The auditor's ICFR audit under PCAOB AS 2201
PCAOB AS 2201 requires an external auditor to provide an independent opinion on the effectiveness of a company's Internal Control over Financial Reporting (ICFR). The auditor must determine whether the company maintained effective internal controls to prevent or detect material misstatements in its financial statements.
What it means
AS 2201 mandates a "top-down, risk-based approach." Instead of testing every single control in an organization, auditors focus on the areas with the highest risk of material misstatement. They start at the consolidated financial statement level and drill down into significant accounts and disclosures to identify the specific controls that mitigate those risks.
In practice, this means the auditor evaluates both "design effectiveness" and "operating effectiveness." Design effectiveness asks: "If this control is performed exactly as written, would it stop a material error?" Operating effectiveness asks: "Was this control actually performed consistently by the assigned person throughout the period under audit?"
The scope includes entity-level controls—such as the company's code of ethics and oversight by the board—as well as activity-level controls, such as manual reconciliations or automated system validations. A failure in a key control can lead to a "significant deficiency" or a "material weakness," the latter of which results in an adverse audit opinion regardless of whether a financial error actually occurred.
How to meet it
- Map Risks to Controls: Maintain a risk-control matrix (RCM) that explicitly links every significant financial statement account to the specific controls designed to mitigate risks associated with that account.
- Document Control Descriptions: Create detailed narratives or flowcharts for all key processes, specifying who performs the control, what evidence they review, how often it occurs, and what action is taken if an error is found.
- Implement a COSO Framework: Adopt a recognized internal control framework (typically COSO) to ensure entity-level controls—like governance and risk assessment—are structured logically.
- Enforce Segregation of Duties (SoD): Ensure that no single individual has the ability to both initiate and approve a financial transaction without oversight.
- Perform Internal Testing: Conduct "dry run" or internal audits throughout the year to identify and remediate control gaps before the external auditor arrives.
- Establish Precision in Reviews: Define exactly what a "review" entails (e.g., checking for variances over $10,000) so that the control is not merely a rubber-stamp signature.
Evidence an auditor asks for
- Control Population and Samples: A complete list of all instances where a control occurred during the year (the population), from which the auditor will select specific samples to test.
- Execution Artifacts: Signed approvals, timestamped system logs, dated reconciliation spreadsheets, and emails showing evidence of review and challenge.
- User Access Reviews: Periodic reports proving that management reviewed system access rights and revoked permissions for terminated employees or those who changed roles.
- Remediation Logs: Documentation showing that when a control failure was found during internal testing, it was corrected and re-tested before the year-end cutoff.
Common pitfalls
- Lack of Evidence