Skip to content

Advanced Audit and Assurance (International) · Evidence and testing considerations

ISA 520 Analytical Procedures, Data Analytics and Automated Audit Tools

Updated 11 October 2026 · Fact-checked

Analytical procedures evaluate financial information by studying plausible relationships between data, then investigating differences from expectations. Under ISA 520 you use them at planning, as substantive tests and at final review. Data analytics and automated tools extend this by testing whole populations, but you still evaluate the results and investigate exceptions.

Understand Data Analytics, Automated Tools and Analytical Procedures (ISA 520)

Analytical procedures compare recorded figures with what you expect them to be. You build an expectation from other data, such as last year's results, budgets, industry figures or non-financial data like staff numbers or units sold. Then you compare it with the recorded amount. A large unexplained difference is a warning sign.

Analytical procedures have three uses. Two are required and one is optional. At the risk assessment stage they help you understand the entity and spot unusual items. This use is required by ISA 315 (Revised), not by ISA 520. Near the end of the audit, ISA 520 requires them as an overall review of whether the financial statements agree with your understanding of the entity. Between these, you may use them as substantive procedures to respond to assessed risks. This use is optional.

A substantive analytical procedure is only as good as its expectation. You must consider the reliability of the data you use, whether the expectation is precise enough to identify a material misstatement, and how big a difference you can accept without further work. Predictable, stable relationships, such as payroll or interest, suit this approach. Volatile balances, such as one-off items, do not. They are generally weak against risks needing detailed testing, such as fraud or estimates.

If results are inconsistent with expectations or other information, you must investigate. That means asking management and obtaining corroborating evidence for their answers, then performing other audit procedures where needed. Management's explanation alone is not enough.

Data analytics and computer-assisted audit techniques (CAATs) use software to test large volumes of data. Examples are recalculating depreciation, matching orders to invoices, finding duplicate payments, journal entry testing and ageing receivables. Their strength is full-population testing and speed. Their weakness is cost, data quality, skills needed and the risk of false positives. They support judgement; they do not replace it.

Key rules to remember

Expectation test
Difference = Recorded amount − Expected amount; investigate if Difference > Threshold
The threshold is the amount of difference you can accept without investigation. Set it so that differences, aggregated with other misstatements, could not cause the financial statements to be materially misstated. It is lower when you need higher assurance.
Gross profit margin
Gross profit margin = Gross profit ÷ Revenue × 100
A common ratio for expectations. Compare with prior year, budget and industry.
Receivables days
Receivables days = Trade receivables ÷ Credit revenue × 365
Increases may signal overstated receivables or weak credit control.
Payables days
Payables days = Trade payables ÷ Credit purchases (or cost of sales) × 365
State which denominator you use and keep it consistent between years.
Inventory days
Inventory days = Inventory ÷ Cost of sales × 365
Increases may suggest obsolete inventory or overstated inventory.
Reasonableness test
Expected amount = Driver × Rate
Example: expected payroll = average staff × average pay, adjusted for known pay rises.

How to solve Data Analytics, Automated Tools and Analytical Procedures (ISA 520) questions

Use this method for any question on analytical procedures or data analytics.

  1. 1Read the requirement. Decide whether it asks for risk assessment, substantive testing, final review, or advantages and disadvantages.
  2. 2Identify the figures or relationships in the scenario that change significantly. Calculate ratios or changes if data is given.
  3. 3Form an expectation using the facts, such as price changes, new stores, or a change in accounting policy.
  4. 4Compare the expectation with the recorded figure and say whether the difference is significant in relation to materiality.
  5. 5Give specific, scenario-linked explanations for the difference, including error, fraud and genuine business reasons.
  6. 6State the further procedures to corroborate the explanation, such as agreeing to invoices, contracts or third-party evidence.
  7. 7For data analytics, state what you would test, on what population, the advantage gained and the limits, such as data reliability and exceptions to follow up.
  8. 8Conclude on the risk or what the evidence means for the audit opinion.

Quickest way: Expect, compare, explain, corroborate

When to use it: Use this when time is short and the question gives movements in figures or ratios.

  1. Calculate only the two or three most significant changes.
  2. Write one line of expectation for each, linked to the scenario.
  3. State the gap and whether it is material.
  4. Give two possible causes: one innocent, one error or fraud.
  5. Add one corroborating procedure for each.
  6. For analytics questions, give a benefit and a limitation for each tool you name.

Common mistakes in Data Analytics, Automated Tools and Analytical Procedures (ISA 520)

  • Listing ratios without interpreting them.

    Calculation feels like progress and earns quick marks in practice.

    Fix: For every ratio, say what it suggests about risk and what you would do next.

  • Accepting management's explanation as evidence.

    The explanation sounds sensible and fits the scenario.

    Fix: Treat the explanation as a lead. Corroborate it with documents or independent evidence.

  • Using analytical procedures for a high-risk balance with no precision.

    Students forget that precision depends on the expectation and data reliability.

    Fix: Say that a high risk needs more precise tests or detailed testing, and that unreliable or volatile data weakens the approach.

  • Saying data analytics replaces sampling and judgement.

    Technology is described as a complete solution.

    Fix: Say it can test whole populations, but the auditor must define the tests, assess data reliability and investigate exceptions.

  • Forgetting the final review stage.

    Analytical procedures are linked in memory only to planning.

    Fix: Remember all three uses: risk assessment (required by ISA 315 (Revised)), substantive (optional) and overall review near the end (required by ISA 520).

  • Giving generic advantages and disadvantages of CAATs.

    Students recall a list, not the client's situation.

    Fix: Tie each point to the client's systems, data volume, cost and staff skills.

Worked examples

Example 1

Bright Ltd's revenue rose from $10,000,000 to $12,000,000. Cost of sales rose from $6,000,000 to $8,400,000. Management says selling prices were unchanged and volumes rose 20%. Evaluate using analytical procedures what this indicates and what you would do next.

Show the solution
  1. Prior year gross profit = 10,000,000 − 6,000,000 = 4,000,000, a margin of 40%.
  2. Current year gross profit = 12,000,000 − 8,400,000 = 3,600,000, a margin of 30%.
  3. Expectation: with unchanged prices and 20% more volume, revenue up 20% is consistent (10,000,000 × 1.2 = 12,000,000). If unit costs were unchanged, cost of sales should be 6,000,000 × 1.2 = 7,200,000, and the margin should stay at 40%.
  4. Recorded cost of sales is 8,400,000, which is 1,200,000 above the expectation. This assumes unit costs were unchanged. No materiality figure is given, so you cannot confirm that the gap is above materiality. A fall in margin from 40% to 30% is significant on any plausible materiality level, so it needs investigation.
  5. Possible causes: higher input costs (which would make the unchanged-unit-cost expectation too low), unrecorded or mis-timed purchases, inventory understated at year end, errors in cost allocation, or theft. Revenue growth fits management's volume and price claims, but those claims are unverified, so revenue still needs testing.
  6. Corroborate: agree supplier price lists and invoices, test inventory counts and valuation, test purchase cut-off, review the cost of sales build-up, and agree sales volumes and prices to despatch records and price lists.

Answer: Gross margin fell from 40% to 30%. Cost of sales is $1,200,000 higher than expected, assuming unchanged unit costs. No materiality is given, but a 10-point margin fall is significant on any plausible materiality. It needs investigation through price, inventory and cut-off testing. Management's explanation cannot be relied on without corroboration.

Example 2

Explain two ways data analytics could be used in the audit of a retailer with 200 stores and high-volume sales, and two limitations.

Show the solution
  1. Use one: test the full sales and receipts population by matching till records to bank receipts. This identifies unmatched or unusual items, with a stronger result than sampling.
  2. Use two: analyse journal entries for unusual features, such as posting at weekends, round sums, unusual users or unusual account combinations. This helps respond to the risk of management override.
  3. Limitation one: the results depend on complete and accurate data. You must test the data extracted, for example by agreeing totals to the ledger.
  4. Limitation two: the tests can generate many false positives, and need skilled staff and software. Exceptions still need follow-up by detailed procedures.
  5. Add a conclusion: analytics improves coverage, but does not remove the need for judgement.

Answer: Match till records to bank receipts across all stores, and analyse journals for override risk. Limitations are data reliability, and false positives plus cost and skills. Exceptions must be investigated with other evidence.

Exam tips

  • Use the scenario figures. Calculate a change, state an expectation, then explain the gap. Generic text earns few marks.
  • Give both innocent and adverse explanations, then say how you would corroborate each.
  • For data analytics, name a concrete test, the population and the advantage. Add a limitation to show balance.
  • Link to professional scepticism in the professional skills marks by questioning management explanations and data reliability.
  • If asked about the final review, say it checks whether the financial statements agree with your understanding of the entity.

Practice questions from Evidence and testing considerations

Data Analytics, Automated Tools and Analytical Procedures (ISA 520) in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Data Analytics, Automated Tools and Analytical Procedures (ISA 520): frequently asked questions

When must an auditor use analytical procedures under ISA 520?

ISA 520 requires analytical procedures near the end of the audit as an overall review. They are also used at risk assessment under ISA 315, and may be used as substantive procedures. Substantive use is a choice, not a requirement.

How do I perform a substantive analytical procedure?

Develop an expectation from reliable data. Decide the difference you can accept without investigation. Compare the recorded amount to the expectation and investigate any larger gap. Corroborate explanations with other evidence.

What are the advantages and disadvantages of CAATs?

Advantages include testing whole populations, speed, consistency and better detection of unusual items. Disadvantages include cost, skills needed, reliance on complete and accurate data, and many exceptions that need follow-up.

Can data analytics replace audit sampling?

Not entirely. Analytics can test full populations for some assertions, but you must still design the tests, check the data, and investigate exceptions. Some evidence, such as confirmations and inspection, still needs other procedures.