CrowdStrike: Can You Trust the Annual Recurring Revenue Numbers?
Audit Committee concerns and ongoing SEC/DOJ investigations raise questions
CrowdStrike Holdings, Inc. – CRWD $191.95 US Mkt Cap: $ 195.5 B
Click here a PDF version of today's report
Summary and Opinion:
With the stock of CrowdStrike up over 100% since spring, the Street’s been giddy with delight over reported growth in Annual Recurring Revenue (ARR) – now one of the central pillars of the CrowdStrike investment narrative. Non-believers are few. We are one of them. In our opinion, the Disclosure Games we cite here, along with governance concerns we found involving the Audit Committee, suggest you cannot trust the ARR story without closer scrutiny. Let’s have a look.
Through clever wordsmithing and use of a term most investors never use in their day-to-day, we contend CrowdStrike was successful in keeping investors from focusing on what we view as serious SEC/DOJ accounting investigations. They involve CrowdStrike’s revenue recognition “and reporting of ARR for transactions with certain customers.”
In today’s report we first speak to our concerns about the Audit Committee, with focus on the following:
- CrowdStrike’s otherwise highly qualified Audit Chair has so many commitments outside of this one that it appears she is spread too thin. The audit committee chair is one of the most demanding roles on any public company board. A company facing dual SEC/DOJ accounting investigations places even more time demands on top of this. We will show you the robust portfolio of board roles this Chair has outside of CrowdStrike, letting you decide for yourself.
- The company Chairman sits on the Audit Committee. We explain why this is less-than-ideal for good governance, especially with ongoing SEC/DOJ probes.
- We found a recent and quiet departure of an Audit Committee member who was in the role since 2017. He was not replaced on the board. Total board size is now reduced, from 9 to 8 current members.
Later, we will show you where we believe CrowdStrike played – and keeps playing its Disclosure Games around its SEC/DOJ investigations. We argue these games had the effect of lulling investors into a false sense of confidence in the integrity of reported ARR numbers at CrowdStrike. At minimum, ARR requires further vetting.
The Current SEC Enforcement Environment
Before we get further into it, now is a good time to remind you that we are in an environment where the SEC is investigating far fewer companies than was the case when Trump came back into office. CrowdStrike’s investigations involve serious accounting matters. Our work suggests the SEC piece has been ongoing for at least 18 months, since Jan-2025. There is potential criminal exposure as well. This should drive home the urgency of finding out what’s really going on regarding these risks at CrowdStrike.
From DI Research
- DI’s Early Signal of SEC probe: 17-Jan-2025
- SEC probe confirmed as ongoing: 24-Apr-2025
- First disclosure of SEC probe: 04-Jun-2025
In Jun-2026, the SEC again confirmed investigative activity remained active and ongoing at CrowdStrike.
The Dual SEC/DOJ Investigations
Even though they never used these words, in Jun-2025, CrowdStrike made its first disclosure of what we recognize as SEC/DOJ investigations into revenue recognition and reporting of Annual Recurring Revenue (ARR).
As you can see above, we first knew of an undisclosed SEC probe at CrowdStrike months earlier, in Jan-2025.
Without change or update, CrowdStrike has repeated the following in every major filing since first disclosed in Jun-2025, most recently in the 10-Q filed on 04-Jun-2026.
From the CrowdStrike 10-Q filed on 04-Jun-2025:
The Company has received requests for information from the U.S. Department of Justice and the U.S. Securities and Exchange Commission relating to the Company’s recognition of revenue and reporting of ARR for transactions with certain customers, the July 19 Incident and related matters. The Company is cooperating and providing information in response to these requests.
Given how these matters usually run, we suspect this exposure is now a formal SEC investigation paired with possible criminal exposure at the DOJ.
Words Matter
The wording here deserves particular attention. We find it to be manipulative and evasive. Sleazy even. This matters because it appears the CrowdStrike stock price is increasingly driven by ARR acceleration.
We also found the wording especially creative. We cannot recall having ever heard a company refer to an SEC investigation into revenue recognition expressed as “recognition of revenue,” as was done here.
Consider this: Even with our sophisticated search strings and decades of going through SEC filings, we almost missed this. This was quite the evasive disclosure.
Have you seen analyst reports or conference calls talk about SEC/DOJ investigations into CrowdStrike’s revenue recognition and reporting of ARR for transactions with unidentified customers? If not, can you have confidence this risk has been assessed and discounted by investors?
We contend it has not.
The Audit Committee was responsible for reviewing the company’s financial disclosures, including this regulatory matter involving revenue recognition and ARR. The company’s use of the terms, “requests for information” and “recognition of revenue” is … well, it’s notable.
Later we will detail the Disclosure Games we found here. Let’s have a closer look at the Audit Committee first.
Governance / Audit Committee Concerns
The oversight responsibility of boards and directors has become increasingly complex amid changes to the political, geopolitical, and economic environment that are expanding the board agenda … Boards face these challenges with the finite resource of director time.
… annual independent director time commitment has increased from less than 250 hours to more than 300 hours over the last decade. However, there are practical limits to how much this time commitment can increase without generating questions about director independence. [emphasis added]
Source: National Association of Corporate Directors, 2025 Inside the Public Company Boardroom, April 01, 2025.
CrowdStrike’s highly qualified Audit Chair may be spread too thin.
Roxanne Austin has chaired CrowdStrike’s Audit Committee since 2018. Her financial background is impressive, with various audit positions early, at Deloitte & Touche from 1983-1993, including Audit Partner. Her reputation in the governance community is stellar.
Talent like Ms. Austin is highly sought after on public company boards. A fair concern, though, is that her current commitments both at, and outside of CrowdStrike are substantial. Quite substantial.
Here we point to the following and ongoing commitments of Ms. Austin, none of which are light engagements –
- Austin Investment Advisors, President and CEO,
Public company boards on which Ms. Austin serves:
- CrowdStrike Holdings (CRWD): Audit Committee Chair
Verizon Communications (VZ): Audit Committee Chair
AbbVie, Inc. (ABBV): Lead Independent Director
Freshworks, Inc. (FRSH): Board Chair, Nominating & Governance Chair
This is not just a busy executive – this is an extraordinarily busy one. When the issue is a potentially serious SEC/DOJ matter involving revenue recognition and ARR reporting, bandwidth of your audit chair becomes a legitimate governance concern.
In governance circles the audit committee chair is seen as one of the most demanding roles on any public company board. Ms. Austin chairs the audit committees of two large public companies – Verizon and CrowdStrike; the latter demanding even more time due to its SEC/DOJ scrutiny.
Ms. Austin is also Lead Independent Director at AbbVie, another large public company. That alone is a sizable time commitment. The cherry on this sundae is she’s also the Board Chair at Freshworks.
The independent Chairman of CrowdStrike also sits on its Audit Committee.
CrowdStrike’s Chairman of the Board, Gerhard Watzinger, is also one of only three members on its Audit Committee.
There is nothing technically wrong with that. But CrowdStrike could readily recruit qualified, independent talent to its Audit Committee. Instead, the Board Chair occupies one of just three seats on the committee responsible for independently challenging management on sensitive financial reporting and disclosure matters. This includes those disclosures we’ve criticized concerning the SEC/DOJ investigations.
A longtime Audit Committee member recently and quietly departed.
Godfrey R. Sullivan, age 72, served on CrowdStrike’s board and Audit Committee since Dec-2017. Sullivan was a Class I director, whose seat came up for renewal in 2026 along with those of Johanna Flower and Denis O’Leary.
This is where things get interesting. The Nominating & Corporate Governance Committee renominated Flower and O’Leary, but not Sullivan. Absent the nomination, his term expired following the 17-Jun-2026 annual meeting. This reduced the board from nine directors to eight. Director Cary Davis subsequently joined the Audit Committee.
Why was Sullivan not renominated, and why was there no contemporaneous explanation for the departure of a long-serving Audit Committee member?
CrowdStrike’s Disclosure Games
“Disclosure Games®” is a term we use to highlight those public companies engaging in disclosure practices that in our opinion may be misleading, confusing, evasive, or otherwise lacking the transparency needed for investors to make well-informed investment decisions regarding a potentially material exposure. For reasons outlined in this report, we have identified CrowdStrike as a company playing Disclosure Games.
We now examine the Disclosure Games we assert CrowdStrike played regarding its SEC/DOJ investigations involving one of the most widely followed metrics of the company.
Disclosure Game #1
“The Company has received requests for information”
Note the absence of the words investors commonly recognize as indicative of a company disclosing an investigation, such as inquiry, probe, investigation, formal, informal, or subpoena.
Instead of telling you they were under investigation by the SEC and DOJ, CrowdStrike gave us the more soothing expression, “The Company has received requests for information.” We’ve seen this game before. It’s evasive.
Here’s what’s missing from this disclosure today:
- When were the first “requests for information”?
When did you last receive a “request for information”?
What information has been requested?
Who requested it?
Were subpoenas involved?
Have there been more requests over time?
Have the matters at issue expanded?
Disclosure Game #2:
“recognition of revenue and reporting of ARR for transactions with certain customers”
Every accountant, every analyst, routinely uses the term, “revenue recognition.” CrowdStrike itself says revenue recognition throughout their filings.
Yet here, just once in each filing in which it appears, when the company is telling you about a serious accounting exposure, CrowdStrike uses the more awkward term, “recognition of revenue.” It’s not just evasive. It’s also where the word ‘sleazy’ enters the chat. It’s not hard to imagine this is catnip for the plaintiff’s bar.
You can also drive a truck through that word lawyers love – certain; as in “certain customers.”
Here’s what’s missing from this disclosure today:
- The best practice here is to call this a revenue recognition matter and not play these word games that make the exposure hard to find.
Those “certain customers” are never named, nor is the scale of the exposure quantified.
Who are these customers?
How big is the exposure?
The initial disclosure has been repeated verbatim, not updated, since first disclosed in Jun-2025. As such, we also cannot tell if the exposure expanded, went beyond “certain customers”, or even into other accounting areas.
Closing Thoughts
Revenue recognition has historically been one of the leading causes of restatements. Yet each quarter, since the SEC/DOJ investigations into revenue recognition were first disclosed in Jun-2025, CrowdStrike assured us “our disclosure controls and procedures were effective.”
This is worth watching.
We also note the lack of discussion regarding what, if any, outside resources the Board and Audit Committee have brought in to help with these investigations. Often, we will hear that forensic accountants or outside law firms have been brought in.
This is worth asking about.
– John P. Gavin, CFA, NACD.DC