Skip to content

CS Professional · Compliance Management, Audit and Due Diligence

Audit Process and Documentation for CS Professional

The audit process is the sequence an auditor follows: plan, accept the engagement, assess risks, gather evidence, document the work, and report. Documentation is the written record of that work. In the exam, you apply each step to a case: state the rule, analyse the facts, and conclude.

What this chapter covers

This chapter walks through an audit from start to finish. You begin with planning and strategy, move to appointment and engagement terms, and then to risk assessment, evidence, working papers and the final report. Each step feeds the next. Risks assessed early decide what evidence you collect later, and the working papers record both.

The chapter sits in the Audit and Due Diligence part of Paper 3, Compliance Management, Audit and Due Diligence. Later topics such as due diligence, internal audit and compliance audit reuse the same ideas: planning, risk, evidence and a written record. If you understand this chapter well, those topics become easier.

The Standards on Auditing (SAs) issued by ICAI are the core source, especially SA 315 on risk assessment and SA 330 on the auditor's responses to assessed risks. Questions are written and case-based, so you must apply these standards to facts and not only recall them.

Paper 3 is a written paper where you are marked on provision, analysis and conclusion. This chapter gives you the base for the whole Audit and Due Diligence part. Case questions often ask what an auditor should do when risk, controls or evidence change, and the answer comes straight from the process covered here. Clear, structured answers on planning, risk and documentation are easy to write once you know the flow, so the effort pays off across many questions.

Audit Process and Documentation: topics in the order to study them

  1. 1Audit Planning and StrategyPlanning is the first step of every audit, and all later topics refer back to the plan and strategy.
  2. 2Audit Engagement and Appointment ProcessOnce you know how an audit is planned, learn how the auditor is appointed and the engagement is accepted and agreed.
  3. 3Internal Control and Risk AssessmentRisk assessment drives the nature, timing and extent of procedures, so learn it before evidence. This is where SA 315 and SA 330 matter most.
  4. 4Audit Evidence and TechniquesEvidence is gathered in response to assessed risks, so it is easier to follow after risk assessment.
  5. 5Audit Working Papers and DocumentationDocumentation records planning, risks and evidence, so you can study it once you know what is being recorded.
  6. 6Audit Reporting and Follow-upReporting is the end point. It makes sense only after you know how the conclusions were reached and documented.

How to prepare Audit Process and Documentation

Study this chapter as one connected process and not as six separate topics. Practise writing short case answers as you go.

  1. Read the six topics once in the study order to see the full flow from planning to follow-up.
  2. For risk assessment, learn SA 315 and SA 330 in plain words. Know that the auditor must understand the entity's risk assessment process and must respond to the risks assessed.
  3. Note the points where the auditor must revise earlier work. SA 330 says an audit is cumulative and iterative, so findings from procedures may change the risk assessment.
  4. Learn what goes into working papers and why the form and extent of documentation depends on the entity's nature, size and complexity and on the team's experience.
  5. Practise two or three case questions per topic. Write in three parts: the rule, the analysis of the facts, and the conclusion.
  6. Prepare a one-page flow chart of the audit process and revise it every week.
  7. Before the exam, revisit your quick revision points and your own past mistakes.

Common mistakes in Audit Process and Documentation

  • Treating the topics as separate lists to memorise

    Fix: Link each topic to the next. Show in your answers how risk assessment shapes evidence and how documentation records both.

  • Listing procedures in a case question without applying them to the facts

    Fix: Use the three-part structure: rule, analysis of the given facts, conclusion. Refer to the entity's size, controls and circumstances.

  • Treating the risk assessment as fixed once done

    Fix: Remember that new evidence, such as misstatements or conflicting records, may require revising the risk assessment and procedures.

  • Stating that documentation must follow one fixed format

    Fix: Say that the auditor decides the manner of documentation by professional judgment, depending on the entity and the audit approach, while meeting SA 230.

  • Relying on previous year's control testing without conditions

    Fix: Name the factors: control environment, manual or automated control, general IT controls, past deviations, personnel changes, and the risk and extent of reliance.

  • Ignoring the internal audit function in risk assessment

    Fix: Mention early and continued communication with internal audit and reading its reports where relevant.

Last-day revision: Audit Process and Documentation

  • The audit runs in order: plan, accept the engagement, assess risk, gather evidence, document, report and follow up.
  • The engagement partner and key team members discuss how susceptible the financial statements are to material misstatement (SA 315).
  • The engagement partner decides which matters to pass on to team members not in the discussion.
  • If the entity has a risk assessment process, the auditor must understand it and its results.
  • If management missed a risk the auditor expected it to find, the auditor must understand why and assess whether there is a significant deficiency.
  • If there is no risk assessment process or only an ad hoc one, the auditor discusses business risks with management and evaluates whether this is appropriate or a significant deficiency.
  • Internal control has manual and often automated elements, and both affect the risk assessment and further procedures.
  • Using control evidence from earlier audits needs the auditor to consider factors such as the control environment, whether the control is manual or automated, general IT controls, past deviations and personnel changes (SA 330).
  • Audit is cumulative and iterative: misstatements found or discrepancies in records can change the risk assessment and the planned procedures.
  • The form and extent of documentation is a matter of professional judgment and depends on the entity's nature, size, complexity and the audit methodology.
  • Less experienced teams may need more detailed documentation, but SA 230 requirements must always be met.
  • Communicate early and often with the internal audit function, as it may bring relevant matters to the auditor's attention.

Audit Process and Documentation practice questions

Audit Process and Documentation in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Audit Process and Documentation: frequently asked questions

Which standards matter most in this chapter?

SA 315 on identifying and assessing risks of material misstatement and SA 330 on the auditor's responses to assessed risks are central. You should also know the planning, evidence and documentation standards at a working level. Learn them in plain words and be ready to apply them to cases.

Is this chapter theory or case-based?

The paper is written and case-based. You will need to state the rule, analyse the facts given and reach a conclusion. Pure recall without application usually scores less.

How should I study documentation?

Understand why working papers exist and what they record. Remember that the form and extent depend on the entity's nature, size and complexity, and on the team's experience. Then practise a case on what the auditor should document.

Why study risk assessment before audit evidence?

Evidence is collected in response to assessed risks. If you know how risks are identified and rated, the choice of procedures and the amount of evidence needed becomes logical and easier to remember.