What Is a Group Audit and How Does It Work?

A group audit is the coordinated audit of consolidated financial statements that combine a parent company with all its subsidiaries into a single economic entity. One engagement partner signs the final opinion, but the underlying work is spread across every business unit whose numbers feed the consolidation, often performed by different audit firms in different countries. The point of the exercise is to gather enough evidence, from enough of those units, that the consolidated statements investors rely on can be opined on as a whole.

Who Does What

The group is the parent plus every subsidiary, division, or branch whose financial data flows into the consolidated statements. Each unit that gets rolled up is a component. Components can be foreign subsidiaries, joint ventures, standalone divisions, or shared service centers that handle accounting for multiple units.

The group engagement team sits at the parent’s headquarters. It plans the overall audit, decides which components need what level of testing, reviews what comes back, and issues the opinion on the consolidated statements. The group engagement partner leads that team and signs the report. That signature carries accountability for the entire engagement, including work performed by others.

A component auditor performs procedures on the financial information of an individual component. Component auditors may belong to the same international firm network as the group team, or they may be entirely separate local firms. When the component auditor is unaffiliated, the group team’s oversight obligations intensify: it must verify the component auditor’s independence, confirm familiarity with the group’s reporting framework, and establish communication protocols before fieldwork begins.

The Standards Behind the Process

Two frameworks shape how group audits are run in practice.

Internationally, ISA 600 (Revised), effective for audits of periods beginning on or after December 15, 2023, is the primary standard. It sets four objectives for the group auditor: determine at the outset whether enough evidence can reasonably be obtained, identify and assess risks of material misstatement in the group financials, stay sufficiently involved in component auditors’ work throughout, and evaluate whether the evidence gathered supports the final opinion. The revised standard replaces the old “significant component” classification, which had sorted components largely by financial size, with a risk-based model. A small subsidiary in a high-risk jurisdiction now gets scoped on its risk, not its size.

For companies registered with the SEC, the Public Company Accounting Oversight Board’s standards apply. AS 1201 makes the engagement partner responsible for the engagement and its performance, including supervision of all team members, even those outside the partner’s firm. Delegating supervisory tasks doesn’t reduce the partner’s own responsibility. AS 1206 covers the narrower situation where the group partner wants to divide responsibility with another firm rather than assume responsibility for its work.

Setting Materiality

Materiality is the threshold below which a misstatement is unlikely to influence an investor’s decision. The group engagement team sets group materiality by applying a percentage to a benchmark drawn from the consolidated statements. No standard prescribes a single formula. Common benchmarks include pre-tax income (often around 3 to 10 percent, with listed companies typically at the lower end), total revenue, total assets, and total equity. The team picks whichever best reflects what users of the statements care about. Pre-tax income usually fits a stable manufacturer. For a startup burning cash, total assets or revenue may be more appropriate.

Group materiality then cascades down to individual components as component materiality, which is always set lower than the group figure. The reason is arithmetic: if every component could tolerate misstatements up to the full group threshold, combined errors across components could easily blow past the group limit. Component materiality doesn’t have to be a straight arithmetic slice, and the sum of all component materiality amounts is allowed to exceed group materiality. The team uses judgment, often supported by probabilistic models, to keep the overall risk of material misstatement at the group level acceptably low.

Scoping Which Components Get Audited

Not every component gets the same treatment. The group engagement team assigns each one a scope of work based on the risk it poses to the consolidated financial statements.

Components representing a large share of group revenue, assets, or other key metrics typically receive a full-scope audit using the assigned component materiality. Many engagement teams aim for their fully audited components to cover roughly 80 percent or more of a key group metric like total assets or revenue. That figure is a widely followed practice benchmark, not a number required by any standard, and the target moves with the group’s risk profile.

A component can also warrant full-scope or targeted testing for reasons unrelated to size. A small subsidiary in a country with weak rule of law, a newly acquired unit still being integrated, or a component involved in complex related-party transactions can all pose outsized risks. Under the revised ISA 600, this risk-based lens is the primary driver of scoping, not a supplement to financial size.

Components that fall short of full-scope audit may still receive targeted procedures on specific accounts or transaction classes, particularly intercompany balances, unusual revenue streams, or accounts flagged as higher risk. The remaining components, those with low individual risk and minimal contribution, may only be covered by analytical procedures at the group level.

The Instruction Package

Once scoping is done, the group engagement team sends each component auditor a formal instruction package. This is the operational backbone of the engagement. It sets the component materiality threshold, reporting deadlines, the financial reporting framework the component must follow (US GAAP, IFRS, or another), and the format for reporting findings back.

Beyond mechanics, the instructions spell out the component auditor’s responsibilities and ethical requirements, flag specific risks the group team has identified, describe related-party relationships relevant to the component, and note any conditions that could raise doubt about the group’s ability to continue as a going concern. The group team also asks for written confirmation that the component auditor will cooperate throughout and communicate promptly when issues arise.

If the component’s local financial statements use a different reporting framework than the consolidated statements, someone has to audit the conversion adjustments that translate the numbers. The instruction package makes clear whether that responsibility sits with the group team or the component auditor.

What Component Auditors Send Back

The component auditor performs risk assessment, tests controls, and substantively tests account balances in line with the assigned scope and component materiality. The depth ranges from a full financial statement audit down to targeted procedures on specific accounts, depending on the instructions.

Every identified misstatement gets documented and reported to the group team, even those below component materiality. A misstatement that looks trivial locally can combine with similar errors at other components to breach the group threshold. The component auditor also reports findings that could affect the consolidated statements more broadly: noncompliance with local laws, fraud indicators, or going-concern issues at the component.

The final deliverable is a formal reporting package transmitted by the deadline in the instructions. It includes a summary of work performed, a schedule of all identified misstatements (corrected and uncorrected), and an assessment of the component’s internal controls. That standardized package is what lets the group team integrate local results into the group-level analysis.

Assuming Responsibility or Making Reference

When another firm audits a component, the group engagement partner faces a choice that shows up directly in the final report: assume responsibility for that firm’s work, or make reference to it.

Assuming responsibility means the group partner treats the component auditor’s work as if the group team had performed it. The final report doesn’t mention another auditor. To take this position, the partner must be satisfied with the other firm’s independence, professional reputation, and audit quality, typically by reviewing key working papers, discussing significant findings, and performing whatever additional procedures are needed. Most large multinational audits work this way, particularly when the component auditor belongs to the same international firm network.

Making reference means the group partner’s report explicitly states that part of the audit was performed by another firm and indicates the portion of the statements that firm covered. Under PCAOB standards, this is a disclosure of divided responsibility, not a qualification of the opinion. The referred-to auditor must confirm independence, proper licensing, and compliance with PCAOB standards, and must be PCAOB-registered if it played a substantial role in the engagement.

If the group partner can neither assume responsibility nor meet the conditions for making reference, the remaining options are a qualified opinion or a disclaimer on the consolidated statements. That backstop keeps the system honest: the partner can’t simply ignore a component auditor whose work isn’t reliable.

Pulling It Together Into One Opinion

Once the component reporting packages arrive, the group engagement team reviews each for quality and compliance with the original instructions. The team evaluates key documentation, assesses whether the work was performed as directed, and follows up on significant judgments or unusual findings.

The team then aggregates every reported misstatement, corrected and uncorrected, from every component and compares the total against group materiality. This is where the math either works or it doesn’t. If combined uncorrected misstatements approach or exceed the group threshold, the team must decide whether to push for corrections or modify the opinion.

Separately, the group team performs its own procedures on the consolidation process: testing that intercompany transactions and balances have been properly eliminated, verifying consolidation adjustments, and confirming the statements present the group as a single economic entity. Intercompany discrepancies that survive elimination can distort the consolidated numbers enough to trigger a modified opinion.

The group partner then forms and issues the final opinion, stating whether the consolidated statements are presented fairly under the applicable framework. That opinion covers everything: the group team’s own work, every component auditor’s work, and the consolidation. If access restrictions prevented the team from obtaining sufficient evidence about a component, that gap doesn’t disappear. The partner has to consider whether it amounts to a scope limitation, which can lead to a qualified opinion or a disclaimer. Restrictions on access don’t eliminate the requirement to obtain sufficient appropriate audit evidence.

When Something Goes Wrong at a Component

The group partner’s ultimate accountability means component-level problems can cascade upward. If a component auditor uncovers fraud, the group team has to evaluate whether it could affect other components or the consolidated statements. If a component operates in a jurisdiction that restricts access to audit documentation, the team may try workarounds: remote reviews, on-site visits, or detailed memoranda from the component auditor. When workarounds fail, the result is a potential scope limitation on the group audit.

If a component auditor’s work turns out to be substandard after the reporting package arrives, the group team can’t accept it and move on. AS 1201 requires the engagement partner to determine that the work performed supports the conclusions reached. If it doesn’t, the team either performs additional procedures itself or directs the component auditor to redo the work. The partner’s signature on the final report vouches for the entire engagement, and delegation doesn’t change that.