ISA 500 (Revised)
Audit Evidence
1Objective and scope
ISA 500 explains what constitutes audit evidence in an audit of financial statements and deals with the auditor's responsibility to design and perform audit procedures to obtain sufficient appropriate audit evidence to be able to draw reasonable conclusions on which to base the opinion. It is the general evidence standard; ISA 501, 505, 510, 520, 530, 540, 550, 560, 570 and 580 address evidence for specific items or situations, and ISA 315 and ISA 330 set how much evidence is needed for the assessed risks. The revised ISA 500, effective for periods beginning on or after 15 December 2026, restates the standard around a principles-based approach: it emphasises professional scepticism in evaluating evidence, addresses information from any source (including the entity's own information, external information sources and technology-generated data), removes the separate treatment of a management's expert in favour of evaluating all information consistently, and recognises automated tools and techniques as legitimate ways to obtain evidence.
The objective is to design and perform audit procedures in such a way as to enable the auditor to obtain sufficient appropriate audit evidence to be able to draw reasonable conclusions on which to base the auditor's opinion.
2Key definitions
3Requirements
Sufficient appropriate audit evidence
The auditor designs and performs audit procedures that are appropriate in the circumstances for the purpose of obtaining sufficient appropriate audit evidence. Evidence is obtained through risk assessment procedures and further audit procedures (tests of controls and substantive procedures). Its persuasiveness increases when items from different sources or of a different nature are consistent; inconsistency between sources is itself a matter requiring resolution. Generalisations about reliability, subject to exceptions, guide the evaluation:
| More reliable | Less reliable |
|---|---|
| Obtained from independent sources outside the entity | Generated internally by the entity |
| Generated internally when the related controls (including over its preparation and maintenance) are effective | Generated internally where controls are weak or absent |
| Obtained directly by the auditor (observation, reperformance, recalculation) | Obtained indirectly or by inference (inquiry about the application of a control) |
| In documentary form, whether paper, electronic or other medium | Oral representations, which are the weakest form on their own |
| Original documents | Photocopies, facsimiles, filmed, digitised or otherwise transformed documents, whose reliability may depend on the controls over their preparation |
Audit procedures for obtaining evidence
- Inspection: examining records or documents, internal or external, in paper, electronic or other form, or physically examining an asset. Inspection of tangible assets gives evidence of existence but not necessarily of rights or valuation.
- Observation: looking at a process or procedure being performed by others (the inventory count, a control activity). Evidence is limited to the point in time and by the fact that being observed may affect how the process is performed.
- External confirmation: audit evidence obtained as a direct written response to the auditor from a third party (ISA 505).
- Recalculation: checking the mathematical accuracy of documents or records, manually or electronically.
- Reperformance: the auditor's independent execution of procedures or controls that were originally performed as part of the entity's internal control.
- Analytical procedures: evaluations of financial information through analysis of plausible relationships among financial and non-financial data, and investigation of fluctuations or relationships inconsistent with other information or expected values (ISA 520).
- Inquiry: seeking information from knowledgeable persons, financial and non-financial, inside or outside the entity. Inquiry alone does not provide sufficient evidence of the absence of a material misstatement at the assertion level, nor of the operating effectiveness of controls; responses are corroborated.
Information to be used as audit evidence
- When designing and performing procedures the auditor considers the relevance and reliability of the information to be used as evidence, including information from an external information source.
- When information to be used has been prepared using the work of a management's expert, the auditor evaluates the competence, capabilities and objectivity of that expert, obtains an understanding of the expert's work, and evaluates its appropriateness as evidence for the relevant assertion (the reasonableness of assumptions and methods, the relevance and completeness of source data).
- When using information produced by the entity, the auditor evaluates whether it is sufficiently reliable for the auditor's purposes, including obtaining evidence about its accuracy and completeness and evaluating whether it is sufficiently precise and detailed. A report of aged receivables is only as good as the ageing logic and the completeness of the ledger behind it.
- When using automated tools and techniques (data analytics over the whole population, scanning for outliers, robotic reperformance), the auditor still evaluates the reliability of the underlying data and the appropriateness of the tool for the purpose.
Selecting items for testing
When designing tests of controls and tests of details the auditor determines means of selecting items that are effective in meeting the purpose of the procedure: selecting all items (100% examination, appropriate for a small number of large items or where a computer-assisted technique makes it efficient), selecting specific items (high value or key items, all items over a certain amount, items to obtain information, or items to test control activities; conclusions are confined to the items selected and are not projected to the population), and audit sampling (ISA 530, designed to allow conclusions to be drawn about the entire population).
Inconsistency in, or doubts over reliability of, evidence
If evidence obtained from one source is inconsistent with that obtained from another, or the auditor has doubts over the reliability of information to be used as evidence, the auditor determines what modifications or additions to procedures are necessary to resolve the matter and considers the effect, if any, on other aspects of the audit. Doubt about the authenticity of a document (an altered invoice, a bank statement that looks generated rather than issued) triggers heightened scepticism under ISA 240 and confirmation directly with the source.
4Documentation and reporting
ISA 500 has no reporting requirement of its own; its outcome is the auditor's conclusion, under ISA 330, on whether sufficient appropriate evidence has been obtained for every relevant assertion, which in turn supports an unmodified opinion or, where evidence is insufficient and cannot be obtained, a qualified opinion or disclaimer under ISA 705. The audit file, under ISA 230, records the procedures performed, the identifying characteristics of the items tested, the information relied on and the evaluation of its reliability (including the evaluation of any management's expert and of entity-produced reports), the resolution of inconsistencies, and the conclusions drawn.
5Examinable focus
What KASNEB tests
Definitions of sufficiency and appropriateness (relevance and reliability) and the reliability hierarchy with examples come up in almost every sitting; so does 'list and explain the procedures for obtaining audit evidence', often abbreviated AEIOU (Analytical, Enquiry, Inspection, Observation, recalculation and reperformance, plus confirmation). Scenario questions present evidence from different sources (a management schedule, a supplier statement, an oral assurance, a photocopy) and ask which is more reliable and why, or describe a valuer's report or a system-generated ageing and ask what the auditor must do before relying on it. In Advanced Auditing expect the revised standard's emphasis on external information sources, entity-produced information and data analytics as evidence.