When Wirecard collapsed in June 2020 after €1.9 billion in supposed cash balances could no longer be verified, the scandal immediately became one of the defining corporate failures of modern Germany. Public attention focused naturally on the missing cash, failed oversight, weak controls, regulatory failures, and the role of EY as long-standing auditor. But for professional-services firms, the deeper story was economic. Wirecard exposed something much larger than a failed audit engagement. It exposed how structurally dangerous public-interest audit had quietly become as a business model for large professional-services firms. (European Parliament – Update on Wirecard Case)
The asymmetry was extraordinary. EY reportedly earned roughly €2.3 million in audit and advisory fees from Wirecard in 2018. What followed after the collapse, however, extended into years of litigation, parliamentary inquiries, APAS sanctions, investor proceedings, criminal investigations, inspection pressure, internal remediation programs, reputational damage, insurance complexity, partner distraction, restructuring scrutiny, and public debate surrounding the credibility of the German audit market itself. A relatively modest annual fee evolved into a multi-year liability environment stretching far beyond the economics of the original engagement. That gap between annual economics and long-tail exposure is ultimately the most important lesson of Wirecard for the professional-services industry. (European Parliament – Wider Supervisory Implications of the Wirecard Case; Financial Times – EY and Wirecard: Anatomy of a Flawed Audit)
Wirecard made this visible because Germany produced an unusually transparent public record of the aftermath. Over multiple years, regulators, courts, lawmakers, journalists, and market participants collectively documented how a major audit failure reverberates through a professional-services institution. The result was a rare view into the mechanisms that normally remain hidden from public sight: governance reviews, quality remediation, regulatory oversight, insurance challenges, partner distraction, and the long process of rebuilding credibility. Wirecard therefore became more than a corporate fraud. It became a case study in how audit risk propagates through an entire firm once the engagement itself is over. (European Parliament – Update on Wirecard Case; Finance Magazin – Wirecard Ticker)
Audit Starts as an Expensive Bet
One of the least understood realities of public-interest audit is that large audit mandates are often economically unattractive long before the actual audit work even begins. Winning a major listed-company audit can require months of internal preparation involving senior partners, technical specialists, independence teams, industry experts, transition planning, pricing exercises, global coordination, and repeated interactions with audit committees and procurement functions. Much of that work is effectively non-billable. Firms absorb the cost upfront because large audit mandates still carry strategic importance beyond the direct economics of the engagement itself. A major listed audit signals institutional credibility, strengthens market position, supports recruitment, and reinforces the standing of the firm inside the corporate and regulatory ecosystem. (FRC – Audit Tendering Helps Improve Audit Confidence; CMA – Statutory Audit Services Market Study)
The economics frequently remain difficult even after the mandate has been won. New audit teams must learn complex treasury structures, IT environments, governance processes, internal controls, tax positions, subsidiary structures, reporting systems, industry-specific accounting treatments, and operational dependencies spread across multiple jurisdictions. The first years of a large audit engagement are therefore often operationally inefficient and partner-intensive. Historically, firms accepted that dynamic because long-tenure relationships eventually allowed them to recover transition costs through accumulated institutional knowledge and delivery efficiency. But mandatory tendering and rotation rules increasingly disrupt that recovery logic. Firms absorb heavy pursuit costs, navigate expensive onboarding periods, remain under constant fee pressure, and may then lose the mandate through rotation just as the engagement becomes operationally efficient. (DeAngelo – Auditor Independence, Low Balling, and Disclosure Regulation; FRC – Audit Committees and Audit Tenders)
At the same time, the economics of the wider professional-services industry changed dramatically. Advisory, tax, technology implementation, managed services, and platform-enabled businesses increasingly scale through operational leverage, recurring revenue models, industrialized delivery structures, and expanding client economics. Public-interest audit increasingly moves in the opposite direction. Independence restrictions limit commercial flexibility. Regulatory expectations continue expanding. Documentation requirements multiply. Quality-management systems grow continuously. Inspection pressure intensifies. More partner time becomes absorbed by technical reviews, consultation layers, defensibility requirements, and remediation processes that generate no direct revenue themselves. The visible audit fee may still appear commercially reasonable on the surface. Underneath it sits an expanding infrastructure whose costs increasingly reshape the economics of the profession itself. (FRC – Ethical Standard for Auditors; FRC – Developments in Audit)
Audit Is a Zero-Sum Prestige Market
Audit operates under very different commercial dynamics from most other professional-services businesses. A company appoints one statutory auditor. If EY wins the mandate, another firm loses it. Growth therefore often comes less from expanding the market itself and more from taking strategically important clients away from competitors. Large listed-company audits consequently carry significance that extends far beyond their direct annual economics. They reinforce credibility with regulators, investors, boards, and future recruits. Inside the firms themselves, flagship audit mandates often function as visible proof that the organization still belongs inside the top tier of the corporate market. (CMA – Statutory Audit Services Market Study)
That dynamic creates incentives that become increasingly difficult to reconcile over time. A prestigious audit relationship may generate only moderate profitability on a standalone basis while still remaining strategically important for the wider organization. Losing visibility in the listed-company market weakens the broader position of the firm itself. Winning therefore matters even when the direct economics remain constrained by procurement pressure, mandatory tendering, independence restrictions, and regulatory overhead. The audit engagement increasingly behaves less like a self-contained commercial service and more like strategic infrastructure supporting the wider market position of the firm. (Bloomberg Tax – How the Wirecard Case Has Impacted the German Audit Market)
Wirecard demonstrated how violently this model can break once audit risk materializes publicly. APAS ultimately concluded that EY breached professional duties in the Wirecard audits from 2016 to 2018, imposed sanctions, and introduced a two-year ban preventing EY from taking on certain new listed-company audit mandates in Germany. The direct financial penalties themselves remained manageable relative to the size of the global network. The broader consequences were far more significant. The scandal intensified regulatory scrutiny, weakened market positioning, expanded litigation exposure, increased inspection pressure, absorbed enormous amounts of leadership attention, and created reputational consequences extending far beyond the original engagement team itself. A single listed-company audit mandate had effectively evolved into a multi-year risk event spreading through large parts of the organization. (Reuters – EY fined, banned from some audits in Germany over Wirecard scandal)
Winning the Audit Can Also Mean Losing
One of the least discussed contradictions inside modern audit economics is that winning a major audit client can simultaneously restrict some of the commercially most attractive opportunities elsewhere inside the firm. Public debate often assumes that large listed-company audits remain highly desirable because they create prestigious long-term client relationships. Historically, that was partly true. But under modern independence regimes, statutory audit increasingly turns large parts of the client relationship into economically restricted territory for the wider organization. Independence teams, conflict checks, approval procedures, and prohibited-services rules increasingly shape what the firm is allowed to do commercially once it becomes auditor of a major public-interest entity. (FRC – Ethical Standard for Auditors; Accountancy Europe – Non-Audit Services and Auditor Independence)
That matters because the economics of the wider professional-services industry changed fundamentally over the last two decades. Large ERP programs, SAP transformations, cloud migrations, cyber programs, AI initiatives, managed services, tax structuring, transaction work, and operating-model transformations often generate significantly larger fee pools and materially better margins than statutory audit itself. Yet many of those opportunities become restricted, heavily controlled, or entirely unavailable once the firm becomes statutory auditor. In practice, the audit engagement may therefore prevent the organization from pursuing some of the commercially most attractive work surrounding the client. The audit team secures the relationship institutionally while large parts of the wider business lose commercial flexibility around it. (CMA – Statutory Audit Services Market Study)
This creates internal tensions that increasingly shape how firms think about public-interest audit strategically. The audit firm often understands the client’s systems, finance architecture, governance structures, control environment, reporting processes, and operational dependencies better than almost any competitor. Yet the same organization may be prohibited from participating meaningfully in major transformation programs connected to those environments. Economically, the firm may therefore sacrifice higher-margin growth opportunities in exchange for a lower-margin regulated assurance mandate carrying substantially higher litigation and reputational risk. Winning the audit relationship can still mean losing commercially elsewhere inside the firm.
Regulation Became a Permanent Cost Layer
Modern audit firms now operate with enormous internal infrastructures dedicated not to growth or delivery scalability, but to defensibility. Quality-management systems, technical consultation environments, ethics reviews, independence-monitoring platforms, inspection-response teams, mandatory training programs, documentation standards, cybersecurity controls, and internal file-review processes increasingly function as permanent layers underneath the audit business. None of these functions generate revenue directly. Yet they absorb growing amounts of partner attention, technology investment, and organizational spending because large audit firms now operate under continuous inspection, litigation, and regulatory exposure rather than occasional scrutiny. (FRC – Developments in Audit; FRC – Audit Thematic Reviews)
Wirecard accelerated this dynamic significantly inside Germany and across the wider industry. Following the scandal, EY Germany and the wider network expanded fraud analytics capabilities, strengthened review mechanisms, increased technical oversight, and invested further into audit-quality and defensibility processes. Similar patterns emerged across the profession after other major failures and inspection findings. Regulatory pressure rarely remains limited to the original engagement itself. It expands into methodology redesign, additional review layers, enhanced escalation procedures, remediation programs, technology investment, and increasingly industrialized quality-management systems operating across the wider organization. (FRC – Sanctions against KPMG over Carillion audits)
This is part of the hidden reality behind rising audit costs across the profession. Public discussions often frame higher audit fees as evidence that firms are charging more aggressively. In practice, much of the increase reflects the rising cost of institutional defensibility. Audit files are no longer built only to support the audit opinion itself. They are increasingly built to survive regulator inspections, parliamentary inquiries, investor proceedings, litigation discovery, media scrutiny, and retrospective reconstruction years after the engagement has ended. The audit file increasingly becomes part of the legal defense architecture of the firm itself. (FRC – Developments in Audit)
AI, Audit and the Expanding Cost of Defensibility
Artificial intelligence is now being presented across the audit industry as the next major productivity revolution. Firms increasingly market AI-enabled audit platforms capable of automating document analysis, anomaly detection, workflow coordination, testing procedures, reporting support, and large parts of the administrative infrastructure surrounding the audit process itself. Underneath the enthusiasm sits an important economic hope. Audit firms face growing delivery pressure from talent shortages, expanding regulation, rising quality expectations, increasing documentation requirements, and structurally difficult margins. AI therefore appears attractive because it promises scalability inside a business that historically remained highly dependent on human labor.
But audit is not a normal automation environment. Unlike many other industries, audit increasingly operates less as an efficiency system and more as a defensibility system. Following Wirecard and other major audit failures, firms now operate under conditions of continuous inspection, litigation exposure, regulatory scrutiny, and retrospective reconstruction risk. Every AI-supported process potentially creates entirely new questions around explainability, accountability, evidence chains, model governance, cyber security, confidentiality, reviewability, and human oversight. If an auditor relies on AI-supported anomaly detection or document analysis, regulators and courts may later ask how the model functioned, how outputs were validated, whether warning signals were challenged appropriately, and who ultimately remained accountable for the judgment itself. Much of the theoretical efficiency gain may therefore become partially absorbed by additional governance, validation, monitoring, and review infrastructure underneath the surface.
This creates an important tension inside the current AI narrative surrounding audit. The profession increasingly presents AI as a margin and productivity story. In practice, however, audit economics are increasingly shaped by the expanding cost of institutional defensibility. AI may industrialize audit operations significantly without transforming the underlying economics to the extent many currently expect. Instead of eliminating cost layers, firms may simply shift them into different parts of the organization: model-governance teams, AI oversight functions, cyber controls, technical review structures, regulatory-response environments, and increasingly complex quality-management systems operating underneath the visible engagement layer. AI may not eliminate audit complexity. It may industrialize and redistribute it into new layers of governance, oversight, and defensibility.
The Litigation Tail Became the Real Business Risk
The legal and regulatory consequences surrounding Wirecard gradually became more important than the original economics of the audit engagement itself. Years after the collapse, EY Germany continued facing investor proceedings, regulatory scrutiny, insurance complexity, forensic work, reputational pressure, and extensive legal-defense costs connected to the case. In February 2025, a German court ruled that EY Germany was not liable in one shareholder lawsuit because the audit reports did not qualify as public capital-market information under the relevant legal framework. But even partial legal victories did little to reduce the broader burden surrounding the proceedings. The litigation environment itself had already evolved into a permanent operational issue absorbing leadership attention, partner capacity, legal coordination, insurance negotiations, and reputational management across the wider organization. The process itself increasingly became part of the punishment. (Reuters – German court says EY not liable for damages in Wirecard lawsuit; Heuking – Auditor liability in the Wirecard case)
What made the situation particularly revealing was how the litigation environment gradually started interacting with the structure of the firm itself. According to reporting by German and international business media, EY Germany reorganized parts of its business following the scandal, including separating consulting and tax operations into different legal entities. Claimant representatives argued that the restructuring could complicate future damages enforcement. EY rejected suggestions that the restructuring was designed to shield assets from plaintiffs and maintained that liabilities remained unaffected. Yet the broader significance extended beyond the legal arguments themselves. Once audit litigation reaches sufficient scale, the structure of the professional-services firm itself increasingly becomes part of the liability discussion. (Euronews – Wirecard shareholders suing audit giant EY Germany over asset-stripping claims; Financial Times – Wirecard shareholders sue EY over alleged asset stripping in Germany)
The situation became even more revealing when German courts later expanded elements of the Wirecard proceedings to include additional EY entities beyond the original audit partnership itself. At that point, the litigation perimeter effectively started following the wider institutional structure of the organization rather than remaining neatly contained within the original engagement environment. That shift exposed something profoundly uncomfortable about modern public-interest audit. Once liability reaches sufficient scale, the audit firm increasingly stops behaving merely like a partnership delivering professional services. It starts behaving more like an institution managing balance-sheet exposure, insurance complexity, legal containment, reputational survivability, and long-tail uncertainty across a much wider operating system. The annual audit fee increasingly becomes only the visible front-end economics attached to a much larger risk environment operating underneath the surface of the profession. (Finance Magazin – EY unter Druck: Drei weitere Gesellschaften im Wirecard-Verfahren; Finance Magazin – Wirecard Ticker)
Many of these tensions also became visible during EY’s failed Project Everest separation attempt, which exposed how difficult it has become to separate audit, advisory, governance, platform investment, and partnership economics inside a large global professional-services firm.
The Audit File Became Public Property
One of the least understood risks inside public-interest audit is that failure can transform confidential professional work into public institutional evidence. Regulators inspect the files. Courts interpret them. Parliamentarians quote them. Journalists reconstruct them. Plaintiffs attack them. Years of professional judgment, documentation decisions, review notes, escalation procedures, fraud assessments, sampling approaches, technical consultations, and internal discussions can suddenly become subject to external interpretation under conditions of hindsight, political pressure, media scrutiny, and public anger. The audit file stops functioning merely as professional documentation supporting an assurance opinion. It increasingly becomes evidence in a much larger reconstruction process surrounding the collapse itself. (European Parliament – Update on Wirecard Case; European Parliament – Wider Supervisory Implications of the Wirecard Case)
Wirecard produced exactly this dynamic. Parliamentary inquiries, APAS investigations, KPMG’s special audit, insolvency proceedings, criminal investigations, investor litigation, and years of media reporting gradually transformed the audit work into publicly scrutinized material reconstructed across multiple institutional arenas simultaneously. The public discussion no longer focused narrowly on whether the audit technically complied with standards at the time. The broader question became how so many institutions surrounding Wirecard had continued functioning normally while underlying problems were already accumulating beneath the surface. That distinction matters enormously because audit firms increasingly operate inside an expectation environment extending far beyond the legal boundaries of reasonable assurance itself. Clients purchase assurance services. Regulators expect evidence. Courts expect accountability. Investors expect protection. Once the company collapses publicly, those expectations collide directly inside the audit firm itself. (European Parliament – Update on Wirecard Case; KPMG – Special Audit Report on Wirecard)
That shift has profound economic implications for the profession because it changes behavior inside the operating model long before the next scandal even occurs. Documentation expands. Review layers multiply. Consultation requirements increase. Escalation procedures become more formalized. Technical specialists become more deeply embedded into engagements. Firms increasingly optimize not only for audit quality itself, but for future defensibility under retrospective scrutiny. The possibility that audit work may eventually become public institutional evidence starts reshaping how the work is performed internally from the beginning. (FRC – Developments in Audit; FRC – Audit Thematic Reviews)
Closing Thoughts
Wirecard became one of the most visible audit failures in Europe because the scandal combined political attention, regulatory scrutiny, media intensity, and the collapse of a high-profile listed technology company at the same time. Yet the broader structural pattern surrounding the case was not unique to EY or to Germany. KPMG faced record sanctions following the collapse of Carillion in the United Kingdom. Deloitte faced scrutiny after the collapse of Singapore oil trader Hin Leong Trading, while PwC came under growing pressure connected to China Evergrande and the wider Chinese property crisis. Different firms, different countries, different industries, yet increasingly similar dynamics once audit risk materialized publicly at sufficient scale. (FRC – Sanctions against KPMG over Carillion audits; Financial Times – Hin Leong founder charged in Singapore over oil trading collapse; Financial Times – PwC’s China business hit by Evergrande fallout)
The memorable lesson from Wirecard is therefore not simply that EY had a failed audit client. The more important lesson is that public-interest audit increasingly operates under an economic model where a relatively modest annual engagement can create years of exposure capable of spreading through the wider operating model of the firm itself. Firms responded by expanding review layers, strengthening technical oversight, industrializing inspection preparedness, and investing heavily into defensibility infrastructure while audit committees and procurement functions often continued pressuring fees downward.
Public-interest audit still functions as one of the core trust mechanisms inside capital markets. Yet economically, the business increasingly behaves differently from most other areas of professional services. Audit continues carrying much of the regulatory exposure, liability burden, and public-interest responsibility, while larger portions of the surrounding economic infrastructure increasingly evolve through platform operating models, centralized delivery environments, and capital-intensive technology systems. This dynamic was explored further in The Regulated Trust Layer: How Private Equity Is Separating Audit From the Economic Platform Around It.
The question now facing the industry is not simply whether audit quality needs to improve further. The harder question is whether the economics of public-interest audit still align with the level of responsibility society increasingly expects the profession to carry.
What This Means for Boards
Boards of professional-services firms should stop evaluating public-interest audit primarily through traditional operating metrics such as revenue growth, utilization, realization, and contribution margin. Increasingly, those metrics no longer capture the real economics of the business. A meaningful assessment now requires visibility into tender costs, independence restrictions, quality-management infrastructure, inspection preparedness, insurance exposure, technology investment, reputational vulnerability, and the wider operational infrastructure supporting audit quality and defensibility.
That tension is likely to become even more important over the next decade as firms continue investing heavily into centralized delivery environments, AI-enabled audit systems, workflow orchestration platforms, and industrialized quality-management systems. The broader question is whether the economics, governance structures, and operating models surrounding public-interest audit are still evolving fast enough to support the institutional role society increasingly expects the profession to perform.
Another uncomfortable tension sits underneath all of this. Public-interest audit remains strategically critical because it anchors trust, credibility, and regulatory legitimacy for large professional-services firms. Yet increasingly, many of the stronger growth and margin opportunities sit elsewhere in advisory, tax, managed services, AI-enabled delivery, and platform businesses surrounding the audit practice itself. Over time, audit risks becoming institutionally indispensable while economically constrained relative to the wider platform developing around it.
I work with boards and executive teams on independent perspectives related to professional-services transformation, governance, operating models, platform economics, and the changing economics of professional-services firms.
If your leadership team is working through similar questions around ownership structures, governance alignment, investment pressure, or operating-model evolution, you may find my Future of Professional Services board sessions and Economic Reality Review valuable. Feel free to reach out.
Sources
Primary Sources
European Parliament – Update on Wirecard Case
European Parliament – Wider Supervisory Implications of the Wirecard Case
FRC – Audit Tendering Helps Improve Audit Confidence
FRC – Audit Committees and Audit Tenders
FRC – Ethical Standard for Auditors
FRC – Developments in Audit
FRC – Audit Thematic Reviews
FRC – Sanctions against KPMG over Carillion audits
FRC – Sanctions against three audit firms over London Capital & Finance
FCA – PwC fined £15 million over London Capital & Finance
CMA – Statutory Audit Services Market Study
Secondary Sources
Reuters – EY fined, banned from some audits in Germany over Wirecard scandal
Reuters – German court says EY not liable for damages in Wirecard lawsuit
Financial Times – EY and Wirecard: Anatomy of a Flawed Audit
Financial Times – EY drops appeal against German sanctions over Wirecard audits
Financial Times – DWS names EY as auditor despite funds suing firm over Wirecard scandal
Financial Times – Wirecard shareholders sue EY over alleged asset stripping in Germany
Finance Magazin – Wirecard Ticker
Finance Magazin – EY unter Druck: Drei weitere Gesellschaften im Wirecard-Verfahren
Euronews – Wirecard shareholders suing audit giant EY Germany over asset-stripping claims
Heuking – Auditor liability in the Wirecard case
Bloomberg Tax – How the Wirecard Case Has Impacted the German Audit Market
Accountancy Europe – Non-Audit Services and Auditor Independence
DeAngelo – Auditor Independence, Low Balling, and Disclosure Regulation