ISA 200
Overall Objectives of the Independent Auditor and the Conduct of an Audit in Accordance with International Standards on Auditing
1Objective and scope
ISA 200 is the foundation standard. It establishes the overall objectives of the independent auditor, explains the nature and scope of an audit designed to meet them, and sets out how the ISAs are structured and must be applied. The purpose of an audit is to enhance the degree of confidence of intended users in the financial statements; the auditor does this by expressing an opinion on whether the statements are prepared, in all material respects, in accordance with an applicable financial reporting framework. An audit provides reasonable assurance, a high but not absolute level, because of the inherent limitations of an audit.
The auditor's overall objectives are (a) to obtain reasonable assurance about whether the financial statements as a whole are free from material misstatement, whether due to fraud or error, enabling an opinion; and (b) to report on the financial statements and communicate as the ISAs require. Where reasonable assurance cannot be obtained and a qualified opinion is insufficient, the auditor disclaims the opinion or withdraws where withdrawal is possible under law or regulation.
2Key definitions
3Requirements
Ethics, scepticism and judgement
- The auditor complies with relevant ethical requirements, including independence, for every audit engagement. The IESBA Code's fundamental principles are integrity, objectivity, professional competence and due care, confidentiality, and professional behaviour.
- The auditor plans and performs the audit with professional scepticism, recognising that circumstances may exist that cause the financial statements to be materially misstated. Evidence that contradicts other evidence, information that questions the reliability of documents or responses, conditions that may indicate fraud, and circumstances suggesting the need for further procedures all demand heightened scepticism.
- The auditor exercises professional judgement in planning and performing the audit, particularly about materiality, audit risk, the nature, timing and extent of procedures, whether evidence is sufficient and appropriate, evaluating management's judgements, and drawing conclusions.
Sufficient appropriate audit evidence and audit risk
To obtain reasonable assurance the auditor obtains sufficient appropriate audit evidence to reduce audit risk to an acceptably low level. Sufficiency is the measure of quantity, affected by the assessed risks and the quality of the evidence; appropriateness is the measure of quality, its relevance and reliability. The audit risk model expresses the relationship: audit risk = risk of material misstatement (inherent risk × control risk) × detection risk. The auditor assesses the risks of material misstatement and responds by setting the nature, timing and extent of procedures so that detection risk, and therefore audit risk, is acceptably low. The higher the assessed risk, the more persuasive the evidence must be.
Inherent limitations of an audit
The nature of financial reporting: many items involve estimates and judgement, so there is a range of acceptable outcomes rather than one right answer.
The nature of audit procedures: management may withhold information, fraud may be concealed by collusion or forgery, and an audit is not an official investigation with powers of search.
Timeliness and cost: users expect an opinion within a reasonable time at a reasonable cost, so the auditor tests rather than examines everything.
Consequence: reasonable, not absolute, assurance; and a later discovery of a misstatement does not by itself mean the audit was not performed in accordance with the ISAs.
Conducting the audit in accordance with ISAs
- The auditor complies with all ISAs relevant to the audit. An ISA is relevant when it is in effect and the circumstances it addresses exist. The auditor must understand the entire text of an ISA, including its application and other explanatory material, to apply its requirements properly.
- The auditor does not represent compliance with ISAs in the report unless every relevant ISA has been complied with.
- Each ISA has an objective; the auditor uses the objectives to judge whether the requirements achieve the aims of the ISAs in the circumstances and whether additional procedures are needed. Failure to achieve an objective is evaluated for its effect on the auditor's overall objectives.
- A requirement is departed from only in exceptional circumstances, when the requirement is a specific procedure that would be ineffective in achieving its aim; the auditor performs alternative procedures and documents the reasons (ISA 230).
- Where the auditor cannot achieve an objective, the auditor evaluates whether that prevents achieving the overall objectives and therefore requires a modified opinion or withdrawal.
4Documentation and reporting
ISA 200 itself contains few documentation requirements; it directs the auditor to ISA 230 for the audit file and to ISA 700 and its family for the report. What it fixes is the reporting frame: the opinion states whether the financial statements are prepared, in all material respects, in accordance with the applicable framework (for a fair presentation framework, whether they present fairly in all material respects or give a true and fair view). The report must not claim compliance with the ISAs unless all relevant ISAs were complied with, and the ISAs are applied together with any national requirements, which cannot override them. The auditor's ethical position (independence, fundamental principles) underpins every representation in the report.
5Examinable focus
What KASNEB tests
The audit risk model is the most frequently examined idea in the whole syllabus: be able to define inherent, control and detection risk, explain why the auditor controls only detection risk, and apply the model to a scenario (a new client with weak controls means high inherent and control risk, so detection risk must be driven down with more substantive work). Expect questions on the inherent limitations of an audit and the meaning of reasonable assurance, on professional scepticism with examples of when it should be heightened, and on the difference between the auditor's and management's responsibilities (the premise). A theory question may ask why an audit is not a guarantee, or how the ISAs are structured (objectives, requirements, application material) and when a departure from a requirement is permitted.