Integrated Audit
An integrated audit is an examination that combines an audit of an organization's financial statements with an assessment of its internal controls, rather than treating these as separate exercises. The aim is to evaluate both whether the financial statements are accurate and whether the controls supporting them are working. In some settings, this combined approach may also consider related operational or technology processes.
An integrated audit is an engagement in which an auditor examines both an entity's financial statements and its internal control over financial reporting as interrelated components of a single audit, applying an integrated consideration of audit risk across both. In the context of PCAOB auditing standards (e.g., AS 1101, Audit Risk), audit risk is considered as part of either an integrated audit or an audit of financial statements alone, reflecting that the two objectives may be addressed together. Beyond the external financial-reporting context, the term is also used more broadly for approaches that assess the interplay between financial, operational, and technology processes against control objectives; the Institute of Internal Auditors describes integrated approaches to internal auditing as flexible methods spanning planning, execution, and reporting. Scope, applicable standards, and reporting requirements vary by whether the entity is an issuer or non-issuer and by jurisdiction, and practitioners should confirm specific obligations against the governing standards; matters of professional and legal interpretation fall outside this definition.
Why it matters
Financial statements and the internal controls that support them are deeply interconnected, yet examining them in isolation can leave gaps. An integrated audit responds to this by treating the accuracy of the financial statements and the effectiveness of internal control over financial reporting as interrelated components of a single engagement. This allows the auditor to consider audit risk across both objectives together, so that conclusions about the reliability of the numbers are informed by an understanding of whether the underlying controls are actually functioning.
For organizations, the significance lies in the assurance this combined approach can offer to boards, audit committees, regulators, and investors. Weak controls may not immediately produce a misstatement, but they raise the likelihood that errors or irregularities go undetected. By assessing controls alongside the financial results, an integrated audit can surface control deficiencies that a financial-statement-only audit might not fully explore. It is important to note, however, that scope and reporting requirements differ depending on whether the entity is an issuer or a non-issuer, and by jurisdiction; an integrated audit does not eliminate risk or guarantee that all misstatements or control failures will be identified.
The term is also used more broadly beyond the external financial-reporting context. Internal audit functions may apply integrated approaches that consider the interplay between financial, operational, and technology processes against control objectives. In these settings the objective is less about a formal audit opinion and more about a flexible, holistic view of how different processes affect the achievement of control objectives, spanning planning, execution, and reporting.
Who it's relevant to
Inside Integrated Audit
Common questions
Answers to the questions practitioners most commonly ask about Integrated Audit.

