Platformed

How should audit firms apply SAS 145 to less complex entities?

Audit planning and risk assessment · last updated 2026-09-02

SAS 145 is scalable. A less complex entity does not need the same volume or depth of risk-assessment work as a complex group, but the auditor still needs an evidenced understanding of the entity, its information system, relevant controls and risks of material misstatement.

Smaller entities often have fewer systems and shorter reporting lines, but they may also have less formal documentation, more manual processes and greater reliance on a small number of people. “Less complex” should therefore be a supported conclusion, not a synonym for “small” or permission to default to a thin checklist.

A proportionate workflow starts with the financial reporting process and technology actually in use. It narrows the questions and controls where the environment is straightforward, then expands the assessment when answers reveal customisation, feeder systems, manual interfaces or other complexity.

Platformed capability: Platformed can use a streamlined workflow for non-complex clients, convert walkthroughs and informal evidence into structured documentation, and expand only the relevant parts of the IT, process and control assessment. The auditor reviews whether the resulting scope and risk assessment are appropriate.

References: AICPA guidance on applying and scaling SAS 145 · AICPA risk-assessment resources

← All 60 questions