CS Professional · Compliance Management, Audit and Due Diligence
Audit Process and Documentation: formula sheet
Key formulas
- Planning hierarchy
- Overall audit strategy → Audit plan → Audit programme
- Each layer is more detailed than the one before. The strategy guides the plan; the plan guides the programme.
- Depth of understanding (SA 315)
- Understanding needed < Understanding held by management
- The test is whether your understanding is enough to identify and assess risks of material misstatement. You use professional judgment.
- Relevant controls (SA 315)
- Not all controls relate to the audit
- Controls relate to financial reporting, operations and compliance, but only those relevant to your risk assessment matter.
- Documentation (SA 230)
- Document the plan and risk assessment; no separate checklist needed where the file itself shows compliance
- A well documented audit plan itself shows you planned the audit. A signed engagement letter shows agreed terms.
- Engagement letter as evidence
- Signed engagement letter in file = proof that terms were agreed with management or those charged with governance
- SA 230, A7. You need not document this separately in a checklist.
- Acceptance feeds risk assessment
- Acceptance/continuance information → consider relevance to risks of material misstatement
- SA 315, para 7. The auditor shall consider it; it is a requirement, not an option.
- Typical engagement letter contents
- Objective and scope + responsibilities of auditor + responsibilities of management + reporting framework + form of report + fees/timing
- A standard checklist for answers. Use it as a memory aid; add facts from the question.
- Engagement team discussion
- Engagement partner and key team members discuss susceptibility to misstatement (fraud or error)
- SA 315, A20-A21. Not every member needs to attend one single discussion.
- Audit evidence = sufficiency + appropriateness
- Sufficient appropriate audit evidence = enough quantity (sufficiency) + relevance and reliability (appropriateness)
- Both are needed. Quality does not replace quantity entirely, and quantity does not cure poor quality.
- Types of audit procedure (SA 330, A5)
- Inspection, observation, inquiry, confirmation, recalculation, reperformance, analytical procedure
- Name all seven when asked for procedures. Purpose is either a test of controls or a substantive procedure.
- Inquiry with other procedures (SA 330, A26)
- Inquiry alone is not sufficient to test operating effectiveness of controls
- Combine it with inspection or reperformance. These give more assurance than inquiry plus observation.
- Insufficient evidence (SA 330, para 27)
- If sufficient appropriate evidence is not obtained: attempt further evidence; if still unable, qualified opinion or disclaimer of opinion
- Link evidence gaps to the opinion in your answer.
- Evaluation of all evidence (SA 330, para 26)
- Consider all relevant evidence, whether it corroborates or contradicts the assertions
- The auditor cannot ignore contradictory evidence.
- Reassessing risk (SA 330, para 25)
- Before concluding the audit, evaluate whether risk assessments at assertion level remain appropriate
- Evidence obtained may show the original assessment was wrong.
- Time limit to assemble the final audit file
- Assembly completed ordinarily within 60 days after the date of the auditor's report
- This is the appropriate time limit under A21 of SA 230, and it is an 'ordinarily' rule set through the firm's quality control policies.
- Minimum retention period
- Retention ordinarily no shorter than 7 years from the date of the auditor's report (or, if later, the group auditor's report)
- SA 230 (A23) says seven years, not the five years in ISA 230, because the Chartered Accountants Act, 1949 and regulations require seven. An earlier ten-year figure was amended to seven.
- No deletion after assembly
- After final file assembly, no audit documentation of any nature may be deleted or discarded before the end of the retention period
- This is the requirement in paragraph 15 of SA 230.
- Changes after the report date
- Only administrative changes are allowed during final assembly; no new procedures and no new conclusions
- Examples in A22: discarding superseded documents, sorting and cross-referencing, signing off completion checklists, and documenting evidence already obtained and agreed before the report date.
- Completion memorandum
- Optional summary of significant matters and how they were addressed, with cross-references
- A11 says it is helpful, especially for large and complex audits, but it is not a mandatory document.
- Audit risk model
- Audit risk = Risk of material misstatement × Detection risk
- A conceptual model, not an exact calculation. Risk of material misstatement = inherent risk × control risk (when assessed separately).
- Risk of material misstatement
- RMM = Inherent risk × Control risk
- Assessed by the auditor at financial statement and assertion levels. The auditor does not control it; the entity's nature and controls drive it.
- Detection risk relationship
- Higher assessed RMM → lower acceptable detection risk → more extensive, persuasive substantive evidence
- Detection risk is the only component the auditor can change, through nature, timing and extent of procedures.
- Five components of internal control (SA 315)
- Control environment; Entity's risk assessment process; Information system and communication; Control activities; Monitoring of controls
- Learn the order. Examiners often ask you to list and explain them.
- Steps in identifying and assessing risks (SA 315, para 26)
- Identify → Assess (pervasive or not) → Relate to assertion level → Consider likelihood and magnitude
- Use as the skeleton for any 'how to assess risk' answer.
- Qualified opinion
- Material but not pervasive → 'except for' opinion
- Used for a misstatement, or an inability to get evidence, that is material but limited in effect.
- Adverse opinion
- Material and pervasive misstatement → financial statements do not give a true and fair view
- The auditor has the evidence; the statements are wrong.
- Disclaimer of opinion
- Unable to obtain evidence + possible effect material and pervasive → no opinion expressed
- The auditor lacks evidence; the auditor does not say the statements are wrong.
- Evidence rule (SA 330, para 27)
- No sufficient appropriate evidence → obtain further evidence; if still unable → qualified opinion or disclaimer
- Do not jump to a modified opinion before trying further procedures.
- Unmodified opinion
- No material misstatement, sufficient evidence obtained → unmodified opinion
- Emphasis of Matter and Other Matter paragraphs do not modify the opinion.
Quick revision
- The audit runs in order: plan, accept the engagement, assess risk, gather evidence, document, report and follow up.
- The engagement partner and key team members discuss how susceptible the financial statements are to material misstatement (SA 315).
- The engagement partner decides which matters to pass on to team members not in the discussion.
- If the entity has a risk assessment process, the auditor must understand it and its results.
- If management missed a risk the auditor expected it to find, the auditor must understand why and assess whether there is a significant deficiency.
- If there is no risk assessment process or only an ad hoc one, the auditor discusses business risks with management and evaluates whether this is appropriate or a significant deficiency.
- Internal control has manual and often automated elements, and both affect the risk assessment and further procedures.
- Using control evidence from earlier audits needs the auditor to consider factors such as the control environment, whether the control is manual or automated, general IT controls, past deviations and personnel changes (SA 330).
- Audit is cumulative and iterative: misstatements found or discrepancies in records can change the risk assessment and the planned procedures.
- The form and extent of documentation is a matter of professional judgment and depends on the entity's nature, size, complexity and the audit methodology.
- Less experienced teams may need more detailed documentation, but SA 230 requirements must always be met.
- Communicate early and often with the internal audit function, as it may bring relevant matters to the auditor's attention.
Common mistakes
- Using audit plan and audit programme as the same thing. Fix: Say the plan is the detailed approach covering risk assessment and further procedures. The programme is the specific step-by-step procedures, with timing and responsibility.
- Leaving out the overall audit strategy. Fix: Always start with strategy: scope, timing, direction and focus areas.
- Treating appointment and engagement as the same thing Fix: Write appointment as the legal act and engagement as the agreement of terms. Say both in your answer.
- Listing the engagement letter contents without applying them to the facts Fix: Tie each item to the case: for a new group company, mention component auditors or the reporting framework.
- Treating sufficiency and appropriateness as the same thing. Fix: Write sufficiency as quantity and appropriateness as relevance plus reliability. Give one line on each.
- Saying inquiry alone proves that a control operates. Fix: State that inquiry alone is not sufficient to test operating effectiveness of controls. Add inspection or reperformance.
- Writing that working papers must be kept for five years or ten years. Fix: Write seven years from the date of the auditor's report, or the group auditor's report if later, as in A23 of SA 230.
- Saying the 60-day limit for assembling the file is a fixed statutory deadline. Fix: Say 'ordinarily not more than 60 days after the date of the auditor's report', as an appropriate limit under the firm's quality control policies.
- Mixing up inherent risk and control risk. Fix: Ask whether the cause is the nature of the item (inherent) or a failure of the entity's controls (control). Inherent risk is considered before controls.
- Saying the auditor controls inherent and control risk. Fix: The auditor only assesses inherent and control risk. Only detection risk is managed through the audit procedures.
Exam tips
- Draw the hierarchy first in two lines; it frames every answer on planning.
- In case questions, name the facts and tie each to a planning step. This earns analysis marks.
- Remember the depth of understanding is less than management's, and only relevant controls matter.
- Mention documentation under SA 230 and updating of the plan; many students skip both.
- For small entities, note that strategy, plan, risks and materiality may be documented together with cross references.
- Open with a one-line sequence: appointment, acceptance, engagement letter, planning.
- Always conclude: accept, accept with conditions, or decline.
- Use the SA references you know exactly (SA 230 A7, SA 315 para 7) and avoid guessing others.