Skip to content

Evidence request lists

PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Controls Testing - Design

ASTWO-4
Walkthroughs, Control Selection, Design Effectiveness Testing

Per PCAOB AS 2201 paragraphs 7, 8-9, 39, 42: walkthroughs + selection + design effectiveness. Requirements include (a) perform Walkthroughs of significant transaction flows to confirm understanding of controls + identify control points + (b) Selecting Controls to Test focused on controls that sufficiently address the risk of misstatement to each relevant assertion + (c) evaluate Design Effectiveness via inquiry + observation + walkthrough + inspection + (d) determine whether the company's controls if operating as prescribed by persons possessing necessary authority + competence would satisfy the company's control objectives + (e) document understanding + selection rationale + design conclusions + (f) update design conclusions as controls or processes change.

Artefacts an auditor will ask for
  • PCAOB AS 2201 evidence for ASTWO-4
Where this commonly fails
  • walkthroughs documentation + deficiency severity assessment + EQR documentation partial

Controls Testing - Operating

ASTWO-5
Operating Effectiveness Testing: Nature, Timing, Extent

Per PCAOB AS 2201 paragraphs 44-46, 52, 14: operating effectiveness. Requirements include (a) test Operating Effectiveness of controls that are sufficiently important to address assertion-level risk + (b) determine Nature of Tests including inquiry + observation + inspection of relevant documentation + reperformance + (c) determine Timing of Tests including interim + roll-forward + period-end procedures + (d) determine Extent of tests including sample size + selection method + considering frequency + control type + reliance on automation + (e) use evidence from other parties including internal audit + management testing where appropriate per AS 2605 + (f) document tests + results + conclusions including sample selection + (g) consider IT general controls reliance for automated controls.

Artefacts an auditor will ask for
  • PCAOB AS 2201 evidence for ASTWO-5
Where this commonly fails
  • walkthroughs documentation + deficiency severity assessment + EQR documentation partial

Deficiency Assessment

ASTWO-7
Deficiency Evaluation, Material Weakness, and Communication

Per PCAOB AS 2201 paragraphs 62-69: deficiency evaluation + classification + communication. Requirements include (a) evaluate Deficiencies including severity considering likelihood + potential magnitude + compensating controls + (b) classify deficiencies as deficiency + significant deficiency + material weakness per AS 2201 definitions + (c) determine Material Weakness existence based on likelihood and magnitude of potential misstatement + (d) Communicate Deficiencies to management and audit committee + (e) communicate material weaknesses in writing to management + audit committee + (f) document evaluation including severity factors + classification + communication + (g) consider aggregated impact of deficiencies + remediation status + management response.

Artefacts an auditor will ask for
  • PCAOB AS 2201 evidence for ASTWO-7
Where this commonly fails
  • walkthroughs documentation + deficiency severity assessment + EQR documentation partial

Entity-Level and Period-End

ASTWO-3
Entity-Level Controls and Period-End Financial Reporting Process

Per PCAOB AS 2201 paragraphs 4, 22-27, 5: entity-level controls + period-end. Requirements include (a) evaluate Entity-Level Controls including control environment + risk assessment + monitoring + information + communication + COSO components + (b) evaluate the Period-End Financial Reporting Process including procedures used to enter transactions + initiate + authorise + record + process + report period-end financial information + (c) consider IT general controls + IT application controls + (d) consider management override + tone at the top + governance + ethics + (e) document evaluation including significant findings + conclusions + (f) determine extent + nature of further testing based on entity-level conclusions.

Artefacts an auditor will ask for
  • PCAOB AS 2201 evidence for ASTWO-3
Where this commonly fails
  • walkthroughs documentation + deficiency severity assessment + EQR documentation partial

Materiality and Scoping

ASTWO-2
Materiality, Significant Accounts, Disclosures, Transaction Flows

Per PCAOB AS 2201 paragraphs 3, 6, 28, 34: materiality + scoping. Requirements include (a) determine Materiality and Tolerable Misstatement at planning consistent with financial statement audit + (b) identify Significant Accounts and Disclosures considering likely sources of potential misstatements + quantitative and qualitative factors + susceptibility to misstatement + (c) understand Transaction Flows including initiation + authorisation + processing + recording + reporting for significant accounts + disclosures + (d) document scoping decisions + materiality determinations + (e) update scope as audit risk evolves + (f) align scoping with COSO + management's risk assessment.

Artefacts an auditor will ask for
  • PCAOB AS 2201 evidence for ASTWO-2
Where this commonly fails
  • walkthroughs documentation + deficiency severity assessment + EQR documentation partial

Planning and Risk Assessment

ASTWO-1
Audit Planning, Scaling, Risk Assessment, and Integration

Per PCAOB Auditing Standard AS 2201 paragraphs 4-14: plan the audit + scale + apply risk assessment + integrate with financial statement audit. Requirements include (a) integrate the audit of Internal Control Over Financial Reporting (ICFR) with the audit of financial statements + (b) scale the audit appropriate to the company including size + complexity + nature + risk + (c) apply risk assessment to identify accounts + disclosures + assertions presenting reasonable possibility of material misstatement + (d) consider entity-level controls + fraud risks + significant risks + risk of misstatement due to error or fraud + (e) document planning decisions including scaling + risk assessment + audit approach + integration decisions + (f) use the work of others (internal audit + others including third-party assurance) where appropriate per AS 2201 + AS 1205 / AS 2605.

Artefacts an auditor will ask for
  • PCAOB AS 2201 evidence for ASTWO-1
Where this commonly fails
  • walkthroughs documentation + deficiency severity assessment + EQR documentation partial

Quality and Subsequent Events

ASTWO-6
Engagement Quality Review and Subsequent Events

Per PCAOB AS 2201 paragraphs 21-22 + AS 1220: engagement quality review + subsequent events. Requirements include (a) perform Engagement Quality Review for issuers per AS 1220 covering significant judgments + conclusions + (b) consider Subsequent Events Affecting ICFR occurring after period-end + before report date + (c) modify conclusions where new evidence arises + (d) document engagement quality review including reviewer qualification + procedures performed + (e) inquire of management + obtain representations covering subsequent events + (f) integrate with financial statement audit subsequent events procedures.

Artefacts an auditor will ask for
  • PCAOB AS 2201 evidence for ASTWO-6
Where this commonly fails
  • walkthroughs documentation + deficiency severity assessment + EQR documentation partial

Reporting

ASTWO-8
ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports

Per PCAOB AS 2201 paragraphs 70, 85-90: report on ICFR. Requirements include (a) determine Impact on Audit Opinion based on deficiency conclusions + material weakness findings + scope limitations + (b) issue Opinion on ICFR addressing whether the company maintained in all material respects effective internal control over financial reporting as of the date specified in the company's assessment + (c) document Basis for Opinion including audit performed + (d) include Definition and Limitations of ICFR per AS 2201 standard wording + (e) determine Combined vs Separate Reports approach + (f) communicate with management + audit committee + and SEC filings + (g) maintain auditor's report quality + documentation.

Artefacts an auditor will ask for
  • PCAOB AS 2201 evidence for ASTWO-8
Where this commonly fails
  • walkthroughs documentation + deficiency severity assessment + EQR documentation partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR) framework page.