Compliance / Assurance Standard
DETAIL

PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

PCAOB AS 2201, An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements, is the standard that governs how an auditor examines and reports on a public company's internal control over financial reporting (ICFR). It establishes the requirements for planning the audit, using a top-down approach to select controls, testing their design and operating effectiveness, evaluating deficiencies, and forming an opinion on whether ICFR was effective as of the company's year end.

The Public Company Accounting Oversight Board (PCAOB) adopted the standard in 2007 as Auditing Standard No. 5 through PCAOB Release No. 2007-005A, approved by the U.S. Securities and Exchange Commission, and later renumbered it AS 2201. It binds the registered public accounting firms that audit issuers subject to Section 404(b) of the Sarbanes-Oxley Act. The PCAOB has since adopted amendments to paragraph .09 and a new paragraph .99; the amended standard is effective on December 15, 2026.

Auditors apply AS 2201 by identifying the risks of material misstatement at the financial statement and assertion level, selecting entity-level controls and the controls that address those risks, testing them, and evaluating any deficiencies as control deficiencies, significant deficiencies, or material weaknesses. Companies prepare for the audit by documenting their ICFR, typically against the COSO Internal Control framework, testing their own controls, and maintaining the evidence auditors will examine.

Why it Matters

An integrated audit under AS 2201 is the independent test behind every public company's assertion that its financial reporting controls work. A material weakness reported under the standard is disclosed to investors, so the way controls are scoped, tested, and evidenced determines both the audit outcome and management's own Section 404(a) assessment.

Key benefits include:

  • One audit, two opinions

The integrated audit achieves the objectives of the financial statement audit and the ICFR audit together, so evidence gathered for one supports the other.

  • Top-down, risk-based scoping

The auditor begins at the financial statement level with the overall risks to ICFR and works down to entity-level controls and the significant accounts, disclosures, and assertions that matter, rather than testing every control.

  • A shared definition of material weakness

The standard defines material weakness and significant deficiency, giving management, auditors, and audit committees the same terms for evaluating control failures.

  • Clear expectations for entity-level controls

Controls over management override, the control environment, and the period-end financial reporting process are singled out as the ones that shape the rest of the audit.

  • Predictable reporting

Paragraphs .85 onward set out what the auditor's report must say, including when a material weakness exists, so companies know how findings will be communicated.

How it Works

AS 2201 is organized in numbered paragraphs. Planning the audit begins at paragraph .09 and covers the role of risk assessment, scaling the audit to the company, fraud risk, and using the work of others; the top-down approach begins at .21 and covers entity-level controls, significant accounts and disclosures and their relevant assertions, likely sources of misstatement, and the selection of controls to test; testing controls begins at .42 and covers the evidence needed to test design and operating effectiveness, the timing of tests, and the use of prior-year evidence; evaluating identified deficiencies begins at .62; wrapping up begins at .71 and covers management's written representations and communicating matters to management and the audit committee; and reporting on ICFR begins at .85. Appendix A defines the terms, Appendix B addresses special topics such as multiple locations and benchmarking automated controls, and Appendix C covers special reporting situations.

In practice the auditor obtains an understanding of the company's ICFR, identifies significant accounts and disclosures and their relevant assertions, walks through transactions to identify the points at which a misstatement could occur, and selects the controls that sufficiently address the assessed risk of misstatement for each assertion. The auditor tests the design and operating effectiveness of those controls with inquiry, observation, inspection, and reperformance, evaluates each deficiency for its severity, and issues an opinion. Management's own assessment, the work of internal audit, and the company's control documentation are inputs the auditor may use, subject to the standard's requirements on competence and objectivity.

Within SmartSuite, finance and compliance teams keep the ICFR control library, risk and control matrices, test plans, and evidence in one system that mirrors the AS 2201 structure: each control is linked to the accounts, assertions, and risks it addresses, tests and their results are recorded with reviewers and dates, and deficiencies are evaluated, aggregated, and tracked to remediation so the auditor's requests can be answered from the record.

Key Elements

  • Integrated audit objective

The auditor plans and performs the ICFR audit and the financial statement audit together so that evidence and conclusions from each inform the other.

  • Top-down approach

Scoping starts at the financial statement level and the overall risks to ICFR, moves to entity-level controls, and then to significant accounts, disclosures, and relevant assertions.

  • Entity-level controls

Controls related to the control environment, management override, and the period-end financial reporting process are evaluated because they affect the extent of testing elsewhere.

  • Testing design and operating effectiveness

Selected controls are tested to determine whether they are designed to prevent or detect material misstatements and whether they operated as designed during the period.

  • Evaluation of deficiencies

Each deficiency is assessed for severity, individually and in combination, to determine whether it is a material weakness.

  • Material weakness definition

A material weakness is a deficiency, or a combination of deficiencies, such that there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis.

  • Reporting on ICFR

The auditor's report expresses an opinion on the effectiveness of ICFR as of the year end and describes any material weakness identified.

Framework Scope

AS 2201 applies to audits of internal control over financial reporting performed by PCAOB-registered firms for issuers whose auditors must attest to ICFR under Section 404(b) of the Sarbanes-Oxley Act. It governs the auditor's work, not management's; management's assessment is addressed by SEC rules, though companies use the standard's definitions and top-down approach to organize their own testing. Smaller reporting companies and emerging growth companies exempt from Section 404(b) are outside its reach unless they obtain an ICFR audit voluntarily.

Framework Objectives

The standard exists so that an auditor can form and report an opinion on the effectiveness of a company's internal control over financial reporting.

Integrate the audit of internal control with the audit of the financial statements so that each supports the other.

Focus audit effort on the controls that address the risk of material misstatement through a top-down, risk-based approach.

Obtain sufficient evidence about the design and operating effectiveness of selected controls.

Evaluate identified deficiencies consistently against the definitions of significant deficiency and material weakness.

Communicate deficiencies to management and the audit committee and obtain management's written representations.

Report clearly to investors on whether ICFR was effective as of the year end.

Framework in Context

AS 2201 operates within the Sarbanes-Oxley Act's Section 404 regime, in which management assesses ICFR and the auditor attests to it, and it relies on a suitable control framework such as the COSO Internal Control – Integrated Framework (2013) as the criteria for that assessment. It connects to other PCAOB standards including AS 1000 on the auditor's general responsibilities, AS 2110 on identifying and assessing risks of material misstatement, AS 2605 on using the work of internal auditors, AS 2801 on subsequent events, AS 2805 on management representations, AS 2905 on subsequent discovery of facts, and AS 4105 on reviews of interim financial information. Service organization reports under SOC 1 and ISAE 3402 supply evidence about outsourced controls, and COBIT 2019 is often used to structure the IT general controls the audit examines.

Common Framework Mappings

AS 2201 is commonly mapped to the law that requires the ICFR audit, the control framework used as its criteria, and the assurance standards that supply evidence about outsourced and IT controls.

Mapped frameworks include:

SOX

COSO IC 2013

COSO ERM 2017

SOC 1

ISAE 3402

ISAE 3000

COBIT 2019

At a Glance
PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements
  • Classification
    Category
    Compliance / Assurance Standard
    Domain
    Financial Services Regulation
    Framework Family
    Other
  • Regulatory Context
    Type
    Standard
    Legal Instrument
    Standard
    Sector
    Cross-Sector
    Industry
    Cross-Industry
  • Region / Publisher
    Region
    North America
    Region Detail
    United States
    Publisher
    Public Company Accounting Oversight Board (PCAOB)
  • Versioning
    Version
    AS 2201 as amended (effective December 15, 2026)
    Effective Date
    December 15, 2026 (amended standard)
    Issue Date
    June 12, 2007 (PCAOB Release No. 2007-005A)
  • Adoption
    Adoption Model
    Regulatory Compliance
    Implementation Complexity
    High
  • Official Reference
License Information

License included / downloadable: Yes

AS 2201 is published free of charge on the PCAOB website, and its structure of accounts, assertions, controls, tests, and deficiencies is reflected in the platform's ICFR templates.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
PCAOB AS 2201 standard text
The current standard with its paragraphs, appendices, amendment history, and effective date.
PCAOB Auditing Standards index
The full list of PCAOB auditing standards, including the related standards AS 2201 refers to.
PCAOB staff guidance
Staff guidance and publications that support application of the auditing standards.
PCAOB Release No. 2007-005A
The 2007 adopting release for Auditing Standard No. 5, the standard now designated AS 2201.
SMARTSUITE

How SmartSuite Supports PCAOB AS 2201

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For PCAOB AS 2201, SmartSuite organizes the ICFR control library by significant account and assertion, records design and operating-effectiveness tests with evidence, and evaluates and tracks deficiencies so management's assessment and the auditor's requests draw on one record.

ICFR Control Library

Hold entity-level, process, and IT general controls with their linked accounts, assertions, and risks in one risk and control matrix.

Ownership, Cadence, and Accountability

Assign control owners and testing cycles, and route sign-offs and management representations through approval workflows.

Evidence Collection and Audit Trail

Attach walkthroughs, samples, screenshots, and reperformance results to each test with timestamps and reviewers for the external auditor.

Control Testing and Operating Effectiveness

Plan design and operating tests, record exceptions, and roll results forward across interim and year-end periods.

Risk and Third-Party Alignment

Link controls to fraud risks, SOC 1 reports from service organizations, and complementary user entity controls.

Deficiency and Audit Committee Reporting

Evaluate deficiencies individually and in aggregate, track remediation, and report status to management and the audit committee.

Related frameworks

SOX

The Sarbanes-Oxley Act requires public companies to maintain reliable financial reporting and robust internal controls to prevent fraud.

COSO IC 2013

COSO ICFR guides organizations in designing and evaluating internal controls to ensure reliable financial reporting and regulatory compliance.

COSO ERM 2017

COSO ERM is a framework that helps organizations identify, assess, manage, and monitor enterprise risks to achieve objectives.

SOC 1

SOC 1 provides assurance about the design and operating effectiveness of controls affecting clients' financial statements.

ISAE 3402

ISAE 3402 provides assurance on service organizations' internal controls relevant to clients' financial reporting and risk management.

ISAE 3000

ISAE 3000 is an international assurance standard for independent assessments of nonfinancial information, internal controls, risk management, and compliance.

COBIT 2019

COBIT 2019 is a governance framework that helps organizations govern and manage IT to meet business goals, risks, and compliance.

ONBOARDING FAQS

Frequently Asked Questions For PCAOB AS 2201

What is PCAOB AS 2201?

AS 2201 is the PCAOB auditing standard for an audit of internal control over financial reporting that is integrated with an audit of the financial statements. It sets out how the auditor plans the audit, selects and tests controls, evaluates deficiencies, and reports an opinion on ICFR.

Who must comply with AS 2201?

The standard binds PCAOB-registered public accounting firms auditing issuers whose ICFR must be attested under Section 404(b) of the Sarbanes-Oxley Act. Companies are not directly bound, but their control documentation, testing, and evidence are what the auditor examines.

What is the top-down approach?

The auditor begins at the financial statement level with the overall risks to ICFR, evaluates entity-level controls, identifies significant accounts, disclosures, and relevant assertions, and then selects for testing the controls that sufficiently address the assessed risk of misstatement for each assertion.

How does AS 2201 define a material weakness?

A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting such that there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis.

When was AS 2201 adopted and what has changed?

The PCAOB adopted it in 2007 as Auditing Standard No. 5 through Release No. 2007-005A and later renumbered it AS 2201. Amendments to paragraph .09 and a new paragraph .99, adopted by the PCAOB and approved by the SEC, are effective on December 15, 2026.

What control framework is used as the criteria?

AS 2201 requires a suitable, recognized control framework; in the United States that is almost always the COSO Internal Control – Integrated Framework (2013), which management also uses for its own Section 404(a) assessment.

How does SmartSuite support AS 2201?

SmartSuite keeps the ICFR control library, risk and control matrices, test plans, evidence, and deficiency evaluations in one workspace, so management's testing is documented in the form the integrated audit requires and auditor requests can be answered from the record.

Operationalize PCAOB AS 2201 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.