What Are External Auditors Responsible For?

External auditors are responsible for independently examining a company’s financial statements and issuing a formal opinion on whether those statements give a materially accurate picture of the company’s finances under the applicable accounting rules. That opinion is the core deliverable, but the role carries a wider set of duties around it: setting materiality, hunting for fraud, judging whether the company can survive the next year, testing internal controls at public companies, staying independent of the client, following professional standards, communicating findings to the audit committee, and escalating illegal acts. Each duty is defined by professional standards, and regulators can fine or bar auditors who fall short.

Issuing an Opinion on the Financial Statements

The single most important thing an external auditor does is issue a written opinion on whether the company’s financial statements are presented fairly, in all material respects, under the applicable framework (usually U.S. Generally Accepted Accounting Principles).1Public Company Accounting Oversight Board. AS 3101 – The Auditor’s Report on an Audit of Financial Statements When the Auditor Expresses an Unqualified Opinion That opinion appears in the auditor’s report attached to the financial statements, and it is the document investors, lenders, and regulators actually read.

A distinction matters here. Management prepares the financial statements and is responsible for their accuracy. The auditor checks management’s work from the outside. The auditor does not draft the numbers, pick the accounting policies, or design the company’s controls. When the auditor signs off, they are saying the picture is materially correct based on the evidence they gathered.

That signoff provides “reasonable assurance,” which is a high level of confidence but not a guarantee. Auditors test samples rather than every transaction, management exercises judgment in applying accounting rules, and sophisticated fraud can defeat even well-designed procedures.

The Four Opinion Types

Every audit opinion falls into one of four categories:

  • An unmodified (clean) opinion says the financial statements are presented fairly in all material respects. This is the standard result.
  • A qualified opinion says the statements are generally fair “except for” a specific material issue the auditor spells out.
  • An adverse opinion says the statements are not presented fairly. Misstatements are both material and pervasive.
  • A disclaimer of opinion says the auditor could not gather enough evidence to form any opinion, usually because access to records was restricted.

A qualified or adverse opinion can raise borrowing costs and trigger loan covenant violations. A disclaimer effectively tells the market the statements cannot be relied on.

Deciding What Counts as Material

Every opinion hinges on materiality, and the concept is less mechanical than it sounds. A misstatement is material if a reasonable investor would consider it important enough to change their decision. That standard comes from the Supreme Court’s “total mix” test, which the PCAOB has built into its auditing standards.2Public Company Accounting Oversight Board. AS 2810 – Evaluating Audit Results

Auditors often start with a quantitative benchmark, such as 5% of pre-tax income, to set a preliminary threshold. But the SEC has made clear that a purely numerical approach is not acceptable. Both quantitative and qualitative factors matter.3U.S. Securities and Exchange Commission. Staff Accounting Bulletin No. 99 – Materiality A small-dollar misstatement can still be material if it turns a reported loss into a profit, masks a failure to meet analyst expectations, involves an illegal payment that could trigger larger liabilities, or hides a loan covenant violation.2Public Company Accounting Oversight Board. AS 2810 – Evaluating Audit Results

Uncorrected misstatements have to be evaluated both individually and in combination. Small errors that each look harmless can add up to a material problem when viewed together, and the auditor also has to consider misstatements carried over from prior years that were never corrected.

Looking for Fraud and Error

Auditors are responsible for obtaining reasonable assurance that the financial statements are free of material misstatement, whether caused by honest mistakes or intentional fraud. Fraud is harder to find because people who commit it actively conceal it, forge documents, and exploit gaps in internal controls.

PCAOB standards require the audit team to hold a brainstorming session during planning to discuss how and where the financial statements could be vulnerable to fraud.4Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit Every member of the engagement team participates, and the discussion has to be documented. The mindset the auditor is expected to bring is “professional skepticism,” which means neither assuming management is lying nor assuming they are telling the truth. The auditor keeps a questioning stance and insists on persuasive evidence before accepting any assertion.

Regardless of assessed risk levels, every audit has to include testing of journal entries and other adjustments for signs of management override of controls.4Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit Management override is the auditor’s toughest problem, because the people running the company can manipulate the accounting records and bypass controls that work perfectly against everyone else. The auditor also has to ask people involved in financial reporting about any inappropriate or unusual activity related to journal entries.

Where fraud risk in a particular area is high, testing gets more intensive. If revenue recognition looks vulnerable, the auditor examines more sales transactions, tests cutoff dates harder, and looks for side agreements or unusual terms. If fraud is actually discovered, it has to be communicated to the appropriate level of management and to the audit committee. None of this makes the auditor an insurer. A well-executed fraud involving collusion or sophisticated document forgery can escape detection even in a properly conducted audit.

Judging Whether the Company Can Keep Operating

Auditors have to evaluate whether there is “substantial doubt” about the company’s ability to continue as a going concern for up to one year beyond the date of the financial statements.5Public Company Accounting Oversight Board. AS 2415 – Consideration of an Entity’s Ability to Continue as a Going Concern It is one of the most consequential calls in an audit. A going concern paragraph in the report can accelerate the very crisis it describes; lenders tighten terms, suppliers demand cash, and investors bail out.

The auditor is not required to design special procedures to hunt for going concern problems. The regular audit work (reviewing debt covenants, analyzing cash flow trends, reading board minutes, confirming financial support arrangements) should surface the warning signs. When those signs appear, the auditor digs into management’s plans for addressing them and assesses whether the plans are realistic. A company burning cash but holding a firm financing commitment is in a different position than one whose turnaround plan rests on vague hopes of improved sales.

If substantial doubt remains after considering management’s plans, the auditor adds an explanatory paragraph to the report and evaluates whether the company’s disclosures adequately warn readers.5Public Company Accounting Oversight Board. AS 2415 – Consideration of an Entity’s Ability to Continue as a Going Concern The auditor is not responsible for predicting the future. They are responsible for flagging present conditions that cast doubt on survival.

Auditing Internal Controls at Public Companies

For public companies, auditors perform an “integrated audit” that covers both the financial statements and the effectiveness of internal controls over financial reporting. The auditor issues two opinions: one on the statements and a separate one on whether the company’s controls are working well enough to prevent or catch material misstatements.6Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated With an Audit of Financial Statements

Testing controls means examining whether the processes the company uses to produce reliable financial data, such as segregation of duties, authorization procedures, and reconciliations, are properly designed and actually operating as intended. The two opinions can appear in a single combined report or in separate reports.

When the auditor finds a “material weakness” (a deficiency serious enough that a material misstatement could slip through undetected), an unqualified opinion on internal controls is not available. The weakness has to be reported to the audit committee.7Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements Investors get visibility into the reliability of the company’s financial reporting infrastructure, not just the end product.

Staying Independent of the Client

Independence is what separates an external audit from an internal review. An auditor with a financial stake in the outcome, or a cozy relationship with management, produces a worthless opinion. The rules push on two dimensions: the auditor must actually be unbiased (independence in fact) and must avoid situations that would make a reasonable outsider question that objectivity (independence in appearance).

Prohibited Financial Interests

SEC rules say an auditor is not independent if any covered person at the firm, or an immediate family member, holds a direct investment in the audit client, including stocks, bonds, options, or other securities. The same goes for material indirect investments.8eCFR. 17 CFR 210.2-01 – Qualifications of Accountants Even ownership through a non-diversified intermediary can be a problem if the intermediary has a significant position in the client. The rules also reach close family members of covered persons who hold beneficial ownership of more than 5% of the client’s equity.

Prohibited Non-Audit Services

Federal law bars a registered accounting firm from providing certain non-audit services to a company it audits. The banned list includes bookkeeping, financial information systems design, appraisal and valuation work, actuarial services, internal audit outsourcing, management functions, broker-dealer or investment advisory services, and legal services unrelated to the audit.9Office of the Law Revision Counsel. 15 USC 78j-1 – Audit Requirements An auditor cannot objectively evaluate work they had a hand in producing.

Partner Rotation

For public company audits, the lead partner and the concurring review partner must rotate off the engagement after five consecutive fiscal years, then observe a five-year cooling-off period before returning to that client.10Securities and Exchange Commission. Strengthening the Commission’s Requirements Regarding Auditor Independence Other audit partners subject to rotation have to rotate after seven years and sit out for two. Long-tenured relationships breed familiarity, and familiarity erodes the skepticism the audit depends on.

Following the Applicable Auditing Standards

Auditors do not exercise free-form judgment. Their work has to conform to a specific body of professional standards that dictates planning, evidence gathering, documentation, and reporting. Which standards apply depends on whether the company is public or private.

For private companies, the governing standards are set by the Auditing Standards Board of the American Institute of Certified Public Accountants, known collectively as Generally Accepted Auditing Standards, or GAAS.11AICPA & CIMA. AICPA Auditing Standards Board For public companies registered with the SEC, auditors must follow standards issued by the Public Company Accounting Oversight Board.12Public Company Accounting Oversight Board. PCAOB Auditing Standards PCAOB standards are generally more detailed and add the integrated internal-controls audit for public companies.

These standards govern everything from how a firm accepts new clients to how audit evidence is evaluated, and they also mandate quality control systems at the firm level covering personnel qualifications, engagement supervision, and ongoing compliance monitoring.

Communicating With the Audit Committee

External auditors have to keep a direct line of communication with the audit committee, or with the full board if no audit committee exists. This is a formal obligation under PCAOB and AICPA standards, and the scope is broad.

The auditor communicates the overall audit strategy and the significant risks identified during planning.13Public Company Accounting Oversight Board. AS 1301 – Communications With Audit Committees As the audit progresses, the auditor updates the committee on significant changes to the planned approach and why they happened. By the end, the committee should understand where the auditor focused attention and why.

Required communications also cover the substance of accounting judgments. The auditor discusses critical accounting policies, the reasonableness of management’s significant estimates, significant unusual transactions, and the qualitative aspects of the company’s financial reporting.13Public Company Accounting Oversight Board. AS 1301 – Communications With Audit Committees If management considered alternative accounting treatments for a material item, the auditor tells the committee what the alternatives were and why management picked the one it did.

Any difficulties (delays in receiving requested information, missing documentation, management-imposed scope restrictions) have to be communicated. So do material disagreements with management, even ones that were eventually resolved. The audit committee needs to know when management pushed back on the auditor’s position. Material weaknesses and significant deficiencies in internal controls have to be communicated in writing so the board has a documented record.7Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements

Reporting Illegal Acts

When an auditor finds information suggesting that an illegal act has occurred, federal law triggers a specific escalation path. Under Section 10A of the Securities Exchange Act, the auditor first determines whether an illegal act likely occurred and assesses its possible effect on the financial statements, including potential fines, penalties, and damages. The auditor then informs the appropriate level of management and makes sure the audit committee is adequately informed, unless the act is clearly inconsequential.9Office of the Law Revision Counsel. 15 USC 78j-1 – Audit Requirements

The escalation does not end there. If the illegal act has a material effect on the financial statements and senior management fails to take timely remedial action, the auditor reports directly to the full board. The board then has one business day to notify the SEC. If the auditor does not receive a copy of that notice within the one-business-day window, the auditor must either resign from the engagement or furnish its own report directly to the SEC.9Office of the Law Revision Counsel. 15 USC 78j-1 – Audit Requirements A board that ignores a material illegal act cannot count on the auditor staying silent.

What Happens When Auditors Fall Short

Auditors of public companies are themselves subject to inspection by the PCAOB. Firms auditing more than 100 public companies are inspected annually; those auditing 100 or fewer are inspected at least every three years.14Public Company Accounting Oversight Board. PCAOB Inspection Procedures Inspectors pick specific audits for review, dig through work papers, and interview engagement team members. They also evaluate the firm’s quality control system, including independence practices, partner management, and internal monitoring.

When violations turn up, consequences are real. The PCAOB can impose censure, temporary or permanent suspension of the firm’s registration, bars on individuals associating with any registered firm, mandatory additional training, and civil money penalties.15Office of the Law Revision Counsel. 15 USC 7215 – Investigations and Disciplinary Proceedings The statutory base for civil penalties is up to $100,000 per violation for an individual and $2,000,000 for a firm; for intentional or knowing misconduct (including recklessness), those caps rise to $750,000 and $15,000,000, and inflation adjustments push the current maximums substantially higher.16U.S. Securities and Exchange Commission. Adjustments to Civil Monetary Penalty Amounts

The SEC has its own tool. Under Rule 102(e), it can censure, suspend, or bar any accountant from appearing or practicing before the Commission. The trigger is “improper professional conduct,” defined to include knowing or reckless misconduct, repeated instances of unreasonable conduct, or a single highly unreasonable deviation from professional standards when the auditor knew or should have known that heightened scrutiny was warranted.17Securities and Exchange Commission. Amendment to Rule 102(e) of the Commission’s Rules of Practice A bar from practicing before the SEC effectively ends a career in public company auditing.

Between PCAOB inspections, PCAOB disciplinary proceedings, and SEC sanctions, auditors face genuine professional and financial risk when they cut corners on any of the responsibilities above. The people checking the numbers have strong reasons to check them honestly.