ISA standards contents

ISA standards

ISA 600 (Revised)

Special Considerations: Audits of Group Financial Statements (Including the Work of Component Auditors)

1Objective and scope

ISA 600 (Revised) deals with special considerations that apply to a group audit, including when component auditors are involved. It applies to an audit of group financial statements (financial statements that include the financial information of more than one entity or business unit through a consolidation process) and, adapted as necessary, when an auditor involves other auditors in the audit of financial statements that are not group financial statements. The 2022 revision, effective for periods beginning on or after 15 December 2023, replaced the component-based 'significant component' approach with a risk-based approach: the group auditor identifies risks of material misstatement of the group financial statements and decides where and how to respond, and component auditors are treated as members of the engagement team under the group engagement partner's direction and supervision, rather than as separate auditors whose work is merely referred to.

The objectives of the group auditor are to determine whether to act as auditor of the group financial statements; to plan and perform the group audit to obtain sufficient appropriate evidence about the group financial statements, including through involvement of component auditors; to communicate clearly with component auditors about the scope and timing of their work and their findings; and to evaluate the evidence obtained as a basis for forming the group opinion. The group engagement partner is responsible for the direction, supervision and review of the whole engagement and for the group audit opinion, and that responsibility is not reduced by the involvement of component auditors.

2Key definitions

Group and group financial statements
A reporting entity for which group financial statements are prepared; financial statements that include the financial information of more than one entity or business unit through a consolidation process (a parent and its subsidiaries, joint ventures, associates, branches and divisions).
Component
An entity, business unit, function or business activity, or some combination of these, determined by the group auditor for purposes of planning and performing audit procedures in a group audit. Components are defined by the group auditor for audit purposes, not simply by the group's legal structure.
Component auditor
An auditor who performs audit work related to a component for purposes of the group audit. Under the revision component auditors are part of the engagement team, so ISA 220's requirements on direction, supervision and review, and on competence and ethics, apply to them through the group engagement partner.
Group engagement partner and group auditor
The engagement partner responsible for the group audit engagement and its performance and for the auditor's report on the group financial statements; 'group auditor' refers to the group engagement partner and the members of the engagement team other than component auditors.
Consolidation process
The recognition, measurement, presentation and disclosure of the financial information of the components in the group financial statements by way of consolidation, proportionate consolidation, or the equity or cost methods; and the aggregation of the financial information of business units into the reporting entity's own statements.
Group-wide controls
Controls designed, implemented and maintained by group management over group financial reporting, including the consolidation process, group accounting policies and manuals, and the monitoring of component reporting.
Component performance materiality
The amount set by the group auditor for a component, lower than group performance materiality, to reduce to an appropriately low level the probability that the aggregate of uncorrected and undetected misstatements in the group financial statements exceeds group materiality.

3Requirements

Acceptance and continuance

  • The group engagement partner determines whether sufficient appropriate evidence can reasonably be expected to be obtained in relation to the consolidation process and the financial information of the components, considering restrictions on access to information or to component auditors (a component in a jurisdiction with secrecy laws, a joint venture partner who controls the books, a refusal by group management to give access).
  • If the group engagement partner concludes that sufficient appropriate evidence cannot be obtained and the effect would be a disclaimer of opinion, the group auditor does not accept the engagement (or withdraws), unless law or regulation requires it, in which case a disclaimer is given.
  • The terms of the group audit engagement are agreed under ISA 210, including the group auditor's expectations about access to information and to component management and auditors.

Overall strategy, plan and understanding

  • Establish the overall group audit strategy and group audit plan under ISA 300, with the group engagement partner involved in and responsible for planning.
  • Obtain an understanding of the group, its components and their environments, the applicable framework, the group-wide controls, and the consolidation process, including the instructions issued by group management to components, sufficient to identify and assess risks at the group financial statement level and the assertion level.
  • Determine the components for audit purposes, and determine the nature, timing and extent of the group auditor's involvement in the work of component auditors: understanding whether the component auditor understands and will comply with the ethical requirements including independence, has the competence and capabilities, and operates in a regulatory environment that allows the group auditor to be involved in their work.
  • Set group materiality, group performance materiality, and component performance materiality where components are audited for group purposes, together with the threshold above which misstatements are communicated to the group auditor (clearly trivial at group level).

Responding to assessed risks

The group auditor designs and performs further audit procedures (including by component auditors) responsive to the assessed risks at the assertion level for the group financial statements, deciding for each significant class of transactions, account balance or disclosure at which component(s) the work will be performed and by whom. The scope of work at a component is driven by the risks of material misstatement of the group financial statements that relate to it, not by whether the component is individually 'significant': it may be an audit of the component's financial information using component performance materiality, audit procedures on specific balances or disclosures, specified procedures responsive to a group risk, analytical procedures at the group level for components whose aggregate is not material, or tests of group-wide controls. Centralised activities (a shared service centre processing payroll for every subsidiary) may be tested once, at the centre.

  • Communicate the group auditor's requirements to component auditors on a timely basis: the work to be performed, its use, and the form and content of the communication back; ethics and independence requirements; component performance materiality and the clearly trivial threshold; identified significant risks relevant to the component; the list of related parties; and the timetable for reporting.
  • Direct and supervise the component auditors and review their work under ISA 220, with the nature, timing and extent of involvement scaled to the assessed risks and the competence of the component auditor: participating in risk assessment discussions, reviewing the component auditor's documentation of significant matters, visiting the component, attending closing meetings.
  • Request component auditors to communicate their findings: whether they complied with the group auditor's instructions, identified deficiencies in internal control, instances of fraud or non-compliance, related parties not on the group list, uncorrected and corrected misstatements above the threshold, indicators of management bias, significant matters communicated or expected to be communicated to component management or those charged with governance, and any other matters relevant to the group audit or to the opinion, including limitations on scope.

The consolidation process and subsequent events

  • Evaluate the appropriateness, completeness and accuracy of consolidation adjustments and reclassifications, and evaluate whether any fraud risk factors or indicators of management bias exist in them: intra-group eliminations, unrealised profits on intra-group sales, fair value adjustments on acquisition, goodwill and impairment, non-controlling interests, harmonisation of accounting policies, translation of foreign operations.
  • If a component's financial information has not been prepared in accordance with the group's accounting policies, evaluate whether it has been appropriately adjusted; if a component has a different reporting date, evaluate whether appropriate adjustments have been made under the framework (IFRS 10 permits a gap of up to three months with adjustments for significant transactions).
  • Reconcile the financial information reported by components to the consolidation package and the group financial statements, and evaluate that the reconciling items are appropriate.
  • Perform, or request component auditors to perform, procedures on subsequent events at the components between the dates of their financial information and the date of the group auditor's report.

Evaluating the evidence and concluding

The group auditor evaluates the component auditors' communications and the adequacy of their work, discusses significant matters with the component auditor, component management or group management as appropriate, and determines whether it is necessary to review other parts of the component auditor's documentation. Where the component auditor's work is insufficient, the group auditor determines what additional procedures are to be performed and by whom. Finally, the group engagement partner evaluates the effect on the group opinion of any uncorrected misstatements (whether identified by the group auditor or communicated by component auditors) and of any instances where sufficient appropriate evidence could not be obtained, and stands back to determine whether the group audit has been conducted in accordance with the ISAs and whether sufficient appropriate evidence has been obtained on the group financial statements as a whole.

4Documentation and reporting

  • Document the basis for determining the components and the scope of work at each, the nature, timing and extent of the group auditor's involvement in and review of the work of component auditors (including the documentation reviewed and the conclusions), the written communications between the group auditor and the component auditors about the group auditor's requirements, and any matters that were the subject of significant judgement, including where access restrictions were overcome or affected the opinion.
  • The auditor's report on the group financial statements does not refer to a component auditor unless required by law or regulation; where such reference is required, the report indicates that the reference does not diminish the group auditor's responsibility for the group opinion. The group engagement partner signs and takes sole responsibility.
  • Communicate with group management and those charged with governance of the group under ISA 260 and ISA 265: an overview of the type of work to be performed on components and the group auditor's planned involvement, deficiencies in group-wide controls and in components' controls, fraud identified or suspected, limitations on scope, and significant findings including those raised by component auditors.
  • Where group management restricts access to a component and sufficient appropriate evidence cannot be obtained by alternative means, the group opinion is qualified or disclaimed for a limitation on scope under ISA 705, depending on the pervasiveness of the component to the group.

5Examinable focus

What KASNEB tests

Group audits are a core Advanced Auditing topic. Expect a scenario with a parent, several subsidiaries (one overseas, one audited by another firm, one newly acquired), a joint venture and an associate, and questions on: acceptance considerations, the matters to understand about a component auditor before relying on them (ethics and independence, competence, regulatory environment, cooperation), the group auditor's involvement and the communications in both directions, the audit of the consolidation (eliminations, fair values, goodwill, NCI, translation, differing year ends and policies), and reporting when access to a component is restricted. State clearly that the group engagement partner is solely responsible for the group opinion and that component auditors are not named in the report. The 2022 revision's shift from 'significant components' to a risk-based scoping is a current discussion point.