Published by Shah Teelani & Associates | PCAOB-Registered Audit Firm | Reg. No. 7161
ICFR testing for accelerated filers is one of the most demanding requirements in public company financial reporting. It goes beyond the standard financial statement audit. It requires an independent auditor to express a separate opinion on whether the company’s internal controls over financial reporting are effective — and that opinion carries real consequences for investors, management, and the board.
Effective internal control over financial reporting provides reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes. Moreover, when ICFR testing fails to detect material weaknesses, investors receive a false assurance that the financial statements resting on those controls can be trusted.
In 2026, the PCAOB’s 2024 Staff Update reported a 39% ICFR deficiency rate — a reminder that design and operating effectiveness remain a moving target even for mature programs. Furthermore, individual firm inspection reports continue to cite ICFR-related issues, particularly around testing design and operating effectiveness of controls and validating the accuracy and completeness of data and reports.
At Shah Teelani & Associates, we perform integrated audits for accelerated filers under PCAOB AS 2201. This blog explains everything accelerated filers must understand about ICFR testing — from the thresholds that trigger the requirement through the 2026 standard updates that reshape how it is performed.
Who Is an Accelerated Filer — and Why It Matters
The first question every public company must answer is whether it qualifies as an accelerated filer. The answer determines whether the company must obtain an independent auditor attestation on ICFR under Section 404(b) of the Sarbanes-Oxley Act.
Under the amended rule, issuers with public float between $75 million and $700 million and $100 million or more in annual revenue qualify as an accelerated filer. Large accelerated filers have public float exceeding $700 million.
However, there is an important carve-out. Companies qualifying as smaller reporting companies with less than $100 million in annual revenues will no longer be subject to the SOX 404(b) requirement to have an auditor attestation report on ICFR. Therefore, a company with a public float between $75 million and $700 million but revenues below $100 million may avoid the ICFR auditor attestation requirement despite meeting the float threshold.
Companies should redetermine their filer status annually. Registrants that determine for the first time that they must follow the accelerated filer requirements should begin planning to comply with Section 404(b) — which requires them to obtain independent auditor attestation on the effectiveness of their ICFR. Consequently, companies approaching accelerated filer thresholds must build ICFR readiness into their planning well before the threshold is crossed.
2026 Filer Status Proposal — A Major Change on the Horizon
In May 2026, the SEC proposed a significant simplification of the filer status framework. The proposal would consolidate the current five-category filer status system into two principal categories — large accelerated filers and non-accelerated filers. It would raise the public float threshold for large accelerated filer status from $700 million to $2 billion. Furthermore, only large accelerated filers would remain subject to the SOX 404(b) ICFR auditor attestation requirement.
This proposal is not yet final. However, companies near current thresholds should monitor its progress closely — it could materially affect their ICFR obligations in future reporting cycles.
What the Integrated Audit Requires Under AS 2201
PCAOB AS 2201 governs ICFR testing for accelerated filers. It requires the auditor to perform an integrated audit — combining the financial statement audit with a separate audit of ICFR. The result is two opinions in one report.
AS 2201 mandates that for accelerated filers and large companies, the auditor must express an opinion on both the financial statements and the effectiveness of the company’s ICFR. The ICFR audit requires the auditor to test the design and operating effectiveness of controls at a level that provides reasonable assurance against material misstatement. This includes evaluating management’s assessment process and testing controls related to significant accounts and disclosures.
Moreover, the integrated audit cannot be separated. The financial statement audit and the ICFR audit must be conducted together. They share the same risk assessment, the same planning process, and the same report date. Therefore, the ICFR work is not an add-on — it is woven into the entire engagement.
Management’s Responsibility vs. the Auditor’s Responsibility
Accelerated filers must understand the distinct but complementary roles of management and the external auditor in ICFR testing.
Management’s responsibility under SOX Section 404(a) is to establish and maintain adequate ICFR and to assess its effectiveness annually. This assessment must use a recognized framework — most commonly the COSO Internal Control — Integrated Framework. Management must document its assessment, identify any material weaknesses, and include its conclusion in the annual report.
The auditor’s responsibility under Section 404(b) and AS 2201 is to independently audit management’s assessment and to form an independent opinion on whether ICFR is effective. The auditor does not simply review management’s work. The auditor performs independent testing — walkthroughs, controls tests, IT general controls evaluation, and deficiency assessment — and reaches independent conclusions.
Importantly, the company’s management is responsible for maintaining effective internal control over financial reporting and for its assessment of the effectiveness of ICFR. The auditor’s responsibility is to express an opinion on the company’s financial statements and an opinion on the company’s internal control over financial reporting based on the audits.
The Top-Down, Risk-Based Approach to ICFR Testing
AS 2201 requires a top-down, risk-based approach to ICFR testing. This approach determines which controls receive the most intensive testing. Additionally, it prevents auditors from testing every control in the company — which would be both impractical and unnecessary.
Auditors begin at the financial statement level, focus first on entity-level controls, and work down to significant accounts, disclosures, and relevant assertions. SOX teams should ensure entity-level controls are well-designed and documented, and process-level controls are explicitly linked to specific assertions and material misstatement risks.
The sequence follows four levels. First, the auditor evaluates entity-level controls. Second, the auditor identifies significant accounts and disclosures. Third, the auditor identifies relevant assertions for each significant account. Fourth, the auditor selects key controls that address the risks associated with those assertions.
Why Entity-Level Controls Shape Everything Below
Control environment assessment shapes every subsequent decision in an integrated audit. Under PCAOB AS 2201, the auditor’s understanding of internal control components — including the control environment — shapes the nature, timing, and extent of audit procedures. When this foundation is weak, auditors expand substantive testing across the entire engagement.
Therefore, accelerated filers with strong entity-level controls reduce the breadth of process-level testing required. Conversely, entity-level weaknesses create a ripple effect — expanding testing scope, extending timelines, and increasing audit costs throughout the engagement.
Identifying Significant Accounts and Key Controls
ICFR testing concentrates on significant accounts — those where there is a reasonable possibility of material misstatement. The auditor identifies significant accounts through the risk assessment process. Materiality, volume of transactions, complexity, and prior-year findings all inform this determination.
For each significant account, the auditor identifies the relevant assertions. Completeness, accuracy, valuation, existence, and presentation each carry different risks and require different controls. Furthermore, the auditor then identifies which controls address those assertion-level risks most directly. These become the key controls subject to testing.
Control precision matters considerably. A high-precision control catches misstatements at a lower threshold. A low-precision control may miss errors that aggregate to a material amount. Consequently, PCAOB inspectors evaluate whether auditors assessed the precision of each key control — not just whether the control operated.
Testing Design Effectiveness
Design effectiveness testing asks one specific question: if this control operated as intended, would it prevent or detect a material misstatement? Testing design effectiveness requires the auditor to understand the control objective, evaluate the logic of how the control addresses the risk, and confirm that the control covers the full population of transactions it is meant to address.
Auditors test the design and effectiveness of controls and whether they are operating as intended by management so that controls can effectively prevent or detect errors or fraud that could result in material misstatements in the financial statements.
Design effectiveness testing must come before operating effectiveness testing. Testing the operation of a poorly designed control produces unreliable conclusions. Moreover, a control that passes operating effectiveness testing but has a fundamental design gap still represents a control deficiency.
Testing Operating Effectiveness
Operating effectiveness testing asks whether the control actually functioned as designed throughout the audit period. This requires evidence — not just documentation of the control’s existence.
The most common Part I.A deficiencies in 2024 related to testing the design or operating effectiveness of controls selected for testing, and testing controls over the accuracy and completeness of data or reports used in controls.
Evidence of operating effectiveness includes inspection of documentation produced by the control, re-performance of control procedures, observation of control execution, and inquiry of control owners supported by independent corroboration. The timing of testing matters additionally. Controls tested only at year-end may not support a conclusion about operating effectiveness throughout the entire period. Therefore, roll-forward procedures and interim testing are essential components of a complete operating effectiveness assessment.
Information Used in Controls: A Persistent Inspection Issue
Evaluating every report and spreadsheet used in the performance of a control is critical. A seemingly single critical report may actually draw from five different data sources. Each one needs to be evaluated. Additionally, the completeness and accuracy of information produced by IT systems — system-generated reports, automated calculations, and data extracts — must be validated before the controls relying on that information can be tested.
This is a recurring PCAOB inspection finding. Auditors who test a control without validating the completeness and accuracy of the underlying data produce unreliable conclusions about operating effectiveness. Consequently, IT general controls testing and information-used-in-controls validation must be completed before key controls testing begins.
IT General Controls in the ICFR Framework
IT general controls underpin the reliability of every automated application control. Where ITGCs are deficient — particularly in logical access, change management, and computer operations — reliance on automated controls becomes unreliable. Consequently, ITGC deficiencies create cascading risks throughout the ICFR framework.
Auditors test ITGCs first because their failure invalidates reliance on automated application controls and system-generated reports — a frequent root cause behind the PCAOB’s 39% ICFR deficiency rate reported in 2024.
Moreover, amended AS 2201 expands the use of benchmarking for fully automated application controls. If IT general controls over the underlying system — particularly change management and access — are effective and the control logic has not changed, auditors can conclude the control remains effective without repeating prior-year operating effectiveness testing.
This benchmarking provision is a meaningful efficiency tool. However, it requires strong ITGC documentation and a confirmed assessment that control logic has not changed during the period. Accelerated filers must therefore maintain comprehensive ITGC evidence throughout the year — not assemble it retroactively at year-end.
Walkthroughs: The Auditor’s Direct Confirmation
AS 2201 requires auditors to perform walkthroughs of each significant process. A walkthrough traces a transaction from initiation through recording in the financial statements. It allows the auditor to confirm their process understanding, identify where controls operate, and evaluate design effectiveness firsthand.
Walkthroughs must be performed by the auditor — not delegated entirely to internal audit or management. Furthermore, they must document specific transactions traced through the system, documents examined, personnel interviewed, and conclusions reached. PCAOB inspection findings consistently identify walkthrough deficiencies where auditors accepted management’s process narrative without independently tracing transactions. Consequently, walkthrough documentation must reflect actual testing — not a review of flowcharts.
Evaluating and Classifying Deficiencies
Where ICFR testing identifies control weaknesses, AS 2201 requires the auditor to classify each deficiency and evaluate whether deficiencies combine to reach a higher severity threshold.
A standards-consistent workflow moves through four steps: gather and document the facts about the deficiency; evaluate likelihood and magnitude with attention to cross-account interactions; test whether compensating controls hold up under precision standards; and conclude on the classification with documentation that ties back to each step.
The three classifications — control deficiency, significant deficiency, and material weakness — carry progressively more serious reporting and disclosure consequences. A material weakness requires an adverse ICFR opinion. PCAOB inspections frequently flag weak compensating-control precision and incomplete aggregation analysis. Early alignment among management, internal audit, and external auditors reduces late-stage severity changes.
What Accelerated Filers Must Do to Prepare for ICFR Testing
Effective ICFR testing begins long before the auditor arrives. Accelerated filers who prepare throughout the year — rather than scrambling at year-end — produce better outcomes and reduce the risk of late-stage deficiency reclassifications.
Specifically, accelerated filers should:
- Maintain current control documentation — process narratives, risk and control matrices, and evidence of control operation must reflect current operations, not prior-year descriptions
- Validate information used in controls — identify every report, spreadsheet, and data extract used in key controls and document their completeness and accuracy throughout the year
- Strengthen IT general controls — particularly logical access reviews, change management procedures, and system-generated report validation
- Perform management’s 404(a) assessment rigorously — do not simply confirm what the auditor found; conduct an independent evaluation with documented conclusions
- Address prior-year deficiencies promptly — PCAOB inspectors evaluate whether firms identify improvements in areas with prior deficiencies; issuers should demonstrate visible remediation
- Engage the external auditor early — align on scope, discuss control environment changes, and identify areas requiring particular attention before fieldwork begins
The 2026 ICFR Testing Environment
Amended PCAOB AS 2201 and AS 2101, effective for audits of fiscal years beginning on or after December 15, 2026, formalize a top-down, risk-based scoping approach centered on entity-level controls. Process-level controls must be explicitly linked to specific assertions and material misstatement risks.
This formalization matters practically. Controls that exist in the documentation but lack explicit assertion-level linkage will not satisfy the amended standard. Accelerated filers must therefore review their control matrices and confirm that every key control connects to a specific risk and a specific assertion before the effective date arrives.
Furthermore, the SEC’s May 2026 proposal to restructure filer categories warrants monitoring. If finalized, it could expand the ICFR attestation requirement to fewer companies — or reshape the thresholds that determine which companies bear the integrated audit obligation.
The Bottom Line
ICFR testing for accelerated filers is not a compliance exercise. It is a meaningful investor protection mechanism that requires rigorous design, thorough execution, and defensible documentation throughout. Where it works well, it produces reliable financial reporting. Where it fails — as a 39% deficiency rate confirms — it exposes investors and companies alike to misstatement risk.
In 2026, with amended AS 2201 taking effect, PCAOB inspections continuing to flag control testing deficiencies, and a potential restructuring of filer categories on the horizon, every accelerated filer must treat ICFR testing readiness as a year-round operational priority.
Shah Teelani & Associates (PCAOB Reg. No. 7161) performs integrated ICFR audits for accelerated filers under PCAOB AS 2201. We work with US-listed and OTC public companies that understand what rigorous ICFR testing requires and want an auditor equally committed to getting it right.
If your organization requires a PCAOB-registered auditor with deep ICFR expertise, we welcome the conversation.
Shah Teelani & Associates PCAOB-Registered Audit Firm | Reg. No. 7161 Ahmedabad | Dubai | United States