PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR)
PCAOB Auditing Standard No. 2201 (AS 2201, originally AS 5) establishes requirements for auditing internal control over financial reporting (ICFR) that is integrated with the audit of financial statements of SEC-registered companies. Required by Sarbanes-Oxley Act Section 404(b) for accelerated filers. Covers top-down risk-based approach, evaluating entity-level controls, selecting controls to test, testing design and operating effectiveness, and forming an opinion on ICFR effectiveness.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (19)
Audit Conclusion
| Code | Title |
|---|---|
| AS2201-20 | Forming an Opinion on ICFR |
| AS2201-21 | Subsequent Events Affecting ICFR |
Audit Planning
| Code | Title |
|---|---|
| AS2201-1 | Integrated Audit Planning |
| AS2201-3 | Materiality and Tolerable Misstatement |
Communication
| Code | Title |
|---|---|
| AS2201-19 | Communication of Control Deficiencies |
Control Evaluation
| Code | Title |
|---|---|
| AS2201-4 | Entity Level Controls Evaluation |
| AS2201-5 | Period End Financial Reporting Process |
Control Selection
| Code | Title |
|---|---|
| AS2201-8 | Selection of Controls to Test |
Control Testing
| Code | Title |
|---|---|
| AS2201-10 | Testing Operating Effectiveness |
| AS2201-11 | Nature, Timing, and Extent of Tests |
| AS2201-12 | Roll Forward Procedures from Interim to Period End |
| AS2201-9 | Evaluating Design Effectiveness |
Deficiency Evaluation
| Code | Title |
|---|---|
| AS2201-17 | Evaluating Identified Deficiencies |
| AS2201-18 | Indicators of Material Weakness |
Evaluating Deficiencies
| Code | Title |
|---|---|
| AS2201.62 | Deficiency Evaluation |
| AS2201.65 | Material Weakness Determination |
| AS2201.69 | Communication of Deficiencies |
| AS2201.70 | Impact on Audit Opinion |
Evidence Quality
| Code | Title |
|---|---|
| AS2201-14 | Testing Information Produced by the Entity |
ITGC Testing
| Code | Title |
|---|---|
| AS2201-13 | Information Technology General Controls |
Identifying Controls to Test
| Code | Title |
|---|---|
| AS2201.22 | Entity-Level Controls |
| AS2201.28 | Significant Accounts and Disclosures |
| AS2201.34 | Understanding Transaction Flows |
| AS2201.39 | Selecting Controls to Test |
Planning the Audit
| Code | Title |
|---|---|
| AS2201.04 | Integration with Financial Statement Audit |
| AS2201.09 | Role of Risk Assessment |
| AS2201.10 | Scaling the Audit |
| AS2201.14 | Using the Work of Others |
Quality Control
| Code | Title |
|---|---|
| AS2201-22 | Engagement Quality Review |
Reliance on Others
| Code | Title |
|---|---|
| AS2201-16 | Use of the Work of Internal Auditors and Others |
Reporting
| Code | Title |
|---|---|
| AS2201.85 | Opinion on ICFR |
| AS2201.86 | Basis for Opinion |
| AS2201.87 | Definition and Limitations of ICFR |
| AS2201.90 | Combined vs Separate Reports |
Risk Identification
| Code | Title |
|---|---|
| AS2201-2 | Top Down Approach to Risk Identification |
| AS2201-6 | Significant Accounts and Disclosures |
Testing Controls
| Code | Title |
|---|---|
| AS2201.42 | Design Effectiveness Testing |
| AS2201.44 | Operating Effectiveness Testing |
| AS2201.46 | Nature of Tests |
| AS2201.52 | Timing of Tests |
Third Party Reliance
| Code | Title |
|---|---|
| AS2201-15 | Service Organisations and SOC Reports |
Understanding of Controls
| Code | Title |
|---|---|
| AS2201-7 | Walkthroughs |
Your Compliance Coverage
If you comply with PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR), you already cover:
FTC Health Breach Notification Rule
17%
7 controls mapped
Compare →SSAE 18 — Attestation Standards (SOC Reporting)
17%
7 controls mapped
Compare →C2M2
17%
7 controls mapped
Compare →+ 589 more: Notifiable Data Breaches Scheme (Australia) (17%), EU Digital Markets Act (17%)
See all 592 mapped frameworks ↓Maps to 592 other frameworks
Frequently Asked Questions
What is PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR)?
PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) is a compliance framework from United States (PCAOB) with 19 domains and 42 controls. PCAOB Auditing Standard No. 2201 (AS 2201, originally AS 5) establishes requirements for auditing internal control over financial reporting (ICFR) that is integrated with the audit of financial statements of SEC-registered companies. Required by Sarbanes-Oxley Act Section 404(b) for accelerated filers. Covers top-down risk-based approach, evaluating entity-level controls, selecting controls to test, testing design and operating effectiveness, and forming an opinion on ICFR effectiveness. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) have?
PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) has 42 controls organised across 19 domains. The largest domains are Control Testing (4 controls), Evaluating Deficiencies (4 controls), Identifying Controls to Test (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) map to?
PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) maps to 592 other compliance frameworks. The top mapping partners are FTC Health Breach Notification Rule (17% coverage), SSAE 18 — Attestation Standards (SOC Reporting) (17% coverage), C2M2 (17% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) compliance?
Start your PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 706 frameworks.
Get Started Free →Free forever — no credit card required