ISA standards contents

ISA standards

ISA 330

The Auditor's Responses to Assessed Risks

1Objective and scope

ISA 330 deals with the auditor's responsibility to design and implement responses to the risks of material misstatement identified and assessed under ISA 315. It sets the two levels of response: overall responses to risks at the financial statement level, and further audit procedures whose nature, timing and extent are based on and responsive to the assessed risks at the assertion level. It contains the rules on when controls must be tested, when evidence from a prior audit may be relied on, the mandatory substantive procedures, and the evaluation at the end of whether sufficient appropriate evidence has been obtained.

The objective is to obtain sufficient appropriate audit evidence regarding the assessed risks of material misstatement, through designing and implementing appropriate responses to those risks.

2Key definitions

Substantive procedure
An audit procedure designed to detect material misstatements at the assertion level. Two types: tests of details (of classes of transactions, account balances and disclosures) and substantive analytical procedures.
Test of controls
An audit procedure designed to evaluate the operating effectiveness of controls in preventing, or detecting and correcting, material misstatements at the assertion level. Distinct from evaluating design and implementation, which is a risk assessment procedure under ISA 315.
Overall responses
Responses to risks at the financial statement level: emphasising scepticism to the team, assigning more experienced staff or experts, providing more supervision, incorporating unpredictability, and changing the overall approach (for example from a controls-based to a fully substantive approach, or performing procedures at period end rather than interim).
Nature, timing and extent
Nature is the purpose (test of controls or substantive) and type (inspection, observation, inquiry, confirmation, recalculation, reperformance, analytical procedure) of a procedure; timing is when it is performed or the period the evidence applies to; extent is the quantity (sample size, number of observations).

3Requirements

Designing further audit procedures

  • Design and perform further audit procedures whose nature, timing and extent are based on and responsive to the assessed risks at the assertion level. Consider the reasons for the assessment (the inherent risk factors, and whether the assessment takes account of controls) and obtain more persuasive evidence the higher the assessed risk.
  • The nature is the most important consideration in responding to risk: for a high inherent risk on valuation the auditor may use an expert, obtain external confirmation, or perform detailed recalculation rather than rely on inquiry.
  • Timing: procedures may be performed at an interim date or at period end; the higher the risk, the closer to period end. Evidence obtained at an interim date must be supplemented with procedures covering the remaining period (roll-forward), and unexpected changes since the interim date require additional or revised procedures.
  • Extent: the quantity of a procedure increases as the risk of material misstatement increases, subject to the quality of the evidence, and is determined under ISA 530 for sampling.

Tests of controls

The auditor designs and performs tests of controls to obtain sufficient appropriate evidence about operating effectiveness when the assessment of risks at the assertion level includes an expectation that controls are operating effectively (that is, the auditor intends to rely on them), or when substantive procedures alone cannot provide sufficient appropriate evidence at the assertion level. Tests of controls obtain evidence about how the controls were applied at relevant times during the period, the consistency with which they were applied, and by whom or by what means. Inquiry alone is not sufficient to test the operating effectiveness of a control; it is combined with inspection, observation, reperformance or recalculation.

  • Where controls depend on indirect controls (general IT controls, the review of exception reports), obtain evidence supporting the effective operation of those indirect controls as well.
  • Where the auditor obtains evidence about operating effectiveness during an interim period, obtain evidence about significant changes to those controls after the interim period and determine the additional evidence needed for the remaining period.
  • Evidence from a previous audit about operating effectiveness may be used if the auditor obtains evidence about whether significant changes have occurred since; where there have been changes, the controls are retested in the current audit. Where there have been no changes, each control is tested at least once in every third audit, and some controls are tested every audit, to avoid testing all of them in a single period. Controls over a significant risk must be tested in the current period every time.
  • Where deviations are detected, understand them and their potential consequences, and determine whether the tests performed provide an appropriate basis for reliance, whether additional tests are necessary, or whether the risk needs to be addressed using substantive procedures.

Substantive procedures

  • Irrespective of the assessed risks, design and perform substantive procedures for each material class of transactions, account balance and disclosure, because the risk assessment is judgemental and internal control has inherent limitations (including management override).
  • For each significant risk, perform substantive procedures that are specifically responsive to that risk; if the approach consists only of substantive procedures, those must include tests of details, not analytical procedures alone.
  • Substantive procedures related to the financial statement closing process must include agreeing or reconciling the financial statements with the underlying accounting records (including disclosures) and examining material journal entries and other adjustments made in preparing the statements.
  • If substantive procedures are performed at an interim date, cover the remaining period by performing substantive procedures combined with tests of controls for the intervening period, or further substantive procedures alone that provide a reasonable basis for extending the conclusions to period end. Misstatements detected at the interim date change the planned nature, timing or extent of the remaining-period work.

Adequacy of presentation and sufficiency of evidence

The auditor performs procedures to evaluate whether the overall presentation of the financial statements is in accordance with the applicable framework, including the classification and description of financial information, the underlying transactions, events and conditions, and the disclosures. Before concluding, the auditor evaluates whether the assessment of risks at the assertion level remains appropriate in the light of the procedures performed and the evidence obtained, and whether sufficient appropriate evidence has been obtained. If it has not, the auditor attempts to obtain further evidence; if sufficient appropriate evidence cannot be obtained, the auditor expresses a qualified opinion or disclaims the opinion.

4Documentation and reporting

The documentation shows the overall responses to address the assessed risks at the financial statement level, the nature, timing and extent of the further audit procedures, the linkage of those procedures with the assessed risks at the assertion level, and the results of the procedures including the conclusions where these are not otherwise clear. Where the auditor relies on evidence about operating effectiveness from a previous audit, the conclusions reached about relying on those controls are documented. The audit programmes, tests of controls schedules, sample selections and deviation evaluations are the working form of this record. Deviations in controls, and misstatements found by substantive procedures, feed the ISA 265 and ISA 450 processes and, where they change the risk assessment, are documented as revisions under ISA 315.

5Examinable focus

What KASNEB tests

Two staples: 'distinguish tests of controls from substantive procedures, with examples' and 'describe the substantive procedures you would perform on [receivables, inventory, non-current assets, payables, revenue, payroll]', where the marker expects procedures written with a verb, a source and an assertion (inspect, recalculate, confirm, observe, inquire, reperform, analyse). Know when tests of controls are mandatory, the rotation rule for relying on prior-period evidence (every third audit, never for significant risks), that inquiry alone is not a test of controls, and the mandatory substantive procedures on the closing process. Scenario questions give an interim visit and ask what roll-forward work is needed, or give control deviations and ask whether reliance is still justified.