0% found this document useful (0 votes)
10 views16 pages

Understanding Audit Evidence Essentials

Chapter 07 discusses audit evidence as per ISA 500, emphasizing the need for sufficient and appropriate evidence to form reasonable conclusions. It covers the types of evidence, financial statement assertions, and procedures for obtaining audit evidence, including tests of controls and substantive procedures. Additionally, it addresses reliance on the work of experts, internal auditors, and service organizations, outlining the necessary evaluations and documentation required for effective auditing.

Uploaded by

Saif Ahamed
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views16 pages

Understanding Audit Evidence Essentials

Chapter 07 discusses audit evidence as per ISA 500, emphasizing the need for sufficient and appropriate evidence to form reasonable conclusions. It covers the types of evidence, financial statement assertions, and procedures for obtaining audit evidence, including tests of controls and substantive procedures. Additionally, it addresses reliance on the work of experts, internal auditors, and service organizations, outlining the necessary evaluations and documentation required for effective auditing.

Uploaded by

Saif Ahamed
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter-07 Evidence

1. Audit evidence- ISA 500 audit evidence states- ‘to design and perform audit
procedures in a such a way to enable the auditor to obtain sufficient
appropriate audit evidence to be able to draw reasonable conclusions on which
base the auditor’s opinion.’
1.1 Sufficient evidence- It relates to the quantity of evidence. The auditor needs
to gather enough evidence to form a conclusion. It is a matter of professional
judgement. When determining whether there is enough evidence the auditor
must consider:
➢ The risk of material misstatement
➢ The materiality of item
➢ The nature of accounting and internal control systems
➢ The result of controls tests
➢ The auditor’s knowledge and experience of the business
➢ The size of a population being tested
➢ The size of the sample selected to test
➢ The reliability of the evidence obtained
1.2 Appropriate evidence- It breaks down into two important concepts:
➢ Reliability
➢ Relevance
a. Reliability-
➢ The auditor should always attempt to obtain evidence from the most
trustworthy and dependable source possible.
➢ Evidence obtained from an independent external source is more reliable
than client generated evidence.
➢ Evidence obtained directly by the auditor is more reliable than evidence
obtained indirectly.
➢ Client generated evidence is the least reliable sources of evidence.
➢ If the client is manipulating the financial statement figures they may
produce fictitious evidence to support the figures.
➢ Written evidence is more reliable than oral evidence as oral
representations can be withdrawn or challenged.
➢ Original documents are more reliable than copies or documents
transformed into electronic form as it may be difficult to see and have
been tampered it.

1
b. Relevance- It means the evidence relates to the financial statement assertions
being tested. When attending an inventory count, the auditor will:
➢ Select a sample of items from physical inventory and trace them to
inventory records to confirm the completeness of accounting records.
➢ Select a sample of items from inventory records and trace them to
physical inventories to confirm the existence of inventory assets.
Whilst the procedures are similar in nature, their purpose is to test difference
assertions regarding inventory balances.
2. Financial statements assertions-
Assertions are used by the auditor to consider the different types of potential
misstatements that may occur when identifying, assessing and responding to the
risks of material misstatement.
2.1 Transactions and Events-
➢ Occurrence- the transactions and events recorded and disclosed have
occurred and pertain to the entity.
➢ Completeness- all transactions and events that should have been recorded
and all related disclosures that should have been included.
➢ Accuracy- amounts and other data have been recorded appropriately and
related disclosures have been appropriately measured and described.
➢ Cutoff- transactions and events have been recorded in the correct
accounting period.
➢ Classification- transactions and events have been recorded in the proper
accounting.
➢ Presentation- transactions and events are appropriately aggregated or
disaggregated and clearly described. Related disclosures are relevant and
understandable in the applicable financial reporting framework.
2.2 Account Balances-
➢ Existence- assets, liabilities and equity interest exits.
➢ Rights and obligations- the entity holds or controls the rights to assets and
liabilities are the obligations of the entity.
➢ Accuracy, valuation and allocation- assets, liabilities and equity interests
have been included in the financial statements at appropriate amounts.
Any resulting valuation or allocation adjustments have been appropriately
recorded. Related disclosures have been appropriately measured and
described.

2
➢ Classification- assets, liabilities and equity interests have been recorded
in the proper accounts.
➢ Presentation- account balances are appropriately aggregated and
disaggregated and clearly described. Related disclosures are relevant and
understandable in the applicable financial reporting framework.
3. Sources of audit evidence-
3.1 Tests of controls- Audit procedures designed to evaluate the operating
effectiveness of controls in preventing or detecting and correcting material
misstatement. In order to be able to rely on controls the auditor will need to:
➢ Ascertain the system operates
➢ Document the system in audit working papers
➢ Assess the design and operating effectiveness of the control system
➢ Test the operation of the system
➢ Determine the impact on the audit approach for specific classes of
transactions, account balances and disclosures.
3.2 Substantive Procedures- Audit procedures designed to detect material
misstatements at the assertion level. It is classified into two types are:
➢ Tests of detail
➢ Analytical procedures
a. Tests of details-
➢ To verify individual transactions and balances.
➢ It looks at the supporting evidence for an individual transaction such as
inspection of a purchase invoice to verify the amount/date/classification
of a specific purchase.
b. Analytical Procedures-
➢ It involves analysing relationships between information to identify
unusual fluctuations which may indicate possible misstatement.
➢ It would be used to assess the reasonableness of the purchase figure in
total.
4. Types of audit procedures- The auditor can adopt the following procedures
to obtain audit evidence:
➢ Inspection of records or documents
➢ Observation
➢ External confirmation
➢ Recalculation
3
➢ Reperformance
➢ Analytical procedures
➢ Enquiry
a. Inspection of records or documents- Examining records or documents in
paper or electronic forms in the following ways are:
➢ May give evidence of right and obligations.
➢ May give evidence that a control is operating
➢ May give evidence about cut-off
➢ Confirms sales values and purchases costs
For intangible assets-
➢ To obtain evidence of existence of the assets.
➢ May give evidence of valuation.
b. Observations- By looking at a process or procedure being performed by
others in the following ways are:
➢ May provide evidence that a control is being operated.
➢ Only provide evidence that control was operating properly at the time of
the observation.
➢ The auditor’s presence may have an influence on the operation of the
control.
➢ Observation of a one-off events.
c. External confirmation-
➢ Obtaining a direct response from an external i.e. third party.
➢ May provide good evidence of existence of balance i.e. receivables
confirmation.
➢ May not provide reliable evidence of valuation i.e. customer may confirm
receivable amount and be unable to pay in the future.
d. Recalculation- Manually or electronically checking the arithmetical accuracy
of documents, records or the client’s calculations i.e. recalculation of the
translation of a foreign currency transaction.
e. Reperformance- The auditor’s independent execution of procedures or
controls that were originally performed as part of the entity’s internal control
system i.e. reperformance of a bank reconciliation.
f. Analytical Procedures- Analysis of plausible relationships between date.

4
g. Enquiry- Seeking Information from knowledgeable persons both financial
and non-financial within the entity or outside.
5. Relying on the work of others-
➢ Experts
➢ Internal audit
➢ Service organisations
5.1 Experts- It is being divided into two types are:
➢ Management’s Expert
➢ Auditor’s Expert
a. Management’s Expert- An employee of the client or someone engaged by
the audit client who has expertise that is used to assist in the preparation of the
financial statements. ISA 500 audit evidence provides guidance that auditor
should consider before relying on the work of a management’s expert. The
auditor must:
➢ Evaluate the competence, capabilities and objectivity of the expert.
➢ Obtain an understanding of the work of the expert.
➢ Evaluate the appropriateness of the expert’s work as audit evidence for
relevant assertion.
b. Auditor’s expert- An employee of the audit firm or someone engaged by the
audit firm to provide sufficient appropriate evidence. ISA 620 using the work of
an auditor’s expert provides guidance to auditors. If the auditor lacks the
required technical knowledge to gather sufficient appropriate evidence to form
an opinion, they may have to rely on the work of an expert.
i. Evaluating competence- Information regarding the competence, capability
and objectivity on an expert may come from a variety of sources including:
➢ Personal experience of working with the expert.
➢ Discussions with the expert.
➢ Discussions with other auditors.
➢ Knowledge of the expert’s qualifications, memberships of professional
bodies and licences.
➢ Published papers or books written by the expert.
➢ The audit firm’s system of quality management.
ii. Evaluating objectivity- Assessing the objectivity of the expert is particularly
difficult. They may not be bound by a similar code of ethics as the auditor. It

5
may be unaware of the ethical requirements and threats which auditors are
familiar. It may be relevant to:
➢ Make enquiries of the client known interest or relationships with the
chosen expert.
➢ Discuss applicable safeguard with the expert.
➢ Discuss financial, business and personal interest in the client with the
expert.
➢ Obtain written representation from the expert.
iii. Agreeing the work- Once the auditor has considered above matters, they
must obtain written agreement from the expert of the following:
➢ The nature, scope and objectives of the expert’s work.
➢ The roles and responsibilities of the auditor and the expert.
➢ The nature, timing and extent of the communication between the two
parties.
➢ The need for the expert to observe confidentiality.
iv. Evaluating the work- Once the expert’s work is complete, the auditor must
scrutinise it and evaluate whether it is appropriate for audit purposes. The
auditor must consider:
➢ The reasonableness of the findings and consistency with other evidence.
➢ The significant assumptions made.
➢ The use and accuracy of source data.
v. Reference to the work of an expert-
➢ The auditor cannot devolve responsibility for forming an audit opinion.
➢ They must use their professional judgement to assess whether the
evidence produced by the expert is sufficient and appropriate to support
the audit opinion.
➢ The use of an auditor’s expert is not mentioned in an unmodified
auditor’s opinion unless required by law or regulations.
➢ It may be included in a modified opinion if it is relevant to the
understanding of the modification.
➢ It doesn’t diminish the auditor’s responsibility for the opinion.
5.2 Relying on internal audit-
➢ ISA 610 using the work of internal auditors provides guidance.
➢ An internal audit department forms part of the client’s system of internal
control.

6
➢ If it is an effective element of the control system, it may reduce control
risk.
➢ It reduces the need for the auditor to perform detailed substantive testing.
➢ External auditors may be able to co-operate with a client’s internal audit
department and place reliance on their procedures in place of performing
their own.
➢ The external auditor must assess the effectiveness of the internal audit
function whether the work produced by the internal auditor is adequate
for the purpose of the audit.
a. Evaluating the internal audit function-
➢ The extend in which the internal audit function’s organisational status and
relevant policies and procedures support the objectivity of the internal
auditors.
➢ The competence of the internal audit function.
➢ Whether the internal audit function applies a systematic and disciplined
approach.
b. Evaluating objectivity-
➢ Whether the internal audit function reports to those charged with
governance and also has the direct access in it.
➢ Whether the internal audit function is free from operational responsibility.
➢ Whether those charged with governance are responsible for employment
decisions such as remuneration.
➢ Whether any constraints are placed on the internal function by
management or those charged with governance.
➢ Whether the internal auditors are members of a professional body which
requires compliance with ethical requirements.
c. Evaluating competence-
➢ Whether the resources of the internal audit function are appropriate and
adequate for the size of the organisation and nature of its operations.
➢ Whether there are established policies for hiring, training and assigning
internal auditors to internal audit engagement.
➢ Whether internal auditors have adequate technical training and
proficiency including relevant professional qualification and experience.
➢ Whether the internal auditors have required knowledge of the entity’s
financial reporting and applicable financial reporting framework.
➢ It possesses the necessary skills to perform work related to the financial
statements.

7
➢ Whether the internal auditors are members of a professional body which
requires continued professional development.
d. Evaluating the systematic and disciplined approach-
➢ Existence, adequate and use of internal audit procedures and guidance.
➢ Application of quality control policies and procedures.
➢ If the external auditor considers appropriate use the work of the internal
auditor, they have to determine the areas and extent the work of the
internal audit can be used in it.
➢ Incorporate into planning to assess the impact on the nature, timing and
extent of further audit procedures.
e. Evaluating the internal audit work-
➢ The work was properly planned, performed, supervised, reviewed and
documented.
➢ Sufficient appropriate evidence has been obtained.
➢ The conclusions reached are appropriate in the circumstances.
➢ The reports prepared are consistent with the work performed.
f. To provide direct assistance-
External auditors can consider whether the internal auditor can provide direct
assistance with gathering audit evidence under the supervision and review of the
external auditor. ISA 610 provides guidance to aim to reduce the risk that the
external auditor over uses the internal auditor.
Where it is agreed that the internal auditor can provide direct assistance:
➢ Management must agree in writing that the internal auditor can provide
such assistance and they will not intervene in the work.
➢ The internal auditors must provide written confirmation that will keep the
external auditors information confidential.
➢ The external auditors will provide direction, supervision and review of
the internal auditor’s work.
➢ The external auditor should remain alert to the risk that the internal
auditor is not objective or competent.
g. Documentation- The auditor should document:
➢ The evaluation of the internal auditor’s objectivity and competence.
➢ The basis for the decision regarding the nature and extent of the work
performed by the internal auditor.

8
➢ The name of the reviewer and the extend of the review of the internal
auditor’s work.
➢ The written agreement of management
➢ The working papers produced by the internal auditor.
5.3 Relying on Service Organisation- Many companies use service organisation
to perform business functions such as:
➢ Payroll processing
➢ Receivables collection
➢ Pension management
If a company uses a service organisation, audit evidence will need to be
obtained from the service organisation or the client. This needs to be considered
when planning the audit.
i. Planning the audit- The auditor will need to:
➢ Obtain an understanding of the service organisation sufficient to identify
and assess the risks of material misstatements.
➢ Design and perform audit procedures responsive to those risks.
This requires the auditor to obtain an understanding of the service provided:
➢ Nature of the services and their effect on internal controls
➢ Nature and materiality of the transactions to the entity
➢ Level of interaction between the activities of the service organisation and
the entity.
➢ Nature of the relationship between the service organisation and entity
including contractual terms.
The auditor should determine the effect the use of a service organisation will
have on their assessment of risk. The following issues should be considered:
➢ Reputation of the service organisation
➢ Existence of external supervision
➢ Extent of controls operated by service provider
➢ Experience of errors and omissions
➢ Degree of monitoring by the user
ii. Sources of information about the service organisation-
a. Obtaining a type 1 and type 2 report from the service organisation’s auditor.
Type 1 report- It provides a description of the design of the controls at the
service organisations prepared by the management of the service organisation. It

9
includes a report by the service auditor providing an opinion on the description
of the system and suitability of the controls.
Type 2 report- It provides a description, design and operating effectiveness of
controls at the service organisation. It contains a report prepared by
management of the service organisation. It includes a report by the service
auditor which provides the opinion on the description of the system, suitability
of the controls, effectiveness of the controls and description of the tests of
controls performed by the auditor.
b. Contacting the service organisation through the client.
c. Visiting the service organisation.
d. Using auditor to perform procedures that will provide the necessary
information about the controls at the service organisation.
iii. Responding to assessed risks- The auditor should determine whether
sufficient appropriate evidence is available from the client and perform further
procedures or use another auditor to perform procedures on behalf. If controls
are expected to operate effectively:
a. Obtain a type 2 report if available and consider:
➢ Whether the date covered by the report is appropriate for the audit.
➢ Whether the client has any complementary controls in place.
➢ The time elapsed since the test of controls were performed.
➢ Whether the tests of controls performed by the auditor are relevant to
financial statement assertions.
b. Perform tests of controls at the service organisation.
c. Use auditor to perform tests of controls,
iv. Impact on the auditor’s report-
➢ If sufficient appropriate evidence has not obtained, a qualified or
disclaimer opinion will be issued.
➢ The use of a service organisation auditor is not mentioned in the auditor’s
report unless required by law or regulations.
➢ Reference to the work of a service organisation auditor may be included
in a report containing a modified opinion if it is relevant to the
understanding of the modification.
➢ It doesn’t diminish the auditor’s responsibility for the opinion.

10
v. Benefits to the audit-
➢ Independence- the service organisation is external to the client, the audit
evidence derived from it is regarded as being more reliable than evidence
generated internally by the client.
➢ Competence- the service organisation is a specialist, it may be more
competent in executing its role than the client’s internal department
resulting in fewer errors.
➢ Possible reliance on the service organisation’s auditor: it may be possible
for the audit firm to confirm information directly with the service
organisation’s auditors.
vi. Drawbacks-
➢ It concerns access information and records.
➢ The auditor has legal right to access the client’s records but it receives
answers and explanations that they consider necessary for the audit.
➢ They don’t have such rights over records and information held by a third
party such as a service organisation.
➢ If access to records and information is denied by service organisation, it
may impose a limitation on the scope of the auditor’s work.
➢ If sufficient appropriate evidence is not obtained, it will result in a
modified audit opinion.
6. Selecting items for testing- The auditor has three options for selecting items
to test:
6.1 Select all items to test-
➢ This approach may be taken where the population is very small and it is
easy for the auditor to test all items.
➢ If is an area that an auditor requires greater audit confidence for example
an area that is material by nature or is considered to be significant risk.
➢ The auditor may decide to test all items within the populations.
6.2 Selecting specific items for testing- Items with specific characteristics may
be chosen for testing such as:
➢ High value items within a populations
➢ All items over a certain amount
➢ Items to obtain information
6.3 Sampling- ISA 530 defines that ‘the application of audit procedures to less
than 100% of items within a population of audit relevance such that all

11
sampling units have a chance of selection in order to provide the auditor with
reasonable basis on which draws conclusions about the entire population.’
a. The need for sampling-
➢ It will usually be impossible to test every item in an accounting
population because of the costs involved.
➢ It is also important to remember that auditors give reasonable not
absolute.
➢ Therefore, don’t certify that financial statements are 100% accurate.
b. Selecting an appropriate sample-
➢ When sampling, the auditor must choose a representative sample.
➢ If a sample is representative, the same conclusion will be drawn from the
sample as would have been drawn had the whole population been tested.
➢ For a sample to be representative, it must have the same characteristics as
the other items in the population from which it was chosen.
➢ In order to reduce sampling risk and ensure the sample is representative,
the auditor can increase the size of the sample selected or use
stratification.
c. Stratification- It is used in conjunction with sampling. It is the process of
breaking down a population into smaller sub-populations. Each sub-population
is a group of items which have similar characteristics.
d. Statistical sampling and Non-statistical sampling-
Statistical sampling-
➢ Random selection- This can be achieved through the use of a random
number generator or table.
➢ Systematic selection- Where a constant sampling interval is used and the
first item is selected randomly.
➢ Monetary unit selection- Selecting items based upon monetary values.
Non-statistical sampling-
➢ Haphazard selection- The auditor doesn’t follow a structural technique
but avoids bias or predictability.
➢ Block selection- This involves selecting a block of contiguous items from
the population. To reduce sampling risk, many blocks should be selected
as valid references cannot be made beyond the period or block examined.
e. Designing a sample- When designing a sample, the auditor has to consider:

12
➢ The purpose of the procedure
➢ The combination of procedures being performed
➢ The nature of evidence sought
➢ Possible misstatement conditions
f. Evaluating deviations and misstatements in a sample-
Deviations- Any issues identified during tests of control are called deviations.
The auditor will:
➢ Determine a level of deviation they are willing to accept- tolerable
deviation rate.
➢ Test the sample stated in the audit plan.
➢ Extend the sample if deviations are identified.
➢ Compare the actual deviation rate to the tolerable deviation rate.
➢ Increase the level of substantive testing over the balance if the actual
deviation rate exceeds the tolerable deviation rate.
➢ Communicate the control deficiency causing the deviation with
management and those charged with governance.
Misstatements- It is the difference between the amounts actually recorded and
should have been recorded in the accounting records. Misstatements are
identified when performing substantive test of details. The auditor will:
➢ Determine a level of deviation they are willing to accept- tolerable
deviation rate.
➢ Test the sample stated in the audit plan.
➢ Consider the nature and cause of the misstatement. If the misstatement is
an anomaly, no further procedures are required as the misstatement is not
representative of further misstatements.
➢ Compare the total project misstatement to tolerable misstatement.
➢ Communicate the misstatement with management and ask them to correct
it.
7. Automated tools and techniques-

Automated tools
and techniques

Data analytical
Test data Audit software
tools

13
7.1 Test data-
➢ It involves the auditor submitting ‘dummy’ data into the client’s system to
ensure that the system correctly processes it and prevents or detects and
corrects misstatements.
➢ The objective of test data is to test the operation of information
processing controls within the system.
➢ To be successful test data should include both data with errors built into it
and data without errors.
➢ Data may be processed during a normal operational cycle or during a
special run at a point in time outside the normal operational cycle.
Advantages of test data-
➢ Enables the auditor to test programmed controls which wouldn’t be able
to tested.
➢ Once designed, cost incurred will be minimal unless the programmed
controls are changed requiring the test data to be redesigned.
Disadvantages of test data-
➢ Risk of corrupting the client’s systems.
➢ Requires time to be spent on the client’s system if it is used in a live
environment which may not be convenient for the client.
7.2 Audit Software-
➢ It is used to interrogate a client’s system.
➢ It can be either packaged, off-the-shelf software or it can be purpose
written to work on a client’s system.
➢ They can be used to scrutinise large volumes of data which would be
inefficient to do manually.
➢ The programs can present the result so that they can be investigated.
Sufficient procedures that can be performed include:
a. Extracting samples according to specified criteria such as:
➢ Random
➢ Over a certain e.g. individually material balances or expenses
➢ Below a certain amount e.g. debit balances on the list of supplier balances
or credit balances on the list of customer balances
➢ At certain dates e.g. receivables or inventory over a certain age
b. Calculating ratios and indicators that fail to meet certain predefined criteria

14
c. Casting ledgers and schedules
d. Recalculation of amounts such as depreciation
e. Preparing reports
f. Stratification of data
g. Identifying changes to standing data e.g. employee or supplier bank details
h. Producing letters to send out to customers and suppliers
Advantages of audit software-
➢ Calculations and casting of reports will be quicker.
➢ More transactions can be tested as compared with manual testing
➢ The computer files are tested rather than printout
➢ Can be cost effective once set up
Disadvantages of audit software-
➢ Bespoke software can be expensive to set up.
➢ Training of audit staff will be required incurring additional cost
➢ The audit software may slow down or corrupt the client’s systems
➢ If errors are made in the design of the software, issues may go undetected
by the auditor.
7.3 Data analytical tools-
➢ It is the science and art of discovering and analysing patterns, deviations
and inconsistences.
➢ It also extracts other useful information in the data of underlying.
➢ Relating subject matter of an audit through analysis, modelling,
visualisation for the purpose of planning and performing the audit.
➢ Big data technology allows the auditor to perform procedures on very
large or complete sets of data rather than samples.
Features of data analytics-
➢ It can be used throughout the audit to help identify the risks, test the
controls and part of substantive procedures.
➢ This result still needs to be evaluated using the professional skills and
judgement of the auditor in order to analyse the results and draw
conclusion.
➢ It can be incorporate a wider range of data.

15
Benefits of data analytics-
➢ It enables the auditor to obtain a greater understanding of the entity and
its environment.
➢ It allows the auditor to manipulate of the data in a population quickly and
reducing sampling risk.
➢ Result can be visualised graphically which may increase the user-
friendliness of the reports.
➢ Audit procedures can be performed more quickly and a higher standard.
➢ Audit procedures can be carried out a continuous basis rather than
focused on the year end.
➢ It may result in more frequent interaction between the auditor and client
over the course of the year.
Limitations of data analytics-
➢ The quality of data analytics depends on the reliability of the underlying
data used and may not be complete, well-controlled or form a reliable
source.
➢ Financial statements still contain a significant number of estimates.
➢ It will not replace the need for auditors to use professional scepticism and
professional judgement.

16

You might also like