Notes of Module 4
Auditing Standards
Auditing Standards are guidelines and principles that auditors must follow while conducting audits
to ensure consistency, reliability, and quality in their work. These standards provide a framework
for performing audits effectively and ensuring that financial statements are free from material
misstatements due to fraud or error.
Auditing Standards are a set of guidelines and principles that auditors must follow while
conducting audits of financial statements. These standards ensure uniformity, reliability, and
credibility in the audit process. They provide a framework for auditors to perform their duties
efficiently and ethically, thereby enhancing the quality of financial reporting.
Auditing Standards cover various aspects such as audit planning, execution, evidence collection,
documentation, and reporting. They are designed to ensure that audits are conducted in a fair,
transparent, and professional manner, reducing the risk of errors and fraud.
Procedure for issuing Auditing Standards in India.
In India, the procedure for issuing auditing standards is governed by the Institute of Chartered
Accountants of India (ICAI), which is responsible for formulating and issuing Standards on
Auditing (SAs). The process involves multiple stages, ensuring transparency, stakeholder
consultation, and regulatory approval. The key steps are:
1. Identification of Need for a New or Revised Standard
● ICAI identifies the need for a new auditing standard or revision of an existing one.
● This may arise due to changes in global auditing practices, regulatory requirements, or
stakeholder feedback.
2. Formation of the Auditing and Assurance Standards Board (AASB)
● The AASB of ICAI is responsible for drafting and reviewing auditing standards.
● It considers international standards (e.g., International Standards on Auditing - ISAs) and
Indian legal requirements.
3. Preparation of Exposure Draft
● A draft standard is prepared by the AASB based on research, global best practices, and
Indian legal framework.
● The Exposure Draft (ED) is then issued for public comments.
4. Public Consultation and Stakeholder Feedback
● The ED is circulated among stakeholders, including:
○ Government regulators (e.g., NFRA, RBI, SEBI, CAG)
○ Industry bodies
○ Auditors and professionals
○ Corporate entities and the general public
● A reasonable time is given for feedback.
5. Finalization by AASB
● The AASB reviews the comments and makes necessary changes.
● A final draft of the Standard on Auditing (SA) is prepared.
6. Approval by the ICAI Council
● The revised draft is submitted to the ICAI Council for approval.
● The Council discusses and approves the final SA.
7. Notification and Implementation
● Once approved, the standard is notified and published.
● ICAI may conduct awareness programs and training sessions for auditors.
8. Regulatory Approval (if applicable)
● In certain cases, regulatory bodies such as NFRA (National Financial Reporting Authority)
may be involved in reviewing and approving standards.
● Standards applicable to specific sectors (e.g., banking, insurance) may require consultation
with SEBI, RBI, or IRDAI.
9. Continuous Review and Updates
● Periodic reviews are conducted to keep auditing standards aligned with changes in financial
reporting laws, corporate governance norms, and international standards.
This process ensures that auditing standards in India are robust, transparent, and aligned with
global best practices.
Significance of Auditing Standards in India .
In India, Auditing Standards play a crucial role in maintaining the integrity of financial reporting
and boosting investor confidence. The Institute of Chartered Accountants of India (ICAI) issues
the Standards on Auditing (SAs), which are aligned with international standards to ensure global
compatibility. The key significance of these standards in India includes:
1. Ensuring Uniformity and Consistency
○ Auditing Standards provide a structured approach for auditors to follow, ensuring
consistency in audit procedures across different industries and organizations.
2. Enhancing Reliability and Credibility
○ They help in improving the reliability of financial statements, which is crucial for
stakeholders, including investors, creditors, and regulators.
3. Regulatory Compliance
○ Following Auditing Standards ensures compliance with various legal and
regulatory frameworks such as the Companies Act, 2013, and SEBI regulations.
4. Preventing Fraud and Misstatements
○ By setting guidelines for risk assessment, evidence gathering, and internal control
evaluation, these standards help in detecting and preventing financial fraud.
5. Improving Investor Confidence
○ Transparent and standardized audits enhance investor trust in the financial health
of companies, promoting a robust capital market.
6. Global Recognition
○ Indian auditing standards are harmonized with International Standards on Auditing
(ISA), facilitating cross-border investments and international business expansion.
7. Accountability and Governance
○ Auditing Standards strengthen corporate governance by ensuring that financial
statements present a true and fair view of an organization's financial position
Auditing Standards are essential for maintaining financial transparency and accountability in India.
They not only help auditors conduct effective audits but also safeguard stakeholders' interests by
ensuring the accuracy and fairness of financial statements. Compliance with these standards
contributes to a stable and trustworthy economic environment.
Role of an auditor in regarding Auditing Standards
An auditor has a critical role in ensuring that an audit is conducted in compliance with Auditing
Standards (SAs) issued by the Institute of Chartered Accountants of India (ICAI). These standards
provide a structured approach to performing audits and maintaining professional quality.
Key Responsibilities of an Auditor Regarding Auditing Standards
1. Compliance with Auditing Standards
● The auditor must conduct audits in accordance with Standards on Auditing (SAs) issued
by ICAI.
● This ensures that the audit is performed systematically, ethically, and in line with best
practices.
2. Exercising Professional Skepticism
● Auditors must approach the audit with a questioning mind and assess audit evidence
critically.
● This helps in detecting potential fraud, misstatements, or irregularities in financial
statements.
3. Understanding and Evaluating Risk
● As per SA 315 (Identifying and Assessing the Risks of Material Misstatement), the auditor
must assess risks associated with fraud, errors, and internal control weaknesses.
● This involves analyzing business risks, financial risks, and operational risks.
4. Obtaining Sufficient and Appropriate Audit Evidence
● As per SA 500 (Audit Evidence), the auditor must collect reliable and sufficient evidence
to support the audit opinion.
●
● Evidence should be gathered through inspection, observation, confirmation, analytical
procedures, and inquiry.
5. Maintaining Independence and Objectivity
● Auditors must follow ethical guidelines and maintain independence from the entity being
audited.
● They should avoid conflicts of interest and not allow personal relationships to affect their
judgment.
6. Proper Documentation of Audit Work
● As per SA 230 (Audit Documentation), the auditor should maintain a complete and
organized record of audit procedures performed, evidence obtained, and conclusions
reached.
● Proper documentation helps in review, accountability, and future reference.
7. Issuing a Fair and Transparent Audit Report
● The auditor is responsible for expressing a true and fair view on the financial statements as
per SA 700 (Forming an Opinion and Reporting on Financial Statements).
● If material misstatements exist, the auditor should modify the opinion accordingly as per
SA 705 and SA 706.
8. Reviewing Internal Controls and Corporate Governance
● The auditor must assess the effectiveness of internal controls as per SA 315 and SA 330.
● This ensures that the company’s financial records are accurate and secure from fraud or
manipulation.
9. Addressing Fraud and Irregularities
● As per SA 240 (The Auditor’s Responsibilities Relating to Fraud in an Audit of Financial
Statements), the auditor must:
○ Identify risks of fraud.
○ Report fraud if found.
○ Take appropriate actions to prevent or mitigate its impact.
10. Following Legal and Regulatory Requirements
● Auditors must comply with laws such as the Companies Act, 2013, SEBI Regulations, and
Income Tax Laws while conducting audits.
● Non-compliance can lead to legal penalties and loss of professional credibility.
The auditor’s responsibility regarding auditing standards is to ensure fairness, transparency,
accuracy, and compliance in the audit process. By following ICAI's Standards on Auditing (SAs),
auditors help maintain public trust in financial statements and contribute to a strong financial
reporting system.
The contents of Standards of Auditing
The Standards of Auditing provide guidelines for auditors to ensure the quality, reliability, and
integrity of the audit process. These standards vary by jurisdiction but are generally based on
principles issued by organizations such as the International Auditing and Assurance Standards
Board (IAASB), American Institute of Certified Public Accountants (AICPA), and Public
Company Accounting Oversight Board (PCAOB).
Contents of Standards of Auditing
1. General Principles & Responsibilities of the Auditor
○ Ethical requirements (integrity, objectivity, independence, confidentiality, etc.)
○ Auditor’s professional skepticism and judgment
○ Responsibility for detecting fraud and errors
○ Audit documentation requirements
2. Audit Planning & Risk Assessment
○ Understanding the entity and its environment
○ Identifying and assessing risks of material misstatement
○ Determining materiality levels
○ Developing an audit plan and strategy
3. Audit Evidence & Procedures
○ Sufficient and appropriate audit evidence
○ External and internal confirmations
○ Analytical procedures
○ Sampling techniques
4. Internal Controls & Risk Management
○ Evaluation of internal controls
○ Risk assessment procedures
○ Testing the effectiveness of controls
5. Audit Execution & Procedures
○ Substantive procedures (tests of details, analytical procedures)
○ Compliance with accounting standards (IFRS, GAAP)
○ Special considerations for related parties and estimates
6. Audit Reporting
○ Types of audit reports (unmodified, qualified, adverse, disclaimer)
○ Communication with management and those charged with governance
○ Reporting on key audit matters (KAMs)
○ Auditor’s responsibility in case of fraud or non-compliance
7. Specialized Audits & Considerations
○ Group audits and component auditors
○ Audits of small entities and non-profits
○ Forensic and investigative audits
○ IT audits and cybersecurity risks
8. Professional & Regulatory Compliance
○ Compliance with legal and regulatory frameworks
○ Auditor's responsibility regarding laws and regulations
○ Quality control and peer reviews
○ Ethical considerations and auditor independence
The International Standards on Auditing (ISA) issued by the IAASB are widely followed globally,
while countries may have their own adapted standards, such as GAAS (Generally Accepted
Auditing Standards) in the U.S. by AICPA or PCAOB standards for publicly traded companies.
The scope of standards of auditing in India.
Standards on Auditing (SAs) in India are issued by the Institute of Chartered Accountants of India
(ICAI) and are aligned with the International Standards on Auditing (ISAs) issued by the
International Auditing and Assurance Standards Board (IAASB). The SAs provide a framework
for auditors to conduct audits effectively and ensure compliance with ethical and professional
standards.
The scope of auditing standards in India covers:
1. The applicability of SAs to different types of audits.
2. The structure and classification of auditing standards.
3. The overall objectives and principles of an audit.
4. The role and responsibilities of auditors.
1. Applicability of Standards on Auditing in India
SAs apply to all audits of financial statements conducted in accordance with the Companies Act,
2013, or other relevant laws and regulations. The following entities are covered:
● Companies registered under the Companies Act, 2013 (Statutory Audits).
● Banks and Financial Institutions (RBI-regulated audits).
● Government Entities and Public Sector Undertakings (PSUs) (CAG Audits).
● Partnership Firms, LLPs, and Sole Proprietorships (Tax Audits under the Income Tax Act,
1961).
● NGOs, Trusts, and Charitable Organizations (Audits under the Societies Registration Act
and other regulations).
Additionally, SAs apply to internal audits, forensic audits, and other assurance engagements based
on their relevance.
2. Classification and Structure of Auditing Standards in India
The SAs in India are categorized into six main areas, covering different stages of the audit process:
A. General Principles & Responsibilities (SA 200 – SA 299)
These standards define the overall objectives, ethics, quality control, and documentation
requirements for auditors.
● SA 200: Overall Objectives of the Independent Auditor and Conduct of an Audit.
● SA 210: Agreeing on the Terms of Audit Engagements.
● SA 220: Quality Control for an Audit of Financial Statements.
● SA 230: Audit Documentation.
● SA 250: Consideration of Laws and Regulations in an Audit.
B. Risk Assessment & Response (SA 300 – SA 499)
These standards guide auditors in understanding the entity, assessing risks, and planning audit
procedures.
● SA 300: Planning an Audit of Financial Statements.
● SA 315: Identifying and Assessing Risks of Material Misstatement.
● SA 320: Materiality in Planning and Performing an Audit.
● SA 330: The Auditor’s Responses to Assessed Risks.
C. Audit Evidence (SA 500 – SA 599)
These standards establish rules for gathering sufficient and appropriate audit evidence.
● SA 500: Audit Evidence.
● SA 501: Audit Evidence – Specific Considerations for Inventory, Litigation & Segment
Reporting.
● SA 505: External Confirmations.
● SA 520: Analytical Procedures.
D. Using Work of Others (SA 600 – SA 699)
These standards cover auditor responsibilities when relying on other professionals’ work.
● SA 600: Using the Work of Another Auditor.
● SA 610: Using the Work of Internal Auditors.
● SA 620: Using the Work of an Expert.
E. Audit Conclusions & Reporting (SA 700 – SA 799)
These standards define audit report formats and requirements.
● SA 700: Forming an Opinion and Reporting on Financial Statements.
● SA 705: Modifications to the Opinion in the Independent Auditor’s Report.
● SA 706: Emphasis of Matter Paragraphs.
F. Specialized Areas (SA 800 – SA 899)
These standards apply to specific types of audits.
● SA 800: Special Purpose Financial Statements.
● SA 805: Audits of Single Financial Statements.
3. Key Principles and Scope of SAs
The scope of auditing standards includes the fundamental principles that guide auditors in
conducting audits:
A. Auditor’s Responsibilities and Ethics
● Compliance with ethical requirements (integrity, objectivity, professional competence).
● Professional skepticism and judgment in assessing risks and evidence.
B. Risk-Based Approach to Auditing
● Understanding business risks and internal control systems.
● Identifying risks of material misstatement in financial statements.
C. Gathering Sufficient and Appropriate Audit Evidence
● Use of substantive procedures and tests of controls.
● Verification of financial data through external confirmations, observations, and analytical
procedures.
D. Audit Documentation and Working Papers
● Maintaining proper audit documentation as per SA 230.
● Ensuring audit working papers support the audit conclusions.
E. Auditor’s Reporting and Communication
● Issuing a clear and fair audit opinion (unmodified, modified, qualified, adverse, or
disclaimer).
● Communicating with management and those charged with governance about audit
findings.
4. Compliance and Legal Framework for SAs in India
The Companies Act, 2013, and ICAI regulations make adherence to SAs mandatory for:
● Statutory audits of companies (Section 143 of the Companies Act, 2013).
● Bank audits and financial institution audits (as per RBI guidelines).
● Tax audits under the Income Tax Act, 1961 (as per ICAI guidelines).
Failure to comply with SAs can lead to professional misconduct proceedings under the Chartered
Accountants Act, 1949.
5. Conclusion
The Standards on Auditing (SAs) in India provide a structured framework for auditors to ensure
transparency, accuracy, and reliability in financial reporting. These standards establish:
1. General principles of auditing (objectivity, skepticism, ethics).
2. Procedures for risk assessment, evidence collection, and audit planning.
3. Guidelines for audit conclusions, reporting, and use of external experts.
By following these mandatory auditing standards, auditors can ensure compliance with legal and
professional requirements, leading to improved stakeholder confidence and financial integrity in
India’s corporate sector.
Standards on Auditing
The provisions of SA 315.
SA 315: Identifying and Assessing the Risks of Material Misstatement
SA 315 (Standard on Auditing 315), issued by the Institute of Chartered Accountants of India
(ICAI), aligns with the International Standard on Auditing (ISA 315). It provides auditors with
guidelines on how to understand an entity and its environment, including its internal controls, to
identify and assess risks of material misstatement in financial statements.
1. Objective of SA 315
The primary objective of SA 315 is to ensure that auditors:
● Identify and assess risks of material misstatement (whether due to fraud or error).
● Gain an understanding of the entity, its environment, and internal controls to design
appropriate audit procedures.
● Provide a foundation for an effective and efficient audit by focusing on high-risk areas.
2. Risk Assessment Procedures
Auditors must perform risk assessment procedures to gather knowledge about the entity. The three
key procedures are:
1. Inquiries of Management and Others:
○ Discussions with management, internal auditors, and employees to understand
business risks and internal control weaknesses.
○ Inquiry about fraud risks and previous misstatements.
2. Analytical Procedures:
○ Comparing financial and non-financial data to identify unusual trends or anomalies.
○ Examining ratios, fluctuations, and relationships that might indicate risks.
3. Observation and Inspection:
○ Inspecting documents such as policies, internal control manuals, and board meeting
minutes.
○ Observing processes like physical inventory counts or cash handling procedures.
3. Understanding the Entity and Its Environment
Auditors must develop a deep understanding of the entity’s business, industry, and regulatory
environment. Key areas include:
a) Industry, Regulatory, and External Factors:
● Economic conditions affecting the business.
● Industry trends, competition, and regulatory requirements.
● Legal and environmental factors.
b) Nature of the Entity:
● Business operations and ownership structure.
● Investment and financing activities.
● Key suppliers, customers, and business partners.
c) Selection and Application of Accounting Policies:
● Accounting policies relevant to the financial statements.
● Changes in accounting methods and their implications.
● Compliance with applicable financial reporting frameworks (e.g., Indian Accounting
Standards).
d) Objectives, Strategies, and Business Risks:
● Business risks that could lead to material misstatements.
● Factors affecting operational and financial performance.
e) Measurement and Review of Financial Performance:
● Key performance indicators (KPIs) used by management.
● Internal performance evaluations and financial reporting practices.
4. Understanding the Entity’s Internal Control System
SA 315 requires auditors to assess internal controls, which are classified into five components:
a) Control Environment:
● Management’s philosophy and operating style.
● Organizational structure and assignment of authority.
● Ethical values and commitment to integrity.
b) Risk Assessment Process of the Entity:
● How the entity identifies and manages risks.
● Whether risks are properly mitigated through internal processes.
c) Information System and Communication:
● IT systems used for financial reporting.
● Methods of processing and recording transactions.
● How management communicates financial and control information.
d) Control Activities:
● Segregation of duties, authorization procedures, and reconciliations.
● Physical controls over assets.
● Policies for preventing fraud and errors.
e) Monitoring of Controls:
● Internal audit functions and independent reviews.
● Management’s role in assessing the effectiveness of controls.
● Corrective actions taken for identified weaknesses.
5. Identifying and Assessing Risks of Material Misstatement
Auditors must assess risks at two levels:
1. Financial Statement Level Risks:
○ Risks that impact the overall financial statements.
○ Examples: Fraud risks, weak corporate governance, complex transactions.
2. Assertion Level Risks:
○ Risks related to specific account balances, transactions, and disclosures.
○ Assertions include completeness, accuracy, occurrence, valuation, and rights &
obligations.
Auditors must categorize risks as:
● Significant Risks (require special audit attention).
● Risks Requiring Special Consideration (complex or unusual transactions).
6. Documentation Requirements Under SA 315
Auditors must document:
● Key aspects of understanding the entity and its environment.
● Identified risks and reasons for classifying them as significant risks.
● Internal control weaknesses and their impact on audit procedures.
● Risk assessment procedures performed and results obtained.
7. Link Between SA 315 and Other Auditing Standards
SA 315 is closely linked with:
● SA 330 (Auditor’s Response to Assessed Risks): Guides on designing audit procedures
based on risk assessment.
● SA 500 (Audit Evidence): Ensures sufficient and appropriate evidence is obtained.
● SA 240 (Fraud Considerations in an Audit): Addresses fraud risk assessment.
Conclusion
SA 315 establishes a systematic framework for auditors to identify and assess risks of material
misstatement. By understanding the entity’s environment, internal controls, and risk factors,
auditors can design effective audit procedures to ensure accurate financial reporting.
The provisions of SA 505.
Standard on Auditing (SA) 505 – External Confirmations is issued by the Institute of Chartered
Accountants of India (ICAI) and provides guidelines on how auditors should use external
confirmations as part of their audit evidence. This standard aligns with International Standard on
Auditing (ISA) 505 and is crucial in verifying the accuracy and existence of financial information
provided by an entity.
External confirmation is a form of audit evidence obtained as a direct written response to the
auditor from a third party. It helps auditors verify balances, transactions, and other financial details.
Objective of SA 505
The main objective of SA 505 is to ensure that auditors:
1. Obtain reliable and relevant audit evidence through direct confirmation from third parties.
2. Assess risks of material misstatement related to the financial statements.
3. Design and perform external confirmation procedures effectively.
4. Evaluate responses (or non-responses) from third parties and take appropriate actions.
Scope of SA 505
SA 505 applies to all external confirmation procedures used in an audit, including:
● Trade Receivables and Payables Confirmations
● Bank Balance Confirmations
● Loan and Borrowing Confirmations
● Legal Claims and Contingencies Confirmations
● Inventory Held by Third Parties
This standard does not apply when auditors rely only on internally generated evidence without
seeking third-party confirmations.
Key Provisions of SA 505
1. Determining the Need for External Confirmations
The auditor must decide whether external confirmations are necessary by considering:
● Materiality of the account balance or transaction.
● Risk of Material Misstatement (RMM) associated with the item.
● Reliability of other forms of audit evidence.
● Effectiveness of internal controls over financial reporting.
For example, if an entity has high credit sales, confirming trade receivables with customers is
essential to verify their existence.
2. Designing the External Confirmation Procedures
The auditor must:
1. Select the items to be confirmed (e.g., key customers, high-value transactions).
2. Choose an appropriate confirmation request type (Positive or Negative).
3. Ensure direct communication with the confirming party (without management
intervention).
4. Maintain professional skepticism in evaluating responses.
Types of External Confirmations
Type of Description When to Use
Confirmation
Positive Requires the respondent to reply whether High-risk items, large
Confirmation they agree or disagree with the given balances, suspected
Request information. misstatements.
Negative Respondent replies only if they disagree Large number of small
Confirmation with the information provided. balances, low-risk items.
Request
Blank Confirmation The respondent is asked to fill in the When auditors suspect
Request details themselves, instead of confirming management influence over
a pre-specified amount. balances.
3. Controlling the External Confirmation Process
The auditor should:
● Prepare and send confirmation requests independently (without entity involvement).
● Ensure responses are sent directly to the auditor to prevent manipulation.
● Use secure communication methods (e.g., official email, postal mail, or verification
portals).
● Follow up on non-responses and assess alternative audit procedures if necessary.
4. Evaluating the Responses to External Confirmations
After receiving responses, the auditor must:
● Verify if the details match with entity records.
● Assess discrepancies and resolve them with further audit procedures.
● Evaluate non-responses and determine whether to send additional requests.
● If responses indicate fraud or irregularities, extend audit procedures accordingly.
Handling Non-Responses
If a confirming party does not respond, the auditor may:
1. Send a second confirmation request.
2. Perform alternative procedures, such as:
○ Checking subsequent payments or bank statements.
○ Inspecting invoices, contracts, or correspondence.
For example, if a debtor does not respond to a receivables confirmation, the auditor can check
bank receipts or subsequent payments to verify the balance
5. Addressing Exceptions in External Confirmations
An exception occurs when the confirming party’s response does not match the entity’s records.
Common reasons for exceptions:
● Errors in entity’s accounting records.
● Timing differences (e.g., payments made but not recorded).
● Fraudulent transactions.
Auditor’s responsibility:
● Investigate exceptions thoroughly.
● Consider their impact on financial statements.
● If fraud is suspected, extend audit procedures and inform management or those charged
with governance.
6. Reliability of External Confirmations
External confirmations are considered strong audit evidence, but their reliability depends on:
● The nature of the confirming party (banks, suppliers, customers).
● Objectivity and independence of the confirming party.
● Response format and authenticity (official letterhead, signed confirmations).
● Mode of communication (email, post, digital portals).
If an external confirmation appears suspicious or altered, the auditor must:
● Verify the confirming party’s identity.
● Directly contact the confirming party via phone or in-person.
● Consider fraud risks and adjust audit procedures.
7. Documentation Requirements under SA 505
The auditor must document:
● Rationale for using external confirmations (or reasons for not using them).
● Details of confirmation requests sent, including addresses and types of requests.
● Responses received, follow-ups made, and alternative procedures performed.
● Evaluations of discrepancies and audit conclusions.
Proper documentation ensures compliance with SA 230 (Audit Documentation) and provides a
basis for audit conclusions.
SA 505 plays a critical role in ensuring the accuracy and reliability of financial statements by
obtaining third-party confirmation of important balances and transactions. By following SA 505,
auditors can:
Enhance audit evidence reliability.
Detects errors, fraud, or misstatements.
Strengthen audit quality and credibility.
Proper use of external confirmations significantly improves audit assurance and ensures
compliance with professional and regulatory standards.
The provisions of SA 200.
SA 200 – Overall Objectives of the Independent Auditor and the Conduct of an Audit in
Accordance with Standards on Auditing
SA 200 is a fundamental auditing standard issued by the Institute of Chartered Accountants of
India (ICAI) that establishes the auditor's overall responsibilities when conducting an audit of
financial statements. It sets out the principles that guide the conduct of an audit in accordance with
other Standards on Auditing (SAs).The following are some of the important provisions of SA 200
-
1. Overall Objectives of the Auditor
The auditor's primary objectives while conducting an audit are:
● To obtain reasonable assurance that the financial statements are free from material
misstatement, whether due to fraud or error.
● To express an opinion on whether the financial statements are prepared in accordance with
the applicable financial reporting framework.
● To report as required by the relevant laws and regulations.
2. Ethical Requirements
The auditor must comply with the Code of Ethics issued by ICAI, which includes:
● Integrity
● Objectivity
● Professional Competence and Due Care
● Confidentiality
● Professional Behavior
3. Professional Skepticism and Judgment
● Professional Skepticism: The auditor must remain alert to evidence that contradicts
management’s statements or indicates fraud.
● Professional Judgment: The auditor must apply judgment while making decisions
regarding materiality, audit risks, and forming an opinion.
4. Conduct of an Audit in Accordance with SA
● The auditor must follow all Standards on Auditing (SAs) relevant to the engagement.
● If an SA is not followed, the auditor must justify the reason and its impact.
5. Risk Assessment and Audit Planning
● The auditor must identify and assess the risks of material misstatement and design audit
procedures accordingly.
● Audit planning must be done in accordance with SA 300 (Planning an Audit of Financial
Statements).
6. Sufficient and Appropriate Audit Evidence
● The auditor must obtain sufficient and appropriate evidence to form a reasonable basis for
the audit opinion.
● The evidence must be reliable and relevant to support the conclusions.
7. Limitations of an Audit
Even with proper audit procedures, limitations exist due to:
● Use of sampling techniques
● Dependence on third-party evidence
● Management fraud or concealment of facts
● Time and cost constraints
SA 200 serves as the foundation for all other auditing standards by defining the auditor’s role,
ethical responsibilities, and key principles for conducting an audit. It emphasizes the importance
of professional skepticism, judgment, and risk assessment to enhance the quality and credibility of
an audit.
The provisions of SA 220.
Provisions of SA 220: Quality Control for an Audit of Financial Statements
SA 220 (Standard on Auditing 220) deals with the auditor's responsibility to implement quality
control procedures at the engagement level while conducting an audit of financial statements. The
standard is issued by the Institute of Chartered Accountants of India (ICAI) and aligns with
international auditing standards.
Objective of SA 220
The primary objective of SA 220 is to ensure that:
● The audit is conducted in accordance with professional standards and regulatory
requirements.
● The audit report issued is appropriate given the circumstances.
● The engagement team maintains high-quality professional judgment throughout the audit.
Key Provisions of SA 220
1. Leadership Responsibilities for Quality
● The engagement partner must take overall responsibility for the audit’s quality.
● He/she should set the right tone to ensure the audit is conducted with integrity, objectivity,
and professional skepticism.
2. Ethical Requirements Compliance
● The engagement team should comply with the Code of Ethics, including principles of:
○ Integrity
○ Objectivity
○ Professional competence
○ Confidentiality
○ Professional behavior
3. Acceptance and Continuance of Client Relationships
● Before accepting or continuing an engagement, the auditor should evaluate:
○ The integrity of the client.
○ Whether the engagement team has the necessary competence and resources.
○ Whether there are any significant risks that may affect the audit’s quality.
4. Assignment of Engagement Teams
● The engagement partner should ensure that team members:
○ Have the necessary skills, competence, and experience.
○ Are allocated responsibilities based on their expertise.
5. Performance of the Audit Engagement
● The audit must be properly planned, supervised, and reviewed.
● The engagement partner must:
○ Direct, supervise, and perform a timely review of work performed.
○ Ensure significant matters are addressed before issuing the audit opinion.
○ Apply professional skepticism while evaluating audit evidence.
6. Consultation and Resolution of Differences
● If the audit team faces complex or contentious issues, they should consult with experts.
● Differences of opinion should be resolved through appropriate discussions and
documented.
7. Monitoring and Engagement Quality Control Review (EQCR)
● For high-risk audits (e.g., audits of listed entities), an Engagement Quality Control
Reviewer (EQCR) should conduct an independent review before the audit report is issued.
● The EQCR evaluates:
○ Critical areas of judgment.
○ Significant risks identified.
○ Whether audit documentation supports the conclusions reached.
8. Documentation of Quality Control
● The engagement partner must ensure that all important audit procedures, judgments, and
conclusions are properly documented.
● Key matters, consultations, and quality control reviews should be included in the audit file.
The provisions of SA 240
Standard on Auditing (SA) 240, issued by the Institute of Chartered Accountants of India (ICAI),
provides guidance on the auditor’s responsibilities in detecting and responding to fraud during an
audit of financial statements.
Fraud can lead to material misstatements, which affect the reliability of financial information. SA
240 ensures that auditors exercise professional skepticism and take appropriate steps to identify
and respond to fraudulent activities.
Objective of SA 240
The primary objectives of SA 240 are:
1. To identify and assess the risks of material misstatement due to fraud.
2. To obtain sufficient audit evidence regarding suspected fraud.
3. To appropriately respond to identified fraud risks.
4. To maintain professional skepticism throughout the audit.
5. To communicate fraud-related matters to management, those charged with governance
(TCWG), and regulatory authorities when necessary.
1. Auditor’s Responsibility Regarding Fraud
● The auditor is responsible for obtaining reasonable assurance that the financial statements
are free from material misstatements, whether caused by fraud or error.
● The primary responsibility for preventing fraud lies with management and those charged
with governance (TCWG).
● The auditor is not responsible for detecting all fraud but must identify fraud risks and take
necessary audit procedures.
2. Characteristics of Fraud
Fraud involves intentional misstatements and is classified into two types:
1. Fraudulent Financial Reporting (Manipulation of financial statements)
○ Overstatement of revenue or assets.
○ Understatement of expenses or liabilities.
○ Misapplication of accounting principles.
2. Misappropriation of Assets (Theft or misuse of company assets)
○ Embezzlement of cash.
○ Fictitious vendors or fraudulent payments.
○ Unauthorized transactions.
3. Risk Assessment and Identification of Fraud Risks
● The auditor should identify fraud risk factors by:
○ Holding discussions with management and TCWG.
○ Conducting analytical procedures to detect unusual transactions.
○ Evaluating internal controls that prevent fraud.
○ Identifying areas where management can override controls.
● The auditor should assume that revenue recognition is a fraud risk unless there is strong
evidence to the contrary.
4. Procedures to Address Fraud Risks
After assessing fraud risks, the auditor should perform additional audit procedures:
● Inquiries with Management and Employees
○ Ask management about their fraud risk assessment and actions taken to prevent
fraud.
○ Obtain written representations from management stating that financial statements
are free from fraud.
● Testing Journal Entries and Adjustments
○ Review unusual or suspicious journal entries made at the end of reporting periods.
○ Check manual adjustments made by management.
● Reviewing Accounting Estimates for Bias
○ Evaluate whether management is using subjective estimates to manipulate profits.
● Unpredictable Audit Procedures
○ Perform unannounced inventory checks.
○ Inspect transactions of related parties for irregularities.
5. Auditor’s Response to Detected Fraud
If fraud is detected, the auditor must:
● Discuss the issue with management and TCWG to determine its impact.
● Evaluate the implications on the financial statements and audit opinion.
● Modify the audit report if the fraud leads to material misstatements.
● Communicate with legal authorities if required (if fraud is severe and involves regulatory
violations).
6. Communication of Fraud
The auditor must communicate:
● To Management and TCWG
○ All suspected or confirmed fraud cases.
○ Weaknesses in internal controls that led to fraud.
● To Regulatory Authorities (if applicable)
○ If fraud involves laws or regulations, it may need to be reported to external
authorities such as SEBI, RBI, or SFIO.
7. Documentation Requirements under SA 240
The auditor must maintain proper documentation, including:
● Risk assessment procedures related to fraud.
● Discussions with management and TCWG regarding fraud risks.
● Details of fraud risks identified and audit procedures performed.
● Any communications regarding fraud to regulatory bodies.
SA 240 ensures that auditors proactively assess fraud risks, exercise professional skepticism, and
take appropriate audit procedures to detect and respond to fraud. While the auditor is not a fraud
investigator, they play a vital role in identifying, assessing, and addressing fraudulent activities
that impact financial reporting.
Analytical Procedures
Analytical procedures performed as risk assessment procedures may identify aspects of the entity
of which the auditor was unaware and may assist in assessing the risks of material misstatement
in order to provide a basis for designing and implementing responses to the assessed risks .
Analytical procedures performed as risk assessment procedures may include both financial and
non-financial information, for example, the relationship between sales and square footage of
selling space or volume of goods sold. Analytical procedures may help identify the existence of
unusual transactions or events, and amounts, ratios, and trends that might indicate matters that
have audit implications. Unusual or unexpected relationships that are identified may assist the
auditor in identifying risks of material misstatement, especially risks of material misstatement due
to fraud. A9. However, when such analytical procedures use data aggregated at a high level (which
may be the situation with analytical procedures performed as risk assessment procedures), the
results of those analytical procedures only provide a broad initial indication about whether a
material misstatement may exist. Accordingly, in such cases, consideration of other information
that has been gathered when identifying the risks of material misstatement together with the results
of such analytical procedures may assist the auditor in understanding and evaluating the results of
the analytical procedures. Some smaller entities may not have interim or monthly financial
information that can be used for purposes of analytical procedures. In these circumstances,
although the auditor may be able to perform limited analytical procedures for purposes of planning
the audit or obtain some information through inquiry, the auditor may need to plan to perform
analytical procedures to identify and assess the risks of material misstatement when an early draft
of the entity’s financial statements is available.
Professional Skepticism -SA 240, "The Auditor’s Responsibilities Relating to Fraud in an Audit
of Financial Statements," emphasizes the importance of professional skepticism in detecting fraud.
Professional skepticism is an attitude that includes a questioning mind, being alert to conditions
that may indicate possible misstatement due to fraud, and critically assessing audit evidence.
Key Aspects of Professional Skepticism under SA 240:
1. Mindset of the Auditor
○ Auditors must approach the audit with a questioning mind and alertness to the
possibility of fraud, regardless of past experiences with the entity or its
management.
2. Risk Assessment and Fraud Indicators
○ The auditor must consider fraud risks at all stages of the audit and be attentive to
red flags, such as inconsistencies in financial records or unusual transactions.
3. Critical Evaluation of Audit Evidence
○ Instead of accepting evidence at face value, the auditor should challenge
assumptions, verify explanations, and seek corroborative evidence.
4. Presumption of Fraud in Revenue Recognition
○ SA 240 requires auditors to presume that there is a risk of fraud in revenue
recognition unless they conclude that the risk is not applicable.
5. Bias and Over-Reliance on Management
○ Auditors must avoid over-reliance on management representations and should seek
independent verification of critical information.
6. Professional Judgment and Documentation
○ Auditors must document their assessment of fraud risks, responses to those risks,
and the rationale behind their conclusions.
By applying professional skepticism, auditors enhance the reliability of their audit opinion and
contribute to fraud detection and prevention.
Maintaining professional skepticism requires an ongoing questioning of whether the
information and audit evidence obtained suggests that a material misstatement due to fraud
may exist. It includes considering the reliability of the information to be used as audit
evidence and the controls over its preparation and maintenance where relevant. Due to the
characteristics of fraud, the auditor’s professional skepticism is particularly important
when considering the risks of material misstatement due to fraud. A8. Although the auditor
cannot be expected to disregard past experience of the honesty and integrity of the entity’s
management and those charged with governance, the auditor’s professional skepticism is
particularly important in considering the risks of material misstatement due to fraud
because there may have been changes in circumstances. A9. As explained in SA 200, an
audit performed in accordance with SAs rarely involves the authentication of documents,
nor is the auditor trained as or expected to be an expert in such authentication.18 However,
when the auditor identifies conditions that cause the auditor to believe that a document may
not be authentic or that terms in a document have been modified but not disclosed to the
auditor, possible procedures to investigate further may include: Confirming directly with
the third party. Using the work of an expert to assess the document’s authenticity
Management Representations
The auditor shall obtain written representations from management and, where applicable, those
charged with governance that:
(a) They acknowledge their responsibility for the design, implementation and maintenance of
internal control to prevent and detect fraud;
(b) They have disclosed to the auditor the results of management’s assessment of the risk that the
financial statements may be materially misstated as a result of fraud;
(c) They have disclosed to the auditor their knowledge of fraud or suspected fraud affecting the
entity involving:
(i) Management;
(ii) Employees who have significant roles in internal control; or
(iii) Others where the fraud could have a material effect on the financial statements; and
(d) They have disclosed to the auditor their knowledge of any allegations of fraud, or suspected
fraud, affecting the entity’s financial statements communicated by employees, former employees,
analysts, regulators or others
While management representations are a necessary source of audit evidence, SA 240 emphasizes
that they alone are not sufficient to support audit conclusions, especially regarding fraud.
Key Points on Management Representation under SA 240:
1. Skepticism Toward Management Representations
○ The auditor should not place unquestioning reliance on representations made by
management.
○ If inconsistencies arise, the auditor must seek corroborative evidence from
independent sources.
2. Written Representations on Fraud
○ As per SA 580 (Written Representations) and SA 240, auditors must obtain written
representations from management, confirming:
■ Their responsibility for designing and implementing fraud prevention
measures.
■ Their awareness (or lack thereof) of fraud or suspected fraud affecting the
financial statements.
3. Limitations of Management Representations
○ Management representation is supportive evidence, not a substitute for other audit
procedures.
○ If other audit evidence contradicts management representations, the auditor must
investigate further and may need to reconsider the reliability of management.
4. Implications for the Auditor’s Opinion
○ If management refuses to provide written representations, it may indicate a scope
limitation, which could lead to:
■ A qualified opinion or
■ A disclaimer of opinion, depending on the severity of the issue.
Conclusion
SA 240 stresses that while management representation is a necessary audit procedure, it must be
tested and corroborated with other substantive and analytical procedures to ensure the reliability
of financial statements.
Documentation under SA 315
1. Understanding the Entity and Its Environment
Document details about the entity’s industry, regulatory environment, business operations, and
financial performance.
Record insights on internal controls, accounting policies, and business risks affecting
financial statements.
2. Identifying Risks of Material Misstatement (RMM)
Document risks related to fraud, errors, and other factors affecting financial reporting.
Assess risks at both financial statement level and assertion level.
3. Internal Control System Assessment
Record the design and implementation of internal controls to address risks.
Identify control deficiencies and their impact on financial reporting.
4. Risk Assessment Procedures Performed
Document procedures such as inquiries, analytical procedures, and observation.
Maintain records of discussions with management and governance bodies.
5. Significant Risks and Auditor’s Response
Identify significant risks that require special attention.
Document how the auditor plans to address these risks in the audit process.
6. Professional Judgment and Audit Evidence
Maintain evidence supporting risk assessments and conclusions.
Justify any modifications in risk assessment based on new information.
7. Linkage Between Risks and Audit Procedures
Document the relationship between identified risks and audit procedures planned.
Ensure audit strategies align with assessed risks.
8. Changes in Risk Assessment During Audit
If new risks arise during the audit, document the changes and revised audit procedures.
Provide reasons for modifications in initial risk assessments.
9. Use of Technology in Risk Assessment
Record any data analytics or software tools used in risk evaluation.
Ensure compliance with SA 315’s guidance on IT controls and risk identification.
10. Compliance with Auditing Standards
Ensure all documentation meets ICAI’s standards on auditing (SAs).
Maintain sufficient evidence to support audit findings and conclusions.
SA 505 – External Confirmations
Standard on Auditing (SA) 505 – External Confirmations provides guidance on the
auditor’s use of external confirmation procedures to obtain audit evidence. External
confirmations help auditors verify the accuracy of financial statement balances and
transactions by obtaining direct responses from third parties (e.g., banks, creditors, or
customers).
Key Aspects of SA 505:
1. Objective of External Confirmation
The objective of external confirmation is to obtain reliable and relevant audit evidence
directly from independent third parties to support financial assertions.
2. When to Use External Confirmations
External confirmations are commonly used for:
Bank balances and transactions (bank confirmations)
Accounts receivable balances (debtor confirmations)
Accounts payable balances (creditor confirmations)
Loan balances and terms
Inventory held by third parties
Contingent liabilities (e.g., guarantees, legal claims, etc.)
3. Designing the Confirmation Request
Auditors should:
Determine the information to be confirmed (amount, terms, balances).
Select the appropriate confirming party (bank, customer, vendor, etc.).
Send direct requests and control the entire process to ensure authenticity.
4. Types of External Confirmations
Positive Confirmation Request – Requires a response from the third party, whether they
agree or disagree with the details.
Negative Confirmation Request – Requires a response only if the third party disagrees
with the information.
Blank Confirmation Request – Requests third parties to fill in their own details, reducing
the risk of bias.
5. Auditor’s Responsibility in Handling Confirmations
Maintain control over the confirmation process (selection, dispatch, and receipt).
Assess the reliability of responses (e.g., verify if the respondent is authorized).
Follow up on non-responses or discrepancies by performing alternative procedures.
6. Alternative Audit Procedures for Non-Responses
If external confirmation is not received, the auditor may:
Examine subsequent cash receipts from customers.
Review original invoices, contracts, or shipping documents.
Verify payment records and reconciliations.
7. Evaluating the Evidence Obtained
The auditor should:
Assess the reliability of the confirmation responses.
Investigate inconsistencies or discrepancies.
Consider the impact on the audit conclusion if responses are missing or unreliable.
8. Documentation and Reporting
The auditor must document:
The nature and extent of external confirmation procedures.
The results of confirmations and any alternative audit procedures performed.
Any issues identified and their impact on the audit opinion.
SA 505 ensures that external confirmations provide reliable and independent audit
evidence, strengthening the credibility of financial statements. Auditors must properly
design, execute, and evaluate confirmation procedures to enhance audit quality and reduce
risks.