A public company’s audit doesn’t run on the same rulebook as a private company’s. The firm doing the audit has to be registered with a specific federal regulator as well as tested against that regulator’s own standards. More so, the auditor has to be inspected by that regulator on a recurring schedule, on top of the audit opinion it issues.
The regulator in question is the Public Company Accounting Oversight Board (PCAOB), created under the Sarbanes-Oxley Act of 2002 after Arthur Andersen – Enron’s auditor – failed to catch the audit failures behind Enron and WorldCom. Since Audit Firms working with a PCOAB-registered auditor have matured and put many processes in place to ensure compliance.
For a legal, compliance, or finance team working with a PCAOB-registered auditor, or preparing for one, the same handful of questions tend to come up: how PCAOB rules differ from the SEC’s, from US GAAP, and from a standard audit, and what the standards actually require in practice. Those are some of the questions this guide will cover.
What is PCAOB?
The Public Company Accounting Oversight Board (PCAOB) is a nonprofit corporation established by Congress under the Sarbanes-Oxley Act of 2002 to oversee the audits of public companies and SEC-registered broker-dealers. Its stated mission is to protect investors and the public interest by promoting informative, accurate, and independent audit reports.
The PCAOB carries out four core functions:
- Registering public accounting firms that audit issuers (i.e. companies that file reports with the SEC) and SEC-registered brokers and dealers. A firm cannot legally audit a public company without first registering with the PCAOB.
- Setting the auditing, attestation, quality control with multiple internal reviews, ethics, and independence standards that registered firms must follow when they audit a public company.
- Inspecting registered firms’ audit engagements and quality control systems on a recurring cycle.
- Investigating and disciplining firms and individuals when they violate PCAOB rules/standards or securities laws related to audits.
The PCAOB is overseen by a five-member board, including a chair, appointed by the SEC to staggered five-year terms. It is privately funded through fees assessed on issuers and broker-dealers, not through Congressional appropriation. That said, the SEC approves its annual budget.
Why is the PCAOB so important?
The PCAOB exists because the accounting profession’s prior framework of self-regulation failed to catch the audit failures behind Enron and WorldCom. Before Sarbanes-Oxley, auditors were policed largely by their own professional body. After Enron’s auditor, Arthur Andersen, collapsed alongside its client, Congress concluded that audit oversight needed to sit outside the profession it was overseeing.
The gap PCAOB fills is independent inspection of audit work, standard-setting with SEC approval rather than industry self-approval, and the power to discipline firms and individual auditors. PCAOB audits are subject to direct, independent inspection by a regulator specifically created by Congress to replace industry self-regulation after the Arthur Andersen/Enron failures.
For investors, the practical effect is that the audit opinion attached to a public company’s financial statements has been through registration, standard-setting, and inspection processes that did not exist before 2002.
What is the difference between SEC and PCAOB?
The SEC and the PCAOB are separate bodies with a direct reporting relationship. The SEC created the PCAOB, appoints and can remove its board members, and approves its budget, rules, and standards before they take effect. The PCAOB cannot adopt a new auditing standard on its own. It proposes the standard, takes public comment, and then submits it to the SEC for approval.
The two agencies also cover different ground. The SEC’s mandate is broad securities regulation: company disclosure, market conduct, and enforcement of the federal securities laws generally.
The PCAOB’s mandate is narrower and specific to the audit profession. It registers audit firms, writes the standards those firms must audit against, inspects their work, and disciplines auditors who fall short. Any firm auditing a public company has to be on that registry, from the Big Four, Deloitte, EY, PwC, and KPMG, down to firms like BDO, RSM, Grant Thornton, and Baker Tilly, which also audit a substantial share of public companies. A company files its financial statements with the SEC, while the PCAOB’s interest is in the quality of the audit that stands behind those financial statements.
What are the key differences between PCAOB and US GAAP?
US Generally Accepted Accounting Principles (GAAP) and PCAOB auditing standards answer two different questions.
GAAP, issued by the Financial Accounting Standards Board (FASB) and recognized by the SEC as the designated private-sector standard setter, governs how a company prepares and presents its financial statements: how to recognize revenue, value inventory, or disclose a lease.
PCAOB standards, on the other hand, govern how an independent auditor verifies that those financial statements are fairly presented: what evidence to gather, how to assess fraud risk, and what to test in a company’s internal controls.
Why is PCAOB more rigorous than GAAS audits?
Audits performed under Generally Accepted Auditing Standards (GAAS) reflect the standards the American Institute of CPAs (AICPA) sets for private companies, nonprofits, and other entities that don’t file with the SEC. A PCAOB audit applies to a narrower population, namely issuers and SEC-registered broker-dealers.
There are also some practical differences between the two audits worth specifying. For accelerated and large accelerated filers, the auditor must also test and report on internal control over financial reporting (ICFR) under AS 2201. This is something most GAAS audits don’t require. PCAOB audits also call for a second-partner engagement quality review under AS 1220. And the audit firm itself is subject to PCAOB registration and inspection, whereas a firm doing only GAAS audits goes through peer review instead.
PCAOB independence and documentation rules tend to be stricter too, since these audits sit behind financial statements that trade in public markets.
What are PCAOB auditing standards?
PCAOB auditing standards (“AS”) are the specific procedures and requirements an auditor must follow when auditing an issuer or a broker-dealer. They sit alongside PCAOB attestation standards, quality control standards, and independence and ethics rules. Together, they make up the PCAOB’s full standard-setting output.
The auditing standards are organized into numbered series by subject:
- AS 1000 series: general principles and responsibilities, including AS 1000 (General Responsibilities of the Auditor), AS 1215 (Audit Documentation), and AS 1220 (Engagement Quality Review).
- AS 2100 through AS 2900 series: audit procedures, covering planning, risk assessment (AS 2110), internal control testing (AS 2201), and specific audit areas such as related parties (AS 2410) and accounting estimates (AS 2501).
- AS 3100 series: auditor reporting, including AS 3101 (The Auditor’s Report on an Audit of Financial Statements).
- AS 4100 series: responsibilities tied to specific SEC filings, such as interim review procedures.
- AS 6100 series: other matters, including letters to underwriters and reports on compliance with agreements.
The PCAOB also maintains QC 1000, a quality control standard adopted in 2024 that sets firm-level requirements for managing audit quality, separate from the engagement-level AS series.
When do PCAOB auditing standards apply?
PCAOB auditing standards apply to the audits of issuers (i.e. companies required to file reports with the SEC) and to audits of SEC-registered broker-dealers. They do not apply to audits of private companies, nonprofits, or government entities, which generally follow AICPA GAAS instead.
Individual standards also carry their own effective dates, tied to fiscal year start or end dates rather than calendar dates. The PCAOB periodically amends or replaces standards.
How long does a PCAOB audit take?
The PCAOB does not set a required duration for an audit. How long an audit takes depends on the company’s size, the complexity of its accounting, whether it is a first-year or recurring client, and whether the auditor must also test internal controls under AS 2201.
The SEC’s own reporting deadline is what constrains the calendar. A large accelerated filer must file its Form 10-K within 60 days of fiscal year end, an accelerated filer within 75 days, and all other filers within 90 days. The audit has to be substantially complete well before that filing date, since the audit opinion is part of the 10-K itself.
One fixed deadline does apply after the audit is done. Under AS 1215, the auditor must assemble a complete and final set of audit documentation for retention no more than 14 days after the report release date. That 14-day window was shortened from a longer period as part of the PCAOB’s 2024 update to its foundational standards. This puts pressure on how quickly a firm can pull together the evidence a workpaper file depends on, including the content, files, comments and documentation from the audit tool used for the audit, as well as Slack and Teams messages, and other collaboration records among them.
How often does the PCAOB review audit firms?
Under Section 104 of the Sarbanes-Oxley Act, the PCAOB inspects a registered firm annually if that firm provides audit opinions for more than 100 issuers in a year. Firms that audit 100 or fewer issuers are generally inspected at least once every three years. The PCAOB publishes firm-specific inspection reports, so a company can look up how its own auditor has performed in recent inspection cycles.
What are PCAOB audit requirements?
An audit performed under PCAOB standards carries a specific set of obligations for both the auditor and, indirectly, the company being audited:
- The auditor must be registered with the PCAOB before it can issue an opinion on an issuer’s or broker-dealer’s financial statements.
- The auditor must maintain independence from the audit client, under both PCAOB and SEC independence rules.
- The engagement must follow the applicable AS series for planning, risk assessment, evidence-gathering, and reporting, and must include an engagement quality review under AS 1220 before the report is released.
- For accelerated and large accelerated filers, the auditor must also test and issue an opinion on internal control over financial reporting under AS 2201.
The auditor must assemble and archive a complete audit file within 14 days of the report release date under AS 1215, and retain that documentation for seven years.
The firm itself is subject to PCAOB registration renewal, inspection, and, where findings warrant it, disciplinary proceedings.
4 best practices for legal and compliance teams preparing for a PCAOB audit
Mapping where the evidence lives before the auditor asks.
A PCAOB audit routinely reaches beyond the general ledger into website content, Slack and Teams channels, and shared drives. Teams that already know which systems hold what, and who owns them, can turn around a request in hours.
Preserving dynamic content as it changes.
An audit tool software or a Slack thread looks different by the time an auditor asks about it months later. Plus, a screenshot taken after the fact doesn’t show what a reader actually saw on the date in question. Capturing it with a timestamp and a way to verify it hasn’t been altered is what makes it usable as evidence.
Tracking ICFR evidence continuously where AS 2201 applies.
For accelerated and large accelerated filers, control testing runs against evidence gathered throughout the year. A control that isn’t documented as it operates is one the auditor has to test some other way, which adds time and cost to the engagement.
Retaining records for the full seven years.
AS 1215’s retention period outlasts most default IT settings. A Slack workspace’s own retention policy can delete something before the seven years are up, unless retention is set independently of those defaults.
What an audit intelligence platform for PCAOB compliance does
The underlying evidence behind a PCAOB audit often sits with the company being audited, not the audit firm. Examples include website content that changed between quarters, Slack or Teams threads relevant to a transaction, or records that support a disclosure. The audit firm still has to assemble and archive that evidence within 14 days of the report release date and retain it for seven years. If the company can’t produce it in reviewable form, the firm’s own deadline cannot be met.
That’s the specific gap a modern audit intelligence platform for PCAOB compliance is built to close. It captures collaboration and web content the way it looked at the time, with a timestamp and a hash value instead of a static screenshot. That way, the record holds up to review months or years later, whether it’s the auditor doing the reviewing or a PCAOB inspector.
Hanzo’s Chronicle and Illuminate products are built around that problem specifically, preserving the underlying records an audit or inspection may ask for in a form that survives scrutiny. See how the solutions work for PCAOB audit-ready evidence.
Sources: PCAOB: About | PCAOB: Auditing Standards | PCAOB: Basics of Inspections | PCAOB: AS 1215, Audit Documentation | PCAOB: Background on the PCAOB (Board Member Steven B. Harris) | SEC: Investor.gov PCAOB glossary | SEC: Policy Statement Reaffirming the Status of the FASB as a Designated Private-Sector Standard Setter | SEC: Form 10-K