HKSA 330 - Responses to Assessed Risks
HKSA 330 - The Auditor's Responses to Assessed Risks
1. INTRODUCTION
Scope of this HKSA
HKSA 330 deals with the auditor's responsibility to design and implement responses to the risks of material misstatement identified and assessed by the auditor in accordance with HKSA 315 (Revised 2019) in an audit of financial statements.
Effective Date
This HKSA is effective for audits of financial statements for periods beginning on or after 15 December 2009.
Objective
The objective of the auditor is to obtain sufficient appropriate audit evidence regarding the assessed risks of material misstatement, through designing and implementing appropriate responses to those risks.
Definitions
For purposes of the HKSAs, the following terms have the meanings attributed below:
(a) Substantive procedure – An audit procedure designed to detect material misstatements at the assertion level. Substantive procedures comprise:
(b) Test of controls – An audit procedure designed to evaluate the operating effectiveness of controls in preventing, or detecting and correcting, material misstatements at the assertion level.
2. REQUIREMENTS
2.1 Overall Responses (Paragraph 5)
Requirement: The auditor shall design and implement overall responses to address the assessed risks of material misstatement at the financial statement level.
Application Guidance (A1-A3):
Overall responses to address the assessed risks of material misstatement at the financial statement level may include:
The assessment of the risks of material misstatement at the financial statement level, and thereby the auditor's overall responses, is affected by the auditor's understanding of the control environment. An effective control environment may allow the auditor to have more confidence in internal control and the reliability of audit evidence generated internally within the entity and thus, for example, allow the auditor to conduct some audit procedures at an interim date rather than at the period end.
Deficiencies in the control environment have the opposite effect; for example, the auditor may respond to an ineffective control environment by:
Such considerations have a significant bearing on the auditor's general approach, for example, an emphasis on substantive procedures (substantive approach), or an approach that uses tests of controls as well as substantive procedures (combined approach).
2.2 Audit Procedures Responsive to the Assessed Risks of Material Misstatement at the Assertion Level (Paragraphs 6-23)
2.2.1 General Requirement (Paragraph 6)
Requirement: The auditor shall design and perform further audit procedures whose nature, timing and extent are based on and are responsive to the assessed risks of material misstatement at the assertion level.
2.2.2 Designing Further Audit Procedures (Paragraph 7)
Requirement: In designing the further audit procedures to be performed, the auditor shall:
>
(a) Consider the reasons for the assessment given to the risk of material misstatement at the assertion level for each significant class of transactions, account balance, and disclosure, including:
- (i) The likelihood and magnitude of misstatement due to the particular characteristics of the significant class of transactions, account balance, or disclosure (that is, the inherent risk); and
- (ii) Whether the risk assessment takes account of controls that address the risk of material misstatement (that is, the control risk), thereby requiring the auditor to obtain audit evidence to determine whether the controls are operating effectively (that is, the auditor plans to test the operating effectiveness of controls in determining the nature, timing and extent of substantive procedures); and
>
(b) Obtain more persuasive audit evidence the higher the auditor's assessment of risk.
Application Guidance (A4-A19):
The Nature, Timing and Extent of Further Audit Procedures (A4-A8):
The auditor's assessment of the identified risks of material misstatement at the assertion level provides a basis for considering the appropriate audit approach for designing and performing further audit procedures. For example, the auditor may determine that:
(a) Only by performing tests of controls may the auditor achieve an effective response to the assessed risk of material misstatement for a particular assertion;
(b) Performing only substantive procedures is appropriate for particular assertions and, therefore, the auditor excludes the effect of controls from the assessment of the risk of material misstatement. This may be because the auditor has not identified a risk for which substantive procedures alone cannot provide sufficient appropriate audit evidence and therefore is not required to test the operating effectiveness of controls. Therefore, the auditor may not plan to test the operating effectiveness of controls in determining the nature, timing and extent of substantive procedures; or
(c) A combined approach using both tests of controls and substantive procedures is an effective approach.
The auditor need not design and perform further audit procedures where the assessment of the risk of material misstatement is below the acceptably low level. However, as required by paragraph 18, irrespective of the approach selected and the assessed risk of material misstatement, the auditor designs and performs substantive procedures for each material class of transactions, account balance, and disclosure.
Nature of audit procedure refers to its purpose (that is, test of controls or substantive procedure) and its type (that is, inspection, observation, inquiry, confirmation, recalculation, reperformance, or analytical procedure). The nature of the audit procedures is of most importance in responding to the assessed risks.
Timing of an audit procedure refers to when it is performed, or the period or date to which the audit evidence applies.
Extent of an audit procedure refers to the quantity to be performed, for example, a sample size or the number of observations of a control.
Responding to the Assessed Risks at the Assertion Level (A9-A18):
Nature (A9-A10):
HKSA 315 (Revised 2019) requires that the auditor's assessment of the risks of material misstatement at the assertion level is performed by assessing inherent risk and control risk. The auditor assesses inherent risk by assessing the likelihood and magnitude of a misstatement taking into account how, and the degree to which the inherent risk factors affect the susceptibility to misstatement of relevant assertions. The auditor's assessed risks, including the reasons for those assessed risks, may affect both the types of audit procedures to be performed and their combination.
For example, when an assessed risk is high, the auditor may confirm the completeness of the terms of a contract with the counterparty, in addition to inspecting the document. Further, certain audit procedures may be more appropriate for some assertions than others. For example, in relation to revenue, tests of controls may be most responsive to the assessed risk of material misstatement of the completeness assertion, whereas substantive procedures may be most responsive to the assessed risk of material misstatement of the occurrence assertion.
The reasons for the assessment given to a risk are relevant in determining the nature of audit procedures. For example, if an assessed risk is lower because of the particular characteristics of a class of transactions without consideration of the related controls, then the auditor may determine that substantive analytical procedures alone provide sufficient appropriate audit evidence. On the other hand, if the assessed risk is lower because the auditor plans to test the operating effectiveness of controls, and the auditor intends to base the substantive procedures on that low assessment, then the auditor performs tests of those controls, as required by paragraph 8(a).
Timing (A11-A14):
The auditor may perform tests of controls or substantive procedures at an interim date or at the period end. The higher the risk of material misstatement, the more likely it is that the auditor may decide it is more effective to perform substantive procedures nearer to, or at, the period end rather than at an earlier date, or to perform audit procedures unannounced or at unpredictable times. This is particularly relevant when considering the response to the risks of fraud.
Performing audit procedures before the period end may assist the auditor in identifying significant matters at an early stage of the audit, and consequently resolving them with the assistance of management or developing an effective audit approach to address such matters.
Certain audit procedures can be performed only at or after the period end, for example:
Relevant factors that influence the auditor's consideration of when to perform audit procedures include:
Extent (A15-A18):
The extent of an audit procedure judged necessary is determined after considering the materiality, the assessed risk, and the degree of assurance the auditor plans to obtain. When a single purpose is met by a combination of procedures, the extent of each procedure is considered separately. In general, the extent of audit procedures increases as the risk of material misstatement increases.
The use of computer-assisted audit techniques (CAATs) may enable more extensive testing of electronic transactions and account files, which may be useful when the auditor decides to modify the extent of testing.
Higher Assessments of Risk (A19):
When obtaining more persuasive audit evidence because of a higher assessment of risk, the auditor may increase the quantity of the evidence, or obtain evidence that is more relevant or reliable, for example, by placing more emphasis on obtaining third party evidence or by obtaining corroborating evidence from a number of independent sources.
2.3 Tests of Controls (Paragraphs 8-17)
2.3.1 Requirement to Perform Tests of Controls (Paragraph 8)
Requirement: The auditor shall design and perform tests of controls to obtain sufficient appropriate audit evidence as to the operating effectiveness of controls if:
>
(a) The auditor's assessment of risks of material misstatement at the assertion level includes an expectation that the controls are operating effectively (that is, the auditor plans to test the operating effectiveness of controls in determining the nature, timing and extent of substantive procedures); or
>
(b) Substantive procedures alone cannot provide sufficient appropriate audit evidence at the assertion level.
2.3.2 Persuasiveness of Audit Evidence (Paragraph 9)
Requirement: In designing and performing tests of controls, the auditor shall obtain more persuasive audit evidence the greater the reliance the auditor places on the effectiveness of a control.
2.3.3 Nature and Extent of Tests of Controls (Paragraph 10)
Requirement: In designing and performing tests of controls, the auditor shall:
>
(a) Perform other audit procedures in combination with inquiry to obtain audit evidence about the operating effectiveness of the controls, including:
- (i) How the controls were applied at relevant times during the period under audit;
- (ii) The consistency with which they were applied; and
- (iii) By whom or by what means they were applied.
>
(b) To the extent not already addressed, determine whether the controls to be tested depend upon other controls (indirect controls), and, if so, whether it is necessary to obtain audit evidence supporting the effective operation of those indirect controls.
Application Guidance (A20-A32):
Designing and Performing Tests of Controls (A20-A24):
Tests of controls are performed only on those controls that the auditor has determined are suitably designed to prevent, or detect and correct, a material misstatement in a relevant assertion, and the auditor plans to test those controls. If substantially different controls were used at different times during the period under audit, each is considered separately.
Testing the operating effectiveness of controls is different from obtaining an understanding of and evaluating the design and implementation of controls. However, the same types of audit procedures are used. The auditor may, therefore, decide it is efficient to test the operating effectiveness of controls at the same time as evaluating their design and determining that they have been implemented.
Although some risk assessment procedures may not have been specifically designed as tests of controls, they may nevertheless provide audit evidence about the operating effectiveness of the controls and, consequently, serve as tests of controls.
The auditor may design a test of controls to be performed concurrently with a test of details on the same transaction, also known as a dual-purpose test.
In some cases, the auditor may find it impossible to design effective substantive procedures that by themselves provide sufficient appropriate audit evidence at the assertion level. This may occur when an entity conducts its business using IT and no documentation of transactions is produced or maintained, other than through the IT system.
Audit Evidence and Intended Reliance (A25):
A higher level of assurance may be sought about the operating effectiveness of controls when the approach adopted consists primarily of tests of controls, in particular where it is not possible or practicable to obtain sufficient appropriate audit evidence only from substantive procedures.
Other audit procedures in combination with inquiry (A26-A27):
Inquiry alone is not sufficient to test the operating effectiveness of controls. Accordingly, other audit procedures are performed in combination with inquiry. In this regard, inquiry combined with inspection or reperformance may provide more assurance than inquiry and observation, since an observation is pertinent only at the point in time at which it is made.
Extent of tests of controls (A28-A31):
When more persuasive audit evidence is needed regarding the effectiveness of a control, it may be appropriate to increase the extent of testing of the control. Matters the auditor may consider in determining the extent of tests of controls include:
Because of the inherent consistency of IT processing, it may not be necessary to increase the extent of testing of an automated control. An automated control can be expected to function consistently unless the IT application is changed.
Testing of indirect controls (A32):
In some circumstances, it may be necessary to obtain audit evidence supporting the effective operation of indirect controls (e.g., general IT controls). General IT controls may have been identified in accordance with HKSA 315 (Revised 2019) because of their support of the operating effectiveness of automated controls or due to their support in maintaining the integrity of information used in the entity's financial reporting, including system-generated reports.
2.3.4 Timing of Tests of Controls (Paragraphs 11-15)
Requirement (Paragraph 11): The auditor shall test controls for the particular time, or throughout the period, for which the auditor intends to rely on those controls, subject to paragraphs 12 and 15 below, in order to provide an appropriate basis for the auditor's intended reliance.
Using audit evidence obtained during an interim period (Paragraph 12):
Requirement: If the auditor obtains audit evidence about the operating effectiveness of controls during an interim period, the auditor shall:
>
(a) Obtain audit evidence about significant changes to those controls subsequent to the interim period; and
>
(b) Determine the additional audit evidence to be obtained for the remaining period.
Application Guidance (A33-A35):
Audit evidence pertaining only to a point in time may be sufficient for the auditor's purpose, for example, when testing controls over the entity's physical inventory counting at the period end. If, on the other hand, the auditor intends to rely on a control over a period, tests that are capable of providing audit evidence that the control operated effectively at relevant times during that period are appropriate.
Relevant factors in determining what additional audit evidence to obtain about controls that were operating during the period remaining after an interim period include:
Using audit evidence obtained in previous audits (Paragraphs 13-14):
Requirement (Paragraph 13): In determining whether it is appropriate to use audit evidence about the operating effectiveness of controls obtained in previous audits, and, if so, the length of the time period that may elapse before retesting a control, the auditor shall consider the following:
>
(a) The effectiveness of other components of the entity's system of internal control, including the control environment, the entity's process to monitor the system of internal controls, and the entity's risk assessment process;
>
(b) The risks arising from the characteristics of the control, including whether it is manual or automated;
>
(c) The effectiveness of general IT controls;
>
(d) The effectiveness of the control and its application by the entity, including the nature and extent of deviations in the application of the control noted in previous audits, and whether there have been personnel changes that significantly affect the application of the control;
>
(e) Whether the lack of a change in a particular control poses a risk due to changing circumstances; and
>
(f) The risks of material misstatement and the extent of reliance on the control.
Requirement (Paragraph 14): If the auditor plans to use audit evidence from a previous audit about the operating effectiveness of specific controls, the auditor shall establish the continuing relevance and reliability of that evidence by obtaining audit evidence about whether significant changes in those controls have occurred subsequent to the previous audit. The auditor shall obtain this evidence by performing inquiry combined with observation or inspection, to confirm the understanding of those specific controls, and:
>
(a) If there have been changes that affect the continuing relevance of the audit evidence from the previous audit, the auditor shall test the controls in the current audit.
>
(b) If there have not been such changes, the auditor shall test the controls at least once in every third audit, and shall test some controls each audit to avoid the possibility of testing all the controls on which the auditor intends to rely in a single audit period with no testing of controls in the subsequent two audit periods.
Application Guidance (A36-A40):
In certain circumstances, audit evidence obtained from previous audits may provide audit evidence where the auditor performs audit procedures to establish its continuing relevance and reliability.
Changes may affect the relevance and reliability of the audit evidence obtained in previous audits such that there may no longer be a basis for continued reliance.
The auditor's decision on whether to rely on audit evidence obtained in previous audits for controls that:
(a) have not changed since they were last tested; and
(b) are not controls that mitigate a significant risk,
is a matter of professional judgment. In addition, the length of time between retesting such controls is also a matter of professional judgment, but is required by paragraph 14(b) to be at least once in every third year.
Factors that may decrease the period for retesting a control, or result in not relying on audit evidence obtained in previous audits at all, include:
Controls over significant risks (Paragraph 15):
Requirement: If the auditor intends to rely on controls over a risk the auditor has determined to be a significant risk, the auditor shall test those controls in the current period.
2.3.5 Evaluating the Operating Effectiveness of Controls (Paragraphs 16-17)
Requirement (Paragraph 16): When evaluating the operating effectiveness of controls upon which the auditor intends to rely, the auditor shall evaluate whether misstatements that have been detected by substantive procedures indicate that controls are not operating effectively. The absence of misstatements detected by substantive procedures, however, does not provide audit evidence that controls related to the assertion being tested are effective.
Requirement (Paragraph 17): If deviations from controls upon which the auditor intends to rely are detected, the auditor shall make specific inquiries to understand these matters and their potential consequences, and shall determine whether:
>
(a) The tests of controls that have been performed provide an appropriate basis for reliance on the controls;
>
(b) Additional tests of controls are necessary; or
>
(c) The risks of material misstatement need to be addressed using substantive procedures.
Application Guidance (A41-A42):
A material misstatement detected by the auditor's procedures is a strong indicator of the existence of a significant deficiency in internal control.
The concept of effectiveness of the operation of controls recognizes that some deviations in the way controls are applied by the entity may occur. Deviations from prescribed controls may be caused by such factors as changes in key personnel, significant seasonal fluctuations in volume of transactions and human error. The detected rate of deviation, in particular in comparison with the expected rate, may indicate that the control cannot be relied on to reduce risk at the assertion level to that assessed by the auditor.
2.4 Substantive Procedures (Paragraphs 18-23)
2.4.1 General Requirement (Paragraph 18)
Requirement: Irrespective of the assessed risks of material misstatement, the auditor shall design and perform substantive procedures for each material class of transactions, account balance, and disclosure.
2.4.2 External Confirmation Procedures (Paragraph 19)
Requirement: The auditor shall consider whether external confirmation procedures are to be performed as substantive audit procedures.
Application Guidance (A50-A53):
External confirmation procedures frequently are relevant when addressing assertions associated with account balances and their elements, but need not be restricted to these items. For example, the auditor may request external confirmation of the terms of agreements, contracts, or transactions between an entity and other parties.
Situations where external confirmation procedures may provide relevant audit evidence include:
Although external confirmations may provide relevant audit evidence relating to certain assertions, there are some assertions for which external confirmations provide less relevant audit evidence. For example, external confirmations provide less relevant audit evidence relating to the recoverability of accounts receivable balances, than they do of their existence.
Factors that may assist the auditor in determining whether external confirmation procedures are to be performed as substantive audit procedures include:
2.4.3 Substantive Procedures Related to the Financial Statement Closing Process (Paragraph 20)
Requirement: The auditor's substantive procedures shall include the following audit procedures related to the financial statement closing process:
>
(a) Agreeing or reconciling information in the financial statements with the underlying accounting records, including agreeing or reconciling information in disclosures, whether such information is obtained from within or outside of the general and subsidiary ledgers; and
>
(b) Examining material journal entries and other adjustments made during the course of preparing the financial statements.
Application Guidance (A54):
The nature, and also the extent, of the auditor's substantive procedures related to the financial statement closing process depends on the nature and complexity of the entity's financial reporting process and the related risks of material misstatement.
2.4.4 Substantive Procedures Responsive to Significant Risks (Paragraph 21)
Requirement: If the auditor has determined that an assessed risk of material misstatement at the assertion level is a significant risk, the auditor shall perform substantive procedures that are specifically responsive to that risk. When the approach to a significant risk consists only of substantive procedures, those procedures shall include tests of details.
Application Guidance (A55):
Paragraph 21 of this HKSA requires the auditor to perform substantive procedures that are specifically responsive to risks the auditor has determined to be significant risks. Audit evidence in the form of external confirmations received directly by the auditor from appropriate confirming parties may assist the auditor in obtaining audit evidence with the high level of reliability that the auditor requires to respond to significant risks of material misstatement, whether due to fraud or error.
For example, if the auditor identifies that management is under pressure to meet earnings expectations, there may be a risk that management is inflating sales by improperly recognizing revenue related to sales agreements with terms that preclude revenue recognition or by invoicing sales before shipment. In these circumstances, the auditor may, for example, design external confirmation procedures not only to confirm outstanding amounts, but also to confirm the details of the sales agreements, including date, any rights of return and delivery terms.
2.4.5 Timing of Substantive Procedures (Paragraphs 22-23)
Requirement (Paragraph 22): If substantive procedures are performed at an interim date, the auditor shall cover the remaining period by performing:
>
(a) substantive procedures, combined with tests of controls for the intervening period; or
>
(b) if the auditor determines that it is sufficient, further substantive procedures only,
>
that provide a reasonable basis for extending the audit conclusions from the interim date to the period end.
Requirement (Paragraph 23): If misstatements that the auditor did not expect when assessing the risks of material misstatement are detected at an interim date, the auditor shall evaluate whether the related assessment of risk and the planned nature, timing or extent of substantive procedures covering the remaining period need to be modified.
Application Guidance (A56-A60):
In most cases, audit evidence from a previous audit's substantive procedures provides little or no audit evidence for the current period. There are, however, exceptions, for example, a legal opinion obtained in a previous audit related to the structure of a securitization to which no changes have occurred, may be relevant in the current period.
In some circumstances, the auditor may determine that it is effective to perform substantive procedures at an interim date, and to compare and reconcile information concerning the balance at the period end with the comparable information at the interim date.
Performing substantive procedures at an interim date without undertaking additional procedures at a later date increases the risk that the auditor will not detect misstatements that may exist at the period end. This risk increases as the remaining period is lengthened.
Factors such as the following may influence whether to perform substantive procedures at an interim date:
When the auditor concludes that the planned nature, timing or extent of substantive procedures covering the remaining period need to be modified as a result of unexpected misstatements detected at an interim date, such modification may include extending or repeating the procedures performed at the interim date at the period end.
2.5 Adequacy of Presentation of the Financial Statements (Paragraph 24)
Requirement: The auditor shall perform audit procedures to evaluate whether the overall presentation of the financial statements is in accordance with the applicable financial reporting framework. In making this evaluation, the auditor shall consider whether the financial statements are presented in a manner that reflects the appropriate:
>
- Classification and description of financial information and the underlying transactions, events and conditions; and
- Presentation, structure and content of the financial statements.
Application Guidance (A61):
Evaluating the appropriate presentation, arrangement and content of the financial statements includes, for example, consideration of the terminology used as required by the applicable financial reporting framework, the level of detail provided, the aggregation and disaggregation of amounts and the bases of amounts set forth.
2.6 Evaluating the Sufficiency and Appropriateness of Audit Evidence (Paragraphs 25-27)
Requirement (Paragraph 25): Based on the audit procedures performed and the audit evidence obtained, the auditor shall evaluate before the conclusion of the audit whether the assessments of the risks of material misstatement at the assertion level remain appropriate.
Requirement (Paragraph 26): The auditor shall conclude whether sufficient appropriate audit evidence has been obtained. In forming an opinion, the auditor shall consider all relevant audit evidence, regardless of whether it appears to corroborate or to contradict the assertions in the financial statements.
Requirement (Paragraph 27): If the auditor has not obtained sufficient appropriate audit evidence related to a relevant assertion about a class of transactions, account balance or disclosure, the auditor shall attempt to obtain further audit evidence. If the auditor is unable to obtain sufficient appropriate audit evidence, the auditor shall express a qualified opinion or disclaim an opinion on the financial statements.
Application Guidance (A62-A64):
An audit of financial statements is a cumulative and iterative process. As the auditor performs planned audit procedures, the audit evidence obtained may cause the auditor to modify the nature, timing or extent of other planned audit procedures. Information may come to the auditor's attention that differs significantly from the information on which the risk assessment was based. For example:
The auditor cannot assume that an instance of fraud or error is an isolated occurrence. Therefore, the consideration of how the detection of a misstatement affects the assessed risks of material misstatement is important in determining whether the assessment remains appropriate.
The auditor's judgment as to what constitutes sufficient appropriate audit evidence is influenced by such factors as:
2.7 Documentation (Paragraphs 28-30)
Requirement (Paragraph 28): The auditor shall include in the audit documentation:
>
(a) The overall responses to address the assessed risks of material misstatement at the financial statement level, and the nature, timing and extent of the further audit procedures performed;
>
(b) The linkage of those procedures with the assessed risks at the assertion level; and
>
(c) The results of the audit procedures, including the conclusions where these are not otherwise clear.
Requirement (Paragraph 29): If the auditor plans to use audit evidence about the operating effectiveness of controls obtained in previous audits, the auditor shall include in the audit documentation the conclusions reached about relying on such controls that were tested in a previous audit.
Requirement (Paragraph 30): The auditor's documentation shall demonstrate that information in the financial statements agrees or reconciles with the underlying accounting records, including agreeing or reconciling disclosures, whether such information is obtained from within or outside of the general and subsidiary ledgers.
Application Guidance (A65):
The form and extent of audit documentation is a matter of professional judgment, and is influenced by the nature, size and complexity of the entity and its system of internal control, availability of information from the entity and the audit methodology and technology used in the audit.
2.8 Conformity and Compliance with International Standards on Auditing (Paragraph 31)
As of March 2023, this HKSA conforms with International Standard on Auditing (ISA) 330, The Auditor's Responses To Assessed Risks. Compliance with the requirements of this HKSA ensures compliance with ISA 330.
3. KEY CONCEPTS SUMMARY
The Three Dimensions of Further Audit Procedures
| Dimension | Definition | Key Considerations |
|---|---|---|
| Nature | Purpose (test of controls vs. substantive procedure) and type (inspection, observation, inquiry, confirmation, recalculation, reperformance, analytical procedure) | Most important dimension; must be responsive to the assessed risk |
| Timing | When performed, or the period/date to which audit evidence applies | Higher risk → perform nearer period end; interim procedures require coverage of remaining period |
| Extent | Quantity to be performed (sample size, number of observations) | Increases as risk increases; CAATs may enable more extensive testing |
Audit Approaches
| Approach | Description | When Appropriate |
|---|---|---|
| Substantive Approach | Emphasis on substantive procedures only | When controls are not relied upon; when substantive procedures alone can provide sufficient evidence |
| Combined Approach | Tests of controls + substantive procedures | When controls are expected to be effective; when substantive procedures alone cannot provide sufficient evidence |
Key Requirements Summary Table
| Paragraph | Requirement | Key Point |
|---|---|---|
| 5 | Overall responses | Address financial statement level risks |
| 6 | Further audit procedures | Nature, timing, extent based on assessed risks |
| 7(a) | Consider reasons for risk assessment | Inherent risk factors and control risk |
| 7(b) | More persuasive evidence for higher risk | Increase quantity or quality of evidence |
| 8 | Tests of controls required when | (a) Expect controls effective; or (b) Substantive procedures alone insufficient |
| 10(a) | Inquiry alone insufficient | Must combine with other procedures |
| 11 | Test controls for period of intended reliance | Point-in-time or throughout period |
| 14(b) | Retest unchanged controls | At least once every third audit |
| 15 | Significant risk controls | Must test in current period |
| 18 | Substantive procedures always required | For each material class/balance/disclosure |
| 21 | Significant risk substantive procedures | Must include tests of details if only substantive approach |
| 24 | Evaluate financial statement presentation | Classification, description, structure, content |
| 25-27 | Evaluate sufficiency/appropriateness of evidence | Consider all evidence; modify approach if needed |
| 28-30 | Documentation | Overall responses, linkage, results, conclusions |
---
❓ Ready to Test Your Knowledge?
50 MCQs covering all sections. Timed at 1.25 min each (62.5 min total).
📝 Start Q&A →🖨️ Save as PDF