Deloitte Bought Wavicle. Check Who Signs Your Audit Opinion.

Deloitte acquired substantially all of Wavicle's assets on August 31, so any statement of work with a standard anti-assignment clause needs your written consent to assign. If Deloitte & Touche LLP signs your audit opinion, SOX 201 may bar the engagement outright.

By Rajesh Beri·September 1, 2026·14 min read
Share:
A single unsigned contract-assignment letter lying on a dark polished boardroom table beside a thick bound audit report and a capped fountain pen, overhead light pooling on the paper, empty chairs around it.

Illustration generated using AI

If Deloitte & Touche LLP signs your audit opinion and Wavicle Data Solutions is building your lakehouse, one of those two things is about to change.

Deloitte acquired substantially all of the assets of Wavicle Data Solutions on August 31, 2026. Because it is an asset purchase and not a stock deal, the contracts have to be individually assigned. If your statement of work carries a standard anti-assignment clause, someone at Deloitte has to ask you to consent — and that request, probably already in a legal inbox somewhere in your company, is the only leverage window you get. Before you answer it, answer a different question first: who signs your audit opinion? For roughly one in seven US public companies, the answer makes this engagement a federal securities problem rather than a procurement one.


What Deloitte Actually Bought on August 31

Deloitte bought the business, the people and the Databricks practice — not the corporate entity. The announcement is explicit that Deloitte acquired "substantially all of the assets" of Wavicle, a Chicago-area data and AI engineering firm founded in 2013 with more than 480 employees. Jason Salzetti, chair and CEO of Deloitte Consulting LLP, framed it as helping clients "strengthen their data foundations and translate AI into lasting business value."

The absorption was not gradual. Wavicle's own domain, wavicledata.com, now issues a 301 redirect to Deloitte's press room page for the deal. The brand is gone as of day one.

What Wavicle does matters more than what it was worth, and the shape of the practice is public. Its Clutch profile breaks the work down as roughly 50% cloud consulting and systems integration, 30% BI and big data, and 10% ERP consulting and SI, delivered from Oak Brook, Illinois, with offices in Coimbatore, India and Montreal. Minimum project size is listed at $75,000, with recent engagements in the seven-figure range and one client spending approximately $3.5 million a year. Deloitte's release names the industries served: consumer goods, manufacturing, financial services, life sciences and healthcare.

Read that service mix again. Cloud data migration, BI, and ERP work is, in plain terms, the business of moving the numbers that end up in a 10-K from one system to another. That is not a compliance abstraction. That is the definition the SEC wrote down.


An Asset Purchase Puts Every SOW Back on the Table

In an asset deal, contracts do not transfer by operation of law — they have to be individually assigned, and a standard anti-assignment clause means the counterparty's written consent is required. As M&A counsel routinely warn, certain contract counterparties may use the leverage of their consent to renegotiate terms or extract concessions.

That leverage is real and it is asymmetric in your favour, briefly. Deloitte has already paid for a book of business it does not yet legally hold. Every client who declines to consent, or consents slowly, is revenue that did not arrive. You are the counterparty. Read your assignment clause before you reply: many contain a "shall not be unreasonably withheld, conditioned or delayed" qualifier, which narrows what you can demand — but "unreasonable" does not cover a genuine independence bar, and it does not stop you asking for the commercial terms you would want from any new supplier.

This is the same window that opens in every acqui-hire and asset carve-out. It closed badly for buyers who did not use it when Klaviyo bought Agency and wound the product down, and it is the reason Descartes' acquisition of Tai left freight brokers with a 60-day renewal notice as their only lever. Here the window is wider, because consent is affirmative rather than a notice period you have to catch.


The Rule That Bites Is Item Two of SOX 201

Sarbanes-Oxley did not leave "financial information systems design and implementation" to interpretation. It is the second of nine non-audit services that 15 U.S.C. § 78j-1(g) flatly prohibits a registered public accounting firm from providing to an audit client, sitting between bookkeeping and appraisal services. This is statute, not guidance.

The implementing regulation is where it gets specific. 17 CFR § 210.2-01(c)(4)(ii) prohibits:

Any service, unless it is reasonable to conclude that the results of these services will not be subject to audit procedures during an audit of the audit client's financial statements, including: (A) Directly or indirectly operating, or supervising the operation of, the audit client's information system or managing the audit client's local area network; or (B) Designing or implementing a hardware or software system that aggregates source data underlying the financial statements or generates information that is significant to the audit client's financial statements or other financial information systems taken as a whole.

"A software system that aggregates source data underlying the financial statements" is a functional description of a lakehouse. If a Wavicle team is landing your order-to-cash data, your ERP extracts, your revenue recognition inputs or your regulatory reporting feeds into Databricks — and that is exactly the work described on the tin — subparagraph (B) is not a stretch. It is the plain reading.

There is a real escape hatch, and it is the clause everyone will argue about: the prohibition applies unless it is reasonable to conclude the results will not be subject to audit procedures. A marketing attribution model in Databricks Mosaic AI is very likely outside it. A general ledger consolidation layer is very likely inside it. Most real programmes are somewhere in between, which is precisely why this needs a documented answer rather than an assumption.


The first response you will hear is that Deloitte Consulting LLP is not Deloitte & Touche LLP. That is legally true and, for this rule, irrelevant.

Deloitte's own US site states that "Deloitte USA LLP, Deloitte LLP, and the subsidiaries of Deloitte LLP are each separate and distinct legal entities" — Deloitte & Touche LLP, Deloitte Consulting LLP, Deloitte Tax LLP, Deloitte Financial Advisory Services LLP and Deloitte Transactions and Business Analytics LLP, each separately capitalized with its own board.

The SEC anticipated this structure and wrote straight through it. Rule 2-01(f)(2) defines "accounting firm" to mean the organization engaged in public accounting "and all of the organization's departments, divisions, parents, subsidiaries, and associated entities, including those located outside of the United States." Consulting LLP is a subsidiary of the same parent as Touche LLP. For independence purposes, they are one firm.

Deloitte says as much itself, in the boilerplate at the bottom of the very press release announcing the acquisition: "Certain services may not be available to attest clients under the rules and regulations of public accounting." That sentence is not decoration. It is the disclosure that this deal just made load-bearing for some number of Wavicle's clients.


The Transition Relief Runs the Wrong Direction

Here is the part that is easy to get backwards, and it is the reason this cannot simply be waived through.

Rule 2-01 does contain transition relief for M&A. Paragraph (e) provides that "an accounting firm's independence will not be impaired because an audit client engages in a merger or acquisition that gives rise to a relationship or service that is inconsistent with this rule," subject to conditions: the firm was compliant when the service originated, it addresses the conflict promptly, and it maintains a quality control system that monitors client M&A activity.

Read the subject of that sentence. The relief is written for the case where your company buys something that drags a conflicting engagement into the audit perimeter. It is not written for the case where the accounting firm buys a consultancy and inherits a book of engagements at its own audit clients. That fact pattern does not get a named grace period in the text.

In practice this means the burden and the clock sit on Deloitte's side of the table, not yours — and you will learn the outcome not through negotiation but through a decision that has already been made about your programme.


The Steel-Man: Deloitte Has Already Run This Check

The strongest version of the other side is straightforward, and it is probably right.

Deloitte operates one of the largest independence compliance functions in professional services, built precisely for this. Its Deloitte Entity Search and Compliance (DESC) system is an internal database of entities restricted for independence purposes, and Deloitte's own guidance confirms that restricted entities include audit clients and their affiliates. Scrubbing an acquisition target's client list against that database before signing is table stakes, not a favour. The firm has bought dozens of practices and knows exactly what a 480-person consultancy's client roster does to its restricted list.

So the risk is almost certainly not that Deloitte missed it. The risk is what the answer costs you. A correctly-run independence check that concludes "Deloitte cannot continue this engagement" is a clean compliance outcome for the firm and a stranded migration for you — delivered in week three, in writing, with your Databricks contract already signed and your internal team already redeployed. Being right about the rule does not make anyone whole.

There is a second, quieter cost even where the work is permitted. Any non-audit service your auditor's firm does provide requires advance approval by the audit committee, with a narrow de minimis exception at 5% of total fees. And Item 9(e) of Schedule 14A requires the fees to be disclosed in your proxy under "All Other Fees," with a description of the services and the percentage pre-approved. A data platform build that used to be an IT line item becomes a governance artifact your shareholders read.


Run the Check Yourself. It Takes an Afternoon.

Start with the base rate, because it is better than you fear and worse than nothing. Deloitte was the largest US audit firm in 2025 with 926 SEC registrant clients and 15% of the market, against a total of 6,286 registrants, per Ideagen Audit Analytics. So roughly one in seven public companies is exposed to the question at all. Six in seven can close it in one email.

Work an example. Cars.com is named as a client in Wavicle's Clutch portfolio. Its stockholders ratified Ernst & Young LLP as independent auditor for fiscal 2026 at the June 3, 2026 annual meeting, 51,534,116 votes to 214,444. Different firm, no independence bar, question closed — the assignment consent is then a purely commercial negotiation. McDonald's, also named in that portfolio, is another public company whose auditor is not Deloitte. The check is cheap and it usually passes.

If it does not pass, the question narrows rather than ending. It becomes: does this specific scope aggregate source data underlying the financial statements, or generate information significant to them? That is a determination for your controller, your audit committee chair and your auditor's national office — not for the delivery partner on the engagement, who has an obvious interest in the answer.


What Getting This Wrong Has Cost

The enforcement record on exactly this service category is not theoretical.

In September 2019, the SEC found that PwC had, from 2013 through 2016 on nineteen engagements involving fifteen SEC-registrant audit clients, performed prohibited work including exercising decision-making authority in designing and configuring a Governance Risk and Compliance module used to monitor controls over financial reporting. PwC paid disgorgement and penalties of nearly $8 million. The SEC's stated rationale is the sentence to keep: designing, implementing or operating systems affecting the financial statements "may also place the accountant in a management role, or result in the accountant auditing his or her own work."

Smaller firms get caught too. On February 29, 2024, the SEC settled with Clark Schaefer Hackett over prohibited non-audit services provided to Lordstown Motors while auditing it, for a censure, a cease-and-desist order and more than $80,000. Separately, PCAOB Rule 3525 requires the auditor to describe non-audit services related to internal control over financial reporting to the audit committee in writing and document the independence discussion.

Note who pays in these cases. The firm pays the fine. The issuer pays in restatement risk, audit committee time, and the possibility that an opinion it already filed was signed by an accountant who was not independent.


This Week:

  1. Find the consent-to-assign request, or ask Deloitte when it is coming. It goes to legal or procurement, not to you. Do not let it be countersigned as routine paperwork before the independence question has an owner.
  2. Name your audit firm on paper, in writing, in the same thread. Not "Deloitte does some work for us" — the legal entity that signs the opinion. If it is not Deloitte & Touche LLP, write that down and move to commercial terms.
  3. Inventory the Wavicle SOWs and, for each, list the source systems it touches. Flag anything reading from the general ledger, sub-ledgers, ERP, billing, revenue recognition, or regulatory reporting.

Before You Sign:

  1. If your auditor is Deloitte & Touche LLP, route the scope inventory to your controller and audit committee chair, and ask Deloitte for its own written independence determination on each SOW. Get it before consent, not after.
  2. Use the leverage while you have it. Lock the rate card for the remaining term, name the individuals who must stay on the engagement, commit the delivery locations, and add termination for convenience with a defined transition-assistance period.
  3. Get data and IP handling restated in the assignment — where your data sits post-integration, and confirmation that Deloitte's broader tooling and offshore delivery network do not silently change the answer you gave your security team.

Before Your Next Audit Committee Meeting:

  1. If any permitted work continues with your auditor's firm, get it pre-approved on the record and budgeted into the "All Other Fees" line your proxy will disclose.
  2. Add one question to your standard SI due-diligence template: is any affiliate of this vendor's parent our independent auditor, now or plausibly in the next three years? This deal will not be the last of its kind.

The Bigger Picture

The industry already ran this experiment and reached the opposite conclusion.

After Enron, Sarbanes-Oxley forced the audit firms to confront exactly this conflict, and most of them resolved it structurally by selling the consulting business. Deloitte spent fifteen months preparing to spin its consulting arm out as Braxton and then abandoned the separation in March 2003, citing harsh capital markets — leaving it, at the time, the only one of the four largest accounting firms still holding a full IT consulting practice.

Twenty-three years later, the most valuable consulting work in the market is building the AI-ready data foundation, and that work lands squarely on the one service category the 2002 statute named second in its list of prohibitions. The structure that made the conflict possible was never dismantled. It was simply out of the money for a while.

This is the same pattern showing up across the AI services layer: AlixPartners buying Artium raised whose-side-are-you-on questions in restructuring, Anaconda buying its own red teamer collapsed an independence boundary in security testing, Visa buying BioCatch put vendor neutrality in play for banks, and the same-vendor problem in AI code review is the engineering version of the identical question. Consolidation keeps merging the builder with the checker. Sometimes the market punishes that. In this case a federal statute does.

Deloitte, which has been betting its own 470,000-person workforce on agentic AI tooling, now owns a premier Databricks practice at a moment when choosing between Databricks and Snowflake is already an exit-cost decision for most buyers. That is a strong strategic position. It is also a smaller addressable market than the headline suggests, by construction — roughly 15% of US public companies are structurally off the table for the most valuable version of this work.

Your consent is worth something for exactly as long as it goes unsigned. Spend it on terms, not on speed.

Continue Reading

Share:

Frequently Asked Questions

Does Deloitte's acquisition of Wavicle automatically transfer my contract?

No. Deloitte acquired substantially all of the assets of Wavicle rather than the company itself, and in an asset purchase contracts do not transfer by operation of law — they have to be individually assigned. Contracts are freely assignable by default, but the anti-assignment clause standard in enterprise services agreements requires your written consent, so most Wavicle clients can expect a consent-to-assign request. That consent request is the only negotiating window most clients will get.

Why would auditor independence rules stop a data platform project?

Sarbanes-Oxley lists financial information systems design and implementation as the second of nine non-audit services a registered public accounting firm may not provide to an audit client. SEC Rule 2-01(c)(4)(ii)(B) specifically prohibits designing or implementing a software system that aggregates source data underlying the financial statements. A lakehouse fed by ERP and general ledger data can fall squarely inside that description.

Deloitte Consulting LLP is a separate entity from Deloitte & Touche LLP. Doesn't that solve it?

No. SEC Rule 2-01(f)(2) defines an accounting firm to include all of the organization's departments, divisions, parents, subsidiaries and associated entities, including those outside the United States. Deloitte Consulting LLP and Deloitte & Touche LLP are separate legal entities under the same parent, so for independence purposes the SEC treats them as one firm.

How likely is this to affect my company?

Deloitte was the largest US audit firm in 2025 with 926 SEC registrant clients out of 6,286 total registrants, about 15% of the market per Ideagen Audit Analytics. So roughly one in seven US public companies needs to ask the question, and six in seven can close it with a single email confirming a different audit firm signs their opinion.

What should I ask for before consenting to the assignment?

Get a written independence determination from Deloitte on each statement of work if Deloitte & Touche LLP is your auditor. Then use the commercial leverage: lock the rate card for the remaining term, name the individuals who must stay on the engagement, commit delivery locations, add termination for convenience with transition assistance, and restate data and IP handling for the new owner.

What has the SEC actually penalized firms for here?

In September 2019 the SEC found PwC had, across nineteen engagements involving fifteen SEC-registrant audit clients from 2013 to 2016, exercised decision-making authority in designing and configuring governance, risk and compliance software used to monitor controls over financial reporting. PwC paid disgorgement and penalties of nearly $8 million. In February 2024 Clark Schaefer Hackett settled over prohibited non-audit services to Lordstown Motors for more than $80,000.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →