SAS 149: Risk-Based Scoping, Component Auditors, and SAS 145

SAS 149 replaces AU-C Section 600 and rewrites how group financial statement audits work, effective for audits of periods ending on or after December 15, 2026. The core change: you no longer classify components as “significant” and apply a prescribed program. You assess the risks of material misstatement at the group level and let those risks drive what work is done, at which components, and by whom. For firms auditing consolidated or combined financial statements, SAS 149 group audits will demand more judgment, more partner involvement, and more documentation than the model they are used to.

What SAS 149 Replaces

SAS 149 supersedes AU-C Section 600, previously titled “Special Considerations — Audits of Group Financial Statements (Including the Work of Component Auditors).” The old standard leaned on the concept of “significant components,” which functioned as a binary test: a component was either significant, which triggered a prescribed set of audit procedures, or it was not. That bright-line approach could lead to over-auditing some components and under-auditing others, regardless of where the actual risk sat.

The AICPA describes the new approach as principles-based. Rather than checking a box for significance, the group auditor evaluates each component through the risks it poses to the group financial statements and tailors procedures accordingly.

Risk-Based Scoping in Place of Significant Components

The biggest conceptual change is scoping. Under the prior standard, a component qualified as significant based on financial size or individually significant risks, and that classification drove the work. SAS 149 abandons the classification entirely. The group auditor determines the nature, timing, and extent of work at each component based on the assessed risks of material misstatement of the group financial statements, using professional judgment.

A financially small subsidiary operating in a high-risk jurisdiction or running complex revenue arrangements could receive more audit attention than a larger but straightforward component. A large subsidiary with stable, low-risk operations might not need a full-scope audit if the risk assessment supports that conclusion. Work follows the risk, not the relative size.

The old model gave a defensible default: if the component was significant, you did the prescribed work. Now every scoping decision needs an affirmative risk-based rationale, and that rationale needs to hold up under peer review.

Component Auditors and Referred-to Auditors

SAS 149 draws a sharp line between two categories of auditors who may work on pieces of a group’s financial statements, and the distinction changes who is responsible for what.

A component auditor performs work on a component as part of the engagement team. The group auditor directs and supervises that work, reviews it, and takes responsibility for it. Treat a component auditor as an extension of your own team at another location.

A referred-to auditor is one whose work is referenced in the group audit report but who is not part of the engagement team. The group auditor does not direct, supervise, or review a referred-to auditor’s work in the same way.

Under the old standard, “component auditor” could describe either arrangement, which blurred accountability. SAS 149 removes that ambiguity. When you involve a component auditor, you bear responsibility for their risk assessment and the sufficiency of their procedures. When you reference a referred-to auditor, you are relying on their independent professional judgment, and your report language reflects that reliance. With a component auditor you control the response to identified risks; with a referred-to auditor you do not.

What the Group Engagement Partner Has to Do

SAS 149 puts the group engagement partner at the center of risk assessment for the whole group. The partner is ultimately responsible and accountable for compliance with the standard, and the standard expects involvement well beyond signing off on the final file.

The partner must be sufficiently and appropriately involved throughout the engagement, including in the work of component auditors, to have a basis for determining whether significant judgments and conclusions are appropriate. In practice, that involvement includes:

  • Direction and supervision of component auditors that accounts for areas of higher assessed risks of material misstatement and areas involving significant judgment.
  • Regular communication with component auditors about identified risks, findings, and conclusions throughout the audit, not only at the end.
  • Review of component auditor work papers, either in person or remotely where law and regulation permit.
  • Attendance at closing meetings or other critical discussions between component auditors and component management.

The partner can delegate the design or performance of specific procedures to other appropriately skilled team members, including component auditors. Delegation does not shift accountability. If a component auditor’s risk assessment misses something material, the group engagement partner owns the outcome.

Two-Way Communication of Risk Information

SAS 149 requires risk-related information to flow in both directions between the group auditor and component auditors. This is an explicit set of requirements with specific content expectations, not guidance buried in an appendix.

The group auditor must communicate to component auditors, on a timely basis, matters relevant to the component auditor’s risk assessment procedures for purposes of the group audit, including identified significant risks of the group financial statements. If a fraud risk identified at the group level could manifest at a particular component, the component auditor needs to know before completing their risk assessment.

Component auditors, in turn, must communicate back to the group auditor any matters related to the component’s financial information that are relevant to identifying and assessing the risks of material misstatement of the group financial statements, whether due to fraud or error. The component auditor functions as the group auditor’s eyes and ears at the component level, and SAS 149 formalizes that feedback loop.

“Timely” means early enough to actually influence the risk assessment and audit plan. A list of component-level risks delivered after fieldwork is complete does not meet the requirement.

Fraud Escalation

Component auditors must report to the group auditor any fraud or suspected fraud involving component management, employees who play significant roles in the group’s internal control at the component, or others where the fraud resulted in a material misstatement of the component’s financial information.

When the group auditor identifies fraud or is told about it by a component auditor or referred-to auditor, the group auditor must communicate that finding on a timely basis to the appropriate level of group management. This closes a gap that existed in practice: under the old standard, a component auditor might treat a fraud indicator as a local issue and never escalate it to a level where a pattern across components could be seen. Under SAS 149, that escalation is mandatory.

Consolidation and Aggregation Risk

The consolidation process is a distinct risk area under SAS 149. The group auditor takes direct responsibility for designing and performing procedures to respond to the assessed risks of material misstatement arising from consolidation, including risks due to fraud in that process. That covers intercompany eliminations, consolidation adjustments, reclassifications, and the mechanical combination of component-level information into group financial statements.

Aggregation risk gets specific attention as well. This is the risk that individually immaterial misstatements across multiple components combine into a material misstatement at the group level. The standard notes that aggregation risk exists in all financial statement audits but is particularly important in group audits, where dozens of components can each carry small errors that accumulate. Focusing energy on the largest components and giving smaller ones minimal attention no longer works: aggregation risk means a component cannot simply be ignored because its individual misstatement risk seems low.

Documentation

SAS 149 raises the documentation bar. The group auditor must document the nature, timing, and extent of direction and supervision of component auditors, along with the review of their work. When the group auditor reviews additional component auditor documentation beyond what was originally planned, that review must also be documented.

The standard addresses situations where access to a component auditor’s work papers is restricted by law, regulation, or practical constraint. The group auditor must document what was done, including any alternative procedures performed to compensate for the restricted access.

For scoping, the rationale for the nature and extent of work performed at each component needs to be traceable to the risk assessment. Under the old model, the “significant component” designation was the justification. Under SAS 149, every scoping decision requires a documented risk-based rationale, and peer reviewers will look for a clear thread from the group-level risk assessment through the component-level work plan to the procedures performed.

How SAS 149 Connects to SAS 145

SAS 149 builds on the risk assessment framework in SAS 145, which revised AU-C Section 315 and took effect for periods ending on or after December 15, 2023. SAS 145 introduced inherent risk factors (subjectivity, complexity, change, uncertainty, and susceptibility to management bias), the spectrum of inherent risk, and enhanced IT risk assessment requirements. Those concepts apply to every audit, group audits included.

SAS 149 extends that framework across a multi-entity structure. The group auditor uses AU-C Section 315 to assess risks at the group level and to guide the risk assessment work performed at each component. Significant risks identified under Section 315 drive decisions about which components need the most attention and what procedures component auditors perform. A firm that implemented SAS 145 for the 2024 audit cycle already has the underlying methodology in place; SAS 149 layers the group audit dimension on top.

Preparing for December 15, 2026

Any audit of group financial statements for a period ending on or after December 15, 2026 must comply with SAS 149. For calendar-year entities that is the December 31, 2026 audit. Preparation falls into three practical areas.

Engagement teams need training on the principles-based scoping model, particularly the move away from the significant-component approach many auditors have used for their entire careers. Communication protocols with component auditors need to build in the two-way risk communication requirements early in the engagement timeline rather than treating them as wrap-up items. Documentation templates and work programs need updates that capture the risk-based rationale for scoping decisions, the group engagement partner’s involvement, and the flow of risk information between auditors.