Skip to main content
Promotional banner for the pentest readiness checklist
Category: Internal Controls & Audit

Integrated Audit

Simply put

An integrated audit is an examination that combines an audit of an organization's financial statements with an assessment of its internal controls, rather than treating these as separate exercises. The aim is to evaluate both whether the financial statements are accurate and whether the controls supporting them are working. In some settings, this combined approach may also consider related operational or technology processes.

Formal definition

An integrated audit is an engagement in which an auditor examines both an entity's financial statements and its internal control over financial reporting as interrelated components of a single audit, applying an integrated consideration of audit risk across both. In the context of PCAOB auditing standards (e.g., AS 1101, Audit Risk), audit risk is considered as part of either an integrated audit or an audit of financial statements alone, reflecting that the two objectives may be addressed together. Beyond the external financial-reporting context, the term is also used more broadly for approaches that assess the interplay between financial, operational, and technology processes against control objectives; the Institute of Internal Auditors describes integrated approaches to internal auditing as flexible methods spanning planning, execution, and reporting. Scope, applicable standards, and reporting requirements vary by whether the entity is an issuer or non-issuer and by jurisdiction, and practitioners should confirm specific obligations against the governing standards; matters of professional and legal interpretation fall outside this definition.

Why it matters

Financial statements and the internal controls that support them are deeply interconnected, yet examining them in isolation can leave gaps. An integrated audit responds to this by treating the accuracy of the financial statements and the effectiveness of internal control over financial reporting as interrelated components of a single engagement. This allows the auditor to consider audit risk across both objectives together, so that conclusions about the reliability of the numbers are informed by an understanding of whether the underlying controls are actually functioning.

For organizations, the significance lies in the assurance this combined approach can offer to boards, audit committees, regulators, and investors. Weak controls may not immediately produce a misstatement, but they raise the likelihood that errors or irregularities go undetected. By assessing controls alongside the financial results, an integrated audit can surface control deficiencies that a financial-statement-only audit might not fully explore. It is important to note, however, that scope and reporting requirements differ depending on whether the entity is an issuer or a non-issuer, and by jurisdiction; an integrated audit does not eliminate risk or guarantee that all misstatements or control failures will be identified.

The term is also used more broadly beyond the external financial-reporting context. Internal audit functions may apply integrated approaches that consider the interplay between financial, operational, and technology processes against control objectives. In these settings the objective is less about a formal audit opinion and more about a flexible, holistic view of how different processes affect the achievement of control objectives, spanning planning, execution, and reporting.

Who it's relevant to

External Auditors
Auditors performing engagements that combine financial-statement examination with an assessment of internal control over financial reporting rely on the integrated audit concept to consider audit risk across both objectives. The applicable standards and reporting requirements differ by whether the client is an issuer or a non-issuer and by jurisdiction, so the governing standards should be confirmed for each engagement.
Internal Auditors
Internal audit functions may adopt integrated approaches that assess the interplay between financial, operational, and technology processes against control objectives. As described in Institute of Internal Auditors guidance, these are flexible methods spanning planning, execution, and reporting rather than a single prescribed procedure.
Audit Committees and Boards
Those charged with governance oversight use the results of integrated audits to understand not only whether the financial statements are reliable but also whether the controls supporting them are operating. This combined view can inform oversight of financial reporting and control deficiencies, though it does not guarantee that all issues are identified.
Compliance and Risk Professionals
Compliance officers and risk managers may find integrated audit findings relevant where control weaknesses affecting financial, operational, or technology processes bear on the organization's control environment. Because applicability and obligations vary by sector and jurisdiction, specific requirements should be verified against the primary sources and, where necessary, professional advice.

Inside Integrated Audit

Combined Assessment of Financial and Control Testing
An integrated audit typically brings together an evaluation of the financial statements or financial reporting with an assessment of the internal controls over financial reporting (ICFR), rather than treating them as wholly separate engagements. The precise scope depends on the applicable standards and, in some jurisdictions, on regulatory requirements applicable to certain issuers.
Internal Control Over Financial Reporting (ICFR) Component
The controls dimension focuses on whether controls designed to provide reasonable assurance over the reliability of financial reporting are suitably designed and operating effectively. This draws on internal control concepts such as those articulated in the COSO Internal Control Integrated Framework, though the specific criteria applied depend on the framework and standards adopted.
Substantive and Controls-Based Evidence
Practitioners typically gather both evidence about the operating effectiveness of controls and substantive evidence about account balances and transactions, with the balance between the two often informed by the assessed strength of controls.
Risk Assessment Linkage
An integrated approach commonly ties identified risks of material misstatement to the controls intended to address them, so that testing effort can be directed toward areas of greater risk. This reflects the distinction between a risk (a potential event affecting objectives) and a control (a measure that modifies risk).
Coordinated Reporting or Opinions
Depending on the engagement and jurisdiction, an integrated audit may result in reporting that addresses both the financial statements and the effectiveness of internal control. Whether separate or combined opinions are issued varies by the standards and regulatory context that apply.

Common questions

Answers to the questions practitioners most commonly ask about Integrated Audit.

Is an integrated audit the same as combining a financial audit and an operational audit into one engagement?
Not precisely. While an integrated audit does bring together more than one dimension of assurance in a single, coordinated engagement, it is typically understood as the integration of an audit over financial reporting with an audit of the internal control over that reporting, rather than simply merging unrelated audit types. The defining feature is that the controls testing and the substantive work are planned and executed in a coordinated way so that evidence from one informs the other. The precise scope depends on the applicable auditing standards and the jurisdiction, so the term should be interpreted against the framework under which the audit is conducted.
Does performing an integrated audit mean the organization's internal controls are effective and its compliance is guaranteed?
No. An integrated audit provides assurance based on testing performed to a defined standard and materiality threshold at a point in time or over a defined period; it does not eliminate risk or guarantee that controls are effective or that the organization is compliant. Audits are subject to inherent limitations, including sampling, reliance on management representations, and the possibility that controls operating effectively during the test period may fail afterward. An audit opinion expresses a conclusion within a defined scope, not an absolute assurance of outcomes.
How should the scope of an integrated audit be defined at the planning stage?
Scope is typically defined by identifying the objectives of the engagement, the relevant financial statement assertions or processes, and the controls that address the associated risks. Planning often involves a risk assessment to determine which areas are material and where control reliance is intended. Because applicable standards, entity size, and sector influence what is in scope, the boundaries, including any areas excluded, such as matters requiring separate legal interpretation, should be documented explicitly and agreed with those charged with governance.
How can internal and external audit teams coordinate on an integrated audit?
Coordination often involves aligning risk assessments, sharing an understanding of the control environment, and, where standards permit, considering the work of internal audit to inform the external auditor's approach. The extent to which one party may rely on another's work is generally governed by the relevant auditing standards, which typically address the competence, objectivity, and quality of the work being relied upon. Clear communication protocols, defined responsibilities, and documentation of what work is shared help avoid duplication while preserving each party's independence and accountability.
What role does the distinction between controls testing and substantive testing play in an integrated audit?
In many frameworks, an integrated audit combines tests of the design and operating effectiveness of controls with substantive procedures over the underlying data or transactions. The results of controls testing can influence the nature, timing, and extent of substantive work: stronger evidence of effective controls may permit reduced substantive testing, whereas control deficiencies may require expanded procedures. Maintaining a clear distinction between a control (a measure that modifies risk) and the risk itself helps auditors document why particular procedures were selected.
How should deficiencies identified during an integrated audit be evaluated and reported?
Identified deficiencies are typically evaluated for severity, for example, distinguishing a deficiency from a significant deficiency or a material weakness, based on the likelihood and potential magnitude of misstatement or control failure they represent. The specific classification thresholds and reporting obligations depend on the applicable standards and, where relevant, regulatory requirements, which vary by jurisdiction and sector. Findings are generally communicated to management and those charged with governance, and organizations should verify reporting requirements against the primary standards and seek professional advice where legal interpretation is involved.

Common misconceptions

An integrated audit merges the compliance, risk, and governance functions into a single review.
The term as used here generally refers to integrating the financial statement audit with the assessment of internal control over financial reporting. It is not a combined governance, risk management, and compliance exercise; those pillars remain distinct, and any given integrated audit has a defined scope that typically does not extend to all three.
Effective controls tested in an integrated audit eliminate the risk of material misstatement.
Controls are measures that modify risk; they do not eliminate it. An integrated audit is typically designed to provide reasonable, not absolute, assurance, and residual risk generally remains even where controls are assessed as operating effectively.
Every organization is required to undergo an integrated audit.
Applicability varies by jurisdiction, sector, and the type and size of the entity. In some jurisdictions integrated audit requirements apply only to certain categories of issuers, while other entities may undergo a financial statement audit without an accompanying opinion on internal control. Specific obligations should be verified against the applicable standards and regulations.

Best practices

Define the scope of the engagement at the outset, clarifying whether it covers the financial statements, internal control over financial reporting, or both, and confirm this against the standards and regulatory requirements that apply to the entity.
Anchor testing in a documented risk assessment that explicitly links identified risks of material misstatement to the specific controls intended to address them, so effort is directed toward higher-risk areas.
Maintain a clear distinction in working papers between evidence of control operating effectiveness and substantive evidence about balances and transactions, and document how the two inform each other.
Reference the internal control criteria being applied, such as a recognized internal control framework, and note the edition or version used, since framework language evolves over time.
Communicate identified control deficiencies to those charged with governance in a timely manner, distinguishing their severity according to the applicable evaluation criteria.
Where reporting or opinion requirements are unclear or jurisdiction-specific, verify obligations against the primary standards and seek appropriate professional or legal advice rather than assuming a uniform requirement.
Promotional banner for the Pentest Readiness checklist download