A non-integrated audit is a financial statement audit in which the auditor issues an opinion only on whether the financial statements are fairly presented, without a separate opinion on the effectiveness of internal controls over financial reporting. It’s the default audit for private companies and for public companies that fall below the thresholds triggering Sarbanes-Oxley Act Section 404(b). The auditor still looks at internal controls during the engagement, but only to figure out where errors might hide, not to grade the controls themselves.
Who Gets a Non-Integrated Audit
Two groups of companies end up with this type of audit: private companies that need audited financials for some outside reason, and public companies that are exempt from SOX 404(b).
Private Companies
No federal law requires a private company to have its financial statements audited. When one does get audited, it’s usually because a lender, bonding company, or insurer wants audited financials as a condition of doing business, or because ownership wants them for internal governance. These engagements follow AICPA standards rather than PCAOB standards, and they are always non-integrated. Private companies have no SOX obligations, so there is no controls opinion to issue.
Public Companies Below the SOX 404(b) Thresholds
SOX Section 404(b) requires an independent auditor to attest to management’s assessment of internal control effectiveness, but only for accelerated filers and large accelerated filers. The SEC’s 2020 amendments broadened the exemption. A public company with a public float below $75 million is exempt regardless of revenue. A company with a public float between $75 million and $700 million is exempt if its annual revenue is below $100 million.1U.S. Securities and Exchange Commission. Accelerated Filer and Large Accelerated Filer Definitions A company that crosses $700 million in public float is a large accelerated filer and must have a full integrated audit.
Exempt public companies still have to do something under SOX Section 404(a): management must assess the effectiveness of internal controls itself. The exemption only removes the requirement that the auditor separately attest to that assessment. The result is a non-integrated audit, with the auditor issuing a single opinion on the financial statements.
How It Differs From an Integrated Audit
An integrated audit produces two opinions: one on the financial statements and one on internal control effectiveness. PCAOB Auditing Standard 2201 governs that engagement and requires the two examinations to run simultaneously so each informs the other.2Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements Dropping the second opinion is the single change that reshapes everything else.
The biggest practical difference is how the auditor gathers evidence. In an integrated audit, the auditor performs extensive tests of whether controls actually work as designed over an extended period. When a control is shown to work reliably, the auditor can lean on it and reduce direct testing of the account balances that control protects. A non-integrated audit skips those operating-effectiveness tests. With no control reliance available, the auditor makes up the difference by testing the numbers themselves more heavily. Every material account balance gets scrutinized through substantive procedures rather than through a mix of control reliance and targeted testing.
Cost follows scope. Integrated audits require substantially more fieldwork hours for control testing, more documentation, and more senior-level review. Non-integrated audits carry lower fees and shorter timelines. That’s one reason private companies and smaller public filers stick with the non-integrated version when they have the choice.
How Controls Still Figure Into the Work
The absence of a controls opinion doesn’t make internal controls irrelevant. PCAOB Auditing Standard 2110 requires the auditor to understand each component of internal control well enough to identify the kinds of misstatements that could occur, assess the factors that drive misstatement risk, and design further audit procedures accordingly.3Public Company Accounting Oversight Board. AS 2110 – Identifying and Assessing Risks of Material Misstatement
In practice, the auditor evaluates whether controls are properly designed and whether the company has actually put them into use. That might involve walking through a revenue transaction from start to finish, interviewing staff who process invoices, or inspecting the documentation behind an approval process. What the auditor does not do is test whether those controls operate effectively over time. Weak controls in a given area simply mean more direct testing of the numbers in that area.
Because control reliance is off the table, substantive procedures do most of the work: confirmations sent to banks and customers, physical inspection of assets, vouching recorded entries back to source documents, tracing source documents forward into the books, cutoff testing around period-end, and analytical review comparing balances and ratios to prior periods, budgets, and industry benchmarks. After the fieldwork, the auditor evaluates all the accumulated evidence, including any uncorrected misstatements, to decide whether the statements as a whole are fairly presented.4Public Company Accounting Oversight Board. AS 2810 – Evaluating Audit Results
Control Deficiencies Still Get Reported
Here is where non-integrated audits surprise some companies. Even without a controls opinion, any significant deficiencies or material weaknesses the auditor identifies during the engagement must be reported in writing to management and the audit committee before the audit report is issued.5Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements The communication has to distinguish clearly between the two categories.
A material weakness is a control deficiency serious enough that a material misstatement of the financial statements could reasonably fail to be prevented or caught in time. A significant deficiency is less severe but still important enough to deserve the attention of those overseeing financial reporting.6Public Company Accounting Oversight Board. Auditing Standard 5 – Appendix A – Definitions A material weakness, even if it didn’t produce an actual misstatement in the current year, signals a gap that needs to be fixed.
For private company audits conducted under AICPA standards, the same obligation applies. The written communication must go out no later than 60 days after the audit report is released, and it must explain that the audit considered internal controls only for planning purposes and did not produce an opinion on control effectiveness.
The Report the Company Receives
The deliverable from a non-integrated audit is a single-opinion report on the financial statements. There is no second opinion on internal controls anywhere in the document, and the report explicitly says the audit was not designed to express one. That statement sets the boundary for lenders, investors, and regulators reading the report.
The best outcome is an unqualified (clean) opinion, meaning the financial statements are presented fairly in all material respects under the applicable framework, usually GAAP. When problems arise, the opinion can be qualified (fairly presented except for a specific issue), adverse (not fairly presented), or a disclaimer (the auditor could not gather enough evidence to form any opinion).7Public Company Accounting Oversight Board. AS 3105 – Departures from Unqualified Opinions and Other Reporting Circumstances A qualified opinion is a yellow flag; an adverse opinion or disclaimer is a red one. For public companies, either can trigger additional SEC scrutiny or covenant problems on existing debt.
Every audit also requires the auditor to evaluate whether the company can continue operating for at least one year beyond the date of the financial statements. If substantial doubt remains after considering management’s plans, the report includes a going concern explanatory paragraph following the opinion.8Public Company Accounting Oversight Board. AS 2415 – Consideration of an Entity’s Ability to Continue as a Going Concern That paragraph doesn’t change the opinion itself, but it’s often the most consequential sentence in the document for a lender or investor.
What Management Still Owes
The audit report belongs to the auditor, but the financial statements belong to management. Before issuing the report, the auditor obtains a written representation letter in which management acknowledges its responsibility for fair presentation of the statements and for designing programs and controls to prevent and detect fraud.9Public Company Accounting Oversight Board. AS 2805 – Management Representations If management refuses to sign, the auditor cannot issue the report. The letter also covers disclosure of any known or suspected fraud and any subsequent events occurring between the balance sheet date and the report date.
For public companies that qualify for a non-integrated audit, management still must assess internal controls under SOX Section 404(a), even though the auditor won’t attest to that assessment.1U.S. Securities and Exchange Commission. Accelerated Filer and Large Accelerated Filer Definitions Skipping that self-assessment is not an option. Exemption from 404(b) removes the auditor attestation, not management’s own obligation to evaluate controls and report on them.