- feature
- AUDIT
SAS 149 is coming: What audit teams need to know
The standard is effective for audits of group financial statements for periods ending on or after Dec. 15, 2026. Find out how it changes group audits and how you can prepare.
Related
PEEC adopts revised definition of ‘attest engagement team’
FASAB provides new guidance on public-private partnerships disclosures
PCAOB seeks feedback on its 5-year strategic plan
A standard set to take effect for audits of group financial statements for periods ending on or after Dec. 15, 2026, represents a major change in how group audits are to be performed.
The most significant change introduced by AICPA’s Statement on Auditing Standards (SAS) No. 149, Special Considerations — Audits of Group Financial Statements (Including the Work of Component Auditors and Audits of Referred-to Auditors), is that it provides a risk-based approach to planning and performing a group audit. SAS No. 149 replaces extant AU-C 600, Special Considerations – Audits of Group Financial Statements (Including the Work of Component Auditors), which focused on the identification of “significant components” at which to perform audit work. This risk-based approach more closely aligns with AU-C section 315, Understanding the Entity and Its Environment and Assessing the Risks of Material Misstatement, and clarifies how the requirements in recent quality management standards apply to a group audit.
Firms that have refined their methodologies and developed the skills of partners and managers will be better positioned to conduct procedures based on assessed risk, produce clearer documentation, and ultimately improve audit quality as the standard is implemented.
Here are the most important changes to prepare for as the new standard takes effect:
Introducing the term ‘referred-to auditor’
SAS No. 149 introduces the term referred-to auditor and defines it as “an auditor who performs an audit of the financial statements of a component to which the group engagement partner determines to make reference in the auditor’s report on the group financial statements.” A referred-to auditor is not a component auditor and, accordingly, is not part of the engagement team for a group audit.
In extant AU-C section 600, an auditor for whom the group auditor assumes responsibility and an auditor to whom the group auditor makes reference are both termed component auditors. In SAS No. 149, the definition of component auditor is revised, and component auditors are part of the engagement team. Therefore, in accordance with AU-C section 220, the group engagement partner is responsible for the nature, timing, and extent of direction and supervision of component auditors, and the review of their work.
New terminology describes reporting options
SAS No. 149 retains the two reporting options available to the group auditor in extant AU-C section 600. In extant AU-C section 600, they are referred to as “assuming responsibility for the work of component auditors” and “making reference to the audit of a component auditor.” In SAS No. 149, the “assuming responsibility” option is now referred to as “being involved in the work of component auditors” or “when component auditors are involved.” The terminology for the “making reference” option is unchanged.
Introducing more room for professional judgment
Extant AU-C section 600 focused on identifying significant components to determine where the group engagement team should perform audit work. In SAS No. 149, the group auditor uses professional judgment in determining the components at which the group auditor should perform procedures that respond to assessed risks.
This shift better reflects the complexity of modern group structures and aligns decisions about the allocation of audit effort across components with the same risk assessment principles applied throughout the audit.
Calibrating aggregation risk
SAS No. 149 recognizes aggregation risk as a key consideration in group audits, defining it as the probability that the aggregate of uncorrected and undetected misstatements exceeds materiality for the group’s financial statements as a whole. To address this risk, the standard enhances guidance on determining group performance materiality and component performance materiality, emphasizing that component performance materiality should be set at a level lower than group performance materiality.
This approach is intended to reduce the likelihood that individually immaterial misstatements arising across multiple components could collectively result in a material misstatement at the group level.
Take, for example, a group that has multiple components spread across different regions. Each component records revenue independently and has a misstatement that is below component-level thresholds. Individually, the misstatements may not trigger concerns on their own, but aggregated they exceed group materiality.
Accordingly, the group engagement partner’s direction and supervision of component auditors, and review of their work should be commensurate with the increased aggregation risk.
How to address the changes ahead
Addressing the following in preparation for and during group audits will be critical for firms and group auditors:
Work effort
Firms need to move from a checklist-driven identification of “significant components” to a risk‑based determination of components. This means applying professional judgment to determine appropriate work effort at the component level based on assessed risks of material misstatement of the group financial statements, including for components that provide centralized services to other components (for example, shared service centers or central functions).
Certain components may now require more extensive or more granular audit work, due to higher assessed risks of material misstatement.
Engagement governance
Firms may need to reassess supervision protocols and instructions to component teams and review programs to ensure alignment with AU-C section 220 and the firm’s quality management system.
Oversight and evaluation of component auditors
If, at any stage, the group auditor concludes that the component auditor’s work is not adequate, the group auditor should determine what additional audit procedures are to be performed. Such procedures may be performed either by the component auditor or directly by the group auditor, as deemed appropriate, to obtain sufficient and appropriate audit evidence.
Also, the new standard discusses circumstances under which group auditors may perform further audit procedures centrally rather than at each component.
Communications and access
SAS No. 149 places greater emphasis on two‑way communication between the group auditor and component auditors and specifies required communications throughout the audit. For example, the group auditor is required to communicate to component auditors any relevant events or conditions identified by group management or the group auditor that may raise substantial doubt about the group’s ability to continue as a going concern for a reasonable period of time.
Equity-method investees
Consistent with extant AU-C section 600, investments accounted for using the equity method of accounting (equity-method investees) are considered components and therefore are included in the scope of SAS No. 149, just as consolidated subsidiaries or other components are.
SAS No. 149 also includes requirements and guidance regarding:
- When the audited financial statements of an equity-method investee can be used as audit evidence;
- Situations in which the auditor may determine that the financial statements of an equity-method investee do not provide sufficient appropriate audit evidence; and
- Additional procedures the group auditor may perform to obtain sufficient appropriate audit evidence.
Practitioner’s readiness checklist
SAS No. 149 represents a meaningful shift in how group audits are planned and executed. The following checklist highlights key areas practitioners generally would focus on as they prepare to implement the new standard:
- Update methodologies and templates: Revisingfirm methodologies, group audit strategy memoranda, component auditor instructions, and related documentation tools to reflect SAS No. 149’s risk‑based approach to determining components and planning audit work.
In particular, component auditor instructions may need to be updated to facilitate the enhanced communication requirements under SAS No. 149. This may include communicating identified risks of material misstatement, other information relevant to the component auditor’s risk assessment procedures, and matters that the group auditor determines to be relevant to the design of responses to assessed risks of material misstatement in the group financial statements.
- Calibrate performance materiality: Developing approaches for determining component performance materiality that are responsive to aggregation risk and component-specific characteristics. That includes risks unique to the financial information of the component and the nature and extent of misstatements identified at the component in prior audits.
- Deepen understanding of group-level systems and controls: Obtaining and documenting an understanding of the group, its environment, and the group’s system of internal control. That includes the group’s organizational structure and business model, the nature and extent of commonality of controls, the locations in which the group has its operations or activities, the extent to which the group’s business model integrates the use of IT, and the consolidation process to support the identification and assessment of risks of material misstatement at both the component and group level.
- Plan the “make-reference” decision early: When the group engagement partner is considering making a reference to the report of a referred-to auditor, it is best that this decision be made early.
— Navneet Sharma is partner for international assurance and accounting advisory at KNAV, a multinational accounting and consulting firm based in Atlanta. To comment on this article or to suggest an idea for another article, contact Jeff Drew at Jeff.Drew@aicpa-cima.com.
