ISA standards contents

ISA standards

ISA 505

External Confirmations

1Objective and scope

ISA 505 deals with the auditor's use of external confirmation procedures to obtain audit evidence in accordance with ISA 330 and ISA 500. It does not address inquiries about litigation and claims (ISA 501). Evidence obtained as a direct written response from a knowledgeable third party is generally more reliable than evidence generated internally by the entity, so confirmations are a natural response to a high assessed risk of material misstatement, provided the auditor controls the process from start to finish. Common uses: bank balances and other information from bankers, receivable balances and terms, inventory held by third parties, property deeds held by lawyers or financiers, investments held by custodians, payable balances and terms, and loan agreements.

The objective is, when using external confirmation procedures, to design and perform them to obtain relevant and reliable audit evidence.

2Key definitions

External confirmation
Audit evidence obtained as a direct written response to the auditor from a third party (the confirming party), in paper form, or by electronic or other medium.
Positive confirmation request
A request that the confirming party respond directly to the auditor indicating whether it agrees or disagrees with the information in the request, or providing the requested information (a 'blank' positive request asks the party to fill in the amount, a stronger test but with a lower response rate).
Negative confirmation request
A request that the confirming party respond directly to the auditor only if it disagrees with the information provided in the request. A non-response is silent about whether the party received the request or verified the information, so it provides less persuasive evidence.
Non-response
A failure of the confirming party to respond, or fully respond, to a positive confirmation request, or a confirmation request returned undelivered.
Exception
A response that indicates a difference between the information requested to be confirmed, or contained in the entity's records, and the information provided by the confirming party.

3Requirements

Designing and controlling the procedure

The auditor maintains control over external confirmation requests, including determining the information to be confirmed or requested, selecting the appropriate confirming party (a person knowledgeable about the matter, at a verified address), designing the requests so they are properly addressed and contain return information for responses to be sent directly to the auditor, and sending the requests, including follow-ups, to the confirming party. The entity may prepare the letters on its letterhead and sign the authority to disclose, but the auditor inserts the balances, checks the addresses, posts or emails the requests, and receives the replies at the auditor's own address.

  • Factors in design: the assertions addressed (a receivables confirmation addresses existence and rights but gives little evidence on valuation or recoverability), the specific risks including fraud risk, the layout and presentation of the request, prior experience, the method of communication, management's authorisation or encouragement to respond, and the confirming party's ability to confirm (some parties respond only to system-generated requests, or only confirm individual invoices).
  • Receivables selection considers materiality and risk: large and overdue balances, nil and credit balances, round-sum balances, balances written off after year end, and a sample of the rest.

Management's refusal to allow confirmation

  • If management refuses to allow the auditor to send a confirmation request, inquire as to the reasons and seek evidence as to their validity and reasonableness (a genuine legal dispute with a customer may be a valid reason; an unwillingness to disturb a major customer is a weak one).
  • Evaluate the implications of the refusal on the assessment of the relevant risks, including the risk of fraud, and on the nature, timing and extent of other procedures.
  • Perform alternative procedures designed to obtain relevant and reliable evidence (subsequent cash receipts, shipping documents and sales invoices for receivables; subsequent payments and supplier statements for payables).
  • If the refusal is unreasonable, or alternative procedures cannot provide sufficient appropriate evidence, communicate with those charged with governance under ISA 260 and determine the implications for the audit and the opinion under ISA 705.

Results of the procedure

  • Reliability of responses: if the auditor identifies factors giving rise to doubts about the reliability of a response (received indirectly, from an unexpected address or email domain, or apparently forwarded through the entity), obtain further evidence to resolve the doubts, for example by telephoning the confirming party at a number obtained independently. A response received electronically involves risks of authenticity; verifying the source and integrity (secure portals, call-backs) mitigates them.
  • If a response is unreliable, evaluate the implications for the risk assessment, including fraud risk, and for other procedures.
  • Non-responses to positive requests: perform alternative procedures to obtain relevant and reliable evidence. Where the auditor has determined that a response to a positive request is necessary to obtain sufficient appropriate evidence (because alternative procedures will not provide it), a non-response means a qualified opinion or disclaimer under ISA 705.
  • Exceptions: investigate each to determine whether it indicates a misstatement (a timing difference, cash in transit or goods in transit, is not a misstatement; a disputed invoice or a balance the customer does not recognise may be), and whether it indicates a control deficiency or fraud. Misstatements found are accumulated under ISA 450 and projected where they arose from a sample under ISA 530.

Negative confirmations

Negative confirmations provide less persuasive evidence than positive ones and are used as the sole substantive procedure to address an assessed risk at the assertion level only when all of the following apply: the auditor has assessed the risk of material misstatement as low and has obtained sufficient appropriate evidence about the operating effectiveness of relevant controls; the population comprises a large number of small, homogeneous balances or transactions; a very low exception rate is expected; and the auditor is not aware of circumstances or conditions that would cause recipients to disregard the requests. Even then, a non-response gives no explicit evidence that the party received the request or checked the balance.

4Documentation and reporting

The file records the selection of confirming parties and balances and the basis for it, copies of the requests sent and the control exercised (dispatch by the auditor, responses returned to the auditor), a summary schedule of responses, non-responses, alternative procedures performed and their results, and the investigation and resolution of every exception with the misstatements carried to the summary of unadjusted differences. Where management refused a confirmation, the reasons, the evaluation of them, the alternative procedures, the communication with those charged with governance and the effect on the opinion are recorded. Confirmation results never appear in the auditor's report except through their effect on the opinion: an unresolved inability to confirm a material balance without alternative evidence is a limitation on scope.

5Examinable focus

What KASNEB tests

Receivables circularisation is the standard question: explain positive versus negative requests and when each is appropriate, describe how the auditor keeps control of the process, state the assertions confirmed (existence and rights, not valuation), and set out what to do with non-responses (alternative procedures: after-date cash, invoices, dispatch notes) and exceptions (timing differences versus real misstatements). The bank confirmation letter, its standard content (balances, loans, security, contingent liabilities, accounts closed in the year) and why it is sent by the auditor, is a common short question. Scenario questions test the response to management's refusal to allow confirmation of a major customer's balance, and the reliability of responses received by email or through the client.