A16. In the case of an audit engagement it is in the public interest and, therefore, required by the Code of Ethics, that the auditor be independent of the entity subject to the audit. The Code describes independence as comprising both independence of mind and independence in appearance. The auditor’s independence from the entity safeguards the auditor’s ability to form an audit opinion without being affected by influences that might compromise that opinion. Independence enhances the auditor’s ability to act with integrity, to be objective and to maintain an attitude of professional skepticism. In addition to the Code, the auditor may also be required to comply with the applicable laws and regulations. For example, section 141(3) of the Companies Act, 2013 lays down the disqualifications for appointment of the auditors of a company, the underlying intention of which is to ensure that a practitioner who is appointed as an auditor is able to maintain independence vis-a-vis the auditee company. Similarly, section 144 of the Companies Act, 2013 lists out the prohibited non-audit services.10
A17. Standard on Quality Control (SQC) 111 sets out the responsibilities of the firm for establishing policies and procedures designed to provide it with reasonable assurance that the firm and its personnel comply with relevant ethical requirements, including those pertaining to independence12. SA 220 sets out the engagement partner’s responsibilities with respect to relevant ethical requirements. These include evaluating whether members of the engagement team have complied with relevant ethical requirements, determining the appropriate action if matters come to the engagement partner’s attention that indicate that members of the engagement team have not complied with relevant ethical requirements, and forming a conclusion on compliance with independence requirements that apply to the audit engagement13. SA 220 recognises that the engagement team is entitled to rely on a firm’s systems in meeting its responsibilities with respect to quality control procedures applicable to the individual audit engagement, unless information provided by the firm or other parties suggests otherwise. 10 The underlined text has been added pursuant to the decision of the Council of ICAI taken at its 350th meeting held in February 2016. 11 Standard on Quality Control (SQC) 1, “Quality Control for Firms that Perform Audits and Reviews of Historical Financial Information, and Other Assurance and Related Services Engagements”. 12 SQC 1, paragraphs 14-27. 13 SA 220, “Quality Control for an Audit of Financial Statements”, paragraphs 9-12.
Professional Skepticism (Ref: Para. 15)
A18. Professional skepticism includes being alert to, for example: Audit evidence that contradicts other audit evidence obtained.
Information that brings into question the reliability of documents and
responses to inquiries to be used as audit evidence. Conditions that may indicate possible fraud. Circumstances that suggest the need for audit procedures in addition to those required by the SAs.
A19. Maintaining professional skepticism throughout the audit is necessary if the auditor is, for example, to reduce the risks of: Overlooking unusual circumstances. Over generalising when drawing conclusions from audit observations.
Using inappropriate assumptions in determining the nature, timing, and
extent of the audit procedures and evaluating the results thereof.
A20. Professional skepticism is necessary to the critical assessment of audit evidence. This includes questioning contradictory audit evidence and the reliability of documents and responses to inquiries and other information obtained from management and those charged with governance. It also includes consideration of the sufficiency and appropriateness of audit evidence obtained in the light of the circumstances, for example in the case where fraud risk factors exist and a single document, of a nature that is susceptible to fraud, is the sole supporting evidence for a material financial statement amount.
A21. The auditor may accept records and documents as genuine unless the auditor has reason to believe the contrary. Nevertheless, the auditor is required to consider the reliability of information to be used as audit evidence14. In cases of doubt about the reliability of information or indications of possible fraud (for example, if conditions identified during the audit cause the auditor to believe that a document may not be authentic or that terms in a document may have been falsified), the SAs require that the auditor investigate further and determine what modifications or additions to audit procedures are necessary to resolve the matter15.
A22. The auditor cannot be expected to disregard past experience of the honesty and integrity of the entity’s management and those charged with governance. Nevertheless, a belief that management and those charged with governance are honest and have integrity does not relieve the auditor of the need to maintain 14 SA 500, “Audit Evidence”, paragraphs 7-9. 15 SA 240, paragraph 13; SA 500, paragraph 11; and SA 505, paragraphs 10-11, and 16. professional skepticism or allow the auditor to be satisfied with less-than- persuasive audit evidence when obtaining reasonable assurance.
Professional Judgment (Ref: Para. 16)
A23. Professional judgment is essential to the proper conduct of an audit. This is because interpretation of relevant ethical requirements and the SAs and the informed decisions required throughout the audit cannot be made without the application of relevant knowledge and experience to the facts and circumstances. Professional judgment is necessary in particular regarding decisions about: Materiality and audit risk. The nature, timing, and extent of audit procedures used to meet the requirements of the SAs and gather audit evidence.
Evaluating whether sufficient appropriate audit evidence has been
obtained, and whether more needs to be done to achieve the objectives of the SAs and thereby, the overall objectives of the auditor.
The evaluation of management’s judgments in applying the entity’s
applicable financial reporting framework. The drawing of conclusions based on the audit evidence obtained, for example, assessing the reasonableness of the estimates made by management in preparing the financial statements.
A24. The distinguishing feature of the professional judgment expected of an auditor is that it is exercised by an auditor whose training, knowledge and experience have assisted in developing the necessary competencies to achieve reasonable judgments.
A25. The exercise of professional judgment in any particular case is based on the facts and circumstances that are known by the auditor. Consultation on difficult or contentious matters during the course of the audit, both within the engagement team and between the engagement team and others at the appropriate level within or outside the firm, such as that required by SA 22016, assist the auditor in making informed and reasonable judgments.
A26. Professional judgment can be evaluated based on whether the judgment reached reflects a competent application of auditing and accounting principles and is appropriate in the light of, and consistent with, the facts and circumstances that were known to the auditor up to the date of the auditor’s report. 16 SA 220, paragraph 18.
A27. Professional judgment needs to be exercised throughout the audit. It also needs to be appropriately documented. In this regard, the auditor is required to prepare audit documentation sufficient to enable an experienced auditor, having no previous connection with the audit, to understand the significant professional judgments made in reaching conclusions on significant matters arising during the audit17. Professional judgment is not to be used as the justification for decisions that are not otherwise supported by the facts and circumstances of the engagement or sufficient appropriate audit evidence.
Sufficient Appropriate Audit Evidence and Audit Risk (Ref: Para. 5
Sufficiency and Appropriateness of Audit Evidence
A28. Audit evidence is necessary to support the auditor’s opinion and report. It is cumulative in nature and is primarily obtained from audit procedures performed during the course of the audit. It may, however, also include information obtained from other sources such as previous audits (provided the auditor has determined whether changes have occurred since the previous audit that may affect its relevance to the current audit18) or a firm’s quality control procedures for client acceptance and continuance. In addition to other sources inside and outside the entity, the entity’s accounting records are an important source of audit evidence. Also, information that may be used as audit evidence may have been prepared by an expert employed or engaged by the entity. Audit evidence comprises both information that supports and corroborates management’s assertions, and any information that contradicts such assertions. In addition, in some cases, the absence of information (for example, management’s refusal to provide a requested representation) is used by the auditor, and therefore, also constitutes audit evidence. Most of the auditor’s work in forming the auditor’s opinion consists of obtaining and evaluating audit evidence.
A29. The sufficiency and appropriateness of audit evidence are interrelated. Sufficiency is the measure of the quantity of audit evidence. The quantity of audit evidence needed is affected by the auditor’s assessment of the risks of misstatement (the higher the assessed risks, the more audit evidence is likely to be required) and also by the quality of such audit evidence (the higher the quality, the less may be required). Obtaining more audit evidence, however, may not compensate for its poor quality.
A30. Appropriateness is the measure of the quality of audit evidence; that is, its relevance and its reliability in providing support for the conclusions on which the 17 SA 230, paragraph 8. 18 SA 315, “Identifying and Assessing the Risks of Material Misstatement Through Understanding the Entity and Its Environment”, paragraph 9. auditor’s opinion is based. The reliability of evidence is influenced by its source and by its nature, and is dependent on the individual circumstances under which it is obtained.
A31. Whether sufficient appropriate audit evidence has been obtained to reduce audit risk to an acceptably low level, and thereby enable the auditor to draw reasonable conclusions on which to base the auditor’s opinion, is a matter of professional judgment. SA 500 and other relevant SAs establish additional requirements and provide further guidance applicable throughout the audit regarding the auditor’s considerations in obtaining sufficient appropriate audit evidence.
A32. Audit risk is a function of the risks of material misstatement and detection risk. The assessment of risks is based on audit procedures to obtain information necessary for that purpose and evidence obtained throughout the audit. The assessment of risks is a matter of professional judgment, rather than a matter capable of precise measurement.
A33. For purposes of the SAs, audit risk does not include the risk that the auditor might express an opinion that the financial statements are materially misstated when they are not. This risk is ordinarily insignificant. Further, audit risk is a technical term related to the process of auditing; it does not refer to the auditor’s business risks such as loss from litigation, adverse publicity, or other events arising in connection with the audit of financial statements.
Risks of Material Misstatement
A34. The risks of material misstatement may exist at two levels:
The overall financial statement level; and
The assertion level for classes of transactions, account balances, and
A35. Risks of material misstatement at the overall financial statement level refer to risks of material misstatement that relate pervasively to the financial statements as a whole and potentially affect many assertions.
A36. Risks of material misstatement at the assertion level are assessed in order to determine the nature, timing, and extent of further audit procedures necessary to obtain sufficient appropriate audit evidence. This evidence enables the auditor to express an opinion on the financial statements at an acceptably low level of audit risk. Auditors use various approaches to accomplish the objective of assessing the risks of material misstatement. For example, the auditor may make use of a model that expresses the general relationship of the components of audit risk in mathematical terms to arrive at an acceptable level of detection risk. Some auditors find such a model to be useful when planning audit procedures.
A37. The risks of material misstatement at the assertion level consist of two components: inherent risk and control risk. Inherent risk and control risk are the entity’s risks; they exist independently of the audit of the financial statements.
A38. Inherent risk is higher for some assertions and related classes of transactions, account balances, and disclosures than for others. For example, it may be higher for complex calculations or for accounts consisting of amounts derived from accounting estimates that are subject to significant estimation uncertainty. External circumstances giving rise to business risks may also influence inherent risk. For example, technological developments might make a particular product obsolete, thereby causing inventory to be more susceptible to overstatement. Factors in the entity and its environment that relate to several or all of the classes of transactions, account balances, or disclosures may also influence the inherent risk related to a specific assertion. Such factors may include, for example, a lack of sufficient working capital to continue operations or a declining industry characterised by a large number of business failures.
A39. Control risk is a function of the effectiveness of the design, implementation and maintenance of internal control by management to address identified risks that threaten the achievement of the entity’s objectives relevant to preparation of the entity’s financial statements. However, internal control, no matter how well designed and operated, can only reduce, but not eliminate, risks of material misstatement in the financial statements, because of the inherent limitations of internal control. These include, for example, the possibility of human errors or mistakes, or of controls being circumvented by collusion or inappropriate management override. Accordingly, some control risk will always exist. The SAs provide the conditions under which the auditor is required to, or may choose to, test the operating effectiveness of controls in determining the nature, timing and extent of substantive procedures to be performed19.
A40. The SAs do not ordinarily refer to inherent risk and control risk separately, but rather to a combined assessment of the “risks of material misstatement”. However, the auditor may make separate or combined assessments of inherent and control risk depending on preferred audit techniques or methodologies and practical considerations. The assessment of the risks of material misstatement may be expressed in quantitative terms, such as in percentages, or in non- quantitative terms. In any case, the need for the auditor to make appropriate risk assessments is more important than the different approaches by which they may be made. 19 SA 330, “The Auditor’s Reponses to Assessed Risks”, paragraphs 7-17.
A41. SA 315 establishes requirements and provides guidance on identifying and assessing the risks of material misstatement at the financial statement and assertion levels.
A42. For a given level of audit risk, the acceptable level of detection risk bears an inverse relationship to the assessed risks of material misstatement at the assertion level. For example, the greater the risks of material misstatement the auditor believes exists, the less the detection risk that can be accepted and, accordingly, the more persuasive the audit evidence required by the auditor.
A43. Detection risk relates to the nature, timing, and extent of the auditor’s procedures that are determined by the auditor to reduce audit risk to an acceptably low level. It is therefore a function of the effectiveness of an audit procedure and of its application by the auditor. Matters such as: adequate planning; proper assignment of personnel to the engagement team; the application of professional skepticism; and supervision and review of the audit work performed, assist to enhance the effectiveness of an audit procedure and of its application and reduce the possibility that an auditor might select an inappropriate audit procedure, misapply an appropriate audit procedure, or misinterpret the audit results.
A44. SA 30020 and SA 330 establish requirements and provide guidance on planning an audit of financial statements and the auditor’s responses to assessed risks. Detection risk, however, can only be reduced, not eliminated, because of the inherent limitations of an audit. Accordingly, some detection risk will always exist.
Inherent Limitations of an Audit
A45. The auditor is not expected to, and cannot, reduce audit risk to zero and cannot therefore obtain absolute assurance that the financial statements are free from material misstatement due to fraud or error. This is because there are inherent limitations of an audit, which result in most of the audit evidence on which the auditor draws conclusions and bases the auditor’s opinion being persuasive rather than conclusive. The inherent limitations of an audit arise from: The nature of financial reporting; 20 SA 300, “Planning an Audit of Financial Statements”.
The nature of audit procedures; and
The need for the audit to be conducted within a reasonable period of time and at a reasonable cost.
The Nature of Financial Reporting
A46. The preparation of financial statements involves judgment by management in applying the requirements of the entity’s applicable financial reporting framework to the facts and circumstances of the entity. In addition, many financial statement items involve subjective decisions or assessments or a degree of uncertainty, and there may be a range of acceptable interpretations or judgments that may be made. Consequently, some financial statement items are subject to an inherent level of variability which cannot be eliminated by the application of additional auditing procedures. For example, this is often the case with respect to certain accounting estimates. Nevertheless, the SAs require the auditor to give specific consideration to whether accounting estimates are reasonable in the context of the applicable financial reporting framework and related disclosures, and to the qualitative aspects of the entity’s accounting practices, including indicators of possible bias in management’s judgments21.
The Nature of Audit Procedures
A47. There are practical and legal limitations on the auditor’s ability to obtain audit evidence. For example: There is the possibility that management or others may not provide, intentionally or unintentionally, the complete information that is relevant to the preparation and presentation of the financial statements or that has been requested by the auditor. Accordingly, the auditor cannot be certain of the completeness of information, even though the auditor has performed audit procedures to obtain assurance that all relevant information has been obtained. Fraud may involve sophisticated and carefully organised schemes designed to conceal it. Therefore, audit procedures used to gather audit evidence may be ineffective for detecting an intentional misstatement that involves, for example, collusion to falsify documentation which may cause the auditor to believe that audit evidence is valid when it is not. The auditor is neither trained as nor expected to be an expert in the authentication of documents. An audit is not an official investigation into alleged wrongdoing. Accordingly, 21 SA 540, “Auditing Accounting Estimates, Including Fair Value Accounting Estimates, and Related Disclosures”, and SA 700(Revised), “Forming an Opinion and Reporting on Financial Statements”, paragraph 12. the auditor is not given specific legal powers, such as the power of search, which may be necessary for such an investigation. Timeliness of Financial Reporting and the Balance between Benefit and Cost
A48. The matter of difficulty, time, or cost involved is not in itself a valid basis for the auditor to omit an audit procedure for which there is no alternative or to be satisfied with audit evidence that is less than persuasive. Appropriate planning assists in making sufficient time and resources available for the conduct of the audit. Notwithstanding this, the relevance of information, and thereby its value, tends to diminish over time, and there is a balance to be struck between the reliability of information and its cost. This is recognised in certain financial reporting frameworks (see, for example, the “Framework for the Preparation and Presentation of Financial Statements” issued by the Institute of Chartered Accountants of India (ICAI)). Therefore, there is an expectation by users of financial statements that the auditor will form an opinion on the financial statements within a reasonable period of time and at a reasonable cost, recognising that it is impracticable to address all information that may exist or to pursue every matter exhaustively on the assumption that information is in error or fraudulent until proved otherwise.
A49. Consequently, it is necessary for the auditor to: Plan the audit so that it will be performed in an effective manner; Direct audit effort to areas most expected to contain risks of material misstatement, whether due to fraud or error, with correspondingly less effort directed at other areas; and Use testing and other means of examining populations for misstatements.
A50. In light of the approaches described in paragraph A49, the SAs contain requirements for the planning and performance of the audit and require the auditor, among other things, to: Have a basis for the identification and assessment of risks of material misstatement at the financial statement and assertion levels by performing risk assessment procedures and related activities22; and Use testing and other means of examining populations in a manner that provides a reasonable basis for the auditor to draw conclusions about the population23. 22 SA 315, paragraphs 5-10. 23 SA 330; SA 500; SA 520, “Analytical Procedures” and SA 530, “Audit Sampling”.
Other Matters that Affect the Inherent Limitations of an Audit
A51. In the case of certain assertions or subject matters, the potential effects of the inherent limitations on the auditor’s ability to detect material misstatements are particularly significant. Such assertions or subject matters include: Fraud, particularly fraud involving senior management or collusion. See SA 240 for further discussion.
The existence and completeness of related party relationships and
transactions. See SA 55024 for further discussion. The occurrence of non-compliance with laws and regulations. See SA 25025 for further discussion. Future events or conditions that may cause an entity to cease to continue as a going concern. See SA 570(Revised)26 for further discussion. Relevant SAs identify specific audit procedures to assist in mitigating the effect of the inherent limitations.
A52. Because of the inherent limitations of an audit, there is an unavoidable risk that some material misstatements of the financial statements may not be detected, even though the audit is properly planned and performed in accordance with SAs. Accordingly, the subsequent discovery of a material misstatement of the financial statements resulting from fraud or error does not by itself indicate a failure to conduct an audit in accordance with SAs. However, the inherent limitations of an audit are not a justification for the auditor to be satisfied with less-than-persuasive audit evidence. Whether the auditor has performed an audit in accordance with SAs is determined by the audit procedures performed in the circumstances, the sufficiency and appropriateness of the audit evidence obtained as a result thereof and the suitability of the auditor’s report based on an evaluation of that evidence in light of the overall objectives of the auditor.
A53. The factors, as discussed in paragraphs A47 to A52, remain relevant even where independent auditors, in the course of their audits, are required by laws or regulations to specifically or separately report on frauds and/or other irregularities to third parties such as the Government or a regulator. For example, the independent auditors of a company in India are, pursuant to section 143(12) of the Companies Act, 2013 and the Rules thereunder, are in the course of performance of their duties as auditors, required to make a report to the Central Government in respect of frauds committed or being committed against the 24 SA 550, “Related Parties”. 25 SA 250, “Consideration of Laws and Regulations in an Audit of Financial Statements”. 26 SA 570(Revised), “Going Concern”. company. Accordingly, the Guidance Note on Reporting on Fraud under section 143(12) of the Companies Act, 2013, appropriately takes into account the existence and effect of aforesaid limitations on the auditor’s ability to obtain evidence.27
Conduct of an Audit in Accordance with SAs
Nature of the SAs (Ref: Para. 18)
A54. The SAs, taken together, provide the standards for the auditor’s work in fulfilling the overall objectives of the auditor. The SAs deal with the general responsibilities of the auditor, as well as the auditor’s further considerations relevant to the application of those responsibilities to specific topics.
A55. The scope, effective date and any specific limitation of the applicability of a specific SA is made clear in the SA. Unless otherwise stated in the SA, the auditor is permitted to apply an SA before the effective date specified therein.
A56. In performing an audit, the auditor may be required to comply with legal or regulatory requirements in addition to the SAs. The SAs do not override laws and regulations that govern an audit of financial statements. In the event that those laws and regulations differ from the SAs, an audit conducted only in accordance with laws and regulations will not automatically comply with SAs.
A57. The SAs are also relevant to engagements in case of certain entities, such as, Central/State governments and related government entities (for example, agencies, boards, commissions).The auditor’s responsibilities of those entities, however, may be affected by the audit mandate, or by obligations on those entities arising from legislation, regulation, ministerial directives, government policy requirements, or resolutions of the legislature, which may encompass a broader scope than an audit of financial statements in accordance with the SAs. These additional responsibilities are not dealt with in the SAs. They may be dealt with in the relevant laws and regulations in which the entities are operating.
Contents of the SAs (Ref: Para. 19)
A58. In addition to objectives and requirements (requirements are expressed in the SAs using “shall”), an SA contains related guidance in the form of application and other explanatory material. It may also contain introductory material that provides context relevant to a proper understanding of the SA, and definitions. The entire text of an SA, therefore, is relevant to an understanding of the objectives stated in an SA and the proper application of the requirements of an SA. 27 The underlined text has been added pursuant to the decision of the Council of ICAI taken at its 350th meeting held in February 2016.
A59. Where necessary, the application and other explanatory material provides further explanation of the requirements of an SA and guidance for carrying them out. In particular, it may: Explain more precisely what a requirement means or is intended to cover.
Include examples of procedures that may be appropriate in the
circumstances. While such guidance does not in itself impose a requirement, it is relevant to the proper application of the requirements of an SA. The application and other explanatory material may also provide background information on matters addressed in an SA.
A60. Appendices form part of the application and other explanatory material. The purpose and intended use of an appendix are explained in the body of the related SA or within the title and introduction of the appendix itself.
A61. Introductory material may include, as needed, such matters as explanation of: The purpose and scope of the SA, including how the SA relates to other SAs. The subject matter of the SA. The respective responsibilities of the auditor and others in relation to the subject matter of the SA. The context in which the SA is set.
A62. An SA may include, in a separate section under the heading “Definitions”, a description of the meanings attributed to certain terms for purposes of the SAs. These are provided to assist in the consistent application and interpretation of the SAs, and are not intended to override definitions that may be established for other purposes, whether in law, regulation or otherwise. Unless otherwise indicated, those terms will carry the same meanings throughout the SAs. The Glossary of Terms relating to Engagement and Quality Control Standards issued by the Auditing and Assurance Standards Board contains a complete listing of terms defined in the SAs. It also includes descriptions of other terms found in SAs to assist in common and consistent interpretation.
A63. When appropriate, additional considerations specific to audits of smaller entities and to certain entities, such as, Central/State governments and related government entities (for example, agencies, boards, commissions), are included within the application and other explanatory material of an SA. These additional considerations assist in the application of the requirements of the SA in the audit of such entities. They do not, however, limit or reduce the responsibility of the auditor to apply and comply with the requirements of the SAs.
Considerations Specific to Smaller Entities
A64. For purposes of specifying additional considerations to audits of smaller entities, a “smaller entity” refers to an entity which typically possesses qualitative characteristics such as: