SAS No. 149 Group Audit Requirements: A Complete Guide to Risk-Based Group Audits

SAS No. 149 Group Audit Requirements: A Complete Guide to Risk-Based Group Audits

Group audits are entering a new phase as organizations become more geographically dispersed, technologically integrated, and operationally complex. Businesses may maintain subsidiaries, branches, shared service centres, joint operations, and strategic investments across several jurisdictions, creating audit environments that cannot always be addressed effectively through traditional component-based approaches.

Statement on Auditing Standards (SAS) No. 149, Special Considerations — Audits of Group Financial Statements (Including the Work of Component Auditors and Audits of Referred-to Auditors), responds to this changing environment by introducing a more risk-focused framework for group audits. The standard applies to audits of group financial statements for periods ending on or after December 15, 2026.

For audit firms, the change goes beyond updating templates. Engagement teams will need to reconsider how risks are identified across a group, where audit procedures should be concentrated, how component auditors are supervised, and whether sufficient appropriate audit evidence has been obtained before the group audit opinion is issued.

Moving Beyond the Significant-Component Model

One of the most consequential changes is the movement away from an approach centred primarily on identifying “significant components.”

Historically, group audit planning often involved determining which subsidiaries, divisions, branches, or other components were sufficiently significant to warrant focused audit attention. SAS No. 149 places greater emphasis on assessed risks of material misstatement when determining where work should be performed.

Consider Meridian Foods Group, a fictional manufacturing company headquartered in Nairobi with operations in Kenya, Tanzania, Rwanda, and Zambia. Its Zambian subsidiary may account for only a modest percentage of consolidated revenue. However, suppose the subsidiary recently implemented a new inventory system, experienced high employee turnover, and holds significant quantities of commodities subject to complex valuation assumptions.

Under a risk-based approach, the relatively small size of the Zambian operation would not automatically justify limited audit attention. Its risk characteristics could require substantial procedures because the group auditor’s focus should follow the areas capable of creating material misstatement in the consolidated financial statements.

This gives engagement teams greater room for professional judgment while also increasing the importance of documenting why audit effort has been allocated to particular components, balances, transactions, or processes.

Understanding Component Auditors and Referred-to Auditors

SAS No. 149 also provides clearer distinctions between professionals involved in group audit work.

A component auditor is part of the group engagement team when that auditor performs audit work relating to a component for purposes of the group audit. This relationship carries important consequences for the group engagement partner, particularly regarding direction, supervision, and review.

The standard separately introduces the term “referred-to auditor.” This refers to an auditor who audits the financial statements of a component where the group engagement partner decides to make reference to that auditor in the group auditor’s report.

A referred-to auditor is not treated as a component auditor and is not part of the group engagement team.

The distinction matters because group engagement leaders must understand precisely which auditors fall within the engagement team and what responsibilities follow from that classification. Firms should therefore avoid treating terminology as merely administrative. Auditor classification affects engagement governance, supervision, communication, documentation, and reporting decisions.

Greater Judgment Means Greater Accountability

The increased reliance on professional judgment creates flexibility, but it also demands stronger reasoning.

Suppose Horizon Infrastructure Holdings operates 18 entities across Southern Africa. Rather than automatically selecting the largest six subsidiaries for extensive audit procedures, the group engagement team may identify elevated risks in procurement at a smaller construction entity, revenue recognition at a regional engineering company, and management estimates within a property subsidiary.

Audit resources could then be directed toward those specific risks.

This approach can make the audit more responsive to the economic realities of the organization. However, engagement documentation should clearly demonstrate how the group auditor understood the business, identified relevant risks, selected components or activities for audit work, and determined the nature, timing, and extent of procedures.

Professional judgment should therefore be visible in the audit file rather than existing only in discussions among senior engagement personnel.

Managing Aggregation Risk Across the Group

A misstatement does not have to be individually material at a single subsidiary to become important to the consolidated financial statements.

SAS No. 149 gives particular attention to aggregation risk—the possibility that uncorrected and undetected misstatements across components may collectively exceed materiality for the group financial statements.

Imagine a retail group with operations in Accra, Lagos, Abidjan, Dakar, and Lomé. Each operation independently records small inventory valuation differences that fall below its applicable threshold. Individually, none appears significant. When combined across the group, however, those differences could become material.

This is why performance materiality requires careful calibration. Component performance materiality should be established below group performance materiality, with the determination reflecting aggregation risk and the characteristics of individual components.

Engagement teams should consider factors such as previous misstatements, the susceptibility of particular accounts to error, complexity of transactions, control deficiencies, and the extent to which similar risks exist across several locations.

Strengthening Direction, Supervision and Review

A risk-based group audit does not reduce the group engagement partner’s responsibility for work performed by component auditors.

Where component auditors participate in the engagement, appropriate direction and supervision become essential. Group auditors need to establish clear expectations regarding identified risks, planned procedures, reporting requirements, significant findings, documentation, and matters requiring escalation.

For example, assume an audit firm in Johannesburg coordinates group audit work performed by teams in Botswana and Namibia. If the Namibian team is responsible for testing a high-risk revenue stream, the group team cannot simply receive a completion memorandum and assume the work is adequate.

The group auditor should evaluate whether the procedures performed properly addressed the relevant risks and whether the resulting evidence is sufficient and appropriate.

Where component work is inadequate, additional procedures will be necessary. Depending on the circumstances, these procedures may be performed by the component auditor or directly by the group audit team.

Building Stronger Two-Way Communication

Communication under a group audit should not operate as a one-directional flow of instructions from headquarters to component teams.

Effective group auditing depends on information moving in both directions throughout the engagement. Component auditors may identify matters that change the group team’s understanding of risk, while the group auditor may obtain information that directly affects procedures being performed locally.

Consider a group whose management informs the lead engagement team of significant liquidity pressure that could raise questions about the group’s ability to continue as a going concern. Relevant information should reach component auditors where it could influence their work.

Similarly, component teams should promptly communicate significant deficiencies, suspected fraud, unexpected transactions, litigation, control failures, or other findings relevant to the consolidated financial statements.

Firms should therefore establish communication protocols early, including reporting deadlines, escalation channels, documentation expectations, and responsibilities for resolving significant matters.

Considering Shared Services and Centralized Functions

Modern groups increasingly centralize important activities such as payroll, procurement, treasury, IT, accounts payable, and financial reporting.

These functions may create risks affecting several legal entities simultaneously.

Suppose an Ethiopian logistics group processes payroll for subsidiaries in four countries through one shared service centre in Addis Ababa. A weakness in user-access controls at that centre could affect employee costs across the entire group.

The audit strategy should recognize such interconnected risks rather than examining each subsidiary in isolation. Depending on the circumstances, performing procedures centrally may provide more effective evidence than duplicating similar work across multiple locations.

Understanding group-wide systems, common controls, technology infrastructure, consolidation processes, and centralized functions is therefore increasingly important to effective risk assessment.

Addressing Equity-Method Investments

Group audit planning should also account for investments recorded using the equity method.

Such investees can qualify as components for group audit purposes even though the investor does not consolidate their financial statements in the same manner as controlled subsidiaries.

The group auditor must consider whether audited financial statements of an equity-method investee provide sufficient appropriate audit evidence. Where they do not, additional procedures may be required.

For example, if a Ghanaian energy company owns a significant interest in a renewable-energy venture in Côte d’Ivoire, the engagement team should assess the reliability and relevance of available audit evidence rather than assuming that another auditor’s report automatically resolves the group audit requirements.

The appropriate response will depend on the assessed risks, significance of the investment, available information, and circumstances surrounding the investee.

Preparing Audit Methodologies for Implementation

Successful implementation of SAS No. 149 should begin before the first affected year-end engagement.

Audit firms should review their group audit methodologies, planning documents, component instructions, risk assessment tools, review procedures, materiality frameworks, and documentation templates. Training should extend beyond technical specialists to engagement partners, managers, seniors, and professionals who coordinate or perform component work.

Particular attention should be given to how component performance materiality is established and documented. Firms should also strengthen procedures for understanding group structures, business models, common controls, IT environments, consolidation processes, and previous component-level misstatements.

Where making reference to another auditor may be appropriate, that possibility should be considered early rather than near the reporting deadline.

Turning Compliance Into Better Audit Quality

SAS No. 149 should not be approached simply as another technical compliance exercise. Its broader significance lies in encouraging audit effort to follow risk more closely across increasingly complex organizations.

The strongest implementation strategies will combine professional judgment with disciplined documentation, meaningful supervision, well-calibrated materiality, effective communication, and a detailed understanding of how individual components interact within the wider group.

For firms auditing multinational and multi-entity organizations, preparation should therefore focus not only on learning new terminology but also on changing how engagement teams think about group risk.

When implemented effectively, the new framework can help auditors direct resources toward the areas that matter most, identify risks that might otherwise remain fragmented across individual components, and obtain more persuasive evidence supporting the group audit opinion.

Important Questions and Answers about SAS No. 149

What is SAS No. 149 designed to achieve?

SAS No. 149 modernizes group audits by shifting greater attention toward assessed risks of material misstatement. Instead of concentrating primarily on the size or significance of individual components, auditors are expected to direct their work toward the areas where meaningful financial reporting risks exist.

When does SAS No. 149 become effective?

The standard applies to audits of group financial statements for periods ending on or after December 15, 2026. Audit firms should therefore update their methodologies, training, documentation, and engagement planning processes ahead of implementation.

What is the biggest change introduced by SAS No. 149?

The major change is the move from a predominantly “significant component” approach to a risk-based model. A smaller subsidiary may require extensive audit work if its activities present significant risks to the group financial statements.

What is a component auditor under the new standard?

A component auditor performs audit work relating to a component for purposes of the group audit and forms part of the group engagement team. Consequently, the group engagement partner has responsibilities for directing, supervising, and reviewing that auditor’s work.

What is a referred-to auditor?

A referred-to auditor audits the financial statements of a component where the group engagement partner decides to make reference to that auditor’s report in the group auditor’s report. Unlike a component auditor, a referred-to auditor is not part of the group engagement team.

Why is professional judgment more important under SAS No. 149?

Auditors have greater responsibility for deciding where and how audit work should be performed based on identified risks. This makes strong professional judgment—and clear documentation explaining those judgments—essential to demonstrating that the audit approach was appropriate.

What is aggregation risk in a group audit?

Aggregation risk is the possibility that individually small uncorrected or undetected misstatements across different components could collectively become material to the group financial statements. A small error repeated across numerous subsidiaries can therefore become a significant group-level issue.

How does SAS No. 149 affect performance materiality?

Component performance materiality should be established below group performance materiality. Auditors should consider aggregation risk, previous misstatements, component-specific risks, transaction complexity, and other relevant circumstances when determining appropriate levels.

Can audit procedures be performed centrally?

Yes. Where appropriate, certain procedures may be performed centrally rather than separately at every component. This can be particularly relevant where a group uses shared systems or centralized functions for activities such as payroll, treasury, procurement, IT, or financial reporting.

What happens if a component auditor’s work is inadequate?

The group auditor must determine what additional procedures are necessary to obtain sufficient appropriate audit evidence. Those procedures may be performed by the component auditor or directly by the group auditor, depending on the circumstances.

Why is two-way communication important in group audits?

Information discovered by one audit team may affect risks elsewhere in the group. Regular two-way communication helps ensure that matters such as fraud concerns, control deficiencies, unusual transactions, litigation, or going-concern issues are communicated to the teams that need to respond.

How should audit firms prepare for SAS No. 149?

Preparation should include updating group audit methodologies, templates, component instructions, materiality frameworks, risk assessment processes, and review procedures. Firms should also train engagement teams and strengthen their understanding of group structures, IT environments, centralized controls, consolidation processes, and component-level risks.