What is PCAOB?
PCAOB = Public Company Accounting Oversight Board. A US regulator established under the Sarbanes-Oxley Act (SOX) 2002 to oversee the audit of public companies and protect investors.
Key point: PCAOB issues Auditing Standards (AS), which are MANDATORY for audits of US public companies. They differ materially from ISA and must be followed even if the client also reports under IFRS.
PCAOB also conducts periodic inspections of audit firms — major and smaller firms face triennial or annual inspections to assess compliance with PCAOB standards.
PCAOB Auditing Standards Overview
PCAOB auditing standards run from AS 1000 to AS 6115 and are grouped by topic:
- AS 1000 series: general responsibilities, supervision, documentation, engagement quality review, and use of specialists
- AS 2000 series: planning, risk assessment, audit responses, evidence, and specific subject areas including fraud, estimates and going concern
- AS 3000 series: reporting. Separate AS 4000, 6000 and QC series cover follow-up matters, special topics and firm quality control
Key standards: AS 1000 (General Responsibilities), AS 1201 (Supervision), AS 1215 (Audit Documentation), AS 1220 (Engagement Quality Review), AS 2101 (Audit Planning), AS 2105 (Materiality), AS 2110 (Identifying and Assessing Risks of Material Misstatement), AS 2201 (Audit of Internal Control Over Financial Reporting), AS 2401 (Consideration of Fraud), AS 2501 (Auditing Accounting Estimates), AS 3101 (The Auditor’s Report on an Audit of Financial Statements When the Auditor Expresses an Unqualified Opinion).
AS 2110: Identifying and Assessing Risks of Material Misstatement
AS 2110 requires the auditor to:
- Obtain an understanding of the company, its environment and its internal control over financial reporting (AS 2110.04 onwards)
- Perform risk assessment procedures: inquiry, observation and inspection, analytical procedures, and consideration of information from the client acceptance process and prior audits
- Identify and assess the risks of material misstatement at the financial statement and assertion level
- Determine which risks are significant risks, requiring specific audit responses
Sitting above it since December 2024 is AS 1000, General Responsibilities of the Auditor in Conducting an Audit, which consolidated a set of long-standing foundational requirements: due professional care, professional scepticism, competence, independence, and the requirement to complete documentation within 14 days of the report release date. If you learned the old AS 1001 to AS 1015 series, that is where it went.
Where PCAOB genuinely differs from ISA. The divergence is not in risk assessment itself, which is close to ISA 315 in substance. It is that for issuers subject to an integrated audit, AS 2201 requires an opinion on the effectiveness of internal control over financial reporting, so controls must be tested for both design and operating effectiveness whether or not the auditor intends to rely on them. Under ISA, controls testing is a matter of audit strategy. That is a difference of scope and mandate, not of risk assessment philosophy.
AS 2101: Audit Planning
AS 2101 requires the auditor to:
- Establish an overall audit strategy setting the scope, timing and direction of the audit
- Develop an audit plan describing the planned risk assessment procedures, planned responses, and other procedures required to comply with PCAOB standards
- Determine whether specialised skill or knowledge is needed
- Evaluate whether the firm's compliance with independence and ethics requirements is intact
Related standards in the same area: AS 1201 (Supervision of the Audit Engagement), AS 2301 (The Auditor's Responses to the Risks of Material Misstatement), and AS 2105 (Consideration of Materiality in Planning and Performing an Audit).
Materiality: AS 2105 uses substantially the same concept as ISA 320, and both frameworks treat qualitative factors as capable of making a quantitatively small misstatement material, for instance where it affects covenant compliance, management remuneration, or the swing from a loss to a profit. The distinctive PCAOB point is the interaction with ICFR: a control deficiency is evaluated against whether it could result in a material misstatement, not against whether one actually occurred.
Fraud Detection & AS 2401
AS 2401 requires auditors to explicitly assess the risk of fraud in two areas:
- Fraudulent financial reporting: Management override of controls, revenue recognition schemes, expense understatement
- Misappropriation of assets: Theft of cash, inventory, or other assets
Key requirement: Auditors must design procedures specifically to detect fraud, including:
- Analytical procedures on journal entries (especially manual entries)
- Tests of unusual transactions
- Confirmations with third parties
- Review of management estimates and judgments
Difference from ISA: PCAOB is stricter on fraud procedures. ISA focuses on "professional skepticism"; PCAOB requires specific, documented fraud procedures. US public company audits have higher fraud-testing demands.
Reference: PCAOB AS 2401, Consideration of Fraud in a Financial Statement Audit.
Quality control: QC 1000 replaced the old regime in December 2025
This is the part of the PCAOB rulebook that changed most, and material written before 2024 describes a system that no longer applies. The interim standards inherited from the AICPA, QC 20 and its companions, governed firm quality control for over two decades. QC 1000, A Firm's System of Quality Control, replaced them for firms' fiscal years beginning on or after 15 December 2025.
The change is not cosmetic. The old regime was a set of policies a firm was expected to have. QC 1000 requires a risk-based system: the firm identifies its own quality risks, designs responses to them, and then evaluates annually whether the system is working. Key features:
- Annual evaluation and reporting. The firm must evaluate its system as of 30 September each year and report the results to the PCAOB on Form QC. The firm's principal executive officer signs it.
- A mandatory conclusion. The firm has to conclude whether the system provides reasonable assurance of quality, and disclose where it does not. That is a materially harder position to occupy than the old "we have policies" posture.
- An external oversight function for firms that issue more than 100 issuer audit reports a year, requiring at least one person outside the firm with the authority to hold it to account on quality.
- Alignment with, but not adoption of, ISQM 1. QC 1000 is close in architecture to the IAASB's ISQM 1, which took effect in December 2022. A global network firm will run one system designed to satisfy both, but the two are not identical and the PCAOB's reporting obligations have no ISQM equivalent.
Engagement quality review sits in AS 1220, not in the quality control standards. It is mandatory for every issuer audit and for engagements performed under PCAOB standards, and the reviewer must be independent of the engagement team and may not have made decisions on its behalf. This is the sharper contrast with the international framework, where ISQM 2 requires an engagement quality review only for listed entities and for engagements the firm identifies as warranting one.
Inspections. The PCAOB inspects annually those firms issuing audit reports for more than 100 issuers, and at least triennially otherwise. Reports are published in two parts: Part I covers deficiencies where the auditor failed to obtain sufficient appropriate evidence to support the opinion, and Part I.B covers instances of non-compliance with standards or rules that did not go to the sufficiency of evidence. Part II, covering quality control criticisms, is not published unless the firm fails to remediate to the Board's satisfaction within twelve months, which is the mechanism that gives the process teeth.
PCAOB vs ISA: Key Differences
| Area | PCAOB | ISA |
|---|---|---|
| Risk Assessment | Design of controls is mandatory testing | Risk assessment; control testing is optional if auditor assesses high risk |
| Fraud Testing | Explicit, documented fraud procedures required | Fraud consideration required but less prescriptive |
| Engagement Review | Independent EQRP mandatory | Review partner optional (some jurisdictions require it) |
| Audit Report | Must include opinion on internal controls over financial reporting (ICFR) for public companies | No ICFR opinion required |
| Materiality | Quantitative + qualitative (emphasizes qualitative) | Primarily quantitative with qualitative consideration |
Worked Example: Fraud Risk Assessment
Scenario: Audit of a US public technology company (SaaS vendor). Revenue is contract-based (multi-year subscriptions). Key fraud risks:
- Revenue recognition scheme: side letters reducing contract value after execution
- Expense understatement: accrual of unused consulting services not reversal
- Management compensation: profit targets tied to revenue, incentive to overstate
PCAOB AS 2401 fraud procedures:
- Analytical: Compare monthly revenue to prior periods and budgets. Flag unusual spikes (potential channel stuffing)
- Journal entry testing: Sample all manual revenue journal entries >£100k. Trace to customer contract and delivery evidence
- Revenue contracts: Select sample of contracts signed near period-end. Confirm with customer that terms match recorded revenue
- Management estimates: Review discount assumptions in revenue models; challenge against market rates
- Refunds and returns: Trace post-year-end refunds back to pre-year-end revenue; identify channel stuffing patterns
Output: Documented fraud risk assessment, specific procedures linked to risks, and evidence of performance. This is more detailed than ISA typical practice.
Audit Implications
- Planning: PCAOB audits require more upfront planning and risk documentation. Allocate time for fraud risk brainstorming and materiality calculation.
- Control testing: Design of controls is non-negotiable under PCAOB. Budget for detailed control documentation and design testing.
- Fraud: Explicit fraud procedures are mandatory. Do not rely on analytical procedures alone; perform confirmations, journal entry testing, and management interviews.
- EQRP: Ensure an independent partner is assigned early and reviews key judgments (materiality, fraud risk, estimates).
- Documentation: PCAOB requires extensive documentation of procedures, judgments, and conclusions. Document your thinking, not just your procedures.
Need help with PCAOB compliance?
Ask an expert in the Meeting Room — free guidance on PCAOB standards and audit procedures.
Ask an Expert →FAQs
What is the PCAOB?
The Public Company Accounting Oversight Board. A US regulator that sets audit standards (AS) and inspects audit firms for compliance. Mandatory for US public company audits.
What is the difference between PCAOB and ISA?
PCAOB is more prescriptive: mandatory control design testing, explicit fraud procedures, and required independent EQRP review. ISA is more principles-based and less prescriptive.
What is AS 2401?
PCAOB Auditing Standard 2401 on fraud detection. Requires auditors to design specific procedures to detect fraudulent financial reporting and misappropriation of assets.
Do I need to audit internal controls under PCAOB?
For US public companies (accelerated filers), yes — AS 2201 requires an opinion on the effectiveness of internal controls over financial reporting (ICFR). For smaller companies, audit may be limited to financial statements.
This guide is simplified for educational purposes. PCAOB audits are complex and depend on specific client facts, risk assessments, and firm quality control policies. Always consult the full PCAOB AS standards and your own supervisors before finalising audit procedures or conclusions.
Real-Life Case Study: A PCAOB Inspection Finding
Scenario. A registered audit firm is inspected. The PCAOB flags that on one engagement the auditor accepted management's goodwill-impairment cash-flow forecasts without independently challenging the growth assumptions.
The finding. Insufficient audit evidence over a significant estimate, a breach of the standard requiring the auditor to evaluate the reasonableness of management assumptions and test the model. The remediation: enhanced procedures, specialist involvement, and revised methodology guidance firm-wide.
Takeaway. The recurring theme in PCAOB findings is estimates and judgement, impairment, fair value, revenue. "Management said so" is never audit evidence; scepticism means independently corroborating or challenging the key assumptions.
Illustrative composite scenario for educational purposes. Figures are indicative and do not represent any specific company.