AU-C 600 is the AICPA auditing standard that governs group financial statement audits — engagements where multiple entities, subsidiaries, or divisions roll up into one set of consolidated financials. It sets the rules for how the group engagement partner scopes the work, coordinates with auditors of individual components, handles materiality across those components, audits the consolidation process, and forms an opinion on the group financial statements. A major revision under SAS No. 149 replaces the current framework with a risk-based model for group audits of periods ending on or after December 15, 2026.
What Counts as a Group and What Counts as a Component
A group audit exists whenever the financial statements being audited include financial information from more than one component. Subsidiaries, divisions, branches, joint ventures, and equity method investments all qualify as components. Equity method investments in particular fall squarely within AU-C 600’s scope rather than AU-C 501, which explicitly excludes them.
Once the components are identified, the group engagement team decides what work each one needs. Some warrant a full-scope audit. Others need only targeted procedures on specific account balances or classes of transactions. That scoping decision drives the entire engagement and depends on the size, risk, and role of each component within the consolidated whole.
What the Group Engagement Partner Is Responsible For
The group engagement partner carries ultimate responsibility for the direction, supervision, and performance of the entire group audit. That responsibility does not shrink because other auditors are doing work on individual components. The partner must determine whether enough reliable evidence can be gathered across every component to support the opinion on the consolidated financial statements.
Access is the gating issue. If the group engagement partner expects restrictions on reaching component information or doubts a component auditor’s professional competence, those problems have to be addressed before the engagement moves forward. In serious cases, the partner may need to modify or disclaim the opinion on the group financials.
When restrictions come from local laws rather than management obstruction, the group auditor has workarounds: visiting the component auditor’s location to review documentation in person, reviewing working papers remotely through technology, or requesting the component auditor to prepare a detailed memorandum covering the relevant findings. If none of those alternatives overcome the restriction, a scope limitation exists and the opinion on the group financials may need to be modified.
Setting Materiality Across the Group
Materiality in a group audit is layered. The group engagement team establishes several interconnected levels, and each one has a specific job.
Group financial statement materiality is the starting point. It is the maximum misstatement that could exist in the consolidated statements without influencing the economic decisions of users. Every other materiality figure flows from this number.
Component materiality must be set lower than group materiality for each component where audit or review procedures are performed. The reason is aggregation risk: if each component auditor works to a threshold equal to group materiality, the combined undetected misstatements across all components could easily exceed the group figure. The lower component threshold acts as a buffer. Auditors typically allocate using proportional methods based on each component’s relative size, or weighted methods that give smaller components a larger share of the pie to reflect their higher per-dollar risk. The allocation is then adjusted for each component’s specific risk profile.
Performance materiality for the group is set below group financial statement materiality. It accounts for the possibility of misstatements that exist but have not been detected, and it guides the extent of substantive procedures on the consolidation process itself. The team also establishes a threshold below which misstatements are considered clearly trivial and are not accumulated for evaluation. That keeps the engagement from drowning in immaterial differences.
Risk Assessment and Significant Components
Risk assessment operates on two levels at once. The group engagement team needs to understand the group’s overall structure and the specific risks that arise from decentralized operations, varied regulatory environments, and complex intercompany relationships. It also needs to assess risks at each component where work will be performed.
Under the current AU-C 600, significant components fall into two categories. The first is components that are individually financially significant to the group, usually determined by total assets, revenue, or earnings. The second is components that are not individually large but carry a heightened likelihood of material misstatement due to their nature — a startup subsidiary in a high-risk market, for example, or a component with unusual related-party transactions.
Group-wide controls get separate attention. The group engagement team must understand and evaluate controls that prevent or detect errors in component financial information and in the consolidation process. Where the group relies on centralized processing, such as a shared service center handling transactions for multiple components, the group engagement team can test those controls centrally and apply the results across affected components.
For each component where a component auditor will work, the group engagement team assesses risks of material misstatement and communicates those assessments in the instructions sent to the component auditor. The team also assesses the component auditor’s professional competence and independence before relying on the work. If there are doubts about competence, the group engagement team must increase its own involvement or perform the procedures directly.
Working With Component Auditors
The group engagement team communicates detailed instructions to each component auditor before work begins. Those instructions cover:
- The assigned component materiality level
- The threshold for accumulating misstatements
- Specific risks of material misstatement requiring targeted procedures
- The required audit procedures
- The nature of the expected report and deadlines
- Ethical requirements, particularly regarding independence
The component auditor acknowledges the instructions to confirm understanding. Communication then runs both ways throughout the engagement. Involvement is proportional to the significance and risk of the component. For high-risk components, the group engagement team may visit the component location, sit in on risk assessment discussions, meet with component management, and review working papers focused on significant risks or complex judgments. For lower-risk components, involvement might be limited to reviewing the component auditor’s summary memorandum and conclusions.
When the component auditor’s work is complete, the group engagement team evaluates whether the evidence is sufficient for the group audit’s purposes, reviews the conclusions on identified misstatements, and confirms that the instructions were followed. If a material misstatement is identified, it must be corrected or adjusted in the consolidated financial statements before the group opinion can rest on that component’s work. If the work is insufficient, the group engagement team either performs additional procedures itself or directs the component auditor to do so.
Making Reference vs. Assuming Responsibility
One of the most consequential choices in a group audit is whether the group engagement partner assumes responsibility for the component auditor’s work or instead makes reference to it in the audit report. This choice shapes the entire engagement structure. It is also a feature that distinguishes the U.S. standard from ISA 600, which does not permit making reference.
When the group engagement partner assumes responsibility, no mention of the component auditor appears in the audit report. The group auditor takes on full accountability for the opinion, and all of the procedures above — setting component materiality, issuing instructions, reviewing working papers, evaluating findings — apply in full. The component auditor functions as an extension of the engagement team.
When the group engagement partner makes reference, the audit report explicitly notes the division of responsibility, typically disclosing the portion of the group financials audited by the other auditor as a percentage of total assets or revenues. Making reference reduces the group auditor’s responsibility for the referenced component but does not eliminate it. The group auditor still must confirm that the component auditor is independent of the group, that the work complies with relevant auditing standards, and that the component auditor’s report is suitable for the group engagement partner’s purposes.
Auditing the Consolidation Itself
Even if every component’s individual numbers are clean, errors in consolidation adjustments, intercompany eliminations, or foreign currency translation can create material misstatements at the group level. The group engagement team handles the consolidation process directly.
Intercompany balances must be identified and eliminated so they do not inflate the consolidated figures. When those transactions cross currencies, the elimination must use exchange rates from the dates of the original sales or transfers, not the reporting-date rate. Errors here are hard to spot because they exist only in the consolidation layer, not in any individual component’s books.
Foreign currency translation for overseas components follows a defined sequence. For entities acquired through a business combination, assets recognized at the acquisition date, including goodwill, must be translated in accordance with the applicable accounting standards. Before translation, each foreign component must first recognize transaction gains or losses on its foreign-currency-denominated obligations by measuring those obligations at the reporting-date exchange rate.
Consolidation adjustments for minority interests, fair value adjustments from acquisitions, and reclassifications also need evaluation. Management judgment runs high in these areas and so does the risk of error.
Reporting, Governance Communication, and Documentation
The group engagement partner forms the opinion on the group financial statements based on the totality of evidence gathered across all components and the consolidation process. When the partner has assumed responsibility for all component auditors’ work, the audit report makes no mention of those auditors. When the partner makes reference, the report discloses the division of responsibility and typically notes the magnitude of the financial statements audited by the other auditor.
The group auditor must perform or direct procedures to address subsequent events occurring between the date of the component’s financial information and the date of the group auditor’s report. Missing events in that gap period is a common source of audit deficiencies. Going concern issues have to be considered for the group and for individual components whose failure could materially affect the consolidated financials.
Communications with those charged with governance at the group level cover the planned scope and timing of the audit, planned involvement in the work of component auditors, significant risks identified during planning, significant difficulties encountered, and matters raised by component auditors that the governance body needs to know about. A control deficiency that is immaterial at one component may become significant when viewed across the group or combined with similar deficiencies at other components. Written representations from group management address the completeness of information about related-party transactions across the group, disclosure of all components and their relationships, and the appropriateness of the consolidation process.
Documentation must clearly support the group engagement partner’s conclusions. That includes the analysis of components behind scoping decisions, the materiality levels established, the instructions sent to component auditors, the evaluation of each component auditor’s work, the procedures performed on the consolidation process, and the resolution of any deficiencies identified.
What Changes Under SAS No. 149
SAS No. 149 supersedes the current AU-C 600 for audits of periods ending on or after December 15, 2026. It is not an incremental update.
The biggest change is the move away from identifying “significant components” as the primary scoping mechanism. Under the current standard, components are categorized as significant or not, and that classification drives the nature and extent of work performed. SAS No. 149 eliminates the classification entirely. The group auditor instead uses professional judgment to determine which components need procedures based on assessed risks of material misstatement, aligning group audit planning with the risk assessment framework in AU-C Sections 315 and 330.
Terminology also shifts. “Assuming responsibility” for a component auditor’s work becomes “being involved in the work of component auditors.” The definition of component auditor is revised so that a component auditor is considered part of the engagement team. A new term, “referred-to auditor,” describes an auditor who performs an audit of a component’s financial statements and whose work the group engagement partner references in the group audit report. A referred-to auditor is not part of the engagement team and is not a component auditor. “Group auditor” replaces “group engagement team” for the partner and other engagement team members who are not component auditors.
The revised standard also emphasizes two-way communication between the group auditor and component auditors, covering ethical requirements, competence assessments, and the appropriate extent of the group auditor’s involvement. Documentation requirements are clarified: component auditor working papers generally do not need to be replicated in the group auditor’s file unless law or regulation requires it, but the group auditor’s documentation still has to demonstrate the basis for its conclusions about the sufficiency of the evidence obtained. The option to divide responsibility by making reference remains available, but the mechanics change to fit the new referred-to auditor concept.