Lessons from Other Fields
Financial Auditing & SEC Disclosure
The closest structural analog to election verification — and the Enron–Sarbanes-Oxley cycle that shows what a serious response to verification failure looks like.
In Brief
When you buy stock in a company, you are trusting numbers you cannot check. You can’t walk into the warehouse and count the inventory, read the supplier contracts, or confirm that the cash on the balance sheet is really in the bank. Every public company in America sits behind that same wall of unverifiable information — and yet the system works, because society built an architecture to close the gap.
That architecture has layers. An independent auditor — barred by law from having a financial stake in the company — examines the books every year. Since the Sarbanes-Oxley Act of 2002, the CEO and CFO must personally certify the numbers under penalty of prison. The filings go into a public database, EDGAR, that anyone can search for free. The auditors are themselves audited by a regulator, the PCAOB. And whistleblowers who report fraud are paid a share of the recovery. None of it requires you to trust any single party.
The system is judged by how it responds when it fails. When Enron collapsed in 2001 — a fraud its auditor missed — Congress didn’t shrug. It passed Sarbanes-Oxley within months, built a new regulator, and made the architecture stronger. A verification system that strengthens itself after a failure is alive. One that rationalizes failure is not.
A voter is in exactly the position of that investor. You cannot walk into the county elections office and count the ballots, or confirm that the total your state published matches what the scanner actually printed at your precinct. But the step that turns precinct counts into official results — the reporting layer — has almost none of the financial system’s safeguards: no independent audit of that step, no certification under penalty, no public database of the primary-source evidence. Actual Vote supplies the missing piece the financial world takes for granted — an independent, primary-source record anyone can check the official numbers against. The full treatment below traces how the financial architecture was built, how it answered Enron, and exactly what it implies for the vote.
I. What This Domain Is
When an investor puts money into a publicly traded American company, they are making a decision based on numbers. The company reports its revenue, its expenses, its assets, its liabilities, its earnings. The investor does not have independent access to the company’s books. They cannot walk into the warehouse and count inventory. They cannot read the contracts with suppliers. They cannot verify that the cash balance on the balance sheet matches the actual cash in the actual bank accounts. Every decision the investor makes depends on information the investor cannot directly check.
This is the same epistemic structure as an American voter evaluating an election result. The voter cannot walk into the county elections office and count the ballots. They cannot pull the memory cards from the tabulators. They cannot verify that the number of votes the state reported for their precinct matches the number of votes the scanner actually printed at the close of polls. The voter’s confidence in the result depends entirely on information they cannot directly check.
In financial markets, the epistemic gap is closed by a comprehensive architecture of independent verification. In elections, it is not. This entry describes the financial architecture, the history of its construction, and the pattern of its response to its own failures — and it asks, at the end, what the equivalent architecture for elections would look like and why it has not yet been built.
II. The Institutional Architecture
Publicly traded American companies are required, by federal securities law, to file regular financial disclosures with the Securities and Exchange Commission. Annual reports on Form 10-K, quarterly reports on Form 10-Q, current reports on Form 8-K when material events occur, proxy statements for shareholder votes, and registration statements for new securities offerings are all filed into a public database (EDGAR) that any citizen can search at any time without charge. The filings are not summaries. They are detailed financial statements, prepared under Generally Accepted Accounting Principles, accompanied by narrative discussion, risk disclosures, executive compensation tables, related-party transaction disclosures, and management’s assessment of internal controls.
Every annual filing must be audited. The audit is performed by an independent accounting firm — independent in the sense that federal law and SEC regulations prohibit the firm from having financial or consulting relationships with the audited company that would compromise its objectivity. The audit is not a casual review. It is a structured examination of the company’s books, internal controls, accounting estimates, disclosure practices, and governance processes, conducted under detailed professional standards set by the Public Company Accounting Oversight Board — an independent regulator established by Congress in 2002 specifically to oversee the auditors of public companies. The auditor’s report is itself filed with the SEC, attached to the financial statements, and becomes part of the public record.
The auditors are themselves regulated. The PCAOB inspects audit firms on a regular cycle, reviews samples of their audit work, identifies deficiencies, publishes inspection reports in part publicly, and can impose sanctions ranging from fines to revocation of the firm’s registration. Individual auditors can be barred from auditing public companies. Audit firms can be prosecuted. The audit profession is not self-regulating in any meaningful sense.
The Sarbanes-Oxley Act of 2002 added a second layer. Corporate chief executive officers and chief financial officers must personally certify, under penalty of criminal prosecution, that the financial statements they sign are accurate and that the company’s internal controls over financial reporting are adequate. They must do this for every annual and quarterly filing. They cannot delegate the certification. They cannot claim ignorance of their company’s books. If the filing turns out to contain material misstatements, the officers who certified it can be prosecuted personally, and in serious cases they have been. CEOs of large companies have gone to federal prison for signing false certifications.
The Dodd-Frank Act of 2010 added a third. Whistleblowers who report violations of securities law to the SEC are entitled to substantial financial rewards — typically 10 to 30 percent of the penalties recovered — and are protected from retaliation by their employers. The reward structure has produced tens of thousands of whistleblower tips in the years since, and hundreds of millions of dollars in recoveries directly attributable to insider reporting. The architecture deliberately creates financial incentives for the people best positioned to detect misconduct to report it.
Surrounding this core are a dense set of adjacent verification systems. Credit rating agencies evaluate corporate debt. Equity research analysts at brokerages cover public companies and publish opinions on them. Short sellers have financial incentives to identify companies whose public disclosures overstate their condition, and have repeatedly been the source of the first public allegations in major fraud cases. Financial journalism, particularly at outlets like The Wall Street Journal, Bloomberg, Reuters, and the Financial Times, maintains dedicated beats covering corporate disclosures and frequently breaks stories about accounting irregularities before regulators act. The SEC’s Division of Enforcement investigates suspected violations, brings civil cases, and refers criminal matters to the Department of Justice. Failed audits and accounting frauds routinely produce shareholder litigation under the Private Securities Litigation Reform Act, with settlements frequently in the hundreds of millions of dollars. The whole apparatus is documented, public, and continuously refined in response to identified failures.
The architecture is not limited to the largest companies. Any company with securities registered with the SEC — a category that includes not just the large-cap names on major exchanges but thousands of smaller public companies — is subject to the same disclosure, audit, certification, and enforcement regime. The architecture is not a prestige marker. It is a baseline.
III. Why This Exists
Financial markets cannot function without a shared baseline of trust in the information that participants use to make decisions. Investors who do not believe financial statements are reliable will not invest, or will demand a discount large enough to compensate for the perceived risk of fraud. The cost of that risk discount, applied to the entire capital market, would be catastrophic. It would substantially reduce the supply of capital available for productive investment; raise the cost of capital for legitimate businesses; concentrate investment in assets and arrangements that do not require trust in disclosure; and push large swaths of the economy toward the informal, self-dealing, insider-driven patterns that characterize markets in countries where financial disclosure is unreliable. The long-run economic cost of that shift would be measured in lost decades of growth, not in basis points of return.
The architecture of independent financial auditing exists because society has determined that the cost of the architecture is much smaller than the cost of operating without it. The benefit is not primarily measured in the catching of individual frauds, though that matters. The benefit is primarily measured in the trust the architecture allows — trust that lets the rest of the capital market function at capital-efficiency levels that would otherwise be impossible. The architecture is the condition for the efficiency. Without it, the market’s outputs become unreliable in ways that compound.
The same logic applies to election reporting, with the participants and the stakes substituted. Citizens cannot function as citizens of a democracy without a shared baseline of trust in the numbers that democracy’s collective decisions are based on. Citizens who do not believe election results are reliable will not participate, or will participate cynically, or will come to treat the outcomes of elections as contests for power to be pursued by other means. The cost of that shift, applied across a population of more than three hundred million people, is not measurable in any simple unit, but it is visibly enormous — measured in political violence, in institutional delegitimation, in the erosion of the procedural consensus without which a large, diverse, modern democracy cannot hold together. The long-run cost of operating without a verification architecture is not less than the long-run cost of operating without one in capital markets. It is probably much greater.
IV. The Cautionary Case: Enron and Sarbanes-Oxley
The Enron case is the most widely understood example of what happens when financial verification architecture fails, and of what the response pattern looks like when the failure is severe enough to force structural change.
Enron Corporation was, in the late 1990s, one of the most admired companies in the United States. Its stock price had climbed steadily for most of a decade. Its reported earnings grew at rates that market analysts treated as characterizing a new kind of energy-trading business model. Its accounting was audited by Arthur Andersen, at the time one of the five largest accounting firms in the world, a firm whose name appeared on the audit reports of a substantial fraction of the S&P 500. Enron’s 10-K filings were public. Its disclosures ran to hundreds of pages. Investors, analysts, regulators, and journalists all had access to the same documents. By every outward sign, Enron was a fully verified public company operating under the standard American architecture of financial transparency.
It was not. Beginning in the mid-1990s and accelerating through 2000, Enron’s senior management constructed an elaborate network of off-balance-sheet partnerships, special-purpose entities, and related-party transactions that had the effect of hiding the company’s actual debt and manufacturing apparent earnings that did not correspond to any real economic activity. The accounting was technically compliant with a narrow reading of certain rules; it was substantively fraudulent. Arthur Andersen, the auditor, either failed to detect the structure or detected it and did not disclose it — the subsequent investigations established varying degrees of complicity depending on the engagement team and the year. The company’s reported numbers bore only the loosest relationship to its actual financial condition.
The disclosure came quickly once it began. In October 2001, Enron announced a significant restatement of earnings and disclosed losses it had previously hidden. Within weeks, the company’s stock price collapsed. In December 2001, Enron filed for bankruptcy, at the time the largest bankruptcy in United States history. Tens of thousands of employees lost their jobs. Shareholders lost approximately sixty billion dollars in market value. Employees who had held Enron stock in their retirement accounts were largely wiped out. Pension funds that had held the stock took major losses. The company’s senior executives — Kenneth Lay, Jeffrey Skilling, Andrew Fastow, and others — were indicted, tried, and convicted of securities fraud, conspiracy, and related crimes. Arthur Andersen was indicted for obstruction of justice for the document destruction that accompanied its failed audits, convicted at trial, and effectively destroyed as a firm: its partners left, its clients left, and its ability to operate as an audit firm ended within a year. One of the five largest accounting firms in the world ceased to exist as a consequence of a single failed engagement.
The institutional response was immediate and structural. In July 2002, less than a year after Enron’s collapse, Congress passed the Sarbanes-Oxley Act. The vote was overwhelming — 99-0 in the Senate, 423-3 in the House. The Act established the Public Company Accounting Oversight Board, which replaced the self-regulatory regime under which the audit profession had previously operated. It imposed the personal CEO and CFO certification requirements described above. It required management to assess and report on the adequacy of internal controls over financial reporting, and required the external auditor to independently attest to that assessment. It prohibited audit firms from performing certain non-audit services for their audit clients, tightening independence. It created criminal penalties for the destruction of audit records. It lengthened the statute of limitations for securities fraud. It strengthened whistleblower protections. It imposed disgorgement of CEO and CFO compensation in the event of financial restatements due to misconduct.
The architecture that existed after Sarbanes-Oxley was materially more rigorous than the architecture that had existed before. Enron did not demonstrate that financial auditing was impossible. It demonstrated that the existing architecture had specific gaps, and the institutional response was to close those gaps. When WorldCom collapsed seven months later in the other direction — a straightforward accounting fraud involving roughly eleven billion dollars of fictitious earnings that its auditors also missed — the response was further tightening of the same apparatus. When Wirecard collapsed in Germany in 2020, the response was significant reform of the German regulatory regime around corporate auditing. When FTX collapsed in late 2022, the response was the beginning of a regulatory regime for cryptocurrency reporting that had not previously existed. The response pattern is the diagnostic feature. A verification architecture that responds to failures by strengthening itself is an architecture that is alive. An architecture that responds to failures by rationalizing them, minimizing them, or arguing that the failure is unrepresentative is an architecture that is no longer performing its function.
V. The Transfer to Elections
The structural parallel between financial auditing and election verification is exact at the level of abstraction that matters. Both are domains in which collective decisions — how capital is allocated, who exercises political authority — depend on the integrity of information about quantities that no individual participant can directly verify. In financial markets, the quantities are revenue, expenses, assets, liabilities, and earnings; the participants are investors. In elections, the quantities are votes cast, votes counted, and outcomes reported; the participants are citizens. In both cases, the information is generated by parties with potential interests in the outcome — companies in the financial case, election administrators and equipment vendors in the election case — who would be in a position to misrepresent it without independent verification. In both cases, operating without independent verification would produce a collapse of trust that would degrade the function of the underlying institution. In both cases, the architecture of verification is what makes the institution work.
The asymmetry in the rigor of the two architectures is striking. Financial markets enforce a dense, comprehensive regime: independent audits by professionally certified firms operating under detailed standards, regulated by an independent body with inspection and sanction authority, with personal criminal liability for corporate officers who certify false disclosures, with mandatory public disclosure on a schedule enforceable by the SEC, with continuous reform in response to identified failures, and with a surrounding ecosystem of analysts, journalists, short sellers, and whistleblowers whose financial incentives push toward exposure of misconduct. Election verification in the United States enforces a much smaller architecture: audit requirements that vary widely by state, often limited to small post-certification samples and often calibrated to the counting layer rather than the reporting layer; independence requirements for auditors that are weak or absent; no requirement analogous to executive certification of accuracy; no regulator analogous to the PCAOB with inspection and sanction authority over election systems; no mandatory public disclosure of primary-source reporting evidence in a format that outside observers can independently examine; no surrounding ecosystem of financial incentives for exposure of misconduct.
The asymmetry is not justified by any difference in the stakes. The social welfare at stake in a U.S. presidential election — across economic policy, foreign policy, judicial appointments, administrative rulemaking, and the quality of democratic institutions themselves — is at least comparable to, and on most reasonable parameterizations substantially larger than, the social welfare at stake in the integrity of the American capital market. If the capital-markets architecture is worth its cost, the election architecture is at least as worth a comparable cost. The gap between the two architectures is not a gap that reflects the relative stakes. It is a gap that reflects the relative political salience of the failures that have so far been documented in each, and the relative institutional appetite for reform in response to those failures.
The case for applying the financial-auditing template to elections is not that elections should be audited by accounting firms. It is that the architectural logic of the financial regime — independent verification by parties with no stake in the outcome, transparent disclosure in a form outsiders can inspect, structural response to failure rather than rationalization, surrounding ecosystems that produce financial and reputational incentives for exposure of misconduct — is the logic that should be applied, in election-appropriate form, to the step in the election process that is currently least verified. That step is the reporting layer: the transmission of precinct-level tabulator totals into published official results. The case studies collection documents the failure modes at that step. The financial-audit architecture, applied with the necessary translations, is one model for what closing the gap would look like.
VI. Where Actual Vote Fits
Actual Vote is a specific, narrowly scoped implementation of the independent-verification principle applied to the election reporting layer. It does not replicate the full financial-audit architecture, and it does not try to. A full election-verification architecture — with the election equivalent of PCAOB inspection, CEO-level certification of accuracy under criminal penalty, and an enforcement division with the SEC’s authority — is a project for legislatures and regulators, not for a civil-society verification tool. What Actual Vote does is supply one of the architectural elements, the one that is currently most absent and most feasible for citizens to supply themselves: the primary-source independent record.
The closest financial-market analog is the role played by short sellers and financial journalists in major corporate fraud cases. Neither is part of the official verification architecture. Neither has regulatory authority. What both have is the independent capacity to examine public disclosures, compare them against primary evidence, and publish the comparison. The short seller who identified the accounting irregularities at Enron before most sell-side analysts did (James Chanos, whose firm Kynikos Associates took short positions in the company starting in late 2000) was not part of the SEC’s enforcement apparatus. He was a private actor with independent analytic capacity operating on public information. His role in the case is instructive precisely because the formal verification architecture — the audit, the accounting standards, the SEC’s filings review — had failed to detect what he detected. The independent outside analyst caught what the architecture missed, and the architecture subsequently strengthened in response.
Actual Vote plays the same structural role in the election case. It is not a regulator, an auditor, or a certifying authority. It is an independent outside capacity for examining primary-source reporting evidence (the precinct tabulator tape) and comparing it against the official disclosure (the published election result). When the comparison matches, the comparison is itself evidence that the reporting layer functioned correctly — the equivalent of a short seller’s public analysis concluding that a company’s disclosures are consistent with its actual financial condition, which is a result the market values even when no fraud is present. When the comparison does not match, the comparison is evidence of a reporting-layer problem — the equivalent of the short seller’s analysis that identifies the discrepancy in a company’s disclosures and makes the evidence public in a form other participants can evaluate for themselves. In both cases, the independent outside capacity does not replace the formal architecture; it supplements it, exposes its gaps when they exist, and — over time, in response to repeated exposure — pushes the formal architecture toward improvement.
The comparison to the financial case also carries a further argument. The financial architecture, as comprehensive as it now is, was built in large part in response to the independent exposure of specific failures. Sarbanes-Oxley would not have been politically possible without Enron. Dodd-Frank would not have been politically possible without the 2008 financial crisis. The PCAOB would not exist without the accumulated documented failures of the pre-2002 self-regulatory regime. The formal architecture got stronger because specific failures were exposed by actors outside the architecture and the exposure was sufficient to force reform. The equivalent dynamic is what Actual Vote is positioned to create for election verification. Its direct contribution is the evidence it produces in real time for specific precincts. Its long-run contribution is the pressure that evidence places on the political economy of election reform. The financial case is the existence proof that this dynamic works. The election case is, at the moment, at the stage the financial case was before Arthur Andersen became a cautionary byword.
VII. Cross-References
This entry most directly illuminates the reporting-layer case studies, where the parallel to financial-disclosure failures is tightest:
-
Shelby County, Tennessee, 2015. Bennie Smith’s single photograph of a poll tape that did not match the official result is the precinct-level equivalent of a short seller’s single slide showing a discrepancy in a 10-K disclosure — one piece of independently captured evidence that makes a subsequent investigation impossible to dismiss.
-
Prince William County, Virginia, 2020. A reporting-layer error that survived a risk-limiting audit with greater than 99 percent confidence in the audited question is the election equivalent of an accounting misstatement that survives an unqualified audit opinion: the audit was calibrated to ask a different question than the one that actually mattered, and the discrepancy lived in the gap.
-
Monmouth County, New Jersey, 2022. A “100 percent accuracy” audit that reported a clean result while the wrong candidate held office is the election equivalent of an audit opinion on financial statements that turned out to be materially wrong — the procedural form of verification was complete and the substantive conclusion was false.
-
The Fraction Magic Architecture. The GEMS database’s floating-point storage of vote totals is the election equivalent of an accounting category whose structure permits material misstatement within the technical letter of the rules: the architectural feature exists, its exploitation is possible, the response in the financial domain would have been prompt regulatory intervention, and the election domain has so far produced no analogous response.
VIII. Further Reading
-
Sarbanes-Oxley Act of 2002, Pub. L. 107-204 (July 30, 2002). The foundational statute establishing the PCAOB, executive certification requirements, and the post-Enron audit regime.
-
Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010, Pub. L. 111-203 (July 21, 2010). Including provisions on whistleblower rewards and protections now administered by the SEC Office of the Whistleblower.
-
United States Senate, Permanent Subcommittee on Investigations, The Role of the Board of Directors in Enron’s Collapse (2002). Contemporaneous congressional analysis of the governance and audit failures.
-
Report of Investigation by the Special Investigative Committee of the Board of Directors of Enron Corp. (“Powers Report”), February 1, 2002. The internal investigation commissioned by Enron’s own board, which is the most detailed public description of the special-purpose-entity structure and its accounting treatment.
-
United States v. Arthur Andersen LLP, 544 U.S. 696 (2005). The Supreme Court’s decision overturning the firm’s obstruction conviction on jury-instruction grounds, by which point the firm had already effectively ceased to exist.
-
Public Company Accounting Oversight Board, Annual Reports and published inspection reports (pcaobus.org). The continuing public record of audit-firm oversight under the post-Sarbanes-Oxley regime.
-
Securities and Exchange Commission, EDGAR filing database (sec.gov/edgar). The public repository of corporate disclosures whose accessibility is itself part of what makes the financial architecture work.
