How PCAOB Auditing Standards Are Organized: A Practical Guide for External Auditors
The Public Company Accounting Oversight Board (PCAOB) establishes auditing and related professional practice standards for registered public accounting firms conducting audits of SEC issuers and registered broker-dealers.
For external auditors, understanding how the PCAOB Auditing Standards are organized is essential to performing compliant, efficient, and well-documented audits.
The standards are not simply a collection of technical requirements. They provide an integrated framework covering audit planning, risk assessment, audit evidence, supervision, reporting, and audit quality.
Understanding the organization of these standards helps auditors identify applicable requirements and connect them to specific audit procedures.
Understanding the PCAOB Auditing Standards Structure
The PCAOB organizes its auditing standards into numbered categories based on their subject matter.
The primary categories are:
Category | Subject |
AS 1000 | General Auditing Standards |
AS 1100 | General Concepts |
AS 1200 | General Activities |
AS 1300 | Auditor Communications |
AS 2000 | Audit Procedures |
AS 2100 | Audit Planning and Risk Assessment |
AS 2200 | Auditing Internal Control Over Financial Reporting |
AS 2300 | Audit Procedures in Response to Risks |
AS 2400 | Audit Procedures for Specific Aspects of the Audit |
AS 2500 | Audit Procedures for Certain Accounts or Disclosures |
AS 2600 | Special Topics |
AS 2700 | Auditor Reporting |
AS 2800 | Audit Conclusions and Reporting |
AS 2900 | Other Matters Associated with Audits |
AS 3000 | Other Professional Standards |
These categories help auditors locate standards applicable to particular audit activities.
However, auditors must understand that the standards operate together. Compliance with one standard does not eliminate responsibilities established by another.
1. General Auditing Standards: AS 1000–AS 1300
These standards establish foundational responsibilities and requirements governing the conduct of audits.
Important standards include:
AS 1000 — General Responsibilities of the Auditor in Conducting an Audit -
Establishes the auditor's fundamental responsibilities, including professional competence, due professional care, professional skepticism, and the objective of obtaining reasonable assurance.
AS 1105 — Audit Evidence - Addresses the sufficiency and appropriateness of audit evidence supporting the auditor's conclusions.
AS 1201 — Supervision of the Audit Engagement - Establishes responsibilities for supervising audit personnel and reviewing their work.
AS 1215 — Audit Documentation - Establishes requirements for documenting audit procedures, evidence, significant findings, and conclusions.
AS 1220 — Engagement Quality Review - Addresses the independent evaluation of significant judgments and conclusions by an engagement quality reviewer.
Together, these standards establish the foundation for conducting and documenting a quality audit.
2. Audit Planning and Risk Assessment: AS 2100
The AS 2100 series addresses how auditors plan their work and identify risks of material misstatement.
Key standards include:
AS 2101 — Audit Planning - Addresses developing the overall audit strategy and audit plan.
AS 2105 — Consideration of Materiality in Planning and Performing an Audit - Establishes requirements for determining and applying materiality.
AS 2110 — Identifying and Assessing Risks of Material Misstatement - Addresses understanding the company, its environment, and internal control to identify and assess risks.
These standards establish the foundation for a risk-based audit approach.
Auditors should be able to demonstrate a clear relationship between identified risks and the audit procedures designed to address them.
3. Internal Control Over Financial Reporting: AS 2200
The AS 2200 series addresses audits of internal control over financial reporting.
The principal standard is:
AS 2201 — An Audit of Internal Control Over Financial Reporting That Is Integrated with an Audit of Financial Statements - AS 2201 addresses the auditor's responsibilities when performing an integrated audit.
Important topics include entity-level controls, significant accounts and disclosures, relevant assertions, control design, operating effectiveness, and the evaluation of control deficiencies.
For auditors performing integrated audits, understanding the relationship between AS 2201 and the risk assessment standards is particularly important.
4. Audit Responses and Evidence: AS 2300–AS 2500
These standards address how auditors respond to identified risks and obtain evidence.
Examples include:
AS 2301 — The Auditor's Responses to the Risks of Material Misstatement - Requires auditors to design and perform procedures responsive to assessed risks.
AS 2305 — Substantive Analytical Procedures - Addresses the appropriate use of analytical procedures as substantive audit evidence.
AS 2315 — Audit Sampling - Establishes requirements for statistical and non-statistical audit sampling.
AS 2401 — Consideration of Fraud in a Financial Statement Audit - Addresses the auditor's responsibilities for considering fraud.
AS 2501 — Auditing Accounting Estimates, Including Fair Value Measurements - Addresses auditing accounting estimates and related disclosures.
These standards are central to audit execution and frequently involve significant professional judgment.
5. Audit Conclusions and Reporting: AS 2700–AS 2900
The reporting and concluding stages of an audit require auditors to evaluate the evidence obtained and determine whether the financial statements are appropriately presented.
Important standards include:
AS 2810 — Evaluating Audit Results- Addresses evaluating identified misstatements, audit evidence, and the results of audit procedures.
AS 3101 — The Auditor's Report on an Audit of Financial Statements When the Auditor Expresses an Unqualified Opinion - Establishes requirements for the standard auditor's report, including applicable critical audit matter reporting.
AS 3105 — Departures from Unqualified Opinions and Other Reporting Circumstances
Addresses qualified opinions, adverse opinions, disclaimers of opinion, and other reporting circumstances.
AS 1301 — Communications with Audit Committees - Although located in the general standards series, AS 1301 is also important during audit completion and reporting.
The auditor must consider these requirements throughout the engagement—not simply when preparing the final audit report.
6. Broker-Dealer Auditing Standards: AS 3000
The AS 3000 series includes specialized standards applicable to certain regulatory engagements.
For registered broker-dealers, important standards include:
AT No. 1 — Examination Engagements Regarding Compliance Reports of Brokers and Dealers
AT No. 2 — Review Engagements Regarding Exemption Reports of Brokers and Dealers
These attestation standards address specialized reporting required under SEC Exchange Act Rule 17a-5.
Broker-dealer auditors must understand both the generally applicable PCAOB auditing standards and the specialized requirements governing their engagements.
How the Standards Work Together
Consider an audit of revenue recognition.
The auditor may need to apply several standards during the same engagement:
AS 2110: Identify revenue-related risks of material misstatement.
AS 2105: Determine relevant materiality considerations.
AS 2401: Evaluate fraud risks associated with revenue recognition.
AS 2301: Design audit responses to identified risks.
AS 1105: Obtain sufficient appropriate audit evidence.
AS 2315: Design and evaluate sampling procedures when sampling is used.
AS 1215: Document the work performed and conclusions reached.
AS 2810: Evaluate the audit results.
This illustrates an essential principle: PCAOB auditing standards are interconnected requirements—not independent checklists.
Why Understanding the Organization Matters
Auditors who understand the structure of PCAOB standards are better positioned to:
Identify requirements applicable to particular audit risks.
Develop appropriate audit methodologies.
Connect risk assessment to audit procedures.
Document significant judgments and conclusions.
Supervise and review audit engagements.
Prepare for PCAOB inspections.
Recognize gaps in audit documentation and evidence.
One of the most important questions during an audit review is:
Can the audit team demonstrate how its work satisfies the applicable PCAOB requirements?
The answer should be evident from the audit workpapers.
The Bottom Line
Understanding the organization of PCAOB Auditing Standards is fundamental to developing professional audit competence.
The numbering system provides a useful way to locate requirements, but auditors must understand how those requirements interact throughout the engagement.
A quality audit requires more than knowing individual standards. It requires understanding how to apply them together to support the auditor's opinion.

Comments