AICPA GAAS: Ten Standards, Audit Opinions, and AU-C Codification

The AICPA’s Generally Accepted Auditing Standards, known as GAAS, are the rules a CPA must follow when auditing the financial statements of a private company in the United States. They are issued by the AICPA’s Auditing Standards Board, organized around ten foundational requirements, and expanded into dozens of detailed AU-C sections covering everything from planning the engagement to signing the report. GAAS governs audits of nonissuers only. Public companies whose securities trade on U.S. markets fall under a separate set of standards issued by the PCAOB.

The Ten Foundational Standards

The AICPA originally grouped GAAS into ten standards under three headings: General Standards, Standards of Fieldwork, and Standards of Reporting. The detailed requirements have since been reorganized into the much larger AU-C codification, but these ten still describe what an audit is and how it must be conducted.

General Standards

The three General Standards address the auditor personally.

  • Training and proficiency. The audit must be performed by someone with adequate technical training and competence.
  • Independence. The auditor must maintain an independent mental attitude in all matters related to the engagement.
  • Due professional care. The auditor must exercise reasonable care in performing the audit and preparing the report.

Independence is the requirement that causes the most trouble in practice. The AICPA’s Code of Professional Conduct requires auditors to be independent in both fact and appearance, and even relationships an auditor cannot directly control can impair that independence if a reasonable observer would question their objectivity.1AICPA & CIMA. AICPA Code of Professional Conduct

Standards of Fieldwork

The three Standards of Fieldwork govern how the work is actually done.

  • Planning and supervision. The audit must be adequately planned, and assistants must be properly supervised.
  • Understanding internal control. The auditor must gain enough understanding of the entity’s internal controls to plan the audit and decide what testing is needed.
  • Sufficient appropriate evidence. The auditor must gather enough relevant evidence through inspection, observation, inquiries, and confirmations to support a reasonable opinion.

These three standards map directly to the performance requirements CPAs use every day, now found in the AU-C 300 through 500 series.2Public Company Accounting Oversight Board. AU Section 150 – Generally Accepted Auditing Standards

Standards of Reporting

The four Standards of Reporting dictate what the auditor communicates at the end of the engagement.

  • GAAP compliance. The report must state whether the financial statements follow generally accepted accounting principles.
  • Consistency. The report must identify any circumstance where accounting principles were not consistently applied compared with the prior period.
  • Adequate disclosure. Disclosures are presumed reasonably adequate unless the report says otherwise.
  • Expression of opinion. The report must contain either an opinion on the financial statements as a whole or an explanation of why no opinion can be given. Whenever the auditor’s name is associated with financial statements, the report must clearly indicate the nature and extent of the auditor’s work.2Public Company Accounting Oversight Board. AU Section 150 – Generally Accepted Auditing Standards

How the Ten Standards Live in the AU-C Codification

The ten original standards still capture the philosophy, but CPAs no longer work from the short list alone. Under the AICPA’s Clarity Project, SAS No. 122 recodified and superseded virtually all prior auditing standards into a reorganized set of AU-C sections aligned more closely with International Standards on Auditing.3AICPA & CIMA. AICPA Statement on Auditing Standards No. 122

The AU-C sections fall into numbered ranges that mirror the three original categories:

  • AU-C 200–299 covers General Principles and Responsibilities, including auditor objectives, independence, professional skepticism, engagement terms, and quality control.
  • AU-C 300–699 covers Performance, including planning, risk assessment, responses to assessed risks, audit evidence, sampling, and using the work of specialists or other auditors.
  • AU-C 700–799 covers Reporting, including forming an opinion, report modifications, emphasis-of-matter paragraphs, and supplementary information.4AICPA & CIMA. AICPA Statements on Auditing Standards – Currently Effective

The codification is updated through new Statements on Auditing Standards as the profession evolves.

Who GAAS Applies To

The dividing line between GAAS and PCAOB standards is straightforward. If a company’s securities are registered with the SEC or the company is required to file SEC reports, it is an “issuer” under the Sarbanes-Oxley Act, and its audit falls under PCAOB standards.5Public Company Accounting Oversight Board. Sarbanes-Oxley Act of 2002 Every other entity is a nonissuer, and its audit is performed under AICPA GAAS.

In practice, privately held businesses, nonprofits, employee benefit plans, and government entities typically fall under GAAS. The AICPA’s Auditing Standards Board sets the rules for these engagements; the PCAOB sets the rules for audits of publicly traded companies.6AICPA & CIMA. AICPA Auditing Standards Board The two frameworks share common roots and many overlapping concepts, but they diverge in specific requirements, report format, and oversight.

Independence, Skepticism, and Due Care

The AU-C 200 series translates the original General Standards into detailed requirements. Three concepts run through every engagement.

Independence means the auditor is free from financial interests, family relationships, and business connections that could bias judgment about the client. The Code of Professional Conduct requires independence in both fact and appearance, and a relationship the auditor cannot directly control can still impair independence if a reasonable observer would question the auditor’s objectivity.1AICPA & CIMA. AICPA Code of Professional Conduct

Professional skepticism is an attitude of questioning and critical assessment of audit evidence. It means staying alert for contradictory evidence, indicators of fraud, unusual circumstances, unreliable documents, the possibility of collusion, and ways management might override controls. Skepticism is not suspicion by default. It is a commitment to not accepting information at face value.

Due professional care requires the auditor to bring the competence and diligence needed to perform the audit properly and issue an appropriate report. The standard is what a reasonably skilled auditor would do under the same circumstances, not perfection.

How the Audit Is Performed

The performance standards are where auditing moves from principles to mechanics. This is the longest section of the AU-C codification and the part where most of the work happens.

Planning and Engagement Terms

Every audit begins with a written agreement between the auditor and the client that spells out the scope of the engagement, management’s responsibilities, and the auditor’s responsibilities. The auditor then develops an overall audit strategy setting the scope, timing, and direction of the work, followed by a detailed audit plan specifying which procedures to perform in which areas. Planning is not a one-time event. The strategy and plan get revised as the auditor learns more about the entity.

Risk Assessment

Risk assessment drives the rest of the audit. The auditor identifies and evaluates the risks that the financial statements contain a material misstatement, whether from error or fraud. This evaluation happens at two levels: the financial statements as a whole and individual account balances and disclosures.

To assess risk, the auditor must understand the entity and its environment, including industry, operations, governance, and internal controls. SAS No. 145 significantly expanded the requirements in this area, particularly around understanding the entity’s use of information technology and evaluating IT general controls.7AICPA & CIMA. AICPA Statement on Auditing Standards No. 145 The assessed risks then determine the nature, timing, and extent of every subsequent procedure. Higher risk areas get more testing.

Materiality

Materiality is the threshold at which a misstatement becomes large enough to influence the decisions of someone reading the financial statements. The auditor sets an overall materiality level during planning, then sets a lower amount called performance materiality. Performance materiality creates a buffer so that individually small misstatements do not add up to something material without being caught.

Materiality is a matter of professional judgment, not a fixed formula. The auditor considers the entity’s size, the nature of its business, and the needs of the people who will use the financial statements. A $50,000 misstatement might be immaterial for a company with $200 million in revenue but highly material for a small nonprofit.

Evidence Gathering

The core of fieldwork is collecting enough relevant, reliable evidence to support the opinion. Evidence quality depends on sufficiency (is there enough?) and appropriateness (is it relevant and reliable?). Evidence the auditor obtains directly, such as physical inspection of inventory or independent confirmation from a bank, is more reliable than evidence provided solely by the client.

Common procedures include inspecting records and documents, observing processes in real time, sending confirmations to third parties like banks and customers, recalculating financial data, and performing analytical procedures that compare reported figures against expected patterns. Throughout, the auditor maintains professional skepticism, particularly when evaluating information provided by management.

Communicating Internal Control Issues

The auditor evaluates internal controls not to opine on their effectiveness but to plan the right procedures. When that evaluation turns up problems, AU-C 265 requires written communication. Two categories matter:

  • A material weakness is a deficiency severe enough that there is a reasonable possibility a material misstatement will not be prevented or caught in time.
  • A significant deficiency is less severe than a material weakness but still important enough to warrant attention from those charged with governance.

The written communication must go to those charged with governance, typically the board or audit committee, no later than 60 days after the audit report is released. The letter explicitly states that the audit was not designed to identify every control deficiency, so additional problems may exist beyond those reported.8AICPA & CIMA. AU-C Section 265 – Communicating Internal Control Related Matters Identified in an Audit

Management Representations

Near the end of the audit, the auditor obtains a signed representation letter from management. AU-C 580 treats these written representations as necessary audit evidence, in which management confirms that it has fulfilled its responsibility for preparing the financial statements, provided all relevant information and access, and recorded all transactions.

If management refuses to provide these representations, the consequences are severe. The auditor must either disclaim an opinion or withdraw from the engagement. Even refusal to provide a single requested representation can result in a qualified opinion or disclaimer, depending on the significance of what is missing.9AICPA & CIMA. AU-C Section 580 – Written Representations

The Audit Report and the Four Types of Opinion

The audit report is the only deliverable most financial statement users ever see, and its format is tightly prescribed by the AU-C 700 series.4AICPA & CIMA. AICPA Statements on Auditing Standards – Currently Effective The standard report includes the auditor’s opinion, the basis for that opinion, a description of management’s responsibilities, and a description of the auditor’s responsibilities. It must state that the audit was conducted in accordance with GAAS.

Unmodified (Clean) Opinion

An unmodified opinion means the auditor concluded that the financial statements are presented fairly in all material respects under the applicable framework, usually GAAP. This is the outcome every entity wants. It tells lenders, investors, and other users that the auditor gathered sufficient evidence and found no material misstatements. The unmodified report is the default structure. Every other opinion type is a departure from it.

Qualified Opinion

A qualified opinion says the financial statements are fairly presented except for the effects of a specific matter. Two situations trigger a qualification: the auditor found a material misstatement that is not pervasive, or the auditor was unable to obtain sufficient evidence on a particular area due to a scope limitation that is similarly not pervasive. The key phrase is “except for.” If management refuses to let the auditor observe a physical inventory count but the rest of the audit proceeds normally, the qualification would address that one limitation.

Adverse Opinion

An adverse opinion is the most damaging conclusion an auditor can reach. It means the misstatements are both material and pervasive, affecting a substantial portion of the financial statements or undermining disclosures fundamental to users’ understanding. The report explicitly states that the financial statements are not presented fairly. An adverse opinion almost always triggers serious consequences with lenders and investors.

Disclaimer of Opinion

A disclaimer means the auditor could not gather enough evidence to form any opinion, and the potential effects of the missing evidence are both material and pervasive. The auditor is not saying the financial statements are wrong. They are saying they cannot tell. A disclaimer is also required when independence has been impaired, regardless of the evidence gathered.

Common triggers include severe client-imposed scope limitations, destruction of records, and situations where the entity’s ability to continue operating is so uncertain that meaningful conclusions are impossible. A disclaimer provides no assurance, which makes it extremely damaging to the entity’s credibility with outside parties.

Emphasis-of-Matter and Other-Matter Paragraphs

Sometimes the auditor wants to draw attention to something properly presented in the financial statements but important enough that users should not miss it. An emphasis-of-matter paragraph serves that purpose. Common examples include a significant related-party transaction, an important subsequent event, or the adoption of a new accounting standard that materially changes how the financial statements look compared with the prior year.

An other-matter paragraph covers issues relevant to understanding the audit itself rather than the financial statements, such as the fact that the prior-year financial statements were audited by a different firm. Neither paragraph type changes the opinion.

Going Concern

AU-C 570 requires the auditor to evaluate whether there is substantial doubt about the entity’s ability to continue operating for a reasonable period. If substantial doubt exists, the financial statements must include adequate disclosure, and the auditor’s report must include an emphasis-of-matter paragraph highlighting the uncertainty. This evaluation looks at factors like recurring operating losses, negative cash flows, loan defaults, and loss of a major customer or supplier. A going concern disclosure does not mean the entity is going to fail. It means the auditor identified conditions that raise serious questions about its future.

What Happens When an Auditor Fails to Follow GAAS

An auditor who fails to follow GAAS faces overlapping layers of accountability, ranging from professional discipline to civil liability.

The AICPA can impose sanctions on members who violate professional standards. Lower-level responses include a letter of required corrective action directing the member to complete up to 80 hours of continuing education, submit future work for outside review, or both. For more serious violations, the AICPA’s Joint Trial Board can publicly admonish a member, suspend membership for up to two years, or expel the member entirely. Expulsions and suspensions are published publicly.10AICPA & CIMA. Explanations of Sanctions

CPA licenses are issued at the state level, and each state’s board of accountancy has independent authority to investigate complaints about audit quality. Depending on the state, penalties can include fines, mandatory additional education, practice restrictions, license suspension, or permanent revocation. A state board action can end an auditor’s career regardless of what the AICPA does, because the license itself comes from the state.

Courts routinely use GAAS as the benchmark for evaluating whether an auditor met their professional obligations. Common claims include professional negligence, breach of contract, and fraud. A negligence claim requires showing the auditor owed a duty of care, breached that duty by failing to follow applicable standards, and that the breach directly caused measurable financial harm. Auditors can also face liability for intentional misconduct, including knowingly misrepresenting financial information or helping a client commit fraud. Fraud claims can carry punitive damages and are much harder to defend than negligence claims.

GAAS Is Not GAAP

People frequently mix up GAAS and GAAP, and the distinction matters. GAAP, Generally Accepted Accounting Principles, governs how the financial statements are prepared: which revenues to recognize, how to value assets, what to disclose. GAAS governs how the audit of those financial statements is performed: what evidence to gather, how to assess risk, and what to report. Management is responsible for following GAAP. The auditor is responsible for following GAAS to determine whether management actually did.