By the end of this chapter you'll be able to…

  • 1Distinguish sufficiency (quantity) from appropriateness (quality) of audit evidence
  • 2Apply the reliability hierarchy to rank different sources and forms of evidence
  • 3State the assertions about classes of transactions and about account balances
  • 4Match a specific identified risk to the assertion it relates to, and the procedure that would address it
  • 5Describe the seven types of audit procedure for obtaining evidence and their relative reliability
  • 6Define audit sampling and sampling risk, and distinguish the two directions each takes for tests of controls and tests of details
  • 7Explain the asymmetry between effectiveness-threatening and efficiency-threatening sampling risk
  • 8Distinguish sampling risk from non-sampling risk and state how each is addressed
  • 9Distinguish statistical from non-statistical sampling
  • 10State the methods of selecting a sample
💡
Why this chapter matters in CA Intermediate
Sufficient appropriate audit evidence is the phrase every later chapter assumes without redefining, and this chapter is where its two components, quantity and quality, are properly separated and shown to be independently necessary. The assertions are the working tool that connects an identified risk to the specific procedure that will actually address it — a completeness risk on inventory quantities and a valuation risk on the same inventory line call for entirely different procedures, and matching risk to assertion to procedure is the skill this chapter exists to build. Sampling then answers a separate, practical question: given that testing every item is neither required nor possible, how does a test on a fraction of a population support a conclusion about the whole, and what can go wrong in that inference.

Audit Evidence and Sampling

Weightage: Chapter 4 of ICAI's Paper 5 syllabus, roughly 14 marks. This is the "gather evidence" stage of the audit sequence — the largest weight of any single chapter and where risk assessment finally becomes concrete testing.

Sufficient appropriate audit evidence

Audit evidence is the information used by the auditor in arriving at the conclusions on which the audit opinion is based, and it comprises both information contained in the accounting records underlying the financial statements and other information.

Sufficiency is the measure of the quantity of audit evidence — how much is needed, which is itself affected by the auditor's assessment of risk (higher risk needs more evidence) and by the quality of the evidence (higher-quality evidence may reduce the quantity required).

Appropriateness is the measure of the quality of audit evidence — its relevance and its reliability in supporting the conclusions on which the opinion is based.

The two are related but distinct, and this is examined precisely: a large quantity of poor-quality evidence does not compensate for its poor quality, and a small quantity of excellent evidence may still be insufficient in quantity for a high-risk area — sufficiency and appropriateness are both necessary, and neither substitutes for the other.

The reliability hierarchy

Though the reliability of evidence depends on the specific circumstances, several generalisations are useful and are directly examinable:

  • Evidence is more reliable when obtained from independent sources outside the entity than evidence obtained from the entity itself.
  • Evidence generated internally is more reliable when the related controls are effective.
  • Evidence obtained directly by the auditor (for instance, observation of a control's application) is more reliable than evidence obtained indirectly or by inference (for instance, inquiry about the application of a control).
  • Evidence in documentary form, whether paper, electronic or other, is more reliable than evidence obtained orally.
  • Evidence provided by original documents is more reliable than evidence provided by photocopies or facsimiles.

The assertions

Assertions are representations by management, explicit or otherwise, embodied in the financial statements, used by the auditor to consider the different types of potential misstatements that may occur. They fall into two groups examined together:

Assertions about classes of transactions and events (for the period under audit): occurrence (transactions recorded have actually occurred and relate to the entity); completeness (all transactions that should have been recorded have been recorded); accuracy (amounts and other data have been recorded appropriately); cutoff (transactions have been recorded in the correct accounting period); classification (transactions have been recorded in the proper accounts); presentation.

Assertions about account balances (at the period end): existence (assets, liabilities and equity interests actually exist); rights and obligations (the entity holds or controls the rights to assets, and liabilities are the obligations of the entity); completeness (all assets, liabilities and equity interests that should have been recorded have been recorded); accuracy, valuation and allocation (amounts are included at appropriate amounts, and valuation or allocation adjustments are appropriately recorded); classification; presentation.

Why assertions matter as a working tool: every audit procedure is designed to gather evidence about one or more specific assertions, and identifying which assertion a specific risk relates to is what tells the auditor which procedure will actually address it — a risk that inventory quantities are overstated is a completeness/existence risk (too much recorded relative to what genuinely exists), addressed by physical verification; a risk that inventory is overvalued is an accuracy/valuation risk, addressed by testing costing and net realisable value, an entirely different procedure. Matching the procedure to the specific assertion at risk, rather than applying a generic test, is precisely the skill this chapter builds.

Audit procedures for obtaining evidence

Inspection — examining records, documents, or physical assets.

Observation — watching a process or procedure being performed (limited by the fact that the observed party may behave differently because they are being observed, and observation provides evidence only for the point in time observed).

External confirmation — audit evidence obtained as a direct written response to the auditor from a third party, in paper or electronic form (a bank confirmation, a receivables confirmation).

Recalculation — checking the mathematical accuracy of documents or records.

Reperformance — the auditor's independent execution of procedures or controls that were originally performed by the entity.

Analytical procedures — evaluations of financial information through analysis of plausible relationships among both financial and non-financial data.

Inquiry — seeking information from knowledgeable persons within or outside the entity (generally the weakest form of evidence standing alone, because of its reliance on the source's knowledge and candour, and is therefore almost always corroborated with other procedures rather than relied on in isolation).

Audit sampling

Audit sampling is the application of audit procedures to less than 100% of items within a population of audit relevance, such that all sampling units have a chance of selection, to provide the auditor with a reasonable basis to draw conclusions about the entire population.

Sampling risk — the risk that the auditor's conclusion based on a sample may be different from the conclusion if the entire population were subjected to the same audit procedure. It runs in two directions:

  • For a test of controls: the risk of assessing control risk too low (concluding controls are more effective than they truly are — this affects audit effectiveness, since it can lead to insufficient substantive testing) or too high (leading to unnecessary additional work — this affects audit efficiency).
  • For a test of details: the risk of incorrect acceptance (concluding a balance is not materially misstated when it is — this affects audit effectiveness, the more serious direction since it risks an inappropriate opinion) or incorrect rejection (concluding a balance is materially misstated when it is not — this affects audit efficiency, since it leads to unnecessary further work to resolve an apparent problem that does not actually exist).

The asymmetry worth remembering: in both a test of controls and a test of details, one direction of sampling risk threatens effectiveness (the audit reaches the wrong conclusion and an inappropriate opinion may follow) and the other threatens only efficiency (extra unnecessary work, but the ultimate opinion is not compromised) — the effectiveness-threatening direction is the more serious one, and this is precisely why auditors design sampling approaches that are, if anything, biased towards the efficiency-costing error rather than the effectiveness-costing one.

Non-sampling risk — the risk that the auditor reaches an erroneous conclusion for any reason not related to sampling risk — for instance, applying inappropriate procedures, or failing to recognise a misstatement in evidence that was examined. Non-sampling risk cannot be eliminated by increasing sample size (unlike sampling risk, which reduces as sample size increases); it is addressed instead through proper training, supervision and review.

Statistical versus non-statistical sampling: statistical sampling uses random selection and applies probability theory to evaluate results, including measuring sampling risk; non-statistical sampling does not, relying instead on the auditor's judgement in both selecting the sample and evaluating results. Both are acceptable audit approaches; the choice is one of auditor judgement about the specific circumstances, not a requirement that one is inherently superior.

Methods of selecting a sample include: random selection (every item has an equal chance); systematic selection (a constant interval is applied, with the starting point determined randomly); haphazard selection (an attempt to select a representative sample without following a structured technique, deliberately avoiding any conscious bias); and monetary unit sampling (a value-weighted selection method, giving each individual rupee of value an equal chance of selection, which naturally increases the probability that larger-value items are selected).

Key formulas & results

Everything to memorise for the exam hall, in one card. Screenshot this for revision.

Sufficiency = quantity of evidence; Appropriateness = quality (relevance + reliability) — both necessary, neither substitutes for the other
Reliability hierarchy: external > internal; effective-controls internal > weak-controls internal; direct auditor observation > inquiry; documentary > oral; original > photocopy
Transaction assertions: occurrence, completeness, accuracy, cutoff, classification, presentation
Balance assertions: existence, rights and obligations, completeness, accuracy/valuation/allocation, classification, presentation
Test of controls sampling risk: assessing control risk too low (effectiveness) or too high (efficiency)
Test of details sampling risk: incorrect acceptance (effectiveness, the serious one) or incorrect rejection (efficiency)
Sampling risk reduces as sample size increases; non-sampling risk does not and is addressed through training/supervision/review
⚠️

Traps CA Intermediate sets — and how to dodge them

These are the exact option-traps and misreads that cost marks under negative marking.

WATCH OUT
Assuming a large quantity of evidence compensates for poor quality, or vice versa, when both sufficiency and appropriateness are independently required
WATCH OUT
Treating inquiry as sufficient evidence on its own without corroboration, when it is generally the weakest form of evidence standing alone
WATCH OUT
Failing to match a specific identified risk to the correct assertion before selecting a procedure — testing existence when the risk is actually about valuation, or the reverse
WATCH OUT
Confusing the transaction assertions with the balance assertions, or omitting cutoff (a transaction assertion) or rights and obligations (a balance assertion)
WATCH OUT
Treating incorrect rejection and incorrect acceptance as equally serious, when incorrect acceptance is the effectiveness-threatening, more serious direction
WATCH OUT
Believing sampling risk can be eliminated by better training or supervision, when only non-sampling risk is addressed that way
WATCH OUT
Assuming statistical sampling is always superior to non-statistical sampling, when both are acceptable and the choice is a matter of judgement
WATCH OUT
Confusing systematic selection (constant interval from a random start) with random selection (every item independently equally likely)

Exam-pattern practice

PYQ-style questions with full solutions. Work through them as a readiness check — mark yourself honestly and get your gap report at the end.

Readiness check

Are you exam-ready for Audit Evidence and Sampling?

15 problems from this chapter. Try each one, reveal the worked solution, mark yourself honestly — get your gap report at the end.

15 questions~11 min

5-minute revision

The whole chapter, distilled. Read this the night before the exam.

  • Sufficiency = quantity, appropriateness = quality — both required, neither substitutes for the other
  • Reliability hierarchy: external over internal, effective-control internal over weak, direct over indirect, documentary over oral, original over photocopy
  • Transaction assertions: occurrence, completeness, accuracy, cutoff, classification, presentation
  • Balance assertions: existence, rights and obligations, completeness, accuracy/valuation/allocation, classification, presentation
  • Match the specific risk to its assertion first, then select the procedure that actually tests that assertion
  • Seven procedures: inspection, observation, external confirmation, recalculation, reperformance, analytical procedures, inquiry
  • Inquiry alone is the weakest evidence — almost always needs corroboration
  • Test of controls sampling risk: assessing control risk too low (effectiveness) or too high (efficiency)
  • Test of details sampling risk: incorrect acceptance (effectiveness, the serious one) or incorrect rejection (efficiency)
  • Sampling risk falls as sample size rises; non-sampling risk does not — it needs training, supervision, review
  • Statistical and non-statistical sampling are both acceptable; the choice is judgement, not a hierarchy
  • Random, systematic, haphazard, and monetary unit sampling are the four selection methods

CA Intermediate question blueprint

How this topic is asked, tier by tier — so you can prep to the pattern.

Typical weightage: 14

Exam-hall strategy

Battle-tested tips from mentors and toppers for this topic under the sectional clock.

  1. State sufficiency and appropriateness as two distinct, both-required concepts whenever evidence adequacy is in question
  2. Rank evidence sources explicitly using the reliability generalisations rather than an intuitive guess
  3. In risk-to-procedure questions, name the specific assertion at risk before naming a procedure, since the assertion is what justifies the procedure choice
  4. Distinguish the transaction assertions from the balance assertions explicitly, since cutoff belongs only to transactions and rights/obligations only to balances
  5. For sampling risk questions, always identify which of the two directions is being asked about and state whether it threatens effectiveness or efficiency
  6. Explain why sample size fixes sampling risk but not non-sampling risk whenever the two are compared
  7. State that statistical and non-statistical sampling are both acceptable, resisting the temptation to declare one superior

Beyond the exam

Where this skill shows up in the job you're competing for — and in life.

Bank and receivables confirmations are sent out on nearly…

Bank and receivables confirmations are sent out on nearly every real audit engagement as one of the most reliable, independent evidence sources available

Matching identified risks to specific assertions is the e…

Matching identified risks to specific assertions is the exact planning exercise real audit teams perform when building a risk-and-procedures matrix for each significant account

Monetary unit sampling is the standard sampling technique…

Monetary unit sampling is the standard sampling technique used by most major audit firms for substantive testing of account balances in practice

The sampling risk asymmetry

The sampling risk asymmetry, tolerating more inefficiency risk to guard against effectiveness risk, is a deliberate design choice embedded in every firm's sampling methodology and statistical tables

Where else this topic is tested

Prepare once, score in every exam that asks it.

CA Final Paper 3 — Advanced Auditing, Assurance and Professional Ethics, where sampling and evidence are extended to complex and group audit scenarios
CS Executive — Secretarial Audit, Compliance Management and Due Diligence
CMA Intermediate — Cost and Management Audit
ACCA Audit and Assurance, where ISA 500 and ISA 530 are examined in near-identical terms

Questions aspirants ask

Pulled from the Q&A community and mentor sessions.

It is generally highly reliable for the specific matter it confirms, being independent, direct and documentary, but it is not universally the most reliable evidence for every purpose or every assertion. A bank confirmation is strong evidence of existence and of the recorded balance, but it says nothing about, for instance, whether a receivable balance the bank has nothing to do with is genuinely collectible, which is a valuation question a confirmation cannot answer. Reliability generalisations describe tendencies across sources and forms of evidence, not an absolute ranking that applies regardless of what specific assertion is being tested, and appropriateness always requires considering both the reliability of a piece of evidence and its relevance to the specific assertion in question.

Not with equal intensity. The auditor's risk assessment identifies which assertions carry the greatest risk of material misstatement for a specific balance or transaction class, and audit effort is concentrated accordingly; a cash balance, for instance, typically carries meaningful existence and completeness risk but comparatively little valuation risk, since cash is generally straightforward to value once its existence is confirmed, whereas a complex financial instrument might carry its most significant risk in valuation rather than existence. All assertions are considered, but the extent of procedures addressing each is calibrated to the risk specifically associated with that assertion for that particular balance, exactly the risk-responsive design principle running through this whole area of the syllabus.

Because it still has a genuine cost, in time, in client relationship, and in audit fee economics, even though it does not threaten the correctness of the ultimate opinion the way incorrect acceptance does. An auditor who frequently and wrongly concludes balances are misstated when they are not will waste substantial resources chasing non-existent problems, frustrate clients with excessive, unwarranted further inquiry, and reduce the overall efficiency of the audit process; efficiency matters both commercially and because time wasted on false positives is time not available for genuine risk areas. It is simply the less serious of the two risks specifically because it does not compromise the reliability of the opinion itself, which is why sampling approaches accept more of it in exchange for reducing incorrect acceptance.
Header Logo