Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Internal Controls & Audit

AS 2101: Audit Planning

Also known as: AS 2101, Auditing Standard No. 9, PCAOB AS 2101, Audit Planning
Simply put

AS 2101 is a PCAOB auditing standard that sets out the requirements for how an auditor should plan an audit. Its purpose is to help the auditor organize the audit so that it is carried out effectively. Planning is treated as a foundational step that precedes the detailed audit work, such as assessing risk and considering materiality.

Formal definition

AS 2101, titled 'Audit Planning,' is a standard issued by the Public Company Accounting Oversight Board (PCAOB) that establishes requirements regarding the planning of an audit. As stated in the standard, its objective is for the auditor to plan the audit so that the engagement is conducted appropriately. Within the PCAOB's auditing standards, AS 2101 sits among the audit planning and risk assessment procedures and is closely related to adjacent standards, including AS 2105 (Consideration of Materiality in Planning and Performing an Audit) and AS 2110 (Identifying and Assessing Risks of Material Misstatement). The precise text, effective date, and specific requirements should be verified against the currently effective standard published by the PCAOB, as standard language may be amended over time.

Why it matters

Audit planning is the foundation on which the reliability of a public company audit rests. AS 2101 establishes the PCAOB's requirements for how an auditor organizes an engagement before detailed testing begins, and the quality of that planning shapes whether the audit is carried out effectively. When planning is thorough, the auditor is better positioned to direct effort toward the areas that matter most; when it is weak, the entire engagement can be built on flawed assumptions about where risk actually lies.

Because AS 2101 sits at the front end of the audit process, it connects directly to adjacent standards that govern materiality and risk assessment. In the PCAOB framework, planning under AS 2101 is closely related to AS 2105 (Consideration of Materiality in Planning and Performing an Audit) and AS 2110 (Identifying and Assessing Risks of Material Misstatement). Treating planning as a distinct, disciplined step helps ensure that the later work of assessing risk and applying materiality proceeds on a sound basis rather than being addressed only in hindsight.

For organizations subject to PCAOB oversight and for the audit firms that serve them, adherence to planning requirements is a matter of regulatory expectation, not merely leading practice. The precise text, effective date, and specific requirements of AS 2101 should be verified against the currently effective standard published by the PCAOB, as standard language may be amended over time.

Who it's relevant to

External Auditors of Public Companies
Auditors performing engagements subject to PCAOB standards apply AS 2101 directly, using it to structure the planning phase before detailed testing and to establish the basis for subsequent materiality and risk assessment work under AS 2105 and AS 2110.
Audit Firm Quality and Methodology Teams
Those responsible for firm-wide audit methodology and quality control rely on AS 2101 to design planning procedures and templates, and to monitor for amendments so that guidance reflects the currently effective PCAOB standard.
Audit Committees and Governance Bodies
Audit committees overseeing the external auditor benefit from understanding AS 2101 to evaluate how the auditor approaches planning, since sound planning underpins the effectiveness of the overall engagement. This is a governance oversight interest rather than a direct compliance obligation on the committee itself.
Internal Audit and Compliance Functions
Internal auditors and compliance professionals at public companies may reference AS 2101 to anticipate how the external audit will be planned and to coordinate their own work, though the standard's requirements apply to the external auditor rather than to internal functions.

Inside AS 2101

Engagement Acceptance and Continuance
AS 2101 is a PCAOB auditing standard addressing audit planning, and it establishes considerations for whether an auditor should accept or continue a client relationship and a specific audit engagement. This typically includes evaluating factors such as management integrity, the auditor's independence, and the firm's ability to perform the engagement competently. Note that specific procedural requirements should be verified against the current text of the standard as issued by the PCAOB.
Establishing an Audit Strategy
The standard generally calls for developing an overall audit strategy that sets the scope, timing, and direction of the audit. This often involves considering the reporting objectives, characteristics of the engagement, and factors significant in directing engagement team efforts.
Developing an Audit Plan
AS 2101 typically addresses the creation of an audit plan that describes the nature, timing, and extent of planned risk assessment procedures, tests of controls, and substantive procedures. The plan is generally expected to be responsive to the assessed risks of material misstatement.
Consideration of Company Risk and Complexity
Planning under this standard often takes into account the size and complexity of the company, the auditor's prior experience with the entity, and changes in circumstances that may affect the audit. This helps direct resources toward areas of greater risk.
Involvement of Engagement Team and Specialists
The standard commonly addresses the determination of the extent to which supervisory personnel, specialists, and other team members should be involved, as well as considerations where other auditors or component auditors participate. Related supervision and multi-location matters may be governed by companion standards.
Materiality Considerations in Planning
Planning typically involves establishing materiality levels used to guide the audit, though the detailed methodology for determining materiality is often addressed in a separate, related PCAOB standard. Practitioners should consult the applicable standard for specifics.

Common questions

Answers to the questions practitioners most commonly ask about AS 2101.

Does AS 2101 apply to all financial statement audits?
No. AS 2101 is an auditing standard issued by the Public Company Accounting Oversight Board (PCAOB), and its authority extends to audits of issuers and other entities subject to PCAOB standards under U.S. securities law. Audits conducted under other frameworks, such as those governed by the AICPA's standards for many private companies, or standards set by authorities in other jurisdictions, are subject to different requirements. Applicability should be confirmed against the entity's regulatory context and the standards that govern the specific engagement.
Is AS 2101 about performing the audit itself, or about something earlier in the process?
AS 2101 addresses audit planning rather than the execution of substantive procedures. It is a governance-and-process standard concerned with how the auditor establishes an overall audit strategy and develops an audit plan, including matters such as engagement staffing and consideration of risks. It should not be conflated with the standards that govern fieldwork, evidence gathering, or the auditor's ultimate reporting; those are addressed by other standards in the framework. The planning contemplated by AS 2101 is typically iterative and may be revised as the audit progresses.
When in the engagement should planning under AS 2101 begin?
Planning is generally treated as an ongoing activity that begins early, often shortly after completion or in connection with the prior period's engagement, and continues throughout the audit. Because planning is iterative, the strategy and plan are typically revisited and updated as new information emerges. Firms should confirm the specific timing expectations against the current text of the standard and any related PCAOB guidance.
What should be documented to demonstrate compliance with the planning requirements?
Auditors are generally expected to document the overall audit strategy, the audit plan, and any significant changes made to them during the engagement, along with the reasons for those changes. The specific documentation expectations should be read together with the PCAOB's audit documentation standard and the current text of AS 2101, as the precise requirements are set by those sources rather than by convention.
How does planning under AS 2101 relate to the assessment of risk?
Audit planning is typically informed by the auditor's understanding of the entity and its environment and by the consideration of risks of material misstatement, which are addressed in related risk-assessment standards. Planning and risk assessment are interconnected, so the audit strategy and plan are often shaped by, and responsive to, identified risks. Practitioners should coordinate application of AS 2101 with the associated risk-assessment standards rather than treating planning in isolation.
What role do specialists, other auditors, or engagement staffing play in planning?
Planning commonly includes determining the nature, timing, and extent of resources needed for the engagement, which can encompass the involvement of specialists, the use of other auditors or component teams, and the assignment and supervision of engagement personnel. The extent of such considerations depends on the size, complexity, and circumstances of the specific engagement. The precise requirements for supervision and for involving other parties are set out in AS 2101 and related standards, which should be consulted directly.

Common misconceptions

AS 2101 is a general governance or compliance framework that any organization can adopt.
AS 2101 is a PCAOB auditing standard applicable to audits of issuers and other entities subject to PCAOB oversight in the United States. It governs how registered public accounting firms plan financial statement audits and is not a voluntary governance or enterprise compliance framework. Its applicability depends on jurisdiction and the regulatory status of the entity being audited.
Following AS 2101 guarantees that the audit will detect all material misstatements or eliminate audit risk.
No auditing standard can guarantee detection of every misstatement. AS 2101 addresses planning intended to help the auditor obtain reasonable, not absolute, assurance. Audit risk is modified and managed through planning and procedures but is not eliminated, and inherent limitations of an audit remain.
Audit planning under AS 2101 is a one-time task completed at the start of the engagement.
Planning is typically described as a continual and iterative process rather than a discrete phase. The audit strategy and plan may be revised as the engagement progresses and as new information or changing conditions come to light.

Best practices

Perform and document engagement acceptance or continuance evaluations before significant planning, addressing independence, competence, and relevant risk factors, and verify the specific procedural requirements against the current PCAOB text.
Develop the overall audit strategy before finalizing the detailed audit plan, ensuring the plan's nature, timing, and extent of procedures are responsive to the assessed risks of material misstatement.
Tailor planning to the size, complexity, and prior history of the entity rather than applying a uniform approach, and reassess as circumstances change.
Coordinate with companion PCAOB standards on related matters such as materiality, risk assessment, supervision, and the use of specialists or other auditors, since AS 2101 operates alongside those standards.
Treat planning as an iterative process, updating the strategy and plan and documenting significant changes and the reasons for them throughout the engagement.
Maintain contemporaneous documentation of planning decisions and confirm any specific effective dates, clause references, or requirements against the authoritative PCAOB source rather than relying on memory.
Promotional banner for the Penetration Report Template Kit