CA Intermediate · Auditing and Ethics
Audit Evidence: formula sheet
Key formulas
- Definition of audit evidence
- Audit evidence = information used by the auditor to arrive at conclusions on which the audit opinion is based
- Includes accounting records and other information. Write both in your answer.
- Core requirement of SA 500
- Evidence must be sufficient AND appropriate
- Both are needed. Sufficient is about quantity. Appropriate is about quality.
- Appropriateness
- Appropriateness = relevance + reliability
- Relevance links to the assertion tested. Reliability depends on source, nature and circumstances.
- Link between risk and quantity
- Quantity needed depends on assessed risk of misstatement and on quality of evidence
- Higher risk needs more evidence. The higher the quality, the less may be required. More evidence may not compensate for poor quality.
- Reliability guide
- Generally: independent external sources > internal sources; direct > indirect; documents > oral; originals > copies
- These are general rules, not always true. Reliability depends on circumstances. Separately, internally generated evidence is more reliable when the related controls are effective.
- Procedures to obtain evidence
- Inspection, observation, external confirmation, recalculation, reperformance, analytical procedures, inquiry
- Inquiry alone is not sufficient to support an assertion.
- Assertions: classes of transactions and events
- Occurrence, Completeness, Accuracy, Cut-off, Classification
- Apply to the statement of profit and loss items for the period. Memory aid: OCACC.
- Assertions: account balances at period end
- Existence, Rights and obligations, Completeness, Accuracy-valuation-allocation
- Apply to balance sheet items. Overstatement risk points to existence; understatement risk points to completeness.
- Assertions: presentation and disclosure
- Occurrence and rights and obligations; Completeness; Classification and understandability; Accuracy and valuation
- The first is a combined assertion, so the set has four items. Test whether disclosures are relevant, clear and correctly measured.
- Audit procedures to obtain evidence
- Inspection, Observation, External confirmation, Recalculation, Reperformance, Analytical procedures, Inquiry
- Choose by assertion. Inquiry alone ordinarily does not provide sufficient appropriate audit evidence.
- Purpose of procedures
- Risk assessment procedures + Further audit procedures (tests of controls and substantive procedures)
- Substantive procedures = tests of details + substantive analytical procedures.
- Purpose of documentation
- Evidence of basis for report and of compliance with SAs + aid to planning, performance, direction, supervision and review + accountability, continuing significance and quality reviews
- Use these three heads as the skeleton of any 'purpose' answer.
- Experienced auditor test
- Experienced auditor with no previous connection must understand: nature, timing, extent of procedures; results and evidence; significant matters and judgments
- SA 230 uses this as the standard for how much to document.
- Documentation of specific items
- Record: who performed the work and when; who reviewed it and when; identifying characteristics of items tested
- Examples of identifying characteristics: invoice number, date, amount, voucher number.
- Assembly of final file
- SA 230: assemble the final audit file on a timely basis after the date of the auditor's report. SQM 1: within 60 days of that date
- Assembly is an administrative process. No new audit procedures or new conclusions are made. The 60 days is from SQM 1, not SA 230.
- Retention period
- Retain for a period not shorter than 8 years from the date of the auditor's report
- Under SQM 1 and SA 230. Retain longer if law requires.
- Changes after file assembly
- Exceptional circumstances only: document reasons, who made and reviewed changes, and when
- Do not delete or discard documentation after assembly before retention ends.
- Projected misstatement (ratio method)
- Projected misstatement = (Misstatement found in sample ÷ Value of items in sample) × Value of population
- One common way to project. Stratified or per-item methods may also be used. Compare the result with tolerable misstatement.
- Sample deviation rate
- Deviation rate = Number of deviations found ÷ Number of items tested
- Used in tests of controls. Compare with the tolerable rate of deviation.
- Sampling interval (systematic selection)
- Sampling interval = Population size (or value) ÷ Sample size
- Pick a random starting point within the first interval, then select every nth item or monetary unit.
- Sample size drivers
- Tests of details: sample size increases when tolerable misstatement falls, assessed risk of material misstatement rises, expected misstatement rises, or reliance on other procedures falls. Tests of controls: sample size increases when tolerable deviation rate falls, expected deviation rate rises, or the assurance wanted from the sample rises
- Higher tolerable misstatement or lower risk allows a smaller sample in tests of details. Higher tolerable deviation rate or lower expected deviation rate allows a smaller sample in tests of controls.
- Risk comparison rule
- Sampling risk ↓ as sample size ↑; non-sampling risk is not reduced by sample size
- A frequent theory point.
- Definition (SA 520)
- Analytical procedures = evaluation of financial information through plausible relationships among financial and non-financial data
- Includes investigating fluctuations or relationships that are inconsistent with other information or differ significantly from expected values.
- Three uses
- Risk assessment (planning) + Substantive (fieldwork) + Overall review (end)
- Overall review is required; substantive use is a choice.
- Fluctuation in amount
- Change % = (Current year − Previous year) ÷ Previous year × 100
- Use it to spot items needing investigation.
- Gross profit ratio
- Gross profit ratio = Gross profit ÷ Net sales × 100
- A common ratio for checking sales, purchases and inventory.
- Difference from expectation
- Difference = Recorded amount − Auditor's expectation
- Compare it with the acceptable difference you set; investigate anything beyond it.
- Investigation rule
- Unusual difference → inquire of management + corroborate with evidence + do other procedures
- Management's reply alone is not audit evidence.
- SA 505 - confirmation rule
- Auditor controls selection, sending and receipt of the request and reply
- A reply that comes through management is not a proper external confirmation. Treat it as less reliable.
- SA 505 - management refuses a request
- Ask why → judge validity → if valid, alternative procedures; if refusal is unreasonable, communicate with TCWG and still try alternative procedures → if reliable evidence cannot be obtained from alternative procedures, communicate with TCWG → determine implications under SA 705 only if the refusal is unreasonable or alternative procedures do not give relevant and reliable evidence
- Write all three outcomes in a theory answer. Communication with TCWG is required when the refusal is unreasonable, even before you see what the alternative procedures give. If the reasons are valid and alternative procedures give adequate evidence, no SA 705 implication arises.
- SA 505 - non-response
- No reply → follow-up request → alternative procedures (e.g., subsequent receipts, shipping documents)
- Alternative procedures depend on the assertion tested.
- SA 580 - status of representations
- Written representations are necessary but not sufficient evidence
- They cannot replace other evidence that should exist.
- SA 580 - date of representation letter
- Date as near as practicable to, but not after, the date of the auditor's report
- The letter covers all financial statements and period(s) referred to in the auditor's report.
- SA 580 - responsibility representations not given
- Management does not give the responsibility representations, or integrity is in serious doubt so those representations are unreliable → after discussion and reevaluation, disclaim an opinion under SA 705 (mandatory); consider withdrawal where permitted by law or regulation
- The disclaimer is mandatory only in these cases. For other representations not given, determine the effect on the opinion under SA 705. A disclaimer does not follow automatically. Withdrawal is considered only where law or regulation permits it.
- SA 620 - evaluating the expert
- Competence + Capabilities + Objectivity
- Then evaluate whether the expert's work is adequate for the audit.
- SA 540 - responses to assessed risk
- Test how management made the estimate | Develop a point estimate or range | Events up to report date (where relevant)
- Under revised SA 540, design further procedures responsive to assessed risks, using one or a combination of these three approaches. Then evaluate, based on the evidence, whether the estimates and related disclosures are reasonable or misstated, and obtain written representations about the estimates.
- SA 501 - inventory
- If inventory is material, attend physical counting unless impracticable
- If attendance is impracticable, perform alternative procedures. If still no evidence, modify the opinion.
- Overriding principle
- Sole responsibility for the audit opinion rests with the auditor (group engagement partner / user auditor / the auditor using internal audit work)
- Using others' work does not reduce your responsibility. - SA 610: do not refer to the internal audit function's work in the auditor's report unless law or regulation requires it. Even where the reference is required, the report must indicate that it does not reduce your responsibility for the opinion. - SA 402: do not refer to the service auditor's work in an unmodified opinion unless law or regulation requires it. If reference is made in a modified opinion, the report must state that the reference does not reduce the user auditor's responsibility for the opinion. In India, the Companies Act, 2013 links two provisions on branch audit. Section 143(8) provides for the audit of branch accounts by the company auditor or another qualified person (the branch auditor). Section 143(3)(c) requires the auditor's report to state whether the report on the accounts of a branch office audited by a person other than the company's auditor has been sent to the auditor and how it has been dealt with.
- SA 610: criteria to decide use of internal audit work
- Objectivity + Technical competence + Systematic and disciplined approach (with quality control)
- If any criterion is weak, do not use the work, or use it only to a limited extent. Also consider whether the work is likely to be adequate for the purposes of the audit.
- SA 610: procedures once work is used
- Evaluate quality of work + Perform own procedures on it (re-performance or reviewing and testing a sample)
- The extent depends on the judgment involved and the assessed risk.
- SA 610: limits on direct assistance
- Direct assistance is not permitted where law or regulation prohibits it. Evaluate threats to objectivity and the level of competence before using it. If the threats cannot be reduced to an acceptable level, or competence is insufficient, do not use direct assistance. Do not assign internal auditors work that involves making significant judgments, work relating to higher assessed risks of material misstatement where the judgment required is more than limited, or decisions about the internal audit function's own objectivity and competence and the use of its work.
- Limit the work assigned to what you can direct, supervise and review. The significant judgments and the decisions on the internal auditors' objectivity and competence stay with you.
- SA 600 (Revised): factors for involvement in a component auditor's work
- Group engagement team involvement = f(Significance of the component + Risks of material misstatement + Component auditor's competence, independence and quality + Group structure)
- These factors decide how much direction, supervision and review of the component auditor's work you need. The older terms 'principal auditor' and 'other auditor' describe the same roles as 'group engagement partner' and 'component auditor'. Follow the terms used in the question.
- SA 402: report types
- Type 1 = design and implementation at a date; Type 2 = design, implementation and operating effectiveness over a period
- Type 1 alone gives no evidence of operating effectiveness.
Quick revision
- Audit evidence is the information the auditor uses to reach conclusions that support the opinion; it includes information from accounting records and from other sources.
- Sufficiency measures the quantity of evidence; appropriateness measures its quality, meaning relevance and reliability.
- Higher assessed risk means more evidence is needed; better quality evidence reduces the quantity needed but does not remove it.
- Procedures include inspection, observation, external confirmation, recalculation, reperformance, analytical procedures and inquiry.
- Inquiry alone is not enough to support an assertion or to test control operation.
- SA 230 requires documentation sufficient for an experienced auditor with no prior link to the audit to understand the work done, results and significant judgements.
- Sampling risk is the risk that the conclusion from a sample differs from the conclusion on the whole population; non-sampling risk is the risk of reaching an erroneous conclusion for any reason not related to sampling risk, for example using an inappropriate procedure or misinterpreting evidence.
- Statistical and non-statistical sampling can both be valid if properly designed. Statistical sampling has both random selection of the sample and use of probability theory to evaluate results; an approach that lacks either element is considered non-statistical sampling. Non-statistical sampling can still use random selection.
- SA 520 deals with analytical procedures used as substantive procedures and in the overall review near the end of the audit; their use as risk assessment procedures is required by SA 315 (Revised).
- Written representations are evidence but cannot replace other evidence; if management refuses them, the auditor considers the effect on the opinion.
- An auditor's expert is an individual or organisation with expertise in a field other than accounting or auditing whose work the auditor uses. The auditor has sole responsibility for the opinion, and that responsibility is not reduced by use of an expert. The auditor evaluates the expert's competence, capabilities and objectivity, and also evaluates the adequacy of the expert's work for the audit's purposes. The auditor does not refer to the expert in an unmodified report unless required by law or regulation; in a modified report, reference may be made if it helps understand the modification, and the report then states that this does not reduce the auditor's responsibility.
- Using an internal auditor's work does not reduce the auditor's responsibility for the opinion.
Common mistakes
- Treating sufficiency and appropriateness as the same thing. Fix: Remember: sufficiency is quantity, appropriateness is quality. Appropriateness has two parts, relevance and reliability.
- Saying a large volume of evidence can make up for poor quality. Fix: State that higher risk needs more evidence, but quantity cannot cure poor quality.
- Confusing existence with completeness. Fix: Existence checks that recorded items are real (overstatement). Completeness checks that nothing real is missing (understatement). Test existence from books to evidence; test completeness from evidence to books.
- Treating inquiry as sufficient evidence. Fix: Inquiry supports other procedures but ordinarily does not by itself provide sufficient appropriate evidence. Pair it with inspection, confirmation or reperformance.
- Saying the client owns the working papers. Fix: Remember that the auditor owns the working papers. The auditor may share extracts at discretion, but the client has no right to them.
- Mixing up the 60-day and 8-year figures, or crediting 60 days to SA 230. Fix: Link 60 days (from SQM 1; SA 230 says timely) with assembling the final file and 8 years with keeping it. Write both with the words 'from the date of the auditor's report'.
- Saying statistical sampling is more reliable than non-statistical sampling. Fix: State that both can give sufficient appropriate evidence if properly designed. The choice depends on cost and practicality.
- Claiming a larger sample reduces non-sampling risk. Fix: A bigger sample reduces only sampling risk. Non-sampling risk falls through proper procedures, training, supervision and review.
- Saying analytical procedures are optional at every stage. Fix: Remember the overall review near the end is required. Risk assessment use is also required under SA 315. Only the substantive use is optional.
- Accepting management's explanation for a fluctuation without further checks. Fix: Write that you inquire of management and then obtain appropriate audit evidence to corroborate the answer, plus other procedures as needed.
Exam tips
- Start every theory answer with the definition and the words 'sufficient and appropriate'. Examiners look for them.
- Use two short headings, sufficiency and appropriateness, and put one clear point under each.
- For reliability questions, give a ranked list with a reason for each ranking, and add 'generally' to avoid overstatement.
- MCQs often test whether a statement is true or false. Watch for words like 'always' and 'only'.
- Attempt every MCQ since there is no negative marking. Eliminate absolute statements first.
- Learn the three assertion sets separately. A common question asks you to name the assertions for a class of transactions, a balance, or a disclosure.
- In scenario questions, first name the assertion and then the procedure. This usually earns marks for both.
- Remember that 'accuracy, valuation and allocation' is the balance assertion, while 'accuracy' is the transaction assertion.