AS · Certificate Level

The Process of Assurance

The audit process from planning through to evidence gathering: audit planning (understanding the entity and its environment, risk assessment procedures), materiality (overall materiality, performance materiality, specific materiality — with a worked calculation example), the distinction between the overall audit strategy and the detailed audit plan, audit evidence (sufficiency and appropriateness, relevance and reliability), the seven types of audit procedure (inspection, observation, inquiry, confirmation, recalculation, reperformance, analytical procedures), and audit documentation requirements under ISA 230.

35 min read

Learning Objectives

  • Explain the importance of audit planning and the key activities involved
  • Describe how the auditor obtains an understanding of the entity and its environment as a basis for risk assessment
  • Explain the concept of materiality and calculate overall materiality and performance materiality from given data
  • Distinguish between the overall audit strategy and the detailed audit plan
  • Explain the concepts of sufficiency and appropriateness of audit evidence
  • Describe the factors affecting the reliability of audit evidence
  • Identify and explain the seven types of audit procedure
  • Explain the purpose and key requirements of audit documentation under ISA 230

Audit Planning

Effective planning is essential to ensure the audit is performed efficiently and effectively. ISA 300 Planning an Audit of Financial Statements requires the auditor to plan the audit so that it is performed in an effective manner.

Why is planning important?

  • Helps the auditor focus attention on the most important areas (areas of higher risk, material account balances)
  • Ensures adequate resources are allocated — the right people with the right skills at the right time
  • Enables proper supervision and coordination of the audit team
  • Helps identify and resolve potential problems early in the engagement
  • Provides a basis for controlling the audit — monitoring progress against the plan

Key planning activities include:

  • Performing engagement acceptance/continuance procedures (ethics, independence, competence)
  • Obtaining an understanding of the entity and its environment (see below)
  • Performing risk assessment procedures to identify and assess risks of material misstatement
  • Determining materiality
  • Developing the overall audit strategy and detailed audit plan
  • Considering the nature, timing, and extent of audit procedures
  • Determining the engagement team composition, including the need for specialists

Understanding the Entity and Its Environment

ISA 315 (Revised 2019) requires the auditor to obtain an understanding of the entity and its environment as a basis for identifying and assessing the risks of material misstatement. This understanding includes:

External factors:

  • Industry conditions: The competitive environment, market demand, industry trends, seasonality, technological changes, regulatory requirements
  • The regulatory environment: Applicable laws and regulations (e.g., Companies Act 2006, tax law, sector-specific regulations), the financial reporting framework (IFRS, UK GAAP)
  • Economic conditions: General economic health (recession, growth), interest rates, inflation, exchange rates, availability of financing

Internal factors:

  • Nature of the entity: Ownership structure, governance, business model, operations, revenue sources, key customers and suppliers
  • Accounting policies: Policies selected and applied, changes in policies, appropriateness for the entity's circumstances
  • Objectives, strategies, and business risks: The entity's strategic direction, risk of material misstatement arising from business risks (e.g., new products, expansion, restructuring)
  • Financial performance: Revenue trends, profitability, cash flows, key performance indicators, budgets and forecasts
  • The entity's internal control system (covered in the Internal Controls topic)

The auditor obtains this understanding through risk assessment procedures: inquiries of management and others, analytical procedures (preliminary), observation and inspection.

Materiality

Materiality is a key concept that drives the entire audit. It determines the scope of the audit, the nature and extent of procedures, and the evaluation of misstatements.

ISA 320 Materiality in Planning and Performing an Audit defines materiality as:

Misstatements, including omissions, are considered to be material if they, individually or in the aggregate, could reasonably be expected to influence the economic decisions of users taken on the basis of the financial statements.

Materiality is not a fixed number — it involves professional judgement and considers both the size (quantitative) and nature (qualitative) of misstatements.

Overall Materiality (Financial Statement Materiality)

Overall materiality is the maximum amount by which the financial statements could be misstated before the misstatement would be expected to influence users' decisions. It is set at the planning stage and may be revised during the audit if circumstances change.

Common benchmarks used to calculate overall materiality:

BenchmarkTypical percentage rangeWhen typically used
Profit before tax5% – 10%Profit-oriented entities (most common)
Revenue0.5% – 1%Entities with volatile or low profits
Total assets1% – 2%Asset-based entities (e.g., property companies, investment funds)
Gross profit1% – 2%Trading companies where GP is a stable measure
Total equity2% – 5%Entities where equity is the key user focus
Total expenditure0.5% – 2%Not-for-profit entities (no profit motive)

The choice of benchmark depends on what users are most interested in. For a commercial company, profit before tax is typically the most relevant measure because investors focus on earnings. The specific percentage within the range depends on the auditor's professional judgement, considering factors such as entity size, industry, ownership structure, and risk.

Qualitative considerations: Some misstatements may be material by nature regardless of their size — e.g., related party transactions, directors' remuneration, illegal acts, breach of loan covenants, items that change a profit to a loss.

Performance Materiality

Performance materiality is the amount(s) set by the auditor at less than overall materiality to reduce to an appropriately low level the probability that the aggregate of uncorrected and undetected misstatements exceeds overall materiality.

In simple terms: the auditor tests at a lower threshold than overall materiality to provide a "buffer" for misstatements that are not detected. This is necessary because:

  • The auditor tests samples, not entire populations — some misstatements will inevitably go undetected
  • Multiple individually immaterial misstatements could add up to a material aggregate amount

Performance materiality is typically set at 50% to 75% of overall materiality, depending on the auditor's assessment of risk:

  • Higher risk (first-year audit, poor internal controls, history of misstatements) → lower performance materiality (e.g., 50% of overall)
  • Lower risk (established client, strong controls, clean prior audit) → higher performance materiality (e.g., 75% of overall)

Clearly Trivial Threshold

The auditor also sets a "clearly trivial" threshold — misstatements below this amount are individually so small that they are not worth accumulating or reporting. This is typically set at about 5% of overall materiality (but can be higher). Misstatements below this threshold are disregarded entirely unless they are qualitatively material.

Overall Audit Strategy vs Detailed Audit Plan

ISA 300 distinguishes between two levels of planning documentation:

Overall audit strategy:

  • A high-level document that sets the scope, timing, and direction of the audit
  • It guides the development of the more detailed audit plan
  • Key contents include: identifying the characteristics of the engagement that define its scope, confirming reporting objectives and timing, determining materiality, identifying areas requiring special attention (significant risks, fraud risk, complex accounting), determining the engagement team composition and need for specialists, considering the results of preliminary engagement activities

Detailed audit plan:

  • A more detailed document that describes the nature, timing, and extent of:
    • Risk assessment procedures (to understand the entity and assess risks)
    • Further audit procedures at the assertion level (tests of controls and substantive procedures) responsive to the assessed risks
    • Other planned audit procedures required by ISAs
  • The audit plan is more specific than the strategy — it identifies which procedures will be performed, when, by whom, and to what extent for each significant account balance, class of transactions, and disclosure

Both the strategy and plan are living documents — they should be updated as the audit progresses and new information comes to light.

Audit Evidence — Sufficiency and Appropriateness

ISA 500 Audit Evidence requires the auditor to design and perform audit procedures to obtain sufficient appropriate evidence on which to base the audit opinion.

Sufficiency = the quantity of evidence. Is there enough? Factors affecting the quantity needed:

  • The assessed risk of material misstatement — higher risk requires more evidence
  • The quality of individual items of evidence — higher quality evidence means fewer items may be needed
  • The materiality of the item being tested — more material items require more evidence

Appropriateness = the quality of evidence, comprising:

1. Relevance: Does the evidence relate to the specific assertion being tested? Evidence that inventory exists (existence assertion) is not relevant to testing whether it is correctly valued (valuation assertion).

2. Reliability: The trustworthiness of the evidence. Reliability is influenced by:

More reliableLess reliable
Evidence from external independent sourcesEvidence generated internally by the entity
Evidence obtained directly by the auditorEvidence obtained indirectly or by inference
Documentary evidence (written/electronic)Oral evidence (verbal representations)
Original documentsCopies (photocopies, scans, faxes)
Evidence from entities with strong internal controlsEvidence from entities with weak internal controls

Important: Sufficiency and appropriateness are interrelated. Obtaining more evidence of low quality does not compensate for poor quality — the auditor needs evidence that is both sufficient and appropriate.

Management representations (written statements from management confirming their responsibilities and the accuracy of information provided) are evidence, but they are not a substitute for other audit evidence that the auditor could reasonably expect to obtain. They are the least reliable form of evidence because they come from the party being audited.

The Seven Types of Audit Procedure

ISA 500 identifies seven types of audit procedure that the auditor uses to obtain audit evidence:

#ProcedureDescriptionExample
1InspectionExamining records, documents, or tangible assets. Provides evidence of existence and, depending on what is inspected, of rights and obligations, valuation, and completeness.Inspecting a title deed for ownership of land; inspecting a sales invoice for details of a transaction; physically inspecting inventory for condition/damage.
2ObservationWatching a process or procedure being performed by others. Provides evidence of how a process is performed at a point in time — but not that it is always performed that way.Observing the entity's inventory count procedures; observing segregation of duties in the cash receipts process.
3InquirySeeking information from knowledgeable persons, both financial and non-financial, inside or outside the entity. Can be formal (written) or informal (oral).Asking management about accounting policies; inquiring of legal counsel about pending litigation; asking warehouse staff about inventory procedures.
4ConfirmationObtaining a direct written response from a third party (the confirming party) verifying information. A specific type of inquiry. Provides strong external evidence.Bank confirmation letter (confirming bank balance, loans, securities held); trade receivable circularisation (asking customers to confirm balances owed); confirmation from a solicitor regarding litigation.
5RecalculationChecking the mathematical accuracy of documents or records. Can be performed manually or electronically (e.g., using CAATs).Recalculating depreciation charges; checking the casting (addition) of a trial balance; verifying the extensions on a sales invoice (quantity × unit price).
6ReperformanceThe auditor's independent execution of procedures or controls that were originally performed by the entity's personnel.Re-performing a bank reconciliation prepared by the client; re-performing the ageing of trade receivables; re-performing a three-way match (purchase order, GRN, invoice) in the purchases cycle.
7Analytical proceduresEvaluating financial information by studying plausible relationships among both financial and non-financial data. Involves identifying and investigating significant fluctuations, unusual items, and unexpected relationships.Comparing current year revenue to prior year and to budget; calculating gross profit margin and comparing to prior year (investigating significant changes); computing the payroll cost as a function of headcount and average salary; comparing monthly revenue patterns for seasonality.

When are analytical procedures used?

  • Risk assessment stage (ISA 315): Mandatory — to help identify risks of material misstatement. Preliminary analytical procedures compare current year data to prior year, budget, industry benchmarks, and expected relationships.
  • Substantive testing (ISA 520): Optional — substantive analytical procedures can be used as a substantive procedure to obtain evidence about an assertion (e.g., proving the reasonableness of depreciation by independently calculating it).
  • Overall review (ISA 520): Mandatory at the completion stage — the auditor must perform analytical procedures near the end of the audit to form an overall conclusion as to whether the financial statements are consistent with the auditor's understanding of the entity.

Audit Documentation (ISA 230)

ISA 230 Audit Documentation requires the auditor to prepare documentation that provides a sufficient and appropriate record of the basis for the auditor's report and evidence that the audit was planned and performed in accordance with ISAs and legal/regulatory requirements.

Purpose of audit documentation ("working papers"):

  • Provides evidence that the audit was planned and performed in accordance with ISAs
  • Assists the engagement team in planning and performing the audit
  • Assists team members responsible for supervision in directing, supervising, and reviewing work
  • Enables the team to be accountable for its work
  • Provides a record of matters of continuing significance for future audits
  • Enables an experienced auditor having no previous connection with the audit to understand the nature, timing, and extent of procedures performed, results obtained, evidence gathered, and conclusions reached
  • Enables quality control reviews and external inspections (e.g., by the FRC's AQR team)

Key ISA 230 requirements:

  • Documentation must be prepared on a timely basis — during the audit, not retrospectively
  • The audit file must be assembled and completed within 60 days of the date of the auditor's report (the "administrative completion" deadline)
  • After assembly, audit documentation must not be deleted or discarded before the end of the retention period (typically at least 5 years from the date of the auditor's report, or longer if required by law or regulation)
  • Documentation of each audit procedure must include: who performed the work and the date, who reviewed it and the date, the identifying characteristics of items or matters tested (e.g., which invoices, which month, which customers), and the results and conclusions

Examiner Focus

Materiality calculations are tested regularly. You must be able to select an appropriate benchmark, justify your choice and the percentage used, and calculate both overall and performance materiality. Always explain WHY you chose the percentage — link it to the risk factors in the scenario.

Common Pitfall

Performance materiality is NOT the same as overall materiality. It is set LOWER to provide a buffer for undetected misstatements. Students often confuse the two or forget to calculate performance materiality separately. The typical range is 50%-75% of overall materiality.

Study Tip

Know the seven audit procedures by heart: Inspection, Observation, Inquiry, Confirmation, Recalculation, Reperformance, Analytical procedures. A useful mnemonic: "I Often Inquire, Confirm, Recalculate, Reperform, and Analyse." Exam questions often ask you to recommend specific procedures for specific assertions.

Watch Out

Analytical procedures are MANDATORY at two stages: (1) risk assessment (ISA 315 — preliminary analytics) and (2) overall review near the end of the audit (ISA 520). They are OPTIONAL as a substantive procedure during the main testing phase.

Examiner Focus

The distinction between the overall audit strategy (high-level scope, direction, timing) and the detailed audit plan (specific procedures, by whom, when, extent) is occasionally tested. Know that both are required by ISA 300 and both are living documents that may be updated.

Common Pitfall

External evidence (e.g., bank confirmation, solicitor letter) is more reliable than internal evidence (e.g., management representations, internally generated reports). Oral evidence (inquiry) alone is usually insufficient — it should be corroborated with documentary evidence. Management representations are the LEAST reliable form of evidence.

Key Definitions

Audit planning

The process of developing the overall audit strategy and detailed audit plan. Ensures the audit is performed effectively, with resources focused on the areas of highest risk.

Overall materiality

The maximum amount by which the financial statements could be misstated before the misstatement would be expected to influence users' economic decisions. Set at the planning stage and may be revised during the audit.

Performance materiality

An amount set by the auditor at LESS than overall materiality to reduce the probability that the aggregate of uncorrected and undetected misstatements exceeds overall materiality. Typically 50%-75% of overall materiality.

Clearly trivial threshold

A threshold below which misstatements are considered individually so insignificant that they are not worth accumulating or reporting. Typically about 5% of overall materiality.

Overall audit strategy

A high-level document setting the scope, timing, and direction of the audit. Guides the development of the more detailed audit plan (ISA 300).

Detailed audit plan

A document describing the nature, timing, and extent of risk assessment procedures, tests of controls, and substantive procedures to be performed at the assertion level (ISA 300).

Sufficiency of evidence

The quantity of evidence — whether enough evidence has been obtained. Affected by the assessed risk of material misstatement, the quality of evidence, and the materiality of the item.

Appropriateness of evidence

The quality of evidence — its relevance (does it relate to the assertion being tested?) and reliability (is it from a trustworthy source and in a dependable form?).

Inspection

Examining records, documents, or tangible assets. Provides evidence depending on what is inspected — existence, rights, valuation, condition.

Observation

Watching a process or procedure being performed by the entity's personnel. Provides evidence of performance at a point in time only.

Inquiry

Seeking information from knowledgeable persons (management, staff, legal counsel, others). Can be formal or informal, written or oral.

External confirmation

Obtaining a direct written response from a third party verifying information. Examples: bank letter, receivables circularisation, solicitor's letter. Strong external evidence.

Recalculation

Checking the mathematical accuracy of documents or records — e.g., recalculating depreciation, checking invoice extensions.

Reperformance

The auditor independently re-executes a procedure or control originally performed by the entity's personnel — e.g., re-performing a bank reconciliation.

Analytical procedures

Evaluating financial information by studying plausible relationships among data. Includes comparisons, ratio analysis, trend analysis, and investigating fluctuations. Mandatory at risk assessment and overall review stages.

Audit documentation (working papers)

The record of audit procedures performed, evidence obtained, and conclusions reached. Must enable an experienced auditor with no prior connection to understand the audit work (ISA 230).

Key Formulas

Worked Examples

Key Takeaways

  • Audit planning (ISA 300) ensures the audit is performed effectively, with resources focused on areas of highest risk. Key activities: understanding the entity, risk assessment, materiality determination, strategy and plan development.
  • Understanding the entity (ISA 315) covers external factors (industry, regulation, economy) and internal factors (nature, policies, strategies, performance, internal controls).
  • Overall materiality = benchmark × percentage. Common: PBT 5-10%, Revenue 0.5-1%, Total assets 1-2%. Choose the benchmark most relevant to users and adjust the percentage for risk.
  • Performance materiality = 50-75% of overall materiality. Set lower for higher-risk engagements. Provides a buffer for undetected misstatements.
  • Clearly trivial threshold ≈ 5% of overall materiality. Misstatements below this are not accumulated.
  • Overall audit strategy = high-level (scope, direction, timing). Detailed audit plan = specific (procedures, by whom, when, extent). Both are living documents.
  • Evidence must be both sufficient (quantity) and appropriate (quality = relevance + reliability). External > internal; direct > indirect; documentary > oral; original > copies.
  • Seven audit procedures: Inspection, Observation, Inquiry, Confirmation, Recalculation, Reperformance, Analytical procedures.
  • Analytical procedures are mandatory at risk assessment and overall review stages; optional as substantive procedures.
  • Audit documentation (ISA 230): prepared on a timely basis, file assembled within 60 days of the report, retained for at least 5 years. Must enable an experienced auditor to understand the work performed.

Practice Questions

Question 1 of 8

An entity has profit before tax of £500,000. Using a benchmark of 5% of PBT, overall materiality is:

Question 2 of 8

Performance materiality is set at a level:

Question 3 of 8

Which of the following provides the MOST reliable audit evidence?

Question 4 of 8

The auditor independently recalculates the depreciation charge on PPE. This is an example of:

Question 5 of 8

Analytical procedures are MANDATORY at which stages of the audit?

Question 6 of 8

The overall audit strategy is best described as:

Question 7 of 8

The audit file must be assembled and completed within how many days of the auditor's report?

Question 8 of 8

Which audit procedure involves the auditor watching entity personnel perform a process?

Source and Version

Syllabus: ICAEW ACA Certificate Level 2026 · Reviewed: 2026-05-04

ICAEW ACA syllabusLocal syllabus coverage review