Key insights
- Calendar-year private companies pick up the new income tax disclosures in FY2026. A rolled-forward nonpublic checklist is already stale.
- The SEC's cyber disclosure rules remain in effect despite a pending rescission petition. Watch for risk factors that still call a real breach hypothetical.
- A signed checklist proves coverage. Adequacy requires judgment, and findings land on that judgment.
Picture the last review night before filing. The trial balance ties, the workpapers are locked, the disclosure checklist is signed. The senior opens the notes one more time and something's off. A related-party disclosure that ran two lines last year is down to one. A fair value table points to a leveling paragraph that got trimmed last week. Every row on the checklist is checked. None of those checks tell you whether each disclosure is right.
This year, the checklist gets new rows. Private-company income tax disclosures and a credit-loss expedient are among the 2026 additions. Checking a new row off is easy. Getting the disclosure behind it right is where the findings come from. What follows covers the 2026 disclosure calendar, where the recurring high-judgment items still generate findings, and where a signed checklist stops answering the question.
The 2026 disclosure calendar
Handled in planning, the changes below are routine. Caught in review, they cost real time, all of it avoidable.
Private company income taxes
The income tax footnote just got bigger for private companies. ASU 2023-09 hit public companies in their FY2025 annual reports. Calendar-year private companies are first subject in FY2026. Two disclosures change for them. They now describe in words the categories of reconciling items and the jurisdictions that drive the gap between their statutory and effective rate. The full numerical rate reconciliation stays a public-company requirement. And income taxes paid get broken out by federal, state, and foreign, with any jurisdiction above 5% of the total shown on its own. It applies prospectively.
Both disclosures lean on data private clients don't usually keep — which items and jurisdictions move the rate, and cash taxes split by federal, state, and foreign. That detail rarely sits in a private company's provision workpapers today. The tax team can usually assemble it, but the ask goes better in the fall, while the provision is still open, than in a March scramble after they've moved on. So raise it before year-end.
Credit-loss expedient
CECL asks you to build a forecast of future economic conditions into the allowance, even for short-dated receivables. The new practical expedient lets you skip that forecast for current accounts receivable and contract assets: you assume balance-sheet-date conditions hold for the asset's remaining life. It's available to any entity in FY2026. Private companies that elect it get one more option, an accounting policy election to factor in cash the client collected after the balance sheet date.
The disclosures are short, which is why they get missed. Say whether you elected the expedient. If the client is a private company that also took the policy election, disclose the date through which it looked at subsequent collections. Easy to overlook precisely because the accounting got shorter.
Public-company catch-up items
FY2025 was the catch-up year on the public side. The new segment expense and chief operating decision maker disclosures moved into interim filings, and the new crypto asset accounting requirements took effect. Both should already be in your PBE checklist by now.
Interim filings are the likeliest place for a segment finding this year. FY2025 is the first year the new segment expense lines appear in quarterly reports, and a quarterly table that doesn't match the annual one it follows is easy to create and easy to catch. Pull the client's most recent annual segment tables and read the interim ones against them. An expense line that doesn't tie, or a segment defined differently than it was at year-end, shows up right away.
Expense disaggregation planning
Not effective yet, but worth scoping now. The expense disaggregation standard applies to public companies only, permits early adoption, and hits calendar-year filers in FY2027. Year one requires no comparative disclosures, and emerging growth companies get no extra time.
The requirement is a table inside the expense captions that breaks out inventory purchases, employee compensation, depreciation, and intangible amortization. It also requires a separate selling expense total and, annually, how the company defines selling expenses. The audit-side question is upstream of the disclosure: can the client's system split expenses that way at all? Scope that before FY2027 planning, not during it.
Cybersecurity and governance disclosures
The SEC's 2023 cybersecurity disclosure rules created two obligations, and both are still in force. Every 10-K now carries an annual disclosure of how the company assesses and manages material cyber risk, and how the board oversees it. Separately, a material cyber incident triggers a Form 8-K. A May 2025 petition asked the SEC to rescind that 8-K item, and comment letters were still arriving through spring 2026, but nothing has changed. You audit the rules as written, and a stale governance disclosure can become a filing problem long before any of this moves.
That annual disclosure is what you review in the 10-K, and it has three parts: the process for assessing and managing material cyber risk, the board's oversight of that risk, and which members of management own it and what expertise they bring. Read each for substance. A company that runs a real process can name who owns it, how often the board hears about it, and what happens when something surfaces. Boilerplate that could describe any company rarely survives that read.
The 8-K filing choice and what enforces it
In May 2024, SEC staff clarified that the material-incident 8-K item is reserved for incidents a company has determined to be material. Filing behavior changed almost immediately. The rescission petition documents that filings under the material-incident item fell from 17 before the statement to nine after it through year-end 2024. Voluntary disclosures went the other way, from six to 28.
That's a materiality determination doing real work, and it's what the review should test. Once made, the determination starts a four business days clock.
Enforcement gives the review its teeth. In October 2024 the SEC charged four companies, Unisys, Avaya, Check Point, and Mimecast, with materially misleading cybersecurity disclosures tied to the SolarWinds Orion compromise. The theory the dissenting commissioners described in two of the cases: the risk factor was left generic or hypothetical after the Orion compromise had already happened.
That's a concrete check any senior can run. If your client had an incident during the year and the risk factor still says a breach "could" occur, flag it.
Where AI oversight is showing up
No rule requires AI-governance disclosure yet, but companies are volunteering it anyway, the way cyber disclosure grew before the rules caught up. The number of S&P 500 companies disclosing a designated committee with AI oversight responsibilities more than tripled in 2025, and audit committees are the most common choice.
The audit consequence is small but real. When a client describes AI oversight in its proxy or 10-K, that description becomes other information: you have to read it against the financial statements and against what you learned during the audit, and raise anything that doesn't square. An oversight process the disclosure lays out in detail but nobody you interviewed seems to actually run is exactly that kind of mismatch.
The recurring high-judgment disclosures
Same items every year. Same findings every year. These aren't gaps in the checklist; they're gaps between what a checklist can ask and what an auditor has to decide.
Where estimates go wrong
Estimates are where the file gets soft. They carry the greatest audit risk, they're the most exposed to management bias, and the auditor's own head works against them: you anchor on the client's number and give more weight to evidence that confirms it. The private side is no easier. 23% of peer reviewers named evaluating assumptions as a challenge in their reviews.
The disclosures sit inside the same problem. The estimate and its narrative are one piece of work, not two. If the number is well supported and the disclosure describes a different world, the finding is on the disclosure.
Judgments no checklist row captures
Going concern is a two-stage judgment. You assess whether there's substantial doubt about the entity's ability to continue, and if so, whether management's plans alleviate it. When the doubt remains, inadequate disclosure is a departure from generally accepted accounting principles (GAAP) and drives the opinion, so the checklist has teeth. When management's plans alleviate the doubt, the checklist goes quiet, and you still have to decide whether the conditions that raised the doubt (and the mitigating factors that answered it) belong in the notes anyway. Nothing mechanical picks that.
Contingencies work the same way. Probable, reasonably possible, and remote have no quantitative thresholds attached, and the SEC has repeatedly pushed registrants to disclose a range of reasonably possible loss or say plainly that an estimate can't be made. Silence isn't a safe answer.
Related parties flip the problem. It's a completeness exercise, so the disclosure question is really an identification question: what didn't get named? Bank confirmations, legal confirmations, and the minutes of shareholder and management meetings are where undisclosed relationships tend to surface.
Fair value is where the risk shows up on inspection reports. One recent example: a firm didn't identify the issuer's omission of, and a misstatement in, required fair value disclosures for warrants recorded as liabilities. The requirement was in the standards; the disclosure just wasn't on the page.
Presentation and consistency checks
Everything above assumes the notes are accurate. This section is about what happens to them after the checklist is signed.
The other-information read
You read the rest of the document (MD&A, the shareholder letter, exhibits) for material inconsistencies with the financial statements. You have no obligation to corroborate what's there, but a number in MD&A that doesn't tie to the statements is your problem to raise. Same for footnote cross-references that point to a note that got renumbered last week, and for comparative periods that no longer match what was actually filed last year.
It's tedious, unglamorous work. But late-stage edits break exactly these things, so this read is what catches a last-minute change before it becomes a filed error.
Non-GAAP measures
Non-GAAP is where the SEC comment letter volume actually lives, along with MD&A. Two rules do most of the enforcement. The GAAP measure needs equal or greater prominence and a quantitative reconciliation, and the filing has to explain why the non-GAAP figure is useful. Non-GAAP measures don't belong on the face of the statements or in the notes at all.
Prominence failures are quiet. The non-GAAP table lands first, in bold, described as "record performance," and the GAAP figure sits below in plain type doing worse. That layout is where the comment letter starts.
XBRL
No auditor attestation, no free pass. Tagging errors still degrade the machine-readable filing, and the SEC staff issue comment letters on Inline XBRL tagging when they see them. Sign flips on credit balances, missing calculations, and custom tags where a standard tag existed are the usual patterns. Give one person on the team ownership of the tagging review; distributed ownership is how these get missed.
A checklist confirms coverage while quality requires judgment
A checklist can confirm every required disclosure is present. It can't confirm they're right, or catch a file that omits something material or buries what matters under detail that doesn't. That's judgment — it's specific to each client, and it's where the findings live.
Segment reporting shows it. The new segment rows went into checklists on schedule, yet SEC comments on segment reporting still rose from 16% to 23% of reviews with comment letters in Deloitte's review, mostly on implementation. Identifying the chief operating decision maker and deciding which expenses are significant are judgment calls. The rows were there. The comments came anyway.
Generative AI now runs these completeness checks, and it's fast. That pays off only if the time it frees goes to the judgment work. Speed up the checklist alone, and you've accelerated the half that was never producing the findings.
Close the gap between coverage and quality
The judgment work in this article is what senior hours are for, and those hours tend to get spent chasing evidence and updating status instead. Fieldguide's Field Agents take on the execution. They analyze and validate client-submitted evidence, execute defined testing steps, and draft documentation across the engagement, so the senior's hours land on the judgment the checklist can't make.
Practitioners direct the work and review every output before it stands. Because Fieldguide runs on one platform across the engagement lifecycle, disclosure review happens alongside the workpapers, the prior-year file, and the client's evidence. That gives reviewers more room to judge materiality, adequacy, and the second-stage going concern call. See how peer firms use Fieldguide or request a demo to walk through where the engagement hours actually go.