Auditing Standard No. 5: SOX 404 Audits and ICFR Opinions

Auditing Standard No. 5 is the Public Company Accounting Oversight Board rule that governs how an external auditor tests and reports on whether a public company’s internal controls over financial reporting actually work. Issued in 2007, it replaced Auditing Standard No. 2, which had been criticized as rigid and expensive, especially for smaller filers. In 2016 the PCAOB renumbered the rule as AS 2201, but the substance did not change and practitioners still refer to it as AS 5.

The standard exists to carry out Section 404 of the Sarbanes-Oxley Act. It tells the auditor how to plan the work, what to test, how to classify what they find, and what opinion to issue at the end.

What SOX 404 Requires

Section 404 of Sarbanes-Oxley has two parts, and they do different things.

Section 404(a) applies to every public company. Management must include an internal control report in each annual filing, state that management is responsible for maintaining an adequate internal control structure, and give management’s own assessment of whether those controls are effective at fiscal year-end.1Office of the Law Revision Counsel. 15 U.S. Code 7262 – Management Assessment of Internal Controls

Section 404(b) adds the auditor. The company’s external auditor must independently evaluate and report on management’s assessment, following PCAOB standards, and the attestation cannot be run as a separate engagement from the financial statement audit.1Office of the Law Revision Counsel. 15 U.S. Code 7262 – Management Assessment of Internal Controls That is why AS 5 is called an integrated audit: one engagement produces two opinions, one on the financial statements and one on the effectiveness of internal control over financial reporting (ICFR).2Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements

The two sides feed each other. A material weakness discovered while testing controls changes the scope of the financial statement audit. Unusual transactions flagged during the financial statement audit prompt more scrutiny of the controls meant to handle them.

Which Companies Are Subject to the AS 5 Audit

Not every public company gets the full auditor attestation. Section 404(b) applies to accelerated filers and large accelerated filers. An accelerated filer generally has a public float between $75 million and $700 million, has been filing with the SEC for at least 12 months, and has filed at least one annual report.3eCFR. 17 CFR 240.12b-2 – Definitions A large accelerated filer has a public float of $700 million or more. Both must have the auditor perform the ICFR audit every year.

Several categories are exempt from 404(b) but still owe the 404(a) management assessment:

  • Non-accelerated filers, meaning companies with a public float below $75 million. Dodd-Frank made this exemption permanent in 2010.
  • Emerging growth companies, which qualify if annual gross revenue stays below an inflation-adjusted threshold (originally $1 billion, now $1.235 billion). EGC status ends at the earliest of the fifth anniversary of the IPO, exceeding the revenue threshold, becoming a large accelerated filer, or issuing more than $1 billion in nonconvertible debt in three years.4U.S. Securities and Exchange Commission. JOBS Act Inflation Adjustments
  • Smaller reporting companies with annual revenues below $100 million, which under 2020 amendments fall outside the accelerated filer definition entirely.5U.S. Securities and Exchange Commission. Accelerated Filer and Large Accelerated Filer Definitions

If you fall into an exempt category, you still need working controls and a written management report. You just do not need the auditor to attest to them.

The Top-Down, Risk-Based Approach

The core methodology of AS 5 is top-down and risk-based.6Public Company Accounting Oversight Board. Auditing Standard No. 5 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements Rather than testing every control a company has, the auditor starts at the financial statement level and works downward to the controls that actually matter for preventing a material misstatement. That was the deliberate departure from AS 2, where auditors ended up testing large numbers of controls regardless of importance.

The auditor first identifies significant financial statement accounts and disclosures and considers the relevant assertions for each: existence, completeness, valuation, rights, and presentation.7Public Company Accounting Oversight Board. Auditing Standard No. 15 – Audit Evidence – Section: Financial Statement Assertions A revenue account carries a high risk of fictitious sales, so existence becomes a priority. That risk assessment drives which controls get selected for testing. The auditor concentrates on “key controls” that directly address a meaningful risk and generally leaves the rest alone.

The standard also lets the auditor scale the work to the company. A smaller, simpler business has fewer significant accounts, simpler transaction flows, and fewer key controls. Sample sizes and testing procedures follow the auditor’s professional judgment about the control environment and inherent risk.6Public Company Accounting Oversight Board. Auditing Standard No. 5 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements

Entity-Level and IT General Controls

Before testing transaction-level controls, the auditor evaluates entity-level controls (ELCs). These are company-wide controls that shape everything underneath them.2Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements AS 5 groups them into several categories:

  • The control environment, or “tone at the top” set by leadership.
  • Controls over management override, which matter most at smaller companies where senior managers are close to daily operations.
  • The company’s risk assessment process for identifying threats to reliable financial reporting.
  • Monitoring controls, including internal audit, audit committee oversight, and self-assessment programs.
  • The period-end financial reporting process, covering journal entries, consolidation adjustments, and disclosures.
  • Policies addressing broader business control and risk management.

Strong ELCs can support reduced testing at the transaction level. Weak ELCs push the auditor to expand transaction-level work. A broken risk assessment process, for example, suggests management may not have identified all the risks that need controls in the first place.

For companies that rely on automated systems for financial reporting, the auditor also evaluates IT General Controls (ITGCs). The main categories are access controls (who can enter financial systems and what they can do), change management (how software updates and system changes are tested and deployed), and audit logging. If ITGCs are weak, the auditor cannot rely on the automated controls those systems perform, and the amount of manual testing rises accordingly.

How the Auditor Tests Controls

Once key controls are identified, the auditor tests whether they operate. AS 5 recognizes four testing procedures, from weakest to strongest evidence:2Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements

  • Inquiry: asking management and staff how a control operates. Never sufficient on its own.
  • Observation: watching the control being performed.
  • Inspection: reviewing documents, reports, or reconciliations that evidence the control.
  • Reperformance: the auditor independently executes the control to see if it produces the same result. The most rigorous test.

The right method depends on the control. A manual review might warrant reperformance. An automated control embedded in software calls for testing access restrictions and change management around it rather than rerunning the calculation. Smaller companies with less formal documentation tend to lean more on inquiry combined with observation and inspection of the records they do keep.

How Deficiencies Are Classified

When testing reveals a control failure, the auditor assigns it one of three severity levels:

  • Control deficiency: a control’s design or operation does not allow employees to prevent or detect misstatements on a timely basis. The lowest-severity finding.8Public Company Accounting Oversight Board. Auditing Standard 5 – Appendix A
  • Significant deficiency: a deficiency, or combination, less severe than a material weakness but serious enough to warrant attention from those overseeing financial reporting.8Public Company Accounting Oversight Board. Auditing Standard 5 – Appendix A
  • Material weakness: a deficiency, or combination, where there is a reasonable possibility that a material misstatement will not be caught in time. This is the finding that changes the opinion.8Public Company Accounting Oversight Board. Auditing Standard 5 – Appendix A

Communication requirements track severity. The auditor must communicate all deficiencies to management in writing and inform the audit committee that such a communication was made.9Public Company Accounting Oversight Board. Auditing Standard No. 5 Paragraph 81 Significant deficiencies and material weaknesses must be communicated in writing to both management and the audit committee.10Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements

The Three Possible ICFR Opinions

The audit ends with an opinion on the effectiveness of ICFR. The auditor can issue one combined report covering both the financial statements and ICFR, or separate reports.2Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements There are three possible outcomes, and no middle ground:

There is no qualified ICFR opinion under this standard. A single material weakness in an otherwise strong control environment still triggers an adverse opinion. That opinion also cascades into the financial statement side: the auditor expands substantive testing to compensate for the unreliable controls, which raises both cost and duration.

Remediating a Material Weakness

A material weakness does not have to be permanent. Most companies begin remediation immediately after an adverse opinion, redesigning controls and demonstrating effective operation by the next year-end ICFR audit.

For faster resolution, the PCAOB offers an optional engagement under AS 6115. The auditor evaluates whether a previously reported material weakness still exists as of a specific date chosen by management, which can be any date after the most recent annual assessment.11Public Company Accounting Oversight Board. AS 6115 – Reporting on Whether a Previously Reported Material Weakness Continues to Exist The opinion is narrow: it covers only the specific material weakness, not overall ICFR effectiveness.

Before the auditor can proceed, management must accept responsibility for ICFR effectiveness, evaluate the new controls using the same criteria from the last annual assessment, assert in writing that the new controls are effective, and support the assertion with sufficient evidence and documentation.11Public Company Accounting Oversight Board. AS 6115 – Reporting on Whether a Previously Reported Material Weakness Continues to Exist If any condition is not met, the engagement cannot be completed. The auditor also has to test both design and operating effectiveness, because a control that looks well-designed on paper is not enough without evidence that it works.