Audit Evidence and Sampling
Weightage: Chapter 4 of ICAI's Paper 5 syllabus, roughly 14 marks. This is the "gather evidence" stage of the audit sequence — the largest weight of any single chapter and where risk assessment finally becomes concrete testing.
Sufficient appropriate audit evidence
Audit evidence is the information used by the auditor in arriving at the conclusions on which the audit opinion is based, and it comprises both information contained in the accounting records underlying the financial statements and other information.
Sufficiency is the measure of the quantity of audit evidence — how much is needed, which is itself affected by the auditor's assessment of risk (higher risk needs more evidence) and by the quality of the evidence (higher-quality evidence may reduce the quantity required).
Appropriateness is the measure of the quality of audit evidence — its relevance and its reliability in supporting the conclusions on which the opinion is based.
The two are related but distinct, and this is examined precisely: a large quantity of poor-quality evidence does not compensate for its poor quality, and a small quantity of excellent evidence may still be insufficient in quantity for a high-risk area — sufficiency and appropriateness are both necessary, and neither substitutes for the other.
The reliability hierarchy
Though the reliability of evidence depends on the specific circumstances, several generalisations are useful and are directly examinable:
- Evidence is more reliable when obtained from independent sources outside the entity than evidence obtained from the entity itself.
- Evidence generated internally is more reliable when the related controls are effective.
- Evidence obtained directly by the auditor (for instance, observation of a control's application) is more reliable than evidence obtained indirectly or by inference (for instance, inquiry about the application of a control).
- Evidence in documentary form, whether paper, electronic or other, is more reliable than evidence obtained orally.
- Evidence provided by original documents is more reliable than evidence provided by photocopies or facsimiles.
The assertions
Assertions are representations by management, explicit or otherwise, embodied in the financial statements, used by the auditor to consider the different types of potential misstatements that may occur. They fall into two groups examined together:
Assertions about classes of transactions and events (for the period under audit): occurrence (transactions recorded have actually occurred and relate to the entity); completeness (all transactions that should have been recorded have been recorded); accuracy (amounts and other data have been recorded appropriately); cutoff (transactions have been recorded in the correct accounting period); classification (transactions have been recorded in the proper accounts); presentation.
Assertions about account balances (at the period end): existence (assets, liabilities and equity interests actually exist); rights and obligations (the entity holds or controls the rights to assets, and liabilities are the obligations of the entity); completeness (all assets, liabilities and equity interests that should have been recorded have been recorded); accuracy, valuation and allocation (amounts are included at appropriate amounts, and valuation or allocation adjustments are appropriately recorded); classification; presentation.
Why assertions matter as a working tool: every audit procedure is designed to gather evidence about one or more specific assertions, and identifying which assertion a specific risk relates to is what tells the auditor which procedure will actually address it — a risk that inventory quantities are overstated is a completeness/existence risk (too much recorded relative to what genuinely exists), addressed by physical verification; a risk that inventory is overvalued is an accuracy/valuation risk, addressed by testing costing and net realisable value, an entirely different procedure. Matching the procedure to the specific assertion at risk, rather than applying a generic test, is precisely the skill this chapter builds.
Audit procedures for obtaining evidence
Inspection — examining records, documents, or physical assets.
Observation — watching a process or procedure being performed (limited by the fact that the observed party may behave differently because they are being observed, and observation provides evidence only for the point in time observed).
External confirmation — audit evidence obtained as a direct written response to the auditor from a third party, in paper or electronic form (a bank confirmation, a receivables confirmation).
Recalculation — checking the mathematical accuracy of documents or records.
Reperformance — the auditor's independent execution of procedures or controls that were originally performed by the entity.
Analytical procedures — evaluations of financial information through analysis of plausible relationships among both financial and non-financial data.
Inquiry — seeking information from knowledgeable persons within or outside the entity (generally the weakest form of evidence standing alone, because of its reliance on the source's knowledge and candour, and is therefore almost always corroborated with other procedures rather than relied on in isolation).
Audit sampling
Audit sampling is the application of audit procedures to less than 100% of items within a population of audit relevance, such that all sampling units have a chance of selection, to provide the auditor with a reasonable basis to draw conclusions about the entire population.
Sampling risk — the risk that the auditor's conclusion based on a sample may be different from the conclusion if the entire population were subjected to the same audit procedure. It runs in two directions:
- For a test of controls: the risk of assessing control risk too low (concluding controls are more effective than they truly are — this affects audit effectiveness, since it can lead to insufficient substantive testing) or too high (leading to unnecessary additional work — this affects audit efficiency).
- For a test of details: the risk of incorrect acceptance (concluding a balance is not materially misstated when it is — this affects audit effectiveness, the more serious direction since it risks an inappropriate opinion) or incorrect rejection (concluding a balance is materially misstated when it is not — this affects audit efficiency, since it leads to unnecessary further work to resolve an apparent problem that does not actually exist).
The asymmetry worth remembering: in both a test of controls and a test of details, one direction of sampling risk threatens effectiveness (the audit reaches the wrong conclusion and an inappropriate opinion may follow) and the other threatens only efficiency (extra unnecessary work, but the ultimate opinion is not compromised) — the effectiveness-threatening direction is the more serious one, and this is precisely why auditors design sampling approaches that are, if anything, biased towards the efficiency-costing error rather than the effectiveness-costing one.
Non-sampling risk — the risk that the auditor reaches an erroneous conclusion for any reason not related to sampling risk — for instance, applying inappropriate procedures, or failing to recognise a misstatement in evidence that was examined. Non-sampling risk cannot be eliminated by increasing sample size (unlike sampling risk, which reduces as sample size increases); it is addressed instead through proper training, supervision and review.
Statistical versus non-statistical sampling: statistical sampling uses random selection and applies probability theory to evaluate results, including measuring sampling risk; non-statistical sampling does not, relying instead on the auditor's judgement in both selecting the sample and evaluating results. Both are acceptable audit approaches; the choice is one of auditor judgement about the specific circumstances, not a requirement that one is inherently superior.
Methods of selecting a sample include: random selection (every item has an equal chance); systematic selection (a constant interval is applied, with the starting point determined randomly); haphazard selection (an attempt to select a representative sample without following a structured technique, deliberately avoiding any conscious bias); and monetary unit sampling (a value-weighted selection method, giving each individual rupee of value an equal chance of selection, which naturally increases the probability that larger-value items are selected).
