Advanced Audit and Assurance (International) · Using the work of others
Using Component Auditors and Group Audit Considerations (ISA 600)
Updated 11 October 2026 · Fact-checked
Under ISA 600 (Revised), the group engagement partner is responsible for the group opinion, even when component auditors do the work. You assess each component auditor's competence, ethics and independence, direct and communicate with them clearly, stay involved in their risk assessment and evaluate their work. You never refer to them in the opinion.
Understand Using the Work of Other Auditors and Group Audit Considerations
A group audit covers financial statements that include more than one entity or business unit. A component is an entity or business activity whose financial information is included in the group financial statements. Often another audit firm audits an overseas subsidiary. That firm is a component auditor.
The group engagement partner signs the group opinion. ISA 600 (Revised) makes the group team fully responsible for the direction, supervision and performance of the group audit, and for the opinion. You cannot pass responsibility to the component auditor. The audit report must not refer to the component auditor, unless law or regulation requires it. Even then, responsibility is not reduced.
ISA 600 (Revised) takes a risk-based approach. You identify and assess risks of material misstatement for the whole group first. Then you decide which components need work and what kind. Scoping is based on these assessed risks, not on predefined component types. The financial significance of a component may still be a factor in assessing risk. A component auditor who performs audit work on the group audit for the group team is part of the group engagement team. That auditor is subject to the group team's direction, supervision and review under ISA 220 (Revised).
When using a component auditor you consider several things. Do they understand and comply with the ethical requirements relevant to the group audit, including independence? Do they have professional competence and the capability and resources to do the work? Can you be involved in their work? Is the component auditor subject to an active independent oversight environment (for example a regulator or inspection regime)? Where concerns cannot be resolved, you do the work yourself or use another auditor.
Communication runs both ways. You tell the component auditor what work to do, the component performance materiality that the group team has determined, the threshold above which misstatements are not clearly trivial, risks identified, relevant ethical requirements, and related parties. They tell you whether they complied, what they found, significant matters and misstatements. Involvement then depends on risk. For higher-risk components you take part in the risk assessment, review their documentation and may perform procedures yourself.
Do not confuse this with other topics. ISA 610 (Revised 2013) covers using the work of internal auditors, including direct assistance. ISA 620 covers an auditor's expert, such as a valuer. A component auditor is not an expert and not an internal auditor. They perform audit procedures on a component and are within the scope of ISA 600.
Key rules to remember
- Responsibility rule
- Group engagement partner = overall responsibility for the group opinion and for direction, supervision and performance of the group audit (not reduced by use of component auditors)
- The report must not refer to the component auditor unless law or regulation requires it, and even then responsibility stays with you.
- Evaluating a component auditor
- Ethics and independence + competence and capability + ability to be involved + oversight environment
- Use this as a checklist. If concerns remain unresolved, perform the work yourself or use another auditor.
- Group planning order
- Understand group and environment → assess group risks → decide scope of work at components → set component performance materiality → direct and communicate → evaluate
- Risk drives scope, not size alone.
- Materiality layers
- Component performance materiality (determined by the group engagement team) must be lower than group performance materiality
- The group team determines component performance materiality and communicates it to the component auditor together with the threshold above which misstatements are not clearly trivial.
- Which standard applies
- Component auditor → ISA 600; internal auditor → ISA 610 (Revised 2013); auditor's expert → ISA 620
- A quick way to answer the ISA 600 versus ISA 620 comparison.
How to solve Using the Work of Other Auditors and Group Audit Considerations questions
Use this approach for any scenario on component auditors. Tie every point to facts in the case.
- 1Identify the component and the component auditor. Note size, location, risk, and whether the auditor is in your network.
- 2Assess the component auditor: ethics and independence, competence and resources, regulatory environment, and language or framework familiarity.
- 3State the group auditor's responsibility. You sign the opinion and are not reduced by relying on others.
- 4Set the scope: decide whether the component needs an audit, specified procedures, or analytical review, based on risk.
- 5Communicate: give instructions on component performance materiality, the threshold above which misstatements are not clearly trivial, risks, ethics, related parties and reporting. Request their findings in return.
- 6Plan your involvement: risk assessment discussion, review of working papers, visits, or doing procedures yourself.
- 7Evaluate their work and conclude on whether you have enough appropriate evidence. Consider further work if not.
- 8Link to the report: no reference to the component auditor, and consider the effect on the opinion if evidence is insufficient.
Quickest way: CCIE check for component auditors
When to use it: Use when the question gives a short scenario and asks whether you can rely on a component auditor.
- C: Competence and capability. Qualifications, experience, resources, familiarity with the framework.
- C: Compliance with ethics and independence rules relevant to the group audit.
- I: Involvement. What will you do: discuss risks, review files, visit, or do the work.
- E: Evaluate and conclude. Is the evidence sufficient and appropriate, and who signs the opinion (you)?
Common mistakes in Using the Work of Other Auditors and Group Audit Considerations
Saying the component auditor shares responsibility for the group opinion.
Students link shared work with shared blame.
Fix: State clearly that the group engagement partner has overall responsibility for the group opinion and for direction, supervision and performance of the group audit. Component auditors are not mentioned in the opinion.
Treating a component auditor as an auditor's expert and citing ISA 620.
Both involve using the work of someone outside the team.
Fix: A component auditor does audit procedures on a component, so ISA 600 applies. ISA 620 is for specialists in a field other than accounting or auditing.
Relying on a component auditor because they are from the same network and ignoring other checks.
Network membership feels like proof of quality.
Fix: Still assess ethics, competence and your ability to be involved. Network membership may help, but it does not replace the evaluation.
Giving a generic list of procedures without linking to the scenario.
Students memorise the list and not the application.
Fix: Quote case facts such as high-risk location, inexperience with the framework, or past misstatements, and then say what you would do.
Using group performance materiality for the component work.
Students forget that errors can aggregate across components.
Fix: The group team determines a lower component performance materiality and communicates it with the threshold above which misstatements are not clearly trivial.
Ignoring the professional skills requirement and giving no recommendation.
Technical answers feel complete.
Fix: End with a clear conclusion on reliance, show scepticism and offer practical next steps, such as a review visit.
Worked examples
Example 1
Zenith Co is a group audited by your firm. Its subsidiary Kora, in a country where your firm has no office, represents a significant share of group revenue. Kora is audited by a local firm, Alba & Co, which you have not used before. Alba is not subject to any independent oversight. Explain the matters you should consider before using Alba's work and how you would respond. (10 marks)
Show the solution
- Identify the facts: Kora is material to the group, so risks are higher. Alba is new to you and is not subject to independent oversight. Therefore reliance needs more evidence.
- Ethics and independence: confirm that Alba understands and complies with the ethical requirements relevant to the group audit, including independence from Zenith group. Obtain written confirmation and enquire about any relationships.
- Competence and capability: check qualifications, experience, resources, training, and knowledge of the financial reporting framework used in the group accounts. Without oversight, ask about their quality management and any past findings.
- Communication: send clear instructions on work to be done, the component performance materiality set by the group team, the threshold above which misstatements are not clearly trivial, identified risks, related parties and the format and timing of reporting.
- Involvement: because Kora is significant and Alba is untested, take part in Alba's risk assessment, review key working papers, and consider visiting Kora to meet Alba and review its audit approach.
- Further work: if concerns are not resolved, perform procedures yourself or use another auditor at Kora.
- Responsibility: state that you remain responsible for the group opinion and will not refer to Alba in the audit report.
Answer: You must evaluate Alba's ethics, competence and resources, direct them clearly, and be more involved because Kora is significant and Alba is new and not subject to independent oversight. If concerns persist, do the work yourself or replace Alba. The group engagement partner remains responsible for the opinion and the report makes no reference to Alba.
Example 2
A junior colleague says: 'We have used the same network firm in Brazil for years, so we can accept their report on the Brazilian subsidiary without further work, and we will say in our audit report that part of the group was audited by them.' Comment on this view. (6 marks)
Show the solution
- Network membership and past experience are helpful, but they do not replace assessment. Under ISA 600 (Revised) you still evaluate ethics, independence, competence and capability for the current audit.
- The group team must communicate its requirements, such as component performance materiality, risks and reporting, and receive the component auditor's findings.
- Your involvement depends on risk. If the subsidiary has high risk, you should review work and take part in risk assessment even for a trusted firm.
- Evaluate the work received. You need sufficient appropriate evidence for the group opinion.
- The audit report should not refer to the component auditor. Referring would suggest a division of responsibility, but the group engagement partner has overall responsibility for the group opinion and for direction, supervision and performance of the group audit, unless law or regulation requires the reference. Even then responsibility is unchanged.
Answer: The view is wrong on both points. You must still assess the network firm and be involved in line with the risk, then evaluate their work. You should not refer to them in the audit report, because the group engagement partner has overall responsibility for the group opinion and for direction, supervision and performance of the group audit.
Exam tips
- Always state that the group engagement partner is responsible for the opinion. Examiners look for this point.
- Tie each consideration to the case: size of the component, location, auditor's experience and regulation. Generic lists score poorly.
- When asked to compare ISA 600 with ISA 620 or ISA 610, name who is being used and what they do: component auditor, expert or internal auditor.
- Finish with a clear recommendation on reliance and next steps. This earns professional skills marks for judgement and communication.
- Mention group-level risk assessment before scoping. ISA 600 (Revised) is risk-based, not just size-based.
Practice questions from Using the work of others
- Delta & Co is auditing Kestrel Foods plc. Kestrel uses an external actuary, engaged by management, to measure its defined benefit obligation…
- Kestrel & Co is auditing Lumina Ltd, which holds a portfolio of unquoted mineral reserves. The audit team lacks valuation expertise and plan…
- Orion Retail uses Paylink Services to process its payroll. Paylink provides a type 2 report under ISAE 3402 covering the design and operatin…
- Delta & Co audits Vantage Logistics, which outsources its inventory warehousing and record keeping to Stockwell Ltd. Stockwell's service aud…
- Harlow Group's auditor, Brindle & Co, plans to use the work of a component auditor from a different network firm for the audit of a signific…
Using the Work of Other Auditors and Group Audit Considerations in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Using the Work of Other Auditors and Group Audit Considerations: frequently asked questions
What are the key changes in ISA 600 (Revised)?
It takes a risk-based approach to scoping the group audit and strengthens the group team's responsibility for direction, supervision and review. It aligns with the quality management standards and makes it clear that the group team must be involved in the work of component auditors. It also clarifies the communication needed in both directions.
Can the audit report mention the component auditor?
The report should not refer to a component auditor, because the group engagement partner is responsible for the opinion. An exception arises only where law or regulation requires reference. Even then, the responsibility for the opinion is not reduced.
What is the difference between ISA 600 and ISA 620?
ISA 600 covers audits of group financial statements, including using component auditors who perform audit work on components. ISA 620 covers using an auditor's expert, who has skill in a field other than accounting or auditing, such as valuation or actuarial work.
What if I cannot be involved in the component auditor's work?
If you cannot obtain sufficient appropriate evidence through the component auditor, you consider performing the work yourself or using another auditor. If you still cannot get enough evidence, you consider the effect on the opinion, which may mean a modification due to a limitation of scope.