AS 2201
AS 2201 is an auditing standard issued by the Public Company Accounting Oversight Board (PCAOB) that sets out how an external auditor should audit a company's internal controls over financial reporting. It applies when an auditor is engaged to evaluate management's assessment of those controls, and it is designed to be carried out together with the audit of the company's financial statements. In practice it helps provide assurance that a company's financial reporting controls are working as intended, though it does not by itself guarantee that all misstatements will be prevented or detected.
AS 2201, titled 'An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements,' is a PCAOB auditing standard establishing requirements and direction for auditors engaged to perform an audit of internal control over financial reporting (ICFR) integrated with the financial statement audit. Per the evidence, it applies when an auditor is engaged to audit management's assessment of ICFR, and it references management's responsibility for maintaining effective internal control along with a definition of ICFR. The standard also establishes objectives that the auditor should achieve to understand likely sources of potential misstatements, and it interacts with related PCAOB standards such as AS 2110 (Identifying and Assessing Risks of Material Misstatement). Specific procedural requirements, applicability thresholds, and the interplay with SEC registration should be verified against the primary standard text, as those details are not fully established in the evidence provided.
Why it matters
AS 2201 sits at the intersection of external assurance and internal governance because it governs how an auditor evaluates whether a company's internal controls over financial reporting (ICFR) are functioning as intended. For public companies, the reliability of financial statements depends not only on the numbers themselves but on the control environment that produces them. By integrating the ICFR audit with the financial statement audit, the standard is designed to give investors, audit committees, and regulators a more coherent basis for trusting reported financial information, while recognizing that no audit can guarantee that every misstatement will be prevented or detected.
For governance and compliance professionals, AS 2201 shapes the expectations placed on management, since the standard references management's responsibility for maintaining effective internal control and relies on a defined concept of ICFR. This creates a chain of accountability: management designs and maintains controls, management assesses their effectiveness, and the external auditor tests that assessment. Weaknesses identified through this process can signal deeper issues in a company's financial reporting discipline and often prompt remediation efforts overseen by the board or audit committee.
Because AS 2201 establishes objectives the auditor should achieve to understand likely sources of potential misstatements, it also connects to the broader risk-assessment work described in related PCAOB standards such as AS 2110. The precise procedural requirements, applicability thresholds, and interaction with SEC registration should be verified against the primary standard text and relevant regulations, as those specifics fall outside what can be stated reliably here and can vary with the facts of a given engagement.
Who it's relevant to
Inside AS 2201
Common questions
Answers to the questions practitioners most commonly ask about AS 2201.

