Group audits anchored in U.S. generally accepted auditing standards (GAAS) are about to change in a meaningful way. Statement on Auditing Standards No. 149, the AICPA Auditing Standards Board’s overhaul of group audit guidance, retires the long-standing “significant components” model in favor of a risk-based approach, and it introduces new auditor terminology that engagement teams need to learn now. If your organization issues consolidated or combined financial statements, or your auditors rely on the work of other firms, this GAAS standard reshapes how the audit is planned, scoped, and documented.
Quick answer: SAS 149, Special Considerations: Audits of Group Financial Statements (Including the Work of Component Auditors and Audits of Referred-to Auditors), is effective for audits of group financial statements for periods ending on or after December 15, 2026. It supersedes AU-C section 600 and replaces the practice of identifying “significant components” with a risk-based method for deciding where to perform audit work, while adding the new terms “component auditor” and “referred-to auditor.”
This article explains what changed under GAAS, why the shift matters for finance leaders, and how to prepare your reporting and audit relationships before the standard’s effective date. Pease Bell CPAs works with multi-entity organizations through our audit and assurance services, and the points below reflect what we are discussing with clients facing their first group audit under the new rules.
What Does SAS 149 Change Under GAAS?
A group audit applies whenever financial statements include the financial information of more than one component, such as a parent with subsidiaries, a company with multiple divisions or branches, or combined statements of commonly controlled entities. Under the prior GAAS framework in AU-C section 600, the group engagement team identified “significant components,” typically based on financial significance or specific risks, and then directed audit work toward those components. That structure often pushed scoping decisions toward size thresholds rather than the actual risk of material misstatement.
SAS 149 removes the concept of significant components entirely. According to the AICPA’s Statement on Auditing Standards No. 149, the group auditor now uses professional judgment to determine the components at which to perform procedures, based on assessed risks. In practice, the group engagement team identifies and assesses risks of material misstatement at the group level, then decides where and how to perform audit procedures so those risks are addressed.
This reorientation aligns U.S. standards more closely with the international risk-based approach to group audits. The change means smaller components can warrant audit attention if they carry elevated risk, and large components may not automatically drive the same procedures if their risk is low. Scoping becomes an exercise in judgment supported by documented risk assessment, not a mechanical sort by balance size.
The standard also strengthens expectations around the group engagement team’s involvement throughout the audit. The team is responsible for the direction, supervision, and review of work performed on components, and for being satisfied that sufficient appropriate audit evidence has been obtained across the group. That accountability does not disappear when work is performed by another office or firm, which is one reason the standard sharpens how it defines the people doing that work.
Component Auditor vs. Referred-to Auditor: What Is the Difference?
One of the most consequential parts of SAS 149 is how it redefines the people doing the work. The standard revises the definition of “component auditor” to make clear that a component auditor is part of the engagement team, even when that auditor sits in a different firm or a different location. Because the component auditor is part of the engagement team, the group engagement partner remains responsible for the overall audit opinion, and the group team must be involved in the component auditor’s risk assessment and procedures.
SAS 149 then introduces an entirely new role: the “referred-to auditor.” As the Journal of Accountancy reports, a referred-to auditor is one who “performs an audit of the financial statements of a component to which the group engagement partner determines to make reference in the auditor’s report on the group financial statements,” and the standard “indicates that a referred-to auditor is not part of the engagement team.” This is the U.S.-specific reporting option that lets a group auditor reference another firm’s audit in the report on the group financial statements.
The distinction is more than vocabulary. When another firm acts as a component auditor, the group engagement team supervises and reviews that work and assumes responsibility for it within the group opinion. When another firm is a referred-to auditor, the group report explicitly references that firm’s audit, and responsibility is shared in a way the report discloses. Deciding which path applies for each component is a planning decision that affects engagement letters, communication protocols, and the wording of the auditor’s report.
Finance leaders should expect their auditors to ask earlier and more specifically about subsidiaries audited by other firms, statutory audits of foreign components, and any equity-method investees. Those conversations determine whether a component flows through as referred-to work or is folded into the group engagement team’s responsibility. Getting that determination right early prevents late-stage changes to report wording and the scope of work each firm performs.
Why Does SAS 149 Matter for Multi-Entity Organizations?
The practical impact lands hardest on companies with complex structures: holding companies, private equity portfolios, nonprofits with affiliated entities, and businesses with international operations. Because scoping is now risk-driven, the audit plan for these organizations may look different from prior years even if the underlying business has not changed. Components that were lightly touched before may receive more procedures, and the timeline for coordinating with other auditors can lengthen.
Documentation expectations rise as well. The group engagement team must show how it assessed group-level risks and connected those risks to the components and procedures it selected. Management can support a smoother audit by maintaining clear, current information on the legal structure, intercompany relationships, consolidation process, and any other auditors involved across the group.
Communication with component and referred-to auditors also needs more lead time under the new model. Engagement teams must establish two-way communication about scope, timing, and findings, which is harder to compress into year-end. Organizations that map their entities and confirm auditor relationships well before the period-end date will avoid the scramble that often accompanies a standards transition.
There is also a budgeting dimension. A more risk-focused, communication-intensive audit can shift where hours are spent, and coordinating across multiple firms takes time that does not show up in a single component’s file. Our audit and assurance team can help you inventory components and plan the group audit approach ahead of the December 15, 2026 effective date so the first-year transition does not catch your finance function off guard.
How to Prepare Before the Effective Date
Preparation starts with an accurate entity map. List every component included in the group financial statements, identify which are audited and by whom, and flag any that are audited by an outside firm. This inventory drives the component auditor versus referred-to auditor decisions and surfaces coordination needs early.
Next, talk with your auditor about scoping expectations under the risk-based model. Because the standard relies on professional judgment rather than size thresholds, the conversation should cover where management sees the greatest risks of material misstatement and how the consolidation is assembled. Aligning on these points before fieldwork reduces surprises and rework.
Then tighten the close and consolidation process. Reliable intercompany eliminations, consistent accounting policies across components, and timely component financial information all reduce audit friction. The transition to SAS 149 is a useful prompt to confirm that your reporting infrastructure can support a more risk-focused, communication-intensive audit.
Finally, document the structure changes as they happen during the year. Acquisitions, dispositions, new foreign operations, and changes in equity-method holdings all affect which components exist and who audits them. Keeping that record current means your auditor can apply the risk-based GAAS model to an accurate picture rather than reconstructing the group at year-end.
Frequently Asked Questions
When is SAS 149 effective?
SAS 149 is effective for audits of group financial statements for periods ending on or after December 15, 2026. Early adoption considerations should be discussed with your audit firm, but for calendar-year entities the standard first applies to the December 31, 2026 audit.
Does SAS 149 apply to my company?
It applies whenever financial statements include the financial information of more than one component, including consolidated parent-subsidiary statements, combined statements of entities under common control, and statements with divisions, branches, or equity-method investees. If your audited statements aggregate multiple entities or units, SAS 149 governs how that audit is planned and performed under GAAS.
What is the difference between a component auditor and a referred-to auditor?
A component auditor is part of the group engagement team, so the group engagement partner directs and reviews that work and takes responsibility for it in the group opinion. A referred-to auditor is not part of the engagement team; instead, the group auditor’s report makes reference to that auditor’s separate audit of a component, a reporting option unique to U.S. standards.
What happened to “significant components” under GAAS?
SAS 149 eliminates the “significant components” concept from AU-C section 600. The group engagement team now uses professional judgment to identify components and procedures based on assessed risks of material misstatement, rather than selecting components primarily by financial size.
Sources: AICPA Statement on Auditing Standards No. 149 and the Journal of Accountancy reporting on the risk-based group audit approach.




