PCAOB vs AICPA Audits: Key Differences and Which One Applies to You
When conducting audits in accordance with United States standards, two main regulatory frameworks come into play: standards set by the Public Company Accounting Oversight Board (PCAOB) and those issued by the American Institute of Certified Public Accountants (AICPA). Although both govern the audit of financial statements, they apply to fundamentally different types of organisations and carry very different levels of regulatory scrutiny.
TY Teoh International is a PCAOB-registered audit firm — one of the few Singapore-headquartered practices authorised to conduct audits for US-listed companies and their subsidiaries. This guide draws on our direct experience with both frameworks to explain what sets them apart, when each applies, and what Singapore businesses need to know before engaging an audit firm.
What Is an AICPA Audit?
The American Institute of Certified Public Accountants (AICPA) is the professional body for Certified Public Accountants (CPAs) in the United States. Founded in the 1940s, it sets audit standards that apply to private companies, non-profit organisations, and government entities not subject to oversight by the US Securities and Exchange Commission (SEC).
The AICPA issues its audit standards under Generally Accepted Auditing Standards (GAAS), most recently through the Statements on Auditing Standards (SAS) series. These standards are applied by independent auditors who are members of the AICPA.
AICPA audits are designed to provide assurance to stakeholders — owners, lenders, boards — that an organisation’s financial statements are accurate, reliable, and free of material misstatements. Because AICPA audits serve a broader but generally lower-risk client base, the standard is inherently less prescriptive than the PCAOB framework. Auditors are afforded greater professional judgement, particularly in areas of lower assessed risk.
AICPA audits apply to:
- Private companies in the US and their foreign subsidiaries
- Non-profit organisations
- Government entities not subject to SEC oversight
- Singapore-incorporated companies with US subsidiaries or investors, where the company is not SEC-registered
Key Recent Update: SAS No. 145 (Effective December 2023)
In October 2021, the AICPA issued Statement on Auditing Standards No. 145, which overhauled how auditors identify and assess the risk of material misstatement. SAS No. 145 introduced a sharper focus on:
- A company’s system of internal control (not just individual controls)
- The role of information technology — IT systems, automated controls, and data environments — in risk assessment
- More granular risk documentation requirements
SAS No. 145 became effective for audits of financial statements for periods ending on or after 15 December 2023. Companies undergoing AICPA audits for the first time after this date should expect more detailed questions about their control environment and IT infrastructure.
What Is a PCAOB Audit?
The Public Company Accounting Oversight Board (PCAOB) was established in 2002 under the Sarbanes-Oxley Act, as a direct response to major accounting scandals — including Enron and WorldCom — that shook investor confidence in public markets. The PCAOB is a non-profit organisation overseen by the SEC, and its mandate is specifically to protect investors in public companies.
Understanding the PCAOB’s full role and scope is essential for any business approaching a US listing or reporting to a US-listed parent.
PCAOB audits are required for any company that files financial statements with the SEC, and must be conducted by an audit firm that is registered with and subject to inspection by the PCAOB. Singapore-incorporated companies that list on a US stock exchange, issue American Depositary Receipts (ADRs), or are subsidiaries of US-listed groups must engage a PCAOB-registered firm.
PCAOB audits are required when:
- Your company is listed — or plans to list — on a US stock exchange (NYSE, NASDAQ)
- You issue US-traded securities or American Depositary Receipts (ADRs)
- You are preparing for a dual listing (e.g. SGX and NASDAQ)
- You are a significant subsidiary of a US-listed group required to file with the SEC
- You are involved in a US SPAC transaction — see our guide on how SPACs work and their accounting requirements
What Makes a PCAOB Audit More Rigorous?
Unlike AICPA audits, a PCAOB audit requires the auditor to express two opinions, not one:
- An opinion on the financial statements — whether they are free of material misstatement
- An opinion on Internal Control over Financial Reporting (ICFR) under AS 2201 — whether the company’s internal controls are effective at preventing material misstatement
This dual-opinion requirement reflects the PCAOB’s investor protection mandate. Public company investors rely on financial statements as the basis for capital allocation decisions; weak internal controls are a known precursor to financial fraud and restatement.
Additional PCAOB requirements that exceed AICPA standards include:
- Critical Audit Matters (CAMs): Matters communicated to the audit committee that involved especially challenging, subjective, or complex auditor judgement. CAMs must be disclosed in the auditor’s report for large accelerated filers.
- Lower materiality threshold: Because PCAOB audits serve investors in public markets, auditors apply a lower materiality level, meaning more items are subject to testing and scrutiny
- Mandatory consultation: Before a PCAOB-registered firm issues its report, a review committee examines every filing for consistency across the firm — this mandatory consultation does not exist in AICPA audits
- PCAOB inspections: The PCAOB inspects registered firms annually (for larger firms) or triennially (for smaller firms), with public inspection reports issued on deficiencies found. There is no equivalent regulator for AICPA audits; enforcement relies on peer review.
Key Recent Updates: PCAOB 2023 Reforms
The PCAOB took more formal actions on standard-setting and rulemaking in 2023 than in any year over the past decade. Key developments include:
- New confirmation standard: Modernises how auditors verify information with third parties (e.g. bank confirmations), enhancing the reliability of audit outcomes
- Proposals on Quality Control: New framework for how audit firms design, implement, and assess their own quality control systems
- Noncompliance with Laws and Regulations (NOCLAR): Updated guidance on how PCAOB auditors should respond when they identify or suspect illegal acts
- Technology-assisted audit procedures: Recognition of how data analytics and AI are changing audit practice, with updated guidance on electronic evidence and automated testing
For a detailed breakdown of current PCAOB auditing standards and their implications for Singapore businesses, see our dedicated guide.
PCAOB vs AICPA: Side-by-Side Comparison
Feature | PCAOB Audit | AICPA Audit |
|---|---|---|
Applies to | Public companies (SEC-registered) | Private companies, non-profits, government |
Overseen by | PCAOB (regulated by SEC) | AICPA (self-regulatory) |
Legal authority | Sarbanes-Oxley Act 2002 | No SEC enforcement |
Standards used | PCAOB Auditing Standards (AS series) | GAAS / Statements on Auditing Standards (SAS) |
Opinions required | Two: financial statements + ICFR | One: financial statements only |
Critical Audit Matters | Required (large accelerated filers) | Not required |
Materiality threshold | Lower (more items tested) | Higher (more professional judgement) |
Inspection regime | Annual/triennial PCAOB inspections | Peer review only |
Documentation | Strict; reviewed before issuance | Less prescriptive |
Timeline | Typically 3–5 months (large public co.) | Typically 6–10 weeks (comparable private co.) |
Internal Controls Over Financial Reporting (ICFR): The Defining Difference
The ICFR requirement is the single most important practical difference between PCAOB and AICPA audits, and the one that generates the most work for companies transitioning from private to public status.
Under PCAOB AS 2201, the auditor must evaluate the design and operating effectiveness of the company’s internal controls — the systems, processes, and checks that prevent or detect errors and fraud in financial reporting. This involves:
- Identifying which controls are relevant to each significant account and disclosure
- Testing whether those controls operated effectively throughout the audit period
- Evaluating any deficiencies found, classified as control deficiencies, significant deficiencies, or material weaknesses
- Communicating material weaknesses to the audit committee and disclosing them in the annual report (Form 10-K)
A material weakness — a control failure that could result in a material misstatement going undetected — is a serious matter for any public company. Its disclosure can affect share price, investor confidence, and access to capital markets. This is why PCAOB audits of companies approaching a US listing require thorough internal control readiness well before the audit begins.
Companies preparing for a US IPO or cross-border listing should assess their internal control readiness as part of the listing preparation process. TY Teoh’s Audit & Assurance team works with companies at each stage of this process.
Auditor Responsibilities: Fraud Detection
Both PCAOB and AICPA audits require auditors to maintain professional scepticism and assess the risk of fraud in financial reporting. However, the intensity of fraud-risk testing differs. Under PCAOB standards, auditors have specific obligations in business fraud detection — including a requirement to perform tests of detail to address significant risks and fraud risks regardless of controls reliance. Under AICPA GAAS, auditors may rely on controls testing in lieu of substantive testing in lower-risk areas.
Why This Matters for Singapore Businesses
As Singapore companies increasingly pursue US listings, cross-border acquisitions, and international financing, the question of which audit framework applies is no longer theoretical. Several practical considerations are specific to Singapore:
PCAOB-registered firms in Singapore
The PCAOB maintains a public register of registered audit firms worldwide. If your company needs a PCAOB audit, it must engage a registered firm — not simply any accounting firm in Singapore. TY Teoh International is listed on the PCAOB register, making us one of the Singapore-headquartered firms authorised to issue PCAOB opinions. This is particularly relevant for Singapore fintech companies, technology businesses, and regional groups pursuing NASDAQ or NYSE listings.
SGX-listed companies with US reporting obligations
Singapore companies with a primary SGX listing generally prepare financial statements under SFRS (Singapore Financial Reporting Standards). However, if the same company has a cross-listing in the US or issues ADRs, it may need to reconcile its SFRS financials to US GAAP and engage a PCAOB-registered auditor. Our team assists with IFRS to US GAAP conversion in Singapore as part of the cross-listing process.
Singapore subsidiaries of US-listed groups
A Singapore subsidiary that is “significant” to its US-listed parent — measured by assets, revenue, or net income relative to the consolidated group — may be required to have its standalone financial statements audited by a PCAOB-registered firm. This catches many Singapore entities by surprise: they assume they can use their existing local auditor, not realising that the parent’s PCAOB compliance extends to significant subsidiaries. For guidance on US GAAP audit services for Singapore businesses, see our dedicated resource.
Private Singapore companies with AICPA obligations
Many Singapore-incorporated companies with US investors, US customers, or US-based founders operate under agreements that require AICPA-standard audits for reporting to those stakeholders. These requirements often appear in shareholder agreements or investment term sheets. Singapore’s own audit standards (SSAs — Singapore Standards on Auditing) are aligned with International Standards on Auditing (ISA), which are conceptually close to AICPA GAAS — but they are not identical, and the distinction matters when an investor explicitly requires AICPA-standard work. For context on Singapore’s rules governing auditors, see our overview.
How to Choose the Right Audit Firm
Choosing between a PCAOB-capable and AICPA-capable firm is not just a question of standards — it is a question of whether your auditor is qualified and registered to issue the opinion you need. Before engaging an audit firm for any transaction involving US markets or reporting, confirm:
- Is the firm PCAOB-registered? Check the public register at pcaobus.org. Only registered firms can issue PCAOB opinions.
- Does the firm have experience with your industry? PCAOB inspections scrutinise audit quality by industry; an auditor unfamiliar with your sector may produce a weaker audit.
- Can the firm handle cross-jurisdictional reporting? Singapore companies often need both SFRS statutory accounts and US GAAP reconciliations. A firm with genuine expertise in both frameworks avoids duplication and error. See our guide on US GAAP for Singapore businesses for context.
- Does the firm understand Singapore regulatory requirements? Audit firms must simultaneously comply with MAS regulatory requirements, SGX listing rules, and PCAOB standards where applicable.
Frequently Asked Questions (FAQ)
The most fundamental difference is who the audit is for and what it covers. PCAOB audits serve investors in public companies registered with the SEC, and require two opinions: one on the financial statements and one on internal controls over financial reporting. AICPA audits serve the stakeholders of private companies and non-profits, and require one opinion on financial statements only. PCAOB audits are subject to mandatory PCAOB inspection; AICPA audits are governed by peer review.
A Singapore company needs a PCAOB audit if it is listed (or preparing to list) on a US stock exchange such as NYSE or NASDAQ, if it issues American Depositary Receipts (ADRs), or if it is a significant subsidiary of a US-listed group that files with the SEC. Singapore fintech companies preparing for a US IPO, and Singapore subsidiaries of US multinationals, are the most common cases we encounter.
Yes — but only if it is registered with the PCAOB. Registration requires the firm to submit to PCAOB inspections and comply with PCAOB quality control standards. TY Teoh International is a PCAOB-registered firm, authorised to conduct PCAOB-compliant audits for Singapore-based entities with US reporting obligations.
Critical Audit Matters are issues that were communicated to the audit committee, arose from accounts or disclosures that are material to the financial statements, and involved especially challenging, subjective, or complex auditor judgement. CAMs must be disclosed in the auditor’s report for large accelerated filers (companies with public float above USD 700 million). Smaller reporting companies and non-accelerated filers are currently exempt.
Internal Control over Financial Reporting (ICFR) refers to the processes and systems a company uses to ensure the accuracy of its financial reporting. Under PCAOB AS 2201, the auditor must independently assess whether a company’s ICFR is effective. A material weakness in ICFR — a significant failure in controls — must be disclosed publicly in the company’s annual report. For companies approaching a US listing, building a robust ICFR framework well before the first PCAOB audit is essential.
A PCAOB audit for a large public company typically takes three to five months from fieldwork commencement to issuance of the auditor’s report. An AICPA audit for a comparable private company may take six to ten weeks. PCAOB audits are longer because of the additional ICFR assessment, mandatory consultation procedures, and lower materiality (more transactions tested). Companies pursuing US listings should build the PCAOB audit timeline into their listing preparation schedule.
Yes. Most major audit firms are registered with both. PCAOB registration covers their public company audit practice; AICPA membership governs their private company and other audit work. TY Teoh International operates under both frameworks to serve clients across the full spectrum of public, private, and cross-border reporting requirements.
Conclusion
The difference between a PCAOB and AICPA audit is not just a technical distinction — it determines whether your audit opinion is valid and whether your company is compliant with US regulatory requirements. For Singapore businesses entering US capital markets or reporting to US stakeholders, choosing the right framework and the right registered firm is a compliance necessity, not a preference.
TY Teoh International’s Audit & Assurance team has direct experience conducting PCAOB-compliant audits for Singapore-incorporated entities with US reporting requirements, as well as AICPA-standard work for private companies with international investors. Contact us to discuss which framework applies to your business and how we can support your audit requirements.
Disclaimer: This article is intended for general informational purposes and does not constitute legal or audit advice. Companies should consult a qualified registered audit firm regarding their specific reporting obligations.



