ISA standards contents

ISA standards

ISA 300

Planning an Audit of Financial Statements

1Objective and scope

ISA 300 deals with the auditor's responsibility to plan an audit of financial statements. It is written for recurring audits; additional considerations for an initial engagement are identified separately. Planning is not a discrete phase but a continual and iterative process that begins shortly after completion of the previous audit and continues until the current audit is complete, because the strategy and plan are updated as the auditor learns more about the entity and as unexpected events, changes in conditions or the results of procedures require.

The objective is for the auditor to plan the audit so that it will be performed in an effective manner. Adequate planning helps the auditor devote appropriate attention to important areas, identify and resolve potential problems on a timely basis, organise and manage the engagement efficiently, select engagement team members with the right competence and assign work to them, direct and supervise them and review their work, and coordinate the work of component auditors and experts.

2Key definitions

Overall audit strategy
The document that sets the scope, timing and direction of the audit and guides the development of the audit plan: the characteristics of the engagement, the reporting objectives and timing, the significant factors directing the team's efforts, the results of preliminary activities, and the nature, timing and extent of resources.
Audit plan
The more detailed document describing the nature, timing and extent of the planned risk assessment procedures, the planned further audit procedures at the assertion level, and any other procedures required to comply with the ISAs. Audit programmes are its working form.
Preliminary engagement activities
The work performed at the start of the engagement: continuance procedures under ISQM 1, evaluation of compliance with ethical requirements including independence, and establishing an understanding of the terms of the engagement under ISA 210.
Initial audit engagement
An engagement in which the financial statements for the prior period were not audited, or were audited by a predecessor auditor. It requires additional planning: communication with the predecessor (subject to ethics rules) and procedures on opening balances under ISA 510.

3Requirements

Involvement of key team members and preliminary activities

  • The engagement partner and other key members of the engagement team are involved in planning the audit, including planning and participating in the discussion among engagement team members required by ISA 315 and ISA 240.
  • At the beginning of the current audit the auditor performs procedures required by ISQM 1 and ISA 220 regarding continuance of the client relationship and the engagement, evaluates compliance with relevant ethical requirements including independence, and establishes an understanding of the terms of the engagement as required by ISA 210. These matters are settled before significant work begins because a problem with any of them may mean the audit cannot proceed.

The overall audit strategy

The auditor establishes an overall audit strategy that sets the scope, timing and direction of the audit and guides the development of the audit plan. In establishing it the auditor identifies the characteristics of the engagement that define its scope (the financial reporting framework, industry reporting requirements, locations, group structure, the use of a service organisation, IT environment, the availability of internal audit work); ascertains the reporting objectives to plan the timing of the audit and the nature of communications (deadlines, meetings with management and those charged with governance, the timing of interim and final visits, component auditor reporting); considers the factors that are significant in directing the team's efforts (materiality, high-risk areas, the approach to internal control, significant developments in the industry or the entity); considers the results of preliminary engagement activities and knowledge from other engagements for the entity; and ascertains the nature, timing and extent of resources necessary (who, how many, when, how managed).

The audit plan

  • The auditor develops an audit plan that includes the nature, timing and extent of planned risk assessment procedures (ISA 315), planned further audit procedures at the assertion level (ISA 330), and other planned procedures required to comply with the ISAs (for example attendance at the inventory count, subsequent events review, going concern, written representations).
  • The strategy and plan are updated and changed as necessary during the audit: the results of risk assessment procedures may alter the assessed risks, and unexpected events may require a revised approach; the reasons for significant changes are documented.
  • The auditor plans the nature, timing and extent of direction and supervision of team members and the review of their work, scaled to the size and complexity of the entity, the area of the audit, the assessed risks and the capabilities of the individuals.

Interim and final visits: what goes where

Interim visit (before year end): update the understanding of the entity and controls, perform tests of controls, perform substantive procedures on transactions to date, resolve accounting issues early.

Final visit (after year end): roll forward the interim work to the period end, perform substantive procedures on year-end balances, subsequent events, going concern, obtain representations, complete the file and draft the report.

Planning decides the split. The more effective the controls and the lower the risk, the more work can be moved to the interim, which spreads staff workload and meets a tight reporting deadline.

Additional considerations in initial engagements

Before starting an initial audit the auditor performs the ISQM 1 procedures regarding acceptance of the client and the specific engagement, and communicates with the predecessor auditor where there has been a change of auditors, in compliance with relevant ethical requirements (professional clearance: the incoming auditor asks the client's permission to contact the outgoing auditor, who, with the client's permission, states whether there is any professional reason the appointment should not be accepted). The overall strategy also covers the arrangements to be made with the predecessor to review working papers, any major issues discussed with management in connection with the appointment, the procedures on opening balances (ISA 510), and other procedures the firm's quality management requires for initial engagements, such as involvement of an engagement quality reviewer.

4Documentation and reporting

The auditor documents the overall audit strategy, the audit plan, and any significant changes made to either during the engagement together with the reasons for those changes. The strategy may be a short memorandum for a small entity or a detailed document for a complex one; the plan is typically evidenced by audit programmes tailored to the assessed risks. The planning memorandum records the key decisions (materiality, significant risks, the controls reliance decision, timing, staffing) so that the file shows the audit was properly planned and so that the record of significant changes explains why the final approach differed from the original one. Planning matters are communicated to those charged with governance as an overview of the planned scope and timing under ISA 260, taking care not to make the audit predictable.

5Examinable focus

What KASNEB tests

Expect 'explain the benefits of planning an audit' and 'distinguish the overall audit strategy from the audit plan' as direct questions, and a scenario giving a new client with a tight deadline, multiple branches and a new ERP system, asking for the matters to include in the audit strategy. Be ready to list the preliminary engagement activities and the additional steps for an initial engagement, including professional clearance with the predecessor auditor. The interim versus final visit split, and why planning is iterative rather than a one-off phase, are common short parts. Link planning to ISA 315 (risk assessment feeds the plan), ISA 320 (materiality is set in planning) and ISA 220 (the partner plans direction, supervision and review).