Advanced Audit and Assurance (International) · Group audits
Using Component Auditors and Group Auditor Involvement
Updated 11 October 2026 · Fact-checked
A component auditor is an auditor who performs work on a group component for the group audit. The group engagement partner stays responsible for the group opinion. You assess their competence, independence and ethics, send clear instructions, then direct, supervise and review their work. Involvement must be enough to obtain sufficient appropriate evidence.
Understand Using Component Auditors and Group Auditor Involvement
In a group audit, the group engagement team issues one opinion on the group financial statements. Some components, such as overseas subsidiaries, may be audited by other auditors. These may be firms in your network or firms outside it. They are called component auditors when they do work for the group audit.
The key idea is that responsibility is not shared out. The group engagement partner is responsible for the group opinion, and the audit report does not refer to component auditors. So you cannot just accept their work. You must decide whether you can use it and be involved enough to be satisfied with it.
The approach has three parts. First, before using them, assess whether they are fit to do the work: competence and capabilities, independence and ethical compliance, and the regulatory environment they work in. Second, communicate clearly what you need and when. Third, after they start, direct, supervise and review their work and evaluate what they report.
The amount of involvement is a judgement. It rises with the risk of material misstatement at the component, the component's significance, and doubts about the auditor. A weak or unfamiliar component auditor, or a risky component, means more involvement, such as joint risk assessment, a visit, or reviewing their working papers. You can also do the work yourself or use another team if the auditor cannot be relied on.
This topic follows the revised group audit standard, ISA 600 (Revised), which builds on ISA 220 (Revised) for direction, supervision and review. In the exam, always tie your points to the facts in the scenario: country, firm size, past quality problems, language, timing and the risk of the component.
Key rules to remember
- Responsibility rule
- Group opinion = group engagement partner's responsibility, with no reference to component auditors in the report
- Using component auditors never reduces the group partner's responsibility.
- Assessment checklist
- Competence + capabilities + independence + ethics + regulatory environment
- Use this as a prompt list when a scenario names a new or unfamiliar component auditor.
- Involvement rule
- Higher component risk or weaker auditor → more group team involvement
- Involvement is a judgement. It can include risk assessment discussions, further procedures, or reviewing working papers.
- Communication cycle
- Instructions out → confirmation of cooperation → reporting back → group evaluation
- Communication must be two-way and timely.
How to solve Using Component Auditors and Group Auditor Involvement questions
Use this method for any question on relying on component auditors. Apply every point to the scenario facts.
- 1Identify the component, its risk and significance, and who audits it. Note whether the auditor is in the network.
- 2Assess competence and capabilities: relevant experience, knowledge of IFRS and ISAs, resources, quality management and any inspection findings.
- 3Assess independence and ethics: the relevant ethical requirements, any threats such as relationships, fees or non-audit services, and confirmation of compliance.
- 4Consider the regulatory environment, oversight, language and access to working papers or people.
- 5Decide the level of involvement needed and the form it takes. Higher risk or lower confidence means more involvement.
- 6Communicate clearly: work to be done, materiality levels, risks, group and related party information, ethics, deadlines and reporting format. Ask for confirmation of cooperation.
- 7Direct, supervise and review: discuss risks, review documentation, and consider visits or calls. Evaluate their communication and whether the evidence is sufficient and appropriate.
- 8Conclude: if evidence is not enough, require more work, do it yourself, or consider the effect on the opinion.
Quickest way: Before, During, After
When to use it: Use when the question is short, or when you have little time left and need a structured list of points.
- Before: competence, independence and ethics, regulatory environment.
- During: written instructions and confirmation, then direction and supervision.
- After: review their reporting and working papers, and evaluate evidence.
- Link each point to a scenario fact and finish with the level of involvement and a clear recommendation.
Common mistakes in Using Component Auditors and Group Auditor Involvement
Saying the group auditor can place full reliance on the component auditor because they are a network firm.
Students assume network membership means quality.
Fix: Still assess competence, independence and ethics, though the network's common policies may inform the assessment. The group partner remains responsible.
Writing that responsibility is shared or transferred to the component auditor.
It sounds logical when someone else does the work.
Fix: State clearly that the group engagement partner is responsible for the opinion and the report does not refer to component auditors.
Giving a generic list of instructions with no link to the scenario.
Students memorise lists and do not apply them.
Fix: Name the specific risks, such as a foreign currency issue or a related party, and tie the instructions to the component's facts.
Stopping once the instructions are sent.
Students treat communication as a one-off step.
Fix: Add direction, supervision, review of working papers and evaluation of what the component auditor reports back.
Ignoring independence and treating only competence as relevant.
Competence is the more obvious factor.
Fix: Always cover the relevant ethical requirements, including independence, and ask for written confirmation of compliance.
Missing the professional skills marks by writing a long list with no recommendation.
Students focus only on technical points.
Fix: Finish with a clear conclusion, show scepticism and commercial awareness, and use the requested format.
Worked examples
Example 1
Your firm audits Darian Group, a listed company. A new subsidiary in a country where your firm has no experience is audited by a small local firm, Kesh & Co. The subsidiary is significant to the group and has complex revenue recognition. Explain the steps you take before deciding to use Kesh & Co's work. (8 marks)
Show the solution
- Significance and risk: the subsidiary is significant and its revenue is complex, so the risk is high and you need strong involvement and a careful assessment.
- Competence: find out Kesh & Co's experience with IFRS, ISAs and listed group reporting, their size, staffing, quality management and any inspection results.
- Independence and ethics: confirm they meet the relevant ethical requirements, including independence from the subsidiary and group, and obtain written confirmation.
- Regulatory environment: consider local oversight of auditors and any legal limits on access to working papers or people.
- Other sources: use enquiries with the network, professional bodies or prior group experience, and consider a visit or meeting.
- Involvement: because of high risk and unfamiliarity, plan joint discussion of the revenue risks, review of their working papers and possibly reperformance.
- Conclusion: if the assessment is unsatisfactory, do the work with your own team or use another auditor, and consider the effect on the group opinion.
Answer: Assess Kesh & Co's competence and capabilities, independence and ethics, and the regulatory setting. Because the component is significant and unfamiliar, plan high involvement including risk discussions and working paper review. If you cannot be satisfied, perform the work yourself or use another auditor, as the group partner stays responsible for the opinion.
Example 2
You are the group audit manager. A component auditor in an overseas subsidiary will audit the subsidiary for the group. List the matters you include in your instructions and say how you supervise and review their work. (7 marks)
Show the solution
- Scope: state the work needed, such as an audit or specified procedures, and the financial reporting framework, which is IFRS with any group accounting policies.
- Materiality: give component materiality and performance materiality, and the threshold for reporting misstatements.
- Risks: identify significant risks and areas of focus from the group risk assessment, and ask them to report other risks they find.
- Group matters: provide a list of related parties and ask for related party transactions, intragroup balances and any non-compliance with laws or fraud.
- Ethics: require compliance with the relevant ethical requirements and written confirmation of independence.
- Timetable and reporting: set deadlines, the format of the report, and ask for confirmation that they will cooperate and for prompt notice of significant issues.
- Supervision: hold planning calls, review key working papers, and visit if risks justify it.
- Review: evaluate their report, ask for explanations of unusual items, and decide whether more evidence is needed.
Answer: Instructions cover scope and framework, materiality, risks, related parties and intragroup items, ethics, timetable and reporting format, with confirmation of cooperation. You then direct and supervise through calls and visits, review key working papers, evaluate what they report, and obtain more evidence if the work is not sufficient.
Exam tips
- Always make the point that the group partner is responsible for the opinion. Examiners reward this when you recommend more involvement.
- Use scenario clues such as a new auditor, a different country, a risky component or a tight deadline to justify the level of involvement.
- Cover independence and ethics, not only competence. Many answers lose marks by leaving them out.
- Make a final recommendation, such as accept, accept with more involvement, or do the work yourself. This also earns professional skills marks.
- If asked to write a letter or email of instructions, use the format requested and keep it clear and professional.
Practice questions from Group audits
- Quill Group's auditor is scoping the audit. Component B is only 4% of group profit before tax, but it operates a trading desk in derivatives…
- Quill Group's auditor is planning the audit and identifies a subsidiary, Rowan Ltd, that is not individually financially significant but inc…
- Marlow & Partners is group auditor of Sandstone Group. In obtaining an understanding of the group, its components and their environments, wh…
- During acceptance of Brightwater Group, the engagement team learns that management of a significant overseas subsidiary, Norvik Ltd, is rest…
- Harlow & Co is considering appointment as group auditor of Verity Group, which has a parent and six subsidiaries. Two subsidiaries are audit…
Using Component Auditors and Group Auditor Involvement: frequently asked questions
What must the group auditor assess about a component auditor?
You assess their competence and capabilities, and whether they comply with the relevant ethical requirements, including independence. You also consider the regulatory environment they work in. The result decides how much involvement you need.
Does the group auditor refer to component auditors in the audit report?
No. The group engagement partner is responsible for the group opinion, and the report does not refer to the work of component auditors. Using them does not reduce that responsibility.
What should group instructions to a component auditor include?
They should set out the work to perform, the reporting framework, materiality levels, significant risks, related party and group information, ethical requirements, deadlines and reporting format. You should also ask the component auditor to confirm that they will cooperate.
What if the component auditor is not competent or independent?
You cannot rely on their work without further action. You can perform the work yourself, use another auditor, or increase your own procedures. If you still cannot get sufficient appropriate evidence, consider the effect on the group opinion.