6.3 Group Audits: AU-C 600 and the SAS No. 149 Transition
Key Takeaways
- The group engagement partner is responsible for the direction, supervision, and performance of the group audit and for the auditor's report on the group financial statements.
- Before using a component auditor's work, the group engagement team evaluates independence, competence, its ability to be involved in the work, and the component auditor's regulatory environment.
- Extant AU-C 600 requires component materiality below group materiality; SAS No. 149 instead requires component performance materiality below group performance materiality.
- US GAAS lets the group auditor either assume responsibility for another auditor's work or make reference to that auditor, and making reference does not modify the opinion.
- SAS No. 149 applies to periods ending on or after December 15, 2026, so under AICPA policy it becomes eligible for CPA Exam testing in January 2027.
6.3 Group Audits: AU-C 600 and the SAS No. 149 Transition
Core Principle: Many enterprises operate through subsidiaries, divisions, joint ventures, and equity-method investees. AU-C 600 (Special Considerations — Audits of Group Financial Statements) makes the group engagement partner responsible for the direction, supervision, and performance of the group audit and for the report on the group financial statements. The ASB has issued SAS No. 149, which supersedes extant AU-C 600 for audits of group financial statements for periods ending on or after December 15, 2026. Because AICPA policy makes a pronouncement testable in the later of the first calendar quarter after its earliest mandatory effective date or six months after issuance, SAS No. 149 becomes testable in January 2027. This section teaches the extant framework and flags what changes.
| Topic | Extant AU-C 600 | SAS No. 149 |
|---|---|---|
| Approach | Components identified largely by their significance to the group | Risk-based: the group auditor determines components for planning and performing procedures |
| Other auditors | Component auditors, who may be referred to in the report | Component auditors are part of the engagement team; auditors the group auditor makes reference to are referred-to auditors |
| Materiality | Component materiality lower than group materiality | Component performance materiality lower than group performance materiality |
| Making reference | Permitted when conditions are met | Still permitted, to a referred-to auditor, when conditions are met |
1. Key Definitions & Architecture Under AU-C 600
Mastering group audit mechanics requires a precise grasp of authoritative standard-setting terminology:
GROUP FINANCIAL STATEMENTS
(Includes financial information of multiple components)
|
GROUP ENGAGEMENT PARTNER
(Bears ultimate audit opinion responsibility)
|
GROUP ENGAGEMENT TEAM
(Directs, supervises, and performs group audit)
|
+--------------------------+--------------------------+
| |
[ INTERNAL WORK ] [ COMPONENT AUDITORS ]
Procedures performed directly Other auditors performing work on
by the group engagement team subsidiaries, divisions, or investments
- Group Financial Statements: Financial statements that include the financial information of more than one component (e.g., consolidated financial statements, combined financial statements, or financial statements reflecting equity-method investments).
- Component: An entity, business unit, function, or business activity (or combination thereof) for which group or component management prepares financial information that is included in the group financial statements (e.g., a foreign subsidiary, an operating segment, or an investee).
- Group Engagement Partner (GEP): The partner or other person in the audit firm who is responsible for the group audit engagement and its performance, and for the auditor's report on the group financial statements that is issued on behalf of the firm.
- Group Engagement Team: Partners (including the group engagement partner) and staff who establish the group audit strategy, communicate with component auditors, perform work on the consolidation process, and evaluate the conclusions drawn from the audit evidence. Under SAS No. 149, component auditors become part of the engagement team.
- Component Auditor: An auditor who performs audit work on financial information of a component for purposes of the group audit. A component auditor may be part of the group auditor's firm network or an entirely unaffiliated independent audit firm.
2. The Group Auditor's Ultimate Responsibility
The most fundamental tenet of AU-C 600 is that the group engagement partner is responsible for the group audit and the auditor's report on the group financial statements. When the group auditor makes reference to another auditor, the report shows the division of responsibility for that portion:
- No Abdication of Responsibility: The group auditor cannot merely compile component audit reports without independently assessing the risks, directing audit effort, and reviewing component auditor work.
- Direction, Supervision, and Review: The group engagement team is responsible for directing, supervising, and performing the group audit engagement in compliance with professional standards and regulatory requirements.
- Determining Sufficiency of Evidence: The group auditor must decide whether the audit evidence obtained from group-level procedures and component auditor work is sufficient and appropriate to form the group audit opinion.
3. Mandatory Evaluation of the Component Auditor
Before relying on the work of a component auditor—or deciding to make reference to them in the group audit report—the group engagement team must thoroughly evaluate four essential pillars:
+-------------------------------------------------------------------------------------------------------+
| FOUR PILLARS OF COMPONENT AUDITOR EVALUATION |
| |
| 1. ETHICS & INDEPENDENCE 2. PROFESSIONAL COMPETENCE & CAPABILITIES |
| Does the component auditor comply Does the component auditor possess technical skill, |
| with ethical requirements and industry expertise, GAAS/IFRS mastery, and adequate |
| independence rules applicable to resources to perform the assigned audit work? |
| the group audit? |
| |
| 3. GROUP TEAM INVOLVEMENT 4. REGULATORY OVERSIGHT ENVIRONMENT |
| Will the group engagement team be Does the component auditor practice within an active, |
| able to be involved in the work of credible regulatory regime with external peer reviews |
| the component auditor as needed? or professional oversight inspections? |
+-------------------------------------------------------------------------------------------------------+
Detailed Evaluation Criteria
- Independence: The component auditor must confirm independence under the specific ethical rules governing the group audit (e.g., AICPA Code of Conduct for US entities, or SEC/PCAOB independence rules if the group is an SEC registrant). If the component auditor is not independent, the group auditor cannot use their work or make reference to them.
- Competence: The group auditor assesses whether the component auditor understands applicable auditing standards (US GAAS or PCAOB standards) and financial reporting frameworks (US GAAP or IFRS), and possesses specialized industry knowledge (e.g., oil and gas extraction, banking regulations).
- Involvement & Access: If the group auditor cannot participate in the component auditor's risk assessment, observe testing, or review workpapers due to legal restrictions, privacy laws, or management obstruction, a scope limitation arises.
4. Two-Way Communication Protocols
AU-C 600 mandates continuous, structured two-way communication between the group engagement team and component auditors:
What the Group Engagement Team Must Communicate
- Confirmation of Cooperation: Requesting written confirmation that the component auditor will cooperate and comply with ethical/independence requirements.
- Materiality Thresholds: Communicating component materiality, component performance materiality, and the threshold above which misstatements cannot be regarded as clearly trivial.
- Identified Significant Risks: Informing the component auditor of identified significant risks of material misstatement of the group financial statements (e.g., group-wide revenue recognition fraud risks or related party transactions).
- List of Related Parties: Providing a comprehensive list of known related parties and requesting notification of any previously unidentified related party relationships.
- Audit Timetable & Deliverables: Setting deadlines for completing fieldwork, reporting deliverables, and closing meetings.
What the Component Auditor Must Communicate to the Group Team
- Compliance Confirmation: Confirmation of compliance with relevant ethical requirements, independence, and group auditor instructions.
- Identification of New Risks: Significant risks of material misstatement identified at the component level, including new fraud risk factors.
- Non-Compliance & Fraud: Any identified or suspected non-compliance with laws, regulations, or fraud involving component management.
- Schedule of Misstatements: A detailed schedule of corrected and uncorrected misstatements in the component's financial information.
- Indicators of Management Bias: Any identified bias regarding significant accounting estimates or accounting policies.
- Internal Control Deficiencies: Significant deficiencies and material weaknesses in internal control identified at the component level.
- Overall Findings & Conclusion: The component auditor's overall audit opinion or conclusion on the component financial information.
5. Determining Component Materiality & Aggregation Risk
One of the most heavily tested topics on the CPA AUD examination is the calculation and relationship of component materiality to group materiality:
+-------------------------------------------------------------------------------------------------------+
| THE COMPONENT MATERIALITY RULE |
| |
| GROUP FINANCIAL STATEMENT MATERIALITY = $1,000,000 |
| |
| --> COMPONENT MATERIALITY MUST BE LOWER THAN GROUP MATERIALITY (e.g., $400,000 or $600,000) |
| |
| MATHEMATICAL & AUDITING RATIONALE: |
| If component materiality were set equal to group materiality ($1,000,000), undetected |
| misstatements of $700,000 in Component A and $600,000 in Component B would remain undetected at |
| the component level, but aggregate to $1,300,000 at the consolidated level, causing the group |
| financial statements to be materially misstated! Setting component materiality lower limits |
| the accumulation of undetected misstatements. |
+-------------------------------------------------------------------------------------------------------+
Authoritative Materiality Standards
- Must Be Lower (extant AU-C 600): Component materiality for components that receive an audit or review must be lower than group materiality. SAS No. 149 applies the same logic to component performance materiality.
- Established by Group Auditor: Component materiality is established by the group engagement team (or determined by the component auditor and reviewed/approved by the group team).
- Different Thresholds per Component: Different components may have different component materiality thresholds based on their relative size, complexity, and assessed risk profile. The sum of individual component materialities may exceed group materiality, but no single component materiality can equal or exceed group materiality.
- Component Performance Materiality: The group auditor must also establish or approve component performance materiality (tolerable misstatement) to reduce aggregation risk at the component assertion level.
6. The Group Reporting Decision: Making Reference vs. Assuming Responsibility
Under US GAAS (AU-C 600), when a component is audited by another auditor, the group engagement partner must make a critical reporting election:
THE GROUP REPORTING DECISION (GAAS)
|
+--------------------------+--------------------------+
| |
[ ASSUME RESPONSIBILITY ] [ MAKE REFERENCE ]
| |
NO REFERENCE MADE IN REPORT REFERENCE MADE IN AUDIT REPORT
| |
- Group auditor takes 100% responsibility - Audit report clearly divides responsibility
- Standard unmodified report language - Permissible ONLY IF strict conditions met
- Group auditor must be extensively involved - States magnitude of audited portion ($, %)
in component auditor's work - NOT a qualified opinion! Unmodified with
- Component auditor is NOT named shared responsibility
Pathway A: Assuming Responsibility (No Reference)
- Mechanics: The auditor's report on the group financial statements makes no reference to the component auditor. The group engagement partner assumes full professional responsibility for all work performed.
- Requirements: The group engagement team must be extensively involved in the component auditor's risk assessment, audit strategy, review of workpapers, and substantive testing.
- Report Format: The audit report reads exactly as if the group auditor had audited 100% of the consolidated entity.
Pathway B: Making Reference to the Component Auditor
Under US GAAS, the group auditor is permitted to refer to the component auditor in the group audit report, provided that three strict prerequisites are met:
- Audited Under GAAS or PCAOB: The component auditor has performed an audit of the component's financial statements in accordance with GAAS (or PCAOB standards when applicable).
- Unrestricted Audit Report: The component auditor's report is not restricted as to use.
- Competence & Independence Confirmed: The group auditor has determined that the component auditor complies with relevant ethical/independence requirements and possesses professional competence.
Report Wording When Reference Is Made
When the group auditor decides to make reference to the component auditor:
- Magnitude Disclosure: The group audit report must clearly disclose the magnitude of the portion of the financial statements audited by the component auditor (expressed as dollar amounts or percentages of total assets, total revenues, or net income).
- Division of Responsibility: In the Opinion section, the report states that the opinion, insofar as it relates to the amounts and disclosures included for that component, is based solely on the report of the component auditor.
- Naming the Component Auditor: The component auditor may be named in the group audit report only with the component auditor's express written permission, and the component auditor's report must be filed or presented together with the group report.
- Crucial Exam Rule: Making reference to a component auditor is NOT a modification or qualification of the audit opinion! It is an unmodified opinion with shared responsibility.
GAAS vs. PCAOB vs. International Standards (ISA)
| Standard Setter | Standard | Making Reference Permitted? | Core Reporting Philosophy |
|---|---|---|---|
| AICPA (US GAAS) | AU-C 600 (SAS No. 149 for periods ending on or after Dec. 15, 2026) | YES (Optional) | Group auditor may choose to assume sole responsibility OR make reference to divide responsibility. |
| PCAOB (US Public) | AS 1206 (replaced AS 1205 for fiscal years beginning on or after Dec. 15, 2024) | YES (Optional) | Permitted to refer to other independent auditors or assume responsibility under supervision rules. |
| IAASB (International) | ISA 600 (Revised) | Not permitted (unless law or regulation requires it) | The report on the group financial statements does not refer to a component auditor unless law or regulation requires the reference. |
In planning a group audit under AU-C 600, the group engagement team calculates materiality for the consolidated group financial statements as a whole at $1,000,000. Which of the following rules strictly governs the determination of component materiality for an operating subsidiary?
The group engagement partner of a US holding company decides to make reference to a component auditor who audited an overseas operating subsidiary. Under US GAAS (AU-C 600), which of the following statements correctly describes the prerequisites and reporting consequences of this decision?
Under AU-C 600, who bears ultimate responsibility for the direction, supervision, and performance of the group audit engagement, as well as the auditor's report issued on the group financial statements?
During the execution of a group audit under AU-C 600, what is a required element of two-way communication between the group engagement team and the component auditor?