PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR)
PCAOB Auditing Standard No. 2201 (AS 2201, originally AS 5) establishes requirements for auditing internal control over financial reporting (ICFR) that is integrated with the audit of financial statements of SEC-registered companies. Required by Sarbanes-Oxley Act Section 404(b) for accelerated filers. Covers top-down risk-based approach, evaluating entity-level controls, selecting controls to test, testing design and operating effectiveness, and forming an opinion on ICFR effectiveness.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Evaluating Deficiencies
| Code | Title |
|---|---|
| AS2201.62 | Deficiency Evaluation |
| AS2201.65 | Material Weakness Determination |
| AS2201.69 | Communication of Deficiencies |
| AS2201.70 | Impact on Audit Opinion |
Identifying Controls to Test
| Code | Title |
|---|---|
| AS2201.22 | Entity-Level Controls |
| AS2201.28 | Significant Accounts and Disclosures |
| AS2201.34 | Understanding Transaction Flows |
| AS2201.39 | Selecting Controls to Test |
Planning the Audit
| Code | Title |
|---|---|
| AS2201.04 | Integration with Financial Statement Audit |
| AS2201.09 | Role of Risk Assessment |
| AS2201.10 | Scaling the Audit |
| AS2201.14 | Using the Work of Others |
Reporting
| Code | Title |
|---|---|
| AS2201.85 | Opinion on ICFR |
| AS2201.86 | Basis for Opinion |
| AS2201.87 | Definition and Limitations of ICFR |
| AS2201.90 | Combined vs Separate Reports |
Testing Controls
| Code | Title |
|---|---|
| AS2201.42 | Design Effectiveness Testing |
| AS2201.44 | Operating Effectiveness Testing |
| AS2201.46 | Nature of Tests |
| AS2201.52 | Timing of Tests |
Maps to 570 other frameworks
Frequently Asked Questions
What is PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR)?
PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) is a compliance framework from United States (PCAOB) with 5 domains and 20 controls. PCAOB Auditing Standard No. 2201 (AS 2201, originally AS 5) establishes requirements for auditing internal control over financial reporting (ICFR) that is integrated with the audit of financial statements of SEC-registered companies. Required by Sarbanes-Oxley Act Section 404(b) for accelerated filers. Covers top-down risk-based approach, evaluating entity-level controls, selecting controls to test, testing design and operating effectiveness, and forming an opinion on ICFR effectiveness. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) have?
PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) has 20 controls organised across 5 domains. The largest domains are Evaluating Deficiencies (4 controls), Identifying Controls to Test (4 controls), Planning the Audit (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) map to?
PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) maps to 570 other compliance frameworks. The top mapping partners are FTC Health Breach Notification Rule (35% coverage), SSAE 18 — Attestation Standards (SOC Reporting) (35% coverage), Notifiable Data Breaches Scheme (Australia) (35% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) compliance?
Start your PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PCAOB AS 2201 — Audit of Internal Control Over Financial Reporting (ICFR) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 20 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required