Walkthrough testing in SOX audits is the procedure an auditor uses to trace a single transaction from its origin through every processing step until it reaches the general ledger, confirming that internal controls over financial reporting are properly designed and functioning at each point. Under PCAOB Auditing Standard 2201, walkthroughs are described as “frequently the most effective way” for an auditor to understand transaction flows, spot where misstatements could occur, and identify the controls meant to prevent or catch them.1Public Company Accounting Oversight Board. PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements It is the point where a control’s paper description gets tested against what actually happens in the business.
Why SOX Requires Walkthroughs
Section 404(a) of the Sarbanes-Oxley Act of 2002 requires management of public companies to assess and report annually on the effectiveness of their internal controls over financial reporting. Section 404(b) requires the company’s independent auditor to attest to that assessment.2GovInfo. Sarbanes-Oxley Act of 2002 Emerging growth companies are exempt from the 404(b) attestation requirement, but management’s own assessment under 404(a) still applies.
AS 2201 is the PCAOB standard governing how auditors carry out the integrated audit of internal controls and financial statements. It sets the objectives a walkthrough must meet: understanding how significant transactions flow, identifying the points at which a material misstatement could arise, and identifying the controls management uses to address those risks.1Public Company Accounting Oversight Board. PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements The walkthrough is one of the main tools for meeting those objectives.
How a Walkthrough Is Performed
The auditor picks one transaction and follows it, using the same documents and systems that company employees use in their daily work.1Public Company Accounting Oversight Board. PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements For a sale, that means beginning with the customer purchase order and moving through credit approval, order entry, shipment, invoicing, and the final revenue entry in the financial records. For a procurement transaction, it would start with the purchase requisition and end with the payment posted to the general ledger.
AS 2201 identifies four procedures the auditor combines during a walkthrough:
- Inquiry: asking employees about their roles and the steps they perform.
- Observation: watching employees perform control activities in real time.
- Inspection of relevant documentation: reviewing the physical or electronic evidence a control produces, such as an approval stamp, signed invoice, or system-generated exception report.
- Re-performance of controls: the auditor independently re-executing the control step to verify the result.
These sit on a spectrum of evidential strength. Inquiry alone is the weakest and, per AS 2201, is never sufficient on its own to conclude that a control works. Re-performance is the strongest. If a control involves matching invoice amounts against purchase order prices, re-performance means the auditor pulls up both records and performs the match independently rather than accepting that someone else did it correctly.1Public Company Accounting Oversight Board. PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements
Selecting the Right Transaction
AS 2201 refers to “the single transaction used as the basis for the walkthrough,” confirming this is a sample-of-one procedure.1Public Company Accounting Oversight Board. PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements Because there is only one, the choice matters. The transaction should touch every key control point, pass through every relevant system interface, and involve each employee responsible for a control activity. A complex transaction such as a multi-line sales order requiring multiple approvals usually exercises more of the process than a simple routine one.
Auditors typically focus on processes tied to accounts and disclosures with a reasonable possibility of material misstatement. The procure-to-pay cycle, revenue recognition, and payroll are common targets, driven by the company’s risk and control matrix. Before speaking with anyone, the auditor reviews existing narratives, flowcharts, and prior year work papers to build an expectation of how the transaction should flow.
How to Question Employees
At each processing step, the auditor asks the employee what the company’s procedures require and what they actually do. AS 2201 calls these “probing questions” and instructs auditors to go beyond the narrow focus of the single transaction so they understand the range of significant transactions the process handles.1Public Company Accounting Oversight Board. PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements
Open-ended questions work best. Ask the employee to walk through what they do as if the auditor knows nothing about the process. Shortcuts such as “is everything the same as last year?” have been flagged by PCAOB inspectors as insufficient because they let an employee confirm a stale narrative without demonstrating anything. Inspection reports have specifically noted firms whose walkthroughs consisted mainly of confirming no changes from the prior year, and those walkthroughs were found inadequate.3Public Company Accounting Oversight Board. Staff Audit Practice Alert No. 11
The auditor also confirms that functional boundaries hold. If the person who initiates purchase requests is the same person authorizing payments, that segregation-of-duties breakdown is a design problem the walkthrough should catch. For smaller companies with limited staff, AS 2201 acknowledges that alternative controls may substitute for traditional segregation, but they still need to be effective.1Public Company Accounting Oversight Board. PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements
Handling Automated and IT Controls
Most transactions today move through information systems, and AS 2201 requires the auditor to understand how IT affects those flows as part of the walkthrough.1Public Company Accounting Oversight Board. PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements The auditor traces how data moves between systems, what automated validations or approvals occur, and where manual intervention enters the process. A three-way match between purchase order, receiving report, and invoice may be fully automated in the ERP, but the auditor still needs to understand the logic, what happens when a mismatch triggers an exception, and who resolves those exceptions manually.
Automated controls carry a specific efficiency. If the underlying IT general controls covering program changes, system access, and computer operations are effective, an automated application control that has not changed since it was last tested may not need its specific tests repeated. The auditor verifies the control has not been modified and that general controls remain sound, then concludes the automated control is still effective.1Public Company Accounting Oversight Board. PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements
When Part of the Process Runs at a Service Organization
Many companies outsource portions of transaction processing to payroll processors, cloud accounting platforms, or investment custodians. When those services form part of the company’s information system and internal controls, the auditor must include the service organization’s activities in the assessment.1Public Company Accounting Oversight Board. PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements This typically involves obtaining a SOC 1 report from the third party and confirming that its scope and timing align with the company’s processes. The user company’s own controls over the service organization’s output, such as reconciling data received back against internal records, still need to be walked through and tested directly.
What a Walkthrough Actually Proves
The primary purpose of a walkthrough is evaluating design effectiveness: whether the control, if operated as intended by someone with the right authority and competence, would prevent or detect a material misstatement.1Public Company Accounting Oversight Board. PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements A control designed to ensure sales are billed at authorized prices fails the design test if anyone can override pricing without proper authorization.
Operating effectiveness is a different question: did the control actually function consistently throughout the audit period? A well-designed control that employees skip half the time is not operationally effective. Testing operating effectiveness normally requires a larger sample of transactions across the period, using the same mix of inquiry, observation, inspection, and re-performance.
There is a nuance many summaries miss. AS 2201 states that walkthroughs “might provide sufficient evidence of operating effectiveness, depending on the risk associated with the control being tested, the specific procedures performed as part of the walkthrough and the results of those procedures.”1Public Company Accounting Oversight Board. PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements For a low-risk control where the walkthrough included robust re-performance, the walkthrough alone can satisfy both requirements. For higher-risk controls, additional testing is required. Either way, confirmed design effectiveness comes first; there is no point testing whether employees consistently followed a control that is poorly designed to begin with.
When a Walkthrough Finds a Deficiency
If a walkthrough reveals a gap between documented procedures and actual practice, or a missing or poorly designed control, the auditor has identified a deficiency. AS 2201 sorts deficiencies by severity into two categories:1Public Company Accounting Oversight Board. PCAOB AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements
- A material weakness is a deficiency, or combination of deficiencies, where there is a reasonable possibility that a material misstatement of the financial statements will not be prevented or detected on a timely basis. It triggers disclosure in both the company’s annual report and the auditor’s report.
- A significant deficiency is less severe than a material weakness but important enough to warrant the attention of those overseeing financial reporting. The auditor must communicate all identified deficiencies in writing to management and inform the audit committee.
Once a design deficiency is identified, the auditor cannot rely on that control to reduce audit risk. The practical consequence is expanded substantive testing, such as detailed verification of account balances or individual transactions, to compensate for the missing assurance. Management, in turn, needs to remediate the deficiency by redesigning the control and updating documentation before it can be tested for operating effectiveness.
Poor walkthroughs create their own risks. PCAOB inspection findings have noted that inadequate walkthroughs lead to flawed risk assessments, which in turn cause auditors to select and test the wrong controls or too few of them.3Public Company Accounting Oversight Board. Staff Audit Practice Alert No. 11
Documenting What Was Done
A walkthrough produces detailed working papers identifying the specific transaction traced (with its unique identifier), the employees interviewed, the dates of inquiry and observation, and the evidence gathered. Two key outputs are an updated process narrative and a revised process flowchart. If the walkthrough revealed that the real process differs from the previously documented version, both documents must reflect observed reality rather than intended design.
The working papers should record specifics of what the auditor saw during re-performance: the authorization stamp used, the system screen where approval was logged, the parameters of a system-generated report. If a design deficiency is found, the documentation must describe the deficiency and the risk it poses to the financial statements. That specificity is what supports the auditor’s conclusion, and what the walkthrough is ultimately for.