to it. That is a reference to an earlier request, not a request made here, so PROC_EXTEND is not coded and the same ask is not counted twice.
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. Brief unaffiliated individual letter stating that internal audit belongs at the foundation of a public company's governance during the critical early years and that waiting five years is too long. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Keep one year | implied retention of the existing requirement; no alternative period named |
| HIRISK | Peak risk window | particularly during the critical early years when systems, controls, risk management, and culture are taking shape |
| INVPROT 2 of 3 | Investor protection standard | Rolling back investor protections has wider economic consequences |
| FOUNDATION | Built at the foundation | Internal audit should be part of the foundation of a public company's governance |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeThe IIA urges the SEC to reject this proposal and instead direct the NYSE to maintain the current one-year phase-in period. IT audit director (CISA, 13 years in internal audit) writing personally opposes the extension, urges rejection and retention of the one-year phase-in, and offers a narrow fallback limited to the smallest newly listed companies with sunset and disclosure conditions. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Manager |
| Remedy | Fallback / compromise | primary ask: maintain the current one-year phase-in period; fallback if some accommodation is warranted: a limited extension only for the smallest newly listed companies, with sunset provisions and investor disclosure requirements |
| HIRISK | Peak risk window | Newly listed companies carry elevated risk by definition. Controls are immature. Organizations are scaling rapidly. Governance infrastructure is still being built. |
| FEAS | The one-year rule is workable | Co-sourced and outsourced internal audit models are widely available and cost-effective for smaller and newly public organizations. |
| INVPROT | Investor protection standard | Burden alone is not sufficient justification for removing a governance safeguard that protects investors. |
| COST | Burden on new issuers | The proposal conflates the cost of building a full in-house internal audit department with the cost of establishing an internal audit function. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. Internal audit professional (Auditor IV, MBA) writing personally objects to the five-year deadline, citing the attestation-exemption overlap, internal audit's non-substitutable role and broad risk coverage, and the absence of evidence that the one-year requirement is an undue burden. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | maintain timely implementation of internal audit; no alternative period named |
| HIRISK | Peak risk window | In my experience, effective governance, risk management, and internal controls are most critical during periods of growth and change. |
| NONSUB | Not substitutes | internal audit provides a unique perspective that complements but does not replace external audit and other oversight activities |
| 404B | Attestation gap | I am also concerned that many newly public companies may already be exempt from certain external auditor attestation requirements related to internal controls. |
| FEAS | The one-year rule is workable | organizations have successfully implemented internal audit functions through a variety of scalable approaches, including outsourced and co-sourced models |
| NOEV | No evidentiary record | I am concerned that the proposal does not provide sufficient evidence demonstrating that the current one-year requirement creates an undue burden for newly listed companies |
| INVPROT | Investor protection standard | I respectfully urge the Commission to carefully evaluate the potential consequences of this proposal on governance, accountability, and investor protection. |
| FOUNDATION | Built at the foundation | Effective governance should begin on day one, not five years after a company enters the public market. |
| SCOPE 2 of 3 | Widened domain | Internal auditors assess a broad range of risks, including operational, compliance, cybersecurity, technology, privacy, and strategic risks |
| COST | Burden on new issuers | Internal audit has long been recognized as a cost-effective means of identifying weaknesses early, strengthening governance, and protecting shareholder value. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Internal audit director with 18 years' experience opposes the five-year extension and urges disapproval, arguing early-stage growth is the highest-risk period and that the one-year requirement is workable because the function can be outsourced or co-sourced. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Chief audit executive / head of function |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | the most critical period for establishing strong governance, risk management, and internal controls is during times of rapid growth and organizational transformation |
| FEAS | The one-year rule is workable | effective Internal Audit functions can be established quickly and scaled appropriately through co-sourced or outsourced models when needed |
| FOUNDATION | Built at the foundation | A company's first years as a public company are when its systems and controls are being built, and when objective assurance over that work matters most. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Internal audit professional with 26 years' experience opposes the five-year extension and urges disapproval, stressing that small or third-party-supported internal audit functions are inexpensive and that companies already meet the one-year deadline. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | one year |
| HIRISK 2 of 3 | Peak risk window | A company's first years as a public company are when its systems and controls are being built, and when objective assurance over that work matters most. |
| FEAS | The one-year rule is workable | These functions do not need to be large or expensive to make an impact. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Internal audit professional who advised newly listed companies from public accounting firms opposes the five-year extension and urges disapproval, citing early-stage compliance and growth pressures and the workability of an outsourced or co-sourced function. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Outsourced / co-sourced provider |
| Remedy | Keep one year | one year |
| HIRISK | Peak risk window | as they navigate the heightened regulatory compliance requirements being a public company while balancing the business growth demands |
| FEAS | The one-year rule is workable | The current one-year requirement is met every year by companies of every size, precisely because the Exchange's own rule allows function to be outsourced or co-sourced and scaled to the company. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI would encourage the Commission to disapprove this proposal, or at minimum to require a substantially shorter transition period than five years CPA/CFE/CIA serving as elected Salt Lake County Auditor opposes the extension and asks the Commission to disapprove, rebutting the filing's SOX and audit-committee safeguards as non-substitutes, arguing risk peaks early, rejecting the Nasdaq benchmark as a race to the bottom, and offering a phased alternative if the proposal proceeds. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Accountant / external auditor (CPA)letterhead Internal audit professional sub-role: Chief audit executive / head of function |
| Remedy | Fallback / compromise | disapprove; failing that, a substantially shorter transition than five years - interim/limited-scope internal audit plan during years one and two, escalating to full function by year three |
| HIRISK | Peak risk window | Risk is highest exactly when the proposed extension would leave internal audit absent. |
| NONSUB | Not substitutes | The cited safeguards are not substitutes for internal audit - they largely assume it exists. |
| NASDAQ | Nasdaq benchmark contested | Diluting it to match a competitor's lower bar is a race to the bottom, not a neutral change. |
| INVPROT 2 of 3 | Investor protection standard | NYSE's one-year requirement has been a genuine point of differentiation and a meaningful investor protection. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeDisapprove the proposed rule change. Participating members of the AAA Auditing Section's Auditing Standards Committee oppose the five-year extension on the empirical literature, arguing the early listing years are the highest internal control risk period with priced capital-market consequences, that SOX and Nasdaq comparisons do not justify the change and the record is empty, and recommending disapproval or proceedings with a two-year cap, EGC-only eligibility, milestones, disclosure and early termination triggers. |
| Entity | Academic researcher or academic body unanimous | primary Academic researcher or academic bodyself-described Academic researcher or academic bodyletterhead Academic researcher or academic body |
| Remedy | Fallback / compromise | primary ask is disapproval; in the alternative institute proceedings and cap any extension at a maximum of two years, limit eligibility to qualifying EGCs, impose audit committee milestones (month 6 charter, month 12 audit plan or provider, month 18 commence testing), require Form 10-K and proxy disclosure, and set conditional early termination triggers |
| Procedural | PROC_PROCEEDINGS | In the alternative, institute proceedings under Section 19(b)(2)(B) of the Act. |
| HIRISK | Peak risk window | The Initial Five Years Are the Period of Highest Internal Control Risk |
| NONSUB | Not substitutes | Where the Sarbanes-Oxley requirements do apply, they remain complements rather than |
| 404B | Attestation gap | Jumpstart Our Business Startups (JOBS) Act is exempt from the Section 404(b) auditor |
| FEAS | The one-year rule is workable | The Proposal Disregards Existing Flexibilities for Establishing an Internal Audit Function |
| NOEV | No evidentiary record | No evidence is offered for that proposition. |
| NASDAQ | Nasdaq benchmark contested | absence of a requirement at another venue justified extending the transition period to five years, |
| INVPROT | Investor protection standard | proposed five-year deferral is designed to protect investors and the public interest, as required by |
| FOUNDATION 2 of 3 | Built at the foundation | corporate governance are still being developed and institutionalized |
| SCOPE | Widened domain | The scope of the function has also widened since Section 303A.07 was adopted in 2003, |
| CAPMKT | Capital-market consequences | High Internal Control Risk Has Capital Market Consequences |
| LEGACY | Why the rule exists, and how it got here | The history of the current one-year period needs to be considered. |
| IMPETUS | No occasion for the change | It does not identify any change since 2013 that would explain why the same circumstances now warrant five years rather than one |
| 5YRS | Five years is unexplained | the filing offers no analytical basis for selecting five years rather than two, three, or any other period. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeReject the proposed five-year transition period CIA/CFSA-credentialed writer strongly opposes the five-year extension on cybersecurity-risk grounds, asking the Commission to reject it or substitute a 12-24 month period and to extend the comment period. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Individualletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Fallback / compromise | reject the five-year period; alternatively replace it with a significantly shorter period of 12-24 months |
| Procedural | PROC_EXTEND | Extend the public comment period to allow broader stakeholder input. |
| HIRISK | Peak risk window | A. Unmonitored Cyber Vulnerabilities During the Most Chaotic Growth Period |
| NONSUB | Not substitutes | rely on controls that internal audit help validate. |
| FEAS | The one-year rule is workable | Yet internal audit can be: |
| FOUNDATION 2 of 3 | Built at the foundation | Internal audit is a cornerstone of trust in public markets. |
| SCOPE | Widened domain | No review of third-party vendor cybersecurity practices |
| CAPMKT 2 of 3 | Capital-market consequences | A single cyber breach can erase billions in market value. |
| COST | Burden on new issuers | The NYSE argues that issuers face competing priorities in their first year. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. Internal audit manager objects that waiting five years is too long, arguing the function should be established within one year of an IPO for control maturity, governance culture and investor confidence; makes no procedural request. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Manager |
| Remedy | Keep one year | within one year of an IPO |
| HIRISK | Peak risk window | particularly during its critical early years when systems, controls, risk management, and culture are taking shape |
| FOUNDATION | Built at the foundation | Every publicly traded company should have an internal audit function as part of its core governance foundation |
| CAPMKT 2 of 3 | Capital-market consequences | protects market integrity and stabilizes long-term valuation |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeKeep it a year! Former federal non-financial auditor/assessor opposes the five-year extension, arguing from COSO, the text of 303A.07(c), the history of audit and internal control, changing risk (cyber/AI), and the Nasdaq comparison that the function should begin at listing; asks the Commission to keep one year. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Retired / former |
| Remedy | Keep one year | Retain the one-year requirement; urges even faster establishment than one year ("Not even a year later to initiate an internal audit function") |
| HIRISK 2 of 3 | Peak risk window | illustrates why waiting up to five years is too long. Even in a year, risks can |
| NONSUB 2 of 3 | Not substitutes | internal audit function to provide an issuer’s management and audit committee with |
| NASDAQ | Nasdaq benchmark contested | nevertheless have such an internal audit function).” So, NYSE requires it and most Nasdaq |
| INVPROT 2 of 3 | Investor protection standard | economy, our capital markets, and people’s lives, with the mission of “protecting investors, |
| FOUNDATION | Built at the foundation | The assessments logically should start even shortly after the company has |
| SCOPE | Widened domain | Cyber, Artificial Intelligence (AI) implementation and governance, |
| LEGACY 2 of 3 | Why the rule exists, and how it got here | Failures and adverse risk events lead to new or improved laws, standards, guidelines, and |
| IMPETUS | No occasion for the change | Why would a newly listed company wait to establish an internal audit function, and why would the NYSE and the SEC allow a change to do so from one year to five years? |
| COST | Burden on new issuers | management’s attention and the challenges of building an internal audit function to assess |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Oppose The letter states no ask. The position is read from what it argues. Career internal auditor and former head of IA/risk/SOX, now principal owner of ARGO LLC, opposes the five-year extension, quotes and rebuts the Exchange's stated rationale as backwards, says he has stood up IA functions in under a year, and separately asks the Commission to extend the comment period and do more research. |
| Entity | Internal audit professional majority | primary Internal audit professionalself-described Internal audit professionalletterhead Consultant / advisory firm sub-role: Retired / former |
| Remedy | Keep one year | Retain the existing end-of-first-year deadline; writer states a basic IA function can be established in less than one year |
| Procedural | PROC_EXTEND | I strongly believe that research and the comment period be extended to practically and diligently assess and then consider approval or disapproval of the new proposal by the SEC. |
| HIRISK 2 of 3 | Peak risk window | especially an initially listed company |
| NONSUB | Not substitutes | do not cover all the areas needed for a listed company, especially an initially listed company |
| FEAS | The one-year rule is workable | It does NOT take 5 years to establish an IA function and serve the needs of an Audit Committee and |
| NOEV | No evidentiary record | I do not believe the SEC has researched adequately the time needed to establish a basic function |
| FOUNDATION 2 of 3 | Built at the foundation | The basic safeguard is for companies to have sound governance practices and effective internal |
| 5YRS | Five years is unexplained | It almost seems that the 5-year extension came out of thin air |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable Opposeurge the Commission to consider whether the proposed transition is consistent with the governance needs of companies before and immediately after listing, and whether a shorter, phased approach would better support effective board oversight Nonprofit board-governance organization argues, citing Larcker & Tayan (2018) and PwC (2025), that internal audit's value peaks around the IPO transition and that scale concerns argue for proportionate implementation rather than delay; urges a shorter, phased transition instead of five years. |
| Entity | Professional body / trade association unanimous | primary Professional body / trade associationself-described Professional body / trade associationletterhead Professional body / trade association |
| Remedy | Shorter extension | Urges the Commission to consider a "shorter, phased approach" and proportionate implementation rather than delayed establishment; no specific period named |
| HIRISK | Peak risk window | Controls are being created, responsibilities are being formalized, new executives are |
| FEAS | The one-year rule is workable | function need not have the scale or maturity of one in a large, established issuer. |
| FOUNDATION | Built at the foundation | governance and control capabilities while preparing to become public |
| COST 2 of 3 | Burden on new issuers | At the same time, we recognize that a newly public company’s internal audit |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully but strongly urge the Commission to reject this proposal and retain the existing one-year requirement. Individual investor urges the Commission to reject the five-year extension and retain the one-year rule, organizing the letter around control validation, regulatory compliance costs, fraud deterrence, and cyber/systemic risk, with a fallback of narrow, case-by-case risk-based accommodations. |
| Entity | Individual unanimous | primary Individualself-described Individualletterhead Individual |
| Remedy | Fallback / compromise | Primary ask is to retain the existing one-year requirement; only if the Commission finds demonstrable resource constraints, a fallback of "narrower, risk-based accommodations" — a modestly phased-in scope of internal audit activity, or a limited extension granted case-by-case on a showing of hardship |
| HIRISK | Peak risk window | new systems, new personnel, and rapid growth are most likely to create control gaps |
| NONSUB | Not substitutes | they are not a substitute for the continuous, risk-based testing of operational and IT controls that internal audit performs throughout the year |
| INVPROT 2 of 3 | Investor protection standard | Extending this timeline by four additional years would materially weaken investor protections |
| FOUNDATION | Built at the foundation | it needs to be in place from the earliest stages of public life |
| SCOPE | Widened domain | Cybersecurity threats have grown substantially in frequency and sophistication |
| CAPMKT | Capital-market consequences | reputational damage, increased cost of capital, or management distraction |
| COST | Burden on new issuers | some newly listed companies face genuine, demonstrable resource constraints in the immediate aftermath of listing |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the SEC to maintain the current one-year requirement and continue prioritizing the protection of investors and the integrity of U.S. capital markets. Internal audit and finance professional (CIA, 20+ years) states strong opposition to the five-year extension, arguing the formative post-listing years most need independent assurance, and urges the SEC to maintain the one-year requirement. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | Maintain the current one-year requirement |
| HIRISK | Peak risk window | The initial years following a public listing are precisely when strong governance and independent assurance are most vital. |
| NONSUB 2 of 3 | Not substitutes | it provides essential, objective assurance to management and the audit committee |
| FOUNDATION | Built at the foundation | risks leaving critical vulnerabilities unaddressed during this formative period |
| COST | Burden on new issuers | Internal audit is not merely a compliance expense |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose majority | primary Opposeliteralist Opposecharitable Support The letter states no ask. The position is read from what it argues. Certified Internal Auditor writes from experience that a first-year internal audit function surfaces control failures that management reporting, external audit and board oversight miss, and asks the SEC to weigh that independent assurance role in considering the proposal; no explicit request to disapprove. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | No modification requested | Makes the case for a first-year internal audit function but requests no specific change to the proposed period; asks only that the Commission recognize internal audit's independent assurance role |
| NONSUB | Not substitutes | identify control failures and operational risks that management reporting, external audit, and Board oversight may not otherwise reveal |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Internal audit professional with 20 years' experience and a CIA, writing in a personal capacity, opposes the five-year extension and urges disapproval, arguing early-years control risk, the foundational value of governance habits, and that the one-year deadline is met today because the rule already permits outsourced, co-sourced and scaled functions. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | Retain the current one-year requirement; no alternative period proposed |
| HIRISK | Peak risk window | A company's first years as a public company are when its systems and controls are being built, and when objective assurance over that work matters most. |
| FEAS | The one-year rule is workable | The current one-year requirement is met every year by companies of every size, precisely because the Exchange's own rule allows the function to be outsourced or co-sourced and scaled to the company. |
| FOUNDATION | Built at the foundation | It is critical to build strong governance and control "habits" from the start. |
| Field | Call | Evidence and reasoning |
|---|---|---|
| Position | Oppose unanimous | primary Opposeliteralist Opposecharitable OpposeI respectfully urge the Commission to disapprove the proposed rule change. Anonymous CIA with 25 years in internal audit, writing personally, opposes the extension on the grounds that the one-year rule is already met by companies of every size because the Exchange permits outsourcing and scaling, and urges the Commission to disapprove. |
| Entity | Internal audit professional unanimous | primary Internal audit professionalself-described Internal audit professionalletterhead Internal audit professional sub-role: Practitioner |
| Remedy | Keep one year | Retain the current one-year requirement; notes the Exchange's rule already permits an outsourced, co-sourced or scaled function |
| HIRISK | Peak risk window | A company’s first years as a public company are when its systems and controls are |
| NONSUB | Not substitutes | independent line of sight into whether governance, risk management, and controls are |
| FEAS | The one-year rule is workable | one-year requirement is met every year by companies of every size, precisely because |
| FOUNDATION | Built at the foundation | being built, and when objective assurance over that work matters most. |
| SCOPE 2 of 3 | Widened domain | technology, cybersecurity, third-party oversight, regulatory compliance, and operational |