PCAOB Auditing Standard No. 12 requires the auditor of a public company to identify and assess where the financial statements are most likely to contain a material misstatement, and to use that assessment as the blueprint for every test performed during the rest of the audit. The standard’s full title is “Identifying and Assessing Risks of Material Misstatement.” It was adopted in 2010 and renumbered AS 2110 when the PCAOB reorganized its auditing standards in 2016.1Public Company Accounting Oversight Board. PCAOB Auditing Standards Reorganized and Pre-Reorganized Reference Table Both designations still appear in practice. They refer to the same standard.
The standard governs audits of SEC-registered issuers. It does not apply to private company audits, which follow AICPA standards. In an integrated audit, the risks identified under AS 12 drive testing for both the financial statement opinion and the internal control opinion — the assessment is done once and serves the entire engagement.2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement
Understanding the Company Before Assessing Risk
The standard requires the auditor to build a detailed picture of the company before drawing any conclusions about risk. That understanding is organized into five categories: relevant industry, regulatory, and external factors; the nature of the company; its accounting principles and disclosures; its objectives, strategies, and related business risks; and its methods for measuring and analyzing financial performance.2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement
External factors cover the competitive environment, technological change, the regulatory setting, and economic conditions. A company operating in a shifting regulatory space carries different reporting risks than one in a mature, stable industry. Changes in accounting standards or SEC disclosure requirements count too.
The nature of the company means the organizational structure, management personnel, capital structure and other funding sources, significant investments such as joint ventures or equity-method interests, and key supplier and customer relationships. A company that depends on a single customer for 40% of revenue presents a different profile than one with a diversified base, even at identical revenue.
Objectives and strategies matter because they trace directly into financial reporting exposure. An aggressive acquisition strategy introduces complex fair value measurements for acquired assets and goodwill impairment work. The auditor connects the company’s ambitions to the accounts where those ambitions create room for misstatement.
Performance measures get their own scrutiny for a specific reason: measures that drive compensation or contractual commitments create pressure to hit targets, and pressure produces biased estimates and aggressive accounting. If management bonuses hinge on an EBITDA target, that incentive belongs in the risk assessment for revenue recognition and expense timing. External measures used by analysts and rating agencies create similar pressure.
Evaluating Internal Controls
AS 12 requires the auditor to obtain a sufficient understanding of each component of the company’s internal control over financial reporting. The standard organizes controls into five components:
- Control environment: the tone at the top, management’s integrity and ethical values, and the culture around controls. A weak control environment often signals problems everywhere else.
- Risk assessment process: how management itself identifies and responds to business risks that could affect financial reporting.
- Control activities: the specific policies and procedures carrying out management’s directives, including approvals, reconciliations, performance reviews, and segregation of duties.
- Information and communication: the accounting systems that capture transactions and communicate financial reporting responsibilities.
- Monitoring: how the company evaluates whether its controls are actually working over time.
The depth of this work scales with the size and complexity of the company. A smaller company with straightforward operations does not require the same procedures as a multinational with dozens of subsidiaries and multiple ERP systems.2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement
For each relevant control, the auditor performs two distinct evaluations. Design asks whether the control, if it operated perfectly, would actually prevent or detect a misstatement. Implementation asks whether the control exists in practice and is being used by the people responsible for it. A well-designed approval process means nothing if nobody follows it. Both conclusions feed the control risk component of the overall assessment.
Technology and IT System Risks
Appendix B of the standard addresses how a company’s use of information technology affects the audit. The auditor must understand the mix of manual and automated controls, including the IT general controls that keep automated processes functioning properly.2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement The IT-specific risks the auditor must consider include:
- Systems that process data inaccurately or process inaccurate data
- Unauthorized access to data, especially when multiple users share a common database
- IT personnel gaining access beyond what their duties require, which breaks down segregation of duties
- Unauthorized changes to data in master files, systems, or programs
- Failure to make necessary changes to systems or programs
- Inappropriate manual intervention in automated processes
- Loss of data or inability to access data when needed
As companies rely more heavily on automated processes to initiate, record, and report transactions, the traditional paper-trail audit gives way to evaluating whether the systems themselves are reliable. A revenue cycle running entirely through an ERP means the auditor cannot just examine invoices. The auditor has to understand whether the system’s logic captures transactions accurately and whether access controls prevent unauthorized changes.
The Mandatory Fraud Brainstorming Session
All key engagement team members, including the engagement partner, must participate in a discussion about how and where the company’s financial statements could be susceptible to material misstatement through fraud.2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement The discussion must be approached with professional skepticism, setting aside prior assumptions about management’s honesty, and it must cover:
- How management could perpetrate and conceal fraudulent financial reporting, including through related party transactions, incomplete disclosures, and biased accounting estimates
- How company assets could be misappropriated
- External and internal factors that create incentives, pressure, or opportunity for fraud
- The risk of management override of controls, which is always present regardless of how strong the control environment appears
- Potential audit responses to the identified fraud susceptibilities
PCAOB inspectors look closely at whether the documentation reflects a genuine exchange of ideas or just a completed form. For multi-location audits, the discussion may occur in several sessions, but the engagement partner or another senior team member must communicate the important takeaways to anyone who was not present.
Identifying Risks and Linking Them to Assertions
Everything gathered so far feeds into the formal risk assessment. Risk of material misstatement has two components. Inherent risk is the likelihood that an assertion is wrong before considering controls; a derivative valuation involving complex models and significant judgment carries more inherent risk than a straightforward cash balance. Control risk is the chance that the company’s own controls will fail to catch or prevent a misstatement. High inherent risk paired with weak controls is the combination that demands the most audit attention.3Public Company Accounting Oversight Board. AS 1101 – Audit Risk
Each identified risk must be tied to specific financial statement assertions at the account and disclosure level. Under AS 1105, assertions fall into five categories: existence or occurrence, completeness, valuation or allocation, rights and obligations, and presentation and disclosure.4Public Company Accounting Oversight Board. AS 1105 – Audit Evidence Linking a risk to an assertion is what makes the audit response precise. A risk that the company may be recording revenue too early directs testing at the occurrence and cutoff aspects of revenue transactions, not at a vague “look at revenue.”
Significant Risks
Some risks rise to the level of “significant risks,” which require special audit consideration. The auditor weighs seven factors:2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement
- The likelihood and potential size of a misstatement based on quantitative and qualitative factors
- Whether the risk involves fraud, in which case it is automatically a significant risk
- Whether the risk relates to recent significant economic, accounting, or other developments
- The complexity of the underlying transactions
- Whether the risk involves significant related party transactions
- The degree of judgment involved in measuring the financial information, especially where a wide range of possible outcomes exists
- Whether the risk involves significant unusual transactions
Fraud risks are automatically significant risks. The audit team cannot treat fraud as a low priority no matter how trustworthy management appears. Significant risks call for more intensive procedures, often performed closer to the balance sheet date to shrink the window for manipulation.
What the Assessment Feeds Into
The risk assessment under AS 12 is the starting point for AS 2301, which governs the auditor’s responses. AS 2301 requires the auditor to design and perform procedures that directly address each assessed risk for every relevant assertion of each significant account and disclosure.5Public Company Accounting Oversight Board. PCAOB Auditing Standards
The connecting principle is proportionality: the higher the assessed risk, the more persuasive the evidence must be. A low-risk account with strong controls may be addressed with analytical procedures and limited sampling. A high-risk area flagged as a significant risk demands detailed testing, larger samples, and procedures timed closer to year-end. When the risk assessment is done poorly, the downstream consequences cascade, which is why PCAOB inspection teams spend so much time on risk assessment documentation.
Documentation Requirements
The workpapers must record the understanding gained about the company and its environment, the evaluation of internal controls (both design and implementation conclusions), and the specific risks of material misstatement identified.2Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement
Each identified risk must be linked to the specific assertion it affects. The documentation should show, for example, that the risk of premature revenue recognition was tied to the occurrence and presentation assertions for revenue accounts. The assessment of likelihood and magnitude has to be recorded for each risk, along with the rationale for designating any risk as significant.
The fraud brainstorming session needs its own documentation. Inspectors evaluate whether the recorded discussion reflects genuine engagement rather than a perfunctory exercise, so the workpapers should capture the specific fraud scenarios considered, the factors creating incentives or opportunities, and the planned response.
Amendments Effective in 2026
The PCAOB has adopted amendments to AS 2110 with an effective date of December 15, 2026.6Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement (Effective on 12-15-2026) Related amendments to AS 1105 and AS 2301, addressing how auditors design and perform procedures involving technology-assisted analysis, take effect for fiscal years beginning on or after December 15, 2025.7Public Company Accounting Oversight Board. Amendments Related to Aspects of Designing and Performing Audit Procedures Firms planning 2026 engagements should review the amended text of AS 2110, which the PCAOB has published with the changes highlighted, to make sure their risk assessment procedures reflect the updated requirements.