Project 02 · Audit

Etsy Audit Risk & Planning Analysis

How a planning team might approach the audit of a high-volume online marketplace, from risk assessment to a client-acceptance call.

Course
ACC 4120, Auditing
Format
Academic team project, three students
Subject
Etsy, Inc., from public reporting
Year
2026

Academic analysis, not an audit. Etsy was not a client, and no one on our team took part in Etsy’s actual audit. PricewaterhouseCoopers (PwC) is named below only because it is Etsy’s auditor of record; this project has no connection to the firm.

01

Overview

The question: should an audit partner take on Etsy, and if so, where should the audit focus?

For our Auditing course, our team analyzed Etsy as if we were planning its audit. We reviewed its business model and audit history, assessed the risk of material misstatement, identified the accounts most exposed to that risk, proposed procedures and timing, and closed with a recommendation on client acceptance.

Etsy earns most of its revenue from required seller fees on its marketplace, and the rest from optional services sellers choose to buy.

Company
Etsy, Inc. (ETSY)
Business
E-commerce marketplace
Headquarters
Brooklyn, New York
Founded
2005
Public since
2015
Fiscal year end
December 31

Marketplace revenue — $2.0B, 69.6% · transaction, payment processing, and listing fees

Services revenue — $876.3M, 30.4% · on-site ads, shipping labels

2025 consolidated revenue of $2.9B, up 2.7% year over year, as presented in the team’s analysis of Etsy’s reporting.

02

Audit environment

We started with Etsy’s audit history: who audits it, what opinions it has received, which matters its auditor called out as critical, and how audit fees have moved.

External auditor
PwC, New York
Auditor since
2012
Opinions, 2016–2025
Unqualified, every year
Financial statements
Audited under PCAOB standards
Internal control
Evaluated against the COSO framework; unqualified
Audit deadline
March 1

Critical audit matters by year

  1. Reverb acquisition valuation
  2. Convertible notes
  3. Depop acquisition valuation
  4. Goodwill impairment — Depop and Elo7
  5. Reverb goodwill assessment
  6. Revenue recognition

The most recent critical audit matter, revenue recognition, lines up with revenue being the highest-risk account in our assessment.

Audit fees

Etsy audit fees, 2016 to 2025Fees ranged from about $2.4 million in 2017 to about $3.65 million in 2021, and were about $3.6 million in 2025.2.22.63.03.43.82016’17’18’19’20’21’22’23’2420252016: about $3.17 million2017: about $2.43 million2018: about $3.23 million2019: about $2.88 million2020: about $2.73 million2021: about $3.65 million2022: about $3.54 million2023: about $3.46 million2024: about $3.17 million2025: about $3.60 million≈ $2.4M≈ $3.65M≈ $3.6M Etsy audit fees, 2016 to 2025Fees ranged from about $2.4 million in 2017 to about $3.65 million in 2021, and were about $3.6 million in 2025.2.22.63.03.43.82016’19’2220252016: about $3.17 million2017: about $2.43 million2018: about $3.23 million2019: about $2.88 million2020: about $2.73 million2021: about $3.65 million2022: about $3.54 million2023: about $3.46 million2024: about $3.17 million2025: about $3.60 million≈ $2.4M≈ $3.65M≈ $3.6M
Annual audit fees paid to Etsy’s external auditor, in $ millions. Redrawn from the team’s chart; values are approximate.
View as table
YearAudit fees (approx.)
2016$3,175K
2017$2,430K
2018$3,235K
2019$2,880K
2020$2,730K
2021$3,650K
2022$3,535K
2023$3,460K
2024$3,170K
2025$3,605K

03

Risk assessment

We worked through the audit risk model — audit risk as the product of inherent, control, and detection risk — and named the specific drivers of each for a business like Etsy.

Inherent risk

Risk of misstatement before considering controls

  • Cybersecurity and technology
  • Fraud
  • Dependence on third parties

Control risk

Risk that controls fail to prevent or catch it

  • IT general controls
  • Revenue processing controls
  • Fraud monitoring controls

Detection risk

Risk that audit procedures miss it

  • Extremely high transaction volume
  • AI and automated systems
  • Fraud concealment

04

Key accounts

We flagged four accounts as risky. Two of them, revenue and accounts receivable, were carried into detailed procedures as the high-risk areas.

Accounts identified in the risk assessment
AccountAssessmentDetailed procedures
RevenueHigh risk; subject of the auditor’s 2024–2025 critical audit matterYes
Accounts receivableHigh riskYes
Cash and cash equivalentsRisky accountNot planned in detail
Refund liabilitiesRisky accountNot planned in detail

05

Audit response

For revenue and accounts receivable we proposed control testing, tests of detail, and analytical procedures.

Revenue

  1. Test internal controls over revenue recognition systems
  2. Select sample transactions and trace them to accounting records
  3. Perform cutoff testing near year-end
  4. Compare revenue trends with prior years
  5. Reconcile platform reports to the general ledger
  6. Verify payment processor reports

Accounts receivable

  1. Review subsequent cash collections
  2. Reconcile receivable balances to the general ledger
  3. Review aging schedules and allowance estimates
  4. Perform cutoff testing

06

Timing & group audit

When each procedure is performed
AccountInterimYear-end
RevenueTest internal controls; compare revenue trendsTrace sample transactions, cutoff testing, reconciliation, and payment processor reports
Accounts receivableReview aging schedules and allowance estimates; reconcile balancesReview subsequent cash collections; cutoff testing

Group audit

Our plan used in-network component auditors for certain foreign operations and subsidiaries. The lead auditor takes full responsibility for their work after evaluating their competence, independence, and procedures, so the component auditors may not need to be named in the audit opinion.

Component work follows the same timeline as the overall audit, so it is finished before the final opinion is issued.

07

Conclusion

Team recommendation

The audit partner should accept Etsy as a client.

  • Significant risks, but manageable with the planned procedures
  • Unqualified opinions for each of the past ten years
  • Audit fees trending higher over the period reviewed
  • Independence: no direct ownership in the investment portfolio

What this project built

  • Risk-based planningStarting from the audit risk model and naming concrete risk drivers.
  • Linking risks to proceduresChoosing tests that respond to the accounts most likely to be misstated.
  • Reading audit reportsUsing opinions, critical audit matters, and fee history to understand an audit environment.
  • Planning the calendarSplitting work between interim and year-end, including component auditors.