IN BRIEF

This article explores the ethical implications of the Boeing 737 MAX crashes through the lens of the AICPA Code of Professional Conduct. It examines the implications of an internal control environment that is not operating as intended, missing the mark of establishing an ethical tone at the top. Integrity is a key issue in the Boeing case due to disclosures that were either omitted or misleading about the manufacturing process of the planes and their safety. It is important to analyze the decisions made in the Boeing case, focusing on the culture of the company, operational problems, and COSO requirements. The Boeing case presents many accounting and professional practice issues of interest to students and practitioners alike.

***

It is important to view the ethical implications of the Boeing 737 MAX crashes—previously covered by the authors in “The Story of Boeing’s Failed Corporate Culture: Putting Profits Ahead of Safety,” The CPA Journal, March/April 2025, https://tinyurl.com/mrxnxaj7—through the lens of the AICPA Code of Professional Conduct, with a focus on learning from the operational problems in order to improve internal control structures. Boeing made changes to its 737 fleet to be larger and more fuel efficient but did not adequately train pilots and seek approval of the Federal Aviation Administration (FAA). These accidents were caused by the faulty flight control software, Maneuvering Characteristics Augmentation System (MCAS), that led to the worldwide grounding of the 737 MAX fleet.

The authors’ conclusion in the prior article—that Boeing put profits ahead of safety—can be expanded by examining the implications of the way Boeing handled the crashes and what lessons can be learned by CPAs and other accounting professionals. The AICPA Code and Boeing’s own code can be utilized to analyze Boeing’s response to the ordeal. The actions taken by the company in light of its corporate culture and the decisions made by top management officials from the perspective of ethical leadership are crucial to an analysis of this situation.

Even though it was obvious (to these authors at least) that Boeing violated ethical standards, the US Justice Department announced on May 23, 2025, that it had struck a deal in principle with Boeing that would allow it to avoid prosecution in a fraud case stemming from two fatal 737 MAX plane crashes that killed 346 people, after a federal judge in Texas granted the government’s request to dismiss the case.

Background

The culture at Boeing was such that decisions could be made without important input from stakeholders. Boeing’s management was driven to accelerate production in order to compete with the European Airbus A320. Communication with the auditors was inadequate, making it difficult to inform the stakeholders about flaws in the production process and related safety concerns.

The authors’ objective is to address the implications of the Boeing tragedy in the context of the AICPA Code, to review obligations for CPAs in practice, auditors, controllers, CFOs, and audit committee members. The code provides expectations of integrity, due care, transparency, and acting in the public interest. This article includes recommendations for CPAs and other accounting professionals to help them apply the lessons learned from the Boeing experience to problems that may be faced when corporate governance systems fail.

The Boeing case shows how weaknesses in the internal control environment can lead to failures of internal controls and risk assessment. Moreover, the audit committee did not live up to its responsibilities, thereby compromising communications with the external auditors. The company did not heed the warnings of whistleblowers, hoping instead that the defects in the manufacturing process would not cause operational issues. The problems with the 737 MAX planes were exacerbated by a lack of training for the pilots. The end result was two major crashes that caused the death of 346 passengers and crew.

This article analyzes the steps taken by Boeing, focusing on the internal control environment, internal quality controls, and the audit committee. The Boeing case raises important issues for CPAs when the culture of an organization fails to support ethical decision making. The authors aim to provide guidance for professionals who might face similar challenges in the workplace.

The AICPA Code of Professional Conduct

The AICPA Code provides a framework to evaluate the ethics of decision-making by CPAs, both internal and external. Thus, it can serve as a model framework within which the actions and decisions made by Boeing management can be evaluated in terms of its effects on internal accountants and external auditors.

The AICPA Code exists to protect the public interest and maintain trust in the profession by requiring CPAs to act with integrity, objectivity, independence, competence, and due care. The Code recognizes the profession’s responsibilities to the public, to clients, and to colleagues, guiding members in the performance of their professional responsibilities. Applying the AICPA Code to the Boeing case helps one evaluate the responsibilities of top management once they became aware of the problems with the 737 MAX planes, and aids in evaluating whether they were held accountable for their actions.

A distinguishing mark of the accounting profession is its acceptance of its responsibility to the public. The public consists of a variety of stakeholders, including clients, creditors, employers, investors, governments, and the business and financial community. The public interest is defined as the collective well-being of the community of people and institutions that the profession serves. CPAs should accept their obligation to act in a way that serves the public interest, honors the public trust, and demonstrates a commitment to professionalism. The AICPA Code provides a useful perspective to consider why the actions of Boeing management did not serve the public interest.

The backbone of the accounting profession is integrity. Integrity requires a CPA to be honest and candid, within the constraints of client confidentiality, and not subordinate the public trust for personal gain. Integrity is measured in terms of what is right and just, and the observation of both the form and the spirit of professional standards. To do any less would mean subordinating one’s judgment to another party. People with integrity act out of principle, not to promote their own self-interest. Simply stated, making decisions with integrity builds confidence that such decisions, as well as the decision-maker, can be relied on. Integrity is an important issue in the Boeing case because disclosures were omitted or misleading about the manufacturing process of the 737 MAX planes and their safety.

Looking at internal accounting issues, the controller and CFO should provide information to stakeholders that is complete, objective, and transparent, even if such disclosures are unfavorable to the organization. In the case of Boeing, concerns about safety risks were not acted upon by management, instead hoping that they would not become a problem down the road. When a management team selectively discloses information or frames it in a way that downplays known risks, they compromise the core ethical requirement of integrity. These accounting officials should have ensured that the information provided to the stakeholders was complete and not misleading, even when that disclosure was unfavorable. They should not have subordinated professional judgment to commercial pressure, such as that which existed because of competition with the European Airbus A320 plane and should have always been cognizant of professional consequences that undermine trust because public communications were downright false or misleading.

Boeing’s Code of Conduct

According to its code of conduct, Boeing’s ethical principles center on core values like safety and quality, integrity, transparency, accountability, and respect. These are consistent with responsibility for one’s actions and acting in accordance with principles in the AICPA Code such as “Due Care and Integrity.” Boeing’s code outlines expected behaviors for all employees and includes the following provisions most related to its responsibility to the stakeholders:

  • Complying with all applicable laws, rules, and regulations
  • Prioritizing safety, quality, and integrity above profit
  • Acting transparently in dealings with regulators, employees, and customers
  • Being respectful of colleagues and not tolerant of harassment
  • Supporting an inclusive environment
  • Protecting Boeing proprietary information and not seeking personal gain
  • Reporting illegal, improper, or unethical conduct to management or through appropriate channels
  • Avoiding retaliation or punishing anyone who speaks up to report a concern (https://tinyurl.com/44bdh5pr).

Most of Boeing’s code provisions were not followed with respect to the 737 MAX planes, including failing to comply with FAA safety standards; prioritizing profit over safety; lack of transparency in dealing with regulators; and retaliating against whistleblowers. In addition, the company did not act on reports of defective parts. Quality controls were ignored or went unreported.

The Ethical Business Conduct Guidelines (https://scribd.com/document/68135511/Boeing-Ethical-Business-Conduct-Guidelines) state that accountability is a shared responsibility, creating an environment of openness and transparency, demonstrating leadership, and developing ethical decision-making skills. They also provide examples of issues related to the culture at Boeing, including fair and impartial treatment of others; integrity in dealing with stakeholders; upholding the company’s reputation; and disclosing only that information which has been approved.

The guidelines also address issues related to competence and diligence, which are the foundations of the Due Care standard in the AICPA Code. One issue is particularly relevant to CPAs and professional accountants in business: whether Boeing, or any company, conducts business fairly, impartially, in an ethical manner, and in full compliance with applicable laws and regulations.

Boeing’s Culture

The systemic problems at Boeing were linked to another culture––a corporate cost-cutting one––that former CEO and Board Chairman Dennis Muilenburg seemed proud of (Rekha Basu, “Ex-Boeing CEO Favored Corporate Interests over Safety, Just Like His Home State of Iowa,” AOL Online, July 21, 2024, https://tinyurl.com/4768y4tr).

Boeing claimed to have a “speak-up” culture that may have motivated at least two employees to inform top management of design defects, but the company did not support them in their efforts to correct the problem. John Barnett worked in quality control and reported safety and quality control issues to Boeing and the FAA. Boeing’s own internal investigation corroborated his complaints, and the FAA ordered remedial action to correct the defects. Barnett subsequently filed a whistleblower complaint alleging he was harassed, intimidated, and forced into early retirement in 2017. He brought a whistleblower’s lawsuit alleging that the company prioritized production speed over safety and installation of substandard parts. His lawsuit, initiated under the Wendell H. Ford Aviation Investment and Reform Act for the 21st Century whistleblower protections (often cited alongside SOX in corporate retaliation cases), was in litigation for seven years prior to his death. Barnett was found dead in March 2024, before testifying, from a self-inflicted gunshot wound (Koh Ewe, “Boeing Whistleblower John Barnett Found Dead Amid Depositions Against Plane Company,” Time, Mar. 12, 2024, https://tinyurl.com/2jdexnm4).

In a US Senate Hearing of the Homeland Security and Governmental Affairs Committee on April 17, 2024, Boeing Quality Engineer Sam Salehpour testified that he had been threatened for raising concerns about gaps between key sections of the 787 Dreamliner aircraft. He mentioned serious concerns, stating: “Despite what Boeing officials state publicly, there is no safety culture at Boeing and employees like me who speak up about defects with its production activities and lack of quality control are ignored, marginalized, threatened, sidelined, and worse” (G. Benitwz et al., “Boeing Safety Culture Under Scrutiny During Senate Committee Hearing,” ABC News, April 17, 2024, https://tinyurl.com/4ad864w3).

Boeing is a perfect example of a company that did not follow their own ethical standards. The culture of a company is negatively affected when its own rules are ignored, and employees who try to do the right thing are punished for it. The Exhibit analyzes what Boeing should have done about the quality control issues (as discussed below) as well as what it did. The difference shows a failure of management and leadership.

EXHIBIT

Evaluating Quality Control Issues at Boeing

 What Boeing Should Have Done; What Boeing Did Prioritized quality, safety, and integrity above profit; Placed profits ahead of safety Assessed how decisions might affect stakeholders; Placed their own interests ahead of those of the stakeholders Fulfilled duties and obligations to others, especially the flying public; Did not keep its promises about safety and transparency Disclosed problems with quality controls and safety to the FAA; Failed to report defective parts and safety concerns to the FAA in a timely manner Acted on whistleblower reports to maintain the integrity of reporting systems; Ignored whistleblower reports

Internal Quality Controls

The internal controls at a manufacturer are designed to ensure the accuracy and reliability of the manufacturing process so that production flaws are identified and corrected. Mintz and Miller point out that it appears Boeing relied mostly on FAA audits to evaluate the company’s operating activities and whether production flaws exist (2025). They conclude that “the company did not assess the internal control environment in a way that would have made a difference in creating a safe production process, or adequately evaluate whether the control systems were operating effectively, or creating a culture of safety and instituting ethical leadership.”

The audit committee maintained a singular focus on financial risks and profit, which explains why operational issues were not adequately considered.

The FAA found that Boeing passed 56 out of 89 product audits that were conducted and failed 33. An independent expert review panel identified that Boeing’s safety culture did not match its stated “foundational commitment to safety” (Chris Isadore and Gregory Wallace, “Aviation Safety Panel Finds Boeing Culture Included Safety ‘Gaps,’ Fear of Retaliation,” CNN, Feb. 26, 2024, https://tinyurl.com/3mz8j6p4).

Mintz and Miller pointed out that none of Boeing’s board of director committees were specifically assigned responsibility for overseeing airplane safety (2025). They noted several examples of where quality control issues were ignored, including the failure to implement priority safety oversight by having a board of directors committee assigned the responsibility for overseeing airplane safety.

Audit Committees

In addressing the role of the audit committee in a speech before the University of Tennessee’s C. Warren Neel Corporate Governance Center, former SEC Chief Accountant Wesley R. Bricker stated that “audit committees play a critical role in contributing to financial statement credibility through their oversight and resulting impact on the integrity of a company’s culture and internal control over financial reporting (ICFR), the quality of financial reporting, and the quality of audits performed on behalf of investors” (“Advancing the Role and Effectiveness of Audit Committees” Mar. 24, 2017, https://tinyurl.com/ybz7bhuf).

The audit committee at Boeing was charged with overseeing risk, but it never examined or even considered airplane safety. The audit committee maintained a singular focus on financial risks and profit, which explains why operational issues were not adequately considered. Safety issues were primarily left to the FAA’s purview.

Sarbanes-Oxley Act

The Sarbanes-Oxley Act (SOX) establishes additional responsibilities for CPAs, including:

  • Strengthening the role of the audit committee;
  • Increased visibility of the audit committee and its responsibilities to investors and other stakeholders;
  • Strengthening the relationship between the audit committee and the independent auditors; and
  • Enhancements to audit committee independence (https://tinyurl.com/bder53z3).

Section 404 of SOX directs the SEC to require annual reports to include an internal control report, which establishes management’s responsibility for maintaining adequate internal control mechanisms for financial reporting and evaluates the efficacy of such mechanisms for financial reporting. It also requires the public accounting firm responsible for the audit report to attest to and report on the assessment made by the issuer. There are no indications that these SOX requirements were met at Boeing. Its failure to do so would certainly account for some of the problems controlling production flaws.

Communications with Audit Committees

CPAs should be cognizant of the communications required under the PCAOB’s AS 1301, “Communications with Audit Committees,” (https://tinyurl.com/ycxxuyd2). One such communication occurs when the auditor provides the audit committee with timely observations arising from the audit that are significant to the financial reporting process, something that would have been important for Boeing’s audit committee to know.

The audit committee is responsible for the integrity of the financial statements, which would include all disclosures necessary to ensure the statements are not materially misleading. The audit committee was responsible for ensuring compliance with safety and quality standards within Boeing, including safety regulations and compliance issues. Boeing’s audit committee does not seem to have had the communications necessary under AS 1301 to ensure that operational and financial reporting issues were properly addressed.

Enterprise Risk Management

Enterprise risk management (ERM) is a structured approach for identifying, assessing, and managing risks that could affect an organization’s ability to achieve its objectives. One such framework that guides ERM implementation is the Committee of Sponsoring Organizations of the Treadway Commission (COSO) internal control environment framework, which is discussed in the next section.

Boeing’s ERM process primarily focused on production and financial risk. It is noteworthy that as far back as Jan. 6, 2020, Internal Audit 360 reported that an internal audit conducted by Boeing in December 2019, at the urging of regulators, identified new safety issues with the 737 MAX, but nothing was done about it (“Internal Audit Identifies New Issues with Boeing’s 737 MAX,” Internal Audit 360, Jan. 6, 2020, https://tinyurl.com/bdhd574a). Moreover, Boeing’s board never learned about any employee or whistleblower safety complaints prior to the crashes. One possible reason is that the internal control environment did not live up to its expectations to establish an ethical culture. Besides, the audit committee did not adequately oversee the ERM process by assessing risk management.

The Boeing 737 MAX scandal is a situation where the board of directors did not carefully monitor safety before the crashes and did not react quickly enough after the disclosure of safety problems following the two crashes. It is a lesson in what can happen when internal controls do not operate as intended, risk assessment is not carefully considered, and whistleblower complaints are ignored.

Internal Control Environment

COSO is a private sector initiative formed to investigate the fraud scandals of the 1970s and 1980s; it resulted in an internal controls framework that was released in 1992 and since updated. COSO defines internal control as “a process effected by an entity’s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.” The control environment is the set of standards, processes, and structures that provide the basis for carrying out internal control access across the organization. The board of directors and senior management establish the tone at the top regarding the importance of internal control including expected standards of conduct (J. Stephen McNally, “The 2013 COSO Framework & SOX Compliance,” Strategic Finance, June 2013, https://www.sechistorical.org/collection/papers/2010/2013_0601_COSOMcNally.pdf).

The COSO Framework consists of five interrelated elements that provide a comprehensive approach to handling an organization’s operational challenges, which are the control environment, risk assessment, control activities, information and communication, and monitoring. By evaluating the relevant components of the framework, organizations decrease the risk of non-compliance, grievances, legal disputes, and other issues that create a negative impact. Moreover, ethical decisions are more likely to occur, and accountability to be enforced (Deb Muller, “What Is the COSO Framework? A Guide for Employee Relations & HR Professionals,” HR Acuity, Feb. 20, 2026, https://tinyurl.com/5cjz7vrf).

COSO’s framework is designed to enhance organizational governance and risk management. Had Boeing instituted such a framework and its related components, it is quite possible that the risks associated with the 737 MAX planes could have been abated. The Exhibit provides additional insight into these issues.

Implications

It is crucial to analyze how Boeing prioritized cost-cutting and profitability above establishing a safety-first culture. Boeing did not follow its own code of conduct, choosing instead to let commercial interests drive decision making. The company ignored design defects— perhaps they thought that the manufacturing defects would not create operational problems. Even when design defects became known, Boeing downplayed them rather than accepting responsibility and holding themselves accountable, a crucial step in ethical behavior. Furthermore, whistleblowers, such as John Barnett and Sam Salehpour, were ignored, which raised doubts about the efficacy of the speak-up culture. Retaliation against the whistleblowers only served to create doubt as to whether production employees would feel comfortable informing management about defects. Boeing seemed to rely too much on FAA audits to identify problem areas, rather than rely on their own internal auditors supported by a strong set of internal controls and backed by the audit committee.

The Boeing case can be used as a “teachable moment” in virtually all accounting courses. The overriding issues are the ethics of the internal control environment, including risk assessment, internal controls, and the corporate culture; internal financial reporting, and the audit committee; the speak up culture; whistleblowing and retaliation; cost-cutting and profitability versus a safety culture; a culture of compliance; and looking for and acting on red flags. These and other issues have been examined in the context of professional practice by CPAs and other accounting professionals.

Lapses in ethical judgment by superiors can destroy trust and lead to the subordination of judgment, as Boeing discovered. When differences of opinion exist on handling operational problems, disclosures, and financial reporting matters, CPAs should rely on the AICPA Code, COSO guidelines, ERM recommendations, as well as the company’s code of ethics. The fact that Boeing lacked an active and involved audit committee meant too much power and influence was placed in the hands of top management, Dennis Muilenburg.

A lack of integrity and transparency may increase regulatory and legal exposures. Safety and compliance failures are often underestimated, leading to increased financial burdens. Lapses in ethical judgment destroy trust and cause costly reputational damage that is often difficult to rebuild, as occurred with Boeing.

There are many lessons one can learn from the Boeing tragedy. First and foremost, the “tone at the top” and ethical culture are not just abstract terms. CPAs should evaluate whether corporate leaders consistently demonstrate integrity, ethical values, and a commitment to competence and due care. If they do not, more attention should be given to the review of the internal control environment.

The authors recommend that organizations make improvements that align with COSO principles on governance, ethics, and risk management. For example, under SOX, public organizations must maintain secure and confidential channels for reporting concerns. Although Boeing employees voiced concerns, they were not taken seriously; often they were ignored. CPAs could aid in the evaluation of the design and effectiveness of whistleblower programs. It is important that organizations ensure timely investigation of all complaints, maintain confidentiality, and prevent retaliation. Organizations should act to improve periodic assessments of hotline trends, control failures, and systemic risk factors.

Audit committees often rely on both internal and external CPAs to satisfy governance and oversight duties. The authors suggest companies improve the accuracy and timeliness of reporting to the audit committee when violations occur. Management should be committed to providing complete and non-misleading information, even when disclosure is unfavorable.

The suggestions provided above and in the accompanying sidebar, Key Takeaways, can be integrated into companies’ operational and reporting systems. Had Boeing been sensitive to these issues in its decision-making process, the decisions they made regarding the safety of the planes might have met expected standards of behavior. In that way, Boeing would have done what was expected of it.

737 MAX: Key Events Timeline (2018–2025)

  • Oct. 29, 2018—Lion Air Flight 610 (737 MAX) crashes in Indonesia, killing 189 people.
  • Mar. 10, 2019—Ethiopian Airlines Flight 302 (737 MAX) crashes, killing 157 people (346 total fatalities).
  • Mar. 2019—All 737 MAX aircraft are grounded following the second crash.
  • Jan. 7, 2021—The DOJ charges Boeing with conspiracy to defraud the FAA; Boeing enters a Deferred Prosecution Agreement (DPA) with penalties and victim compensation.
  • Sept. 22, 2022—The SEC finds that Boeing and former CEO Dennis Muilenburg misled investors about MCAS; Boeing pays $200M, Muilenburg $1M, and a Fair Fund is created.
  • Dec. 5, 2024—Federal judge rejects Boeing’s proposed guilty plea tied to violation of the DPA.
  • May 26, 2025—DOJ and Boeing reach a Non-Prosecution Agreement (NPA) dismissing the felony charge; Boeing agrees to pay $1.1 billion in fines and compensation.
  • Nov. 6, 2025—Judge Reed O’Connor approves dismissal of the criminal case, stating it fails to ensure accountability and safety of the flying public (Reuters, “Boeing Ordered to Pay More than $28 million to 737 MAX Crash Victim’s family,” NBC News, Nov. 12, 2025, https://tinyurl.com/35e77m8n).
  • Nov. 2025—Boeing ordered to pay $28 million (later $35.85 million with interest) to the family of Shikha Garg, the first jury verdict among 737 MAX civil cases.
  • Mar. 31, 2026—Boeing’s breach of the 2024 DPA meant that the agreement “no longer bound the contracting parties and any challenge based on its terms became moot.”

Key Takeaways

  • “Tone at the top” directly affects ethical culture and control effectiveness.
  • Strong internal controls and independent internal audit functions must not be outsourced—implicitly or explicitly—to regulators.
  • Whistleblower programs must be more than symbolic; responsiveness and protection from retaliation are essential.
  • Audit committees play a critical role in preventing excessive concentration of power in senior management.
  • Ethical lapses can evolve into material financial, legal, and reputational risks if left unaddressed.

Recommendations for CPAs

  • Properly document any internal control deficiencies, safety, and ethical concerns.
  • Identify observations, scope, policies, and regulations, that the issue relates to.
  • Retain copies of key emails, analyses, and workpapers in accordance with policy.
  • Document and discuss all concerns with the appropriate management level.
  • If no corrective action is taken, a CPA should use the appropriate reporting channel and escalate the concern to the next level of management, consistent with company policy and the AICPA Code of Conduct.
  • Report concerns to the organization’s ethics hotline and the audit committee.

Recommendations for CFOs and Controllers

  • Ensure that financial and operational performance metrics do not incentivize unsafe or unethical behavior.
  • Promote transparency and candor in internal and external reporting, particularly when disclosures may be unfavorable.
  • Reinforce compliance with the organization’s code of conduct and ethical standards through consistent actions, not just policies.
  • Support effective escalation mechanisms for safety, compliance, and internal control-related concerns.

Recommendations for Internal Auditors

  • Maintain independence and objectivity when evaluating safety-related controls, compliance risks, and cultural indicators.
  • Assess the design and operating effectiveness of internal controls related to safety, quality, and regulatory compliance.
  • Evaluate whistleblower and hotline programs for timeliness and confidentiality, as well as retaliation risk.
  • Report significant control failures and emerging risks promptly to the audit committee.

Recommendations for the Audit Committee/Board of Directors

  • Actively oversee management’s handling of safety, compliance, and ethical risk.
  • Ensure internal audit has sufficient authority, resources, and direct access to the audit committee.
  • Demand complete, accurate, and transparent information from management, even when issues reflect poorly on leadership.
  • Regularly assess whether management’s actions align with the organization’s stated values and risk tolerance.

Recommendations for External Auditors

  • Exercise professional skepticism when management emphasizes cost reductions that may affect safety or compliance.
  • Consider whether weaknesses in ethical culture or internal controls could have broader financial reporting implications.
  • Communicate significant concerns regarding governance, control environment, or management integrity directly to the audit committee.

Compliance/ERM

  • Integrate safety, ethics, and compliance risks into enterprise-wide risk assessments.
  • Conduct periodic analysis of hotline data, compliance trends, and systemic control weaknesses.
  • Ensure alignment with COSO principles on governance, ethics, and risk management.
  • Monitor retaliation risks and ensure prompt corrective actions are taken when deficiencies are identified.
Steven M. Mintz, PhD, is a professor emeritus of accounting at California Polytechnic State University, San Luis Obispo, Calif.
William F. Miller CPA, CGMA, is a professor emeritus of accounting at University of Wisconsin–Eau Claire.
Tara J. Shawver, DBA, CMA, is a professor of accounting at King’s College, Wilkes-Barre, Pa.