Skip to main content
Promotional banner for the pentest readiness checklist
Category: Internal Controls & Audit

AS 2201

Also known as: An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements
Simply put

AS 2201 is an auditing standard issued by the Public Company Accounting Oversight Board (PCAOB) that sets out how an external auditor should audit a company's internal controls over financial reporting. It applies when an auditor is engaged to evaluate management's assessment of those controls, and it is designed to be carried out together with the audit of the company's financial statements. In practice it helps provide assurance that a company's financial reporting controls are working as intended, though it does not by itself guarantee that all misstatements will be prevented or detected.

Formal definition

AS 2201, titled 'An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements,' is a PCAOB auditing standard establishing requirements and direction for auditors engaged to perform an audit of internal control over financial reporting (ICFR) integrated with the financial statement audit. Per the evidence, it applies when an auditor is engaged to audit management's assessment of ICFR, and it references management's responsibility for maintaining effective internal control along with a definition of ICFR. The standard also establishes objectives that the auditor should achieve to understand likely sources of potential misstatements, and it interacts with related PCAOB standards such as AS 2110 (Identifying and Assessing Risks of Material Misstatement). Specific procedural requirements, applicability thresholds, and the interplay with SEC registration should be verified against the primary standard text, as those details are not fully established in the evidence provided.

Why it matters

AS 2201 sits at the intersection of external assurance and internal governance because it governs how an auditor evaluates whether a company's internal controls over financial reporting (ICFR) are functioning as intended. For public companies, the reliability of financial statements depends not only on the numbers themselves but on the control environment that produces them. By integrating the ICFR audit with the financial statement audit, the standard is designed to give investors, audit committees, and regulators a more coherent basis for trusting reported financial information, while recognizing that no audit can guarantee that every misstatement will be prevented or detected.

For governance and compliance professionals, AS 2201 shapes the expectations placed on management, since the standard references management's responsibility for maintaining effective internal control and relies on a defined concept of ICFR. This creates a chain of accountability: management designs and maintains controls, management assesses their effectiveness, and the external auditor tests that assessment. Weaknesses identified through this process can signal deeper issues in a company's financial reporting discipline and often prompt remediation efforts overseen by the board or audit committee.

Because AS 2201 establishes objectives the auditor should achieve to understand likely sources of potential misstatements, it also connects to the broader risk-assessment work described in related PCAOB standards such as AS 2110. The precise procedural requirements, applicability thresholds, and interaction with SEC registration should be verified against the primary standard text and relevant regulations, as those specifics fall outside what can be stated reliably here and can vary with the facts of a given engagement.

Who it's relevant to

External auditors of public companies
Auditors engaged to evaluate management's assessment of ICFR apply AS 2201 directly, integrating the control audit with the financial statement audit and following its objectives for understanding likely sources of potential misstatements. They should work from the current standard text and related standards such as AS 2110 rather than from summaries.
Management and finance leadership
Because the standard references management's responsibility for maintaining effective internal control and for assessing ICFR, finance and accounting leaders are responsible for designing, operating, and assessing the controls that the auditor will test. Understanding AS 2201's expectations helps management prepare for the integrated audit.
Audit committees and boards
Those charged with governance oversee the ICFR process and any control deficiencies identified during the audit. AS 2201 shapes the assurance the board can expect from the external auditor, though the specific applicability to a given company depends on its regulatory status and should be confirmed.
Internal auditors and compliance officers
Internal audit and compliance functions often support management's ICFR assessment and remediation of deficiencies. Familiarity with how external auditors approach controls under AS 2201 helps align internal testing with the objectives the external auditor is required to pursue.

Inside AS 2201

Integrated Audit Approach
AS 2201 is a PCAOB auditing standard addressing an audit of internal control over financial reporting (ICFR) that is integrated with an audit of the financial statements. It contemplates that the auditor plans and performs the two audits to achieve the objectives of both simultaneously, rather than as fully separate engagements.
Internal Control Over Financial Reporting (ICFR)
The subject matter of the standard is management's system of controls designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements. AS 2201 concerns the auditor's evaluation of the design and operating effectiveness of these controls.
Top-Down Risk-Based Approach
The standard generally describes a top-down approach in which the auditor begins at the financial statement level, considers entity-level controls, and focuses attention on accounts, disclosures, and assertions that present a reasonable possibility of material misstatement, so that testing effort is directed toward areas of higher risk.
Entity-Level Controls
Controls that operate across the organization, such as the control environment, controls over management override, and the period-end financial reporting process. The standard treats the evaluation of entity-level controls as an input that can affect the nature, timing, and extent of testing of other controls.
Design and Operating Effectiveness
The auditor typically assesses both whether a control is designed effectively to prevent or detect material misstatements and whether it operated effectively over the relevant period. These are distinct evaluations addressed within the standard.
Material Weakness and Deficiency Classification
The standard distinguishes among control deficiencies by severity, including the concept of a material weakness, which is generally described as a deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement of the financial statements will not be prevented or detected on a timely basis. Classification affects the auditor's opinion on ICFR.
Auditor's Opinion on ICFR
AS 2201 addresses the auditor's expression of an opinion on the effectiveness of ICFR. This is distinct from, though integrated with, the opinion on the fairness of the financial statements themselves.

Common questions

Answers to the questions practitioners most commonly ask about AS 2201.

Does AS 2201 apply to every company's financial statement audit?
No. AS 2201, an auditing standard of the Public Company Accounting Oversight Board (PCAOB), addresses the audit of internal control over financial reporting (ICFR) that is integrated with an audit of financial statements. It is directed at audits of issuers subject to PCAOB standards. A financial statement audit does not always include an ICFR audit under this standard, and its applicability depends on the entity's regulatory status and any exemptions available under applicable law. Whether an integrated audit is required in a given engagement should be verified against the relevant rules and the entity's filing obligations.
Is AS 2201 the same as management's own assessment of internal control?
No. AS 2201 governs the external auditor's audit of ICFR, not management's separate responsibility to assess and report on internal control. These are distinct exercises: management performs its own evaluation, and the auditor conducts an independent audit that may rely in part on, but does not substitute for, management's process. Conflating the two obscures the boundary between the responsibilities of management and those of the independent auditor. The specifics of each party's obligations should be confirmed against the applicable standards and regulatory requirements.
How does AS 2201 relate to a company's use of a control framework such as COSO?
AS 2201 concerns how the auditor audits internal control over financial reporting, while a framework such as the COSO Internal Control Integrated Framework typically provides the criteria against which the design and operating effectiveness of controls are evaluated. In practice, an organization commonly selects a recognized framework as the basis for structuring and assessing its controls, and the auditor evaluates ICFR against suitable criteria. The choice and application of a framework, and how it maps to audit procedures, should be determined with reference to the primary source materials and professional judgment.
What is the significance of the top-down, risk-based approach often associated with AS 2201?
The standard is generally understood to describe a top-down, risk-based approach in which the auditor begins at the financial statement level, focuses on entity-level controls, and directs attention toward the accounts, disclosures, and assertions that present a reasonable possibility of material misstatement. The intent is typically to concentrate audit effort where risk is greatest rather than testing all controls uniformly. How this approach is scoped and applied depends on the specific engagement and should be carried out consistent with the standard's actual text and applicable professional judgment.
How should organizations distinguish a control deficiency, a significant deficiency, and a material weakness in this context?
These terms reflect differing levels of severity in deficiencies in internal control over financial reporting, generally distinguished by the likelihood and potential magnitude of a resulting misstatement. A material weakness is typically the most severe category, reflecting a reasonable possibility that a material misstatement would not be prevented or detected on a timely basis. Precise definitions and thresholds are matters of interpretation under the applicable standards, and their classification often requires professional judgment. Specific determinations should be verified against the primary source and, where necessary, appropriate professional advice.
What documentation and evidence considerations tend to arise when working under AS 2201?
Because an integrated audit of ICFR generally requires the auditor to obtain sufficient appropriate evidence about the design and operating effectiveness of relevant controls, organizations often find that maintaining clear documentation of control design, ownership, and operation supports the audit process. The nature, timing, and extent of testing typically vary with assessed risk. What constitutes sufficient evidence and appropriate documentation is a matter of professional judgment governed by the applicable standards, and the specific requirements should be confirmed against the primary source rather than assumed.

Common misconceptions

AS 2201 is management's own framework for establishing internal controls.
AS 2201 is a PCAOB auditing standard governing how the external auditor conducts an integrated audit of ICFR; it is directed at auditors. Management's responsibility to establish and assess controls arises from other sources, and management often uses a separate control framework, such as a recognized internal control framework, as the basis for its assessment. The auditing standard and the control framework serve different roles.
An unqualified opinion under AS 2201 guarantees that no material misstatement or control failure exists.
An audit provides reasonable, not absolute, assurance. A favorable opinion on ICFR reflects the auditor's judgment based on testing and evidence at a point in time and does not eliminate the possibility of undetected misstatements, control failures, or subsequent breakdowns, particularly given inherent limitations such as management override and human error.
The auditor must test every control in the organization.
The standard generally reflects a top-down, risk-based approach, so the auditor focuses testing on controls addressing risks of material misstatement in significant accounts, disclosures, and assertions. Not all controls are tested with equal depth, and coverage is a matter of professional judgment rather than exhaustive examination.

Best practices

Confirm applicability before relying on AS 2201, as it is a PCAOB standard relevant to audits of issuers within its scope; verify whether it applies to a given entity's circumstances and jurisdiction and consult the primary standard and current PCAOB guidance for authoritative requirements.
Maintain a clear separation between management's responsibility to design, operate, and assess ICFR and the auditor's responsibility to audit it, and ensure management performs its own robust assessment supported by a recognized control framework rather than deferring to the auditor.
Apply a top-down, risk-based lens when scoping, starting from financial statement risks and entity-level controls to focus effort on significant accounts, disclosures, and assertions with a reasonable possibility of material misstatement.
Evaluate both the design effectiveness and the operating effectiveness of key controls, documenting the basis for conclusions so that judgments are defensible and reviewable.
Assess identified control deficiencies for severity, distinguishing among deficiencies, significant deficiencies, and material weaknesses, and consider deficiencies in combination when evaluating whether a material weakness exists.
Coordinate the ICFR and financial statement audit work so evidence from each informs the other, and treat the resulting opinions as related but distinct, recognizing that assurance is reasonable rather than absolute.
Promotional banner for the Pentest Readiness checklist download