Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Internal Controls & Audit

PCAOB Auditing Standards

Also known as: PCAOB AS, PCAOB Standards, PCAOB Auditing and Related Professional Practice Standards
Simply put

PCAOB Auditing Standards are the rules that auditors must follow when they audit the financial statements of public companies and other issuers in the United States. They are set by the Public Company Accounting Oversight Board (PCAOB), a nonprofit corporation established by Congress to oversee such audits with the goal of protecting investors and serving the public interest. The standards are intended to promote high-quality, consistent audit work.

Formal definition

PCAOB Auditing Standards are the auditing and related professional practice standards established and maintained by the Public Company Accounting Oversight Board for audits of public companies and other issuers. As defined in the PCAOB's rules, the term "auditing and related professional practice standards" encompasses auditing standards, related attestation standards, quality control standards, and ethical standards. These standards govern the conduct of audit engagements, including, in the case of certain standards, integrated audits addressing both a company's financial statements and related matters; the applicable requirements depend on the specific standard and the nature of the engagement. The PCAOB, a nonprofit corporation established by Congress, oversees issuer audits to protect investors and further the public interest. Practitioners should note that individual standards are subject to amendment and supersession over time (some standards are archived), and the precise requirements applicable to a given engagement should be verified against the current standards in effect.

Why it matters

PCAOB Auditing Standards sit at the center of the assurance framework for U.S. public company financial reporting. Because these standards govern how audits of public companies and other issuers must be conducted, they directly influence the reliability of the financial statements on which investors, lenders, and markets depend. The PCAOB was established by Congress as a nonprofit corporation specifically to oversee such audits with the aim of protecting investors and furthering the public interest, which means the standards are not merely professional convention but part of a statutory oversight regime.

For organizations subject to these standards, the requirements shape the expectations placed on their external auditors and, by extension, on the internal control and financial reporting processes that support the audit. Where a standard addresses integrated audits, it establishes requirements applying when an auditor is engaged to audit both a company's financial statements and related matters, meaning the quality of a company's control environment can affect the conduct and outcome of the engagement. High-quality, consistent audit work supports confidence in reported financial information, while gaps in audit quality can undermine that confidence.

Because individual standards are subject to amendment and supersession over time, and some standards are archived, the specific requirements applicable to any given engagement change as the standards evolve. This makes ongoing attention to the current standards in effect important for both auditors and the companies they audit, and it underscores that the precise obligations for a particular engagement should be verified against the standards currently in force rather than assumed from prior editions.

Who it's relevant to

External auditors of issuers
Registered public accounting firms and their audit teams must follow PCAOB Auditing Standards when auditing the financial statements of public companies and other issuers. Because standards can be amended, superseded, or archived over time, these practitioners need to confirm which requirements apply to a specific engagement under the current standards in effect.
Financial reporting and controls functions at issuers
Controllers, financial reporting teams, and internal control owners at public companies are affected by these standards through the expectations they place on the external audit, particularly where a standard addresses integrated audits covering both the financial statements and related matters. Understanding the applicable requirements helps these functions prepare for and support the audit process.
Audit committees and governance bodies
Audit committees and boards responsible for overseeing the external audit relationship benefit from understanding the standards that govern that audit. This supports their oversight role in an environment where the PCAOB, as a body established by Congress, oversees issuer audits to protect investors and further the public interest.
Compliance and legal professionals
Compliance officers and general counsel supporting public companies may need to understand how PCAOB Auditing Standards interact with the broader audit oversight regime. Given that specific requirements and effective standards change over time, these professionals should verify applicable obligations against the current standards and seek professional advice where legal interpretation is involved.

Inside PCAOB AS

Standard-Setting Authority
PCAOB Auditing Standards are issued by the Public Company Accounting Oversight Board, a body established under the Sarbanes-Oxley Act to oversee the audits of public companies and certain other issuers in the United States. The standards typically require approval by the Securities and Exchange Commission before taking effect. Applicability is generally limited to audits within the PCAOB's jurisdiction and does not automatically extend to private-company or non-U.S. audits, which may follow other frameworks.
Scope of Coverage
The standards generally address the conduct of audits of issuers, including areas such as audit planning, risk assessment, evidence gathering, internal control over financial reporting, use of the work of others, and audit reporting. The specific topics and their organization have evolved over time, and practitioners should confirm the current standard applicable to a given engagement against the primary source.
Relationship to Internal Control Over Financial Reporting (ICFR)
Certain PCAOB standards address the integrated audit of financial statements and ICFR, reflecting the compliance obligations that arise under the Sarbanes-Oxley Act. This is one area where the standards intersect the compliance pillar (adherence to legal requirements) and the governance pillar (structures for financial reporting oversight), while remaining fundamentally about audit conduct.
Enforcement and Inspection Context
PCAOB standards are supported by the Board's inspection and, where applicable, disciplinary functions, which assess registered firms' compliance with the standards. Adherence to the standards is a professional and, within the Board's jurisdiction, a regulatory obligation rather than a voluntary leading practice, though the precise enforcement mechanisms and thresholds fall outside the scope of this definition.
Evolving Editions and Reorganization
The body of PCAOB standards has been reorganized and amended over time, including efforts to renumber and consolidate standards. Because clause references and titles change across editions, any citation to a specific standard number should be verified against the current authoritative text rather than assumed.

Common questions

Answers to the questions practitioners most commonly ask about PCAOB AS.

Do PCAOB Auditing Standards apply to all financial statement audits?
No. PCAOB Auditing Standards generally govern audits of public companies (issuers) and, in the United States, certain broker-dealers whose audits fall within the PCAOB's oversight authority. Audits of many private companies are typically conducted under different standards, such as those issued by the AICPA's Auditing Standards Board in the U.S. Applicability depends on the nature of the audited entity and the jurisdiction, so the specific scope should be confirmed against the relevant regulatory requirements and the auditor's professional obligations.
Are PCAOB Auditing Standards the same as the internal controls a company is required to maintain?
No, and it is important to keep these distinct. PCAOB Auditing Standards direct how an external auditor plans and performs an audit, including, in many cases, an audit of internal control over financial reporting. The internal controls themselves are established and operated by the company's own management and governance structures. The standards guide the auditor's evaluation of those controls rather than serving as the controls, so responsibility for designing and maintaining effective controls remains with the organization, not with the auditing standards.
How does an organization determine whether PCAOB Auditing Standards apply to its audit?
Applicability typically turns on whether the entity is subject to PCAOB oversight, which commonly includes public companies and certain regulated entities within the PCAOB's authority. Organizations often make this determination in consultation with their external auditor and legal or accounting advisers, since the classification of the entity and the applicable jurisdiction drive the outcome. Because thresholds and categories can change and vary by circumstance, the specifics should be verified against current regulatory requirements rather than assumed.
What should management do to prepare for an audit conducted under PCAOB Auditing Standards?
Preparation commonly involves ensuring that relevant financial records, supporting documentation, and evidence of controls are organized and accessible, and that personnel are available to respond to auditor inquiries. Where an audit of internal control over financial reporting is in scope, management often assesses and documents the design and operation of those controls in advance. The precise expectations should be coordinated with the external auditor, as the audit approach is shaped by the auditor's application of the applicable standards to the specific engagement.
How do PCAOB Auditing Standards interact with an organization's own GRC program?
An external audit performed under these standards is separate from, but often informed by, an organization's governance, risk, and compliance activities. A well-functioning internal control environment and reliable compliance processes can support the auditor's work, while audit findings may in turn inform the organization's control improvements. It is generally advisable to treat the external audit and the internal GRC program as complementary rather than interchangeable, since each serves a distinct role and responsibility.
How should an organization stay current as PCAOB Auditing Standards evolve?
Standards and related guidance can be revised over time, so organizations often monitor updates through their external auditor, professional bodies, and the standard-setter's published materials. Compliance and internal audit functions may track changes that could affect audit scope, documentation expectations, or control evaluation. Because interpretations and effective dates can shift, specific requirements should be confirmed against the primary source and, where the implications are unclear, discussed with qualified professional advisers.

Common misconceptions

PCAOB Auditing Standards apply to all audits performed in the United States.
The standards generally govern audits within the PCAOB's jurisdiction, which centers on issuers and certain other entities. Audits outside that scope, such as many private-company engagements, typically follow other standard-setting frameworks. Applicability should be determined by the nature of the entity and engagement.
Following PCAOB Auditing Standards guarantees that financial statements are free of misstatement or that an audit will detect all problems.
Auditing standards are designed to provide a framework for obtaining reasonable, not absolute, assurance. Compliance with the standards modifies but does not eliminate the risk that misstatements go undetected, and it does not guarantee any particular audit outcome.
PCAOB standards and the underlying financial reporting rules are the same thing.
PCAOB Auditing Standards govern how auditors conduct and report on an audit; they are distinct from the accounting and reporting requirements that management follows in preparing financial statements. Conflating audit standards with reporting obligations blurs the boundary between the auditor's role and the reporting entity's responsibilities.

Best practices

Confirm at engagement acceptance whether the entity falls within the PCAOB's jurisdiction, since this determines whether PCAOB Auditing Standards or another framework applies.
Verify the current standard number, title, and text against the authoritative PCAOB source before citing it, because the standards have been reorganized and amended across editions.
Maintain a clear separation in documentation between the auditor's responsibilities under the standards and management's responsibilities for the financial statements and internal control.
Track amendments and SEC approvals that affect effective dates, and confirm effective dates against the primary source rather than relying on convention.
Where an engagement involves an integrated audit of financial statements and internal control over financial reporting, align the audit approach with the specific applicable standards and the related Sarbanes-Oxley compliance obligations.
Consult qualified professional or legal advice for matters of interpretation, jurisdictional carve-outs, or enforcement exposure, as these fall outside a general definition.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.