AU-C 330: Performing Audit Procedures for Assessed Risks

AU-C 330 is the AICPA auditing standard that tells an auditor what to do with the risks identified under AU-C 315. It requires the auditor to design and perform “further audit procedures” whose nature, timing, and extent respond to those assessed risks, and then to evaluate whether the evidence obtained is sufficient and appropriate to support the opinion. The standard applies to audits of non-issuers, and it was updated through conforming amendments when SAS No. 145 overhauled AU-C 315, effective for audits of periods ending on or after December 15, 2023.1Wiley Online Library. AU-C 330 Performing Audit Procedures in Response to Assessed Risks and Evaluating the Audit Evidence Obtained

Overall Responses at the Financial Statement Level

Before touching any account, the auditor designs responses that shape the whole engagement. The most fundamental is heightened professional skepticism across the team: evidence isn’t accepted at face value, and management representations get harder questions when risks are elevated.

Staffing is part of the response. When risks are high, particularly fraud risk or complex accounting judgments, the standard calls for assigning team members with more experience or specialized knowledge. Fair value estimates on exotic financial instruments need someone who understands the valuation models, not a staff auditor running a standard confirmation.

Timing and mix change too. A common adjustment is shifting substantive testing from interim dates to year-end, because period-end evidence is more direct and harder for management to manipulate. The auditor may lean more heavily on external evidence sources when internal evidence looks less reliable, or extend coverage to locations and subsidiaries that wouldn’t ordinarily receive detailed attention.

One related requirement sits in a different standard. The obligation to build unpredictability into audit procedures — testing accounts or locations without prior notice, varying sampling, adjusting timing from what the client expects — comes from AU-C 240 on fraud, not from AU-C 330 itself. It dovetails with the overall response framework because unpredictability is one of the most effective ways to address fraud risk at the financial statement level.2Ohio State University. AU-C 240 Consideration of Fraud in a Financial Statement Audit

Designing Further Audit Procedures

AU-C 330 requires the auditor to design further audit procedures whose nature, timing, and extent are responsive to and clearly linked with the assessed risks at the assertion level.1Wiley Online Library. AU-C 330 Performing Audit Procedures in Response to Assessed Risks and Evaluating the Audit Evidence Obtained “Assertion level” is doing real work in that sentence. The response isn’t to a general sense that accounts receivable feels risky; it targets the specific assertion at risk, whether that is existence (are these receivables real?), valuation (are they recorded at the right amount?), or completeness (are all receivables captured?).

Further audit procedures fall into two categories:

  • Tests of controls, which evaluate whether the entity’s internal controls are operating effectively. The auditor tests controls when planning to rely on them to reduce the extent of substantive work.
  • Substantive procedures, which are aimed directly at detecting material misstatements in account balances, transaction classes, or disclosures. These come in two forms: tests of details, which examine specific transactions or items, and substantive analytical procedures, which analyze relationships in the data to identify unexpected patterns.

The interplay matters. A high-risk assertion demands more persuasive evidence, which usually means tests of details performed at or near year-end with a larger sample. A lower-risk assertion might be handled with a substantive analytical procedure at an interim date. A dual-purpose test is also possible: a single procedure that evaluates a control’s effectiveness while also providing substantive evidence about the underlying transactions. The test-of-controls component and the substantive component each still have to be evaluated against their own criteria.

Tests of Controls

Testing controls isn’t optional in two situations. First, when the risk assessment assumes controls are operating effectively — you can’t reduce substantive testing based on a control you haven’t tested. Second, when substantive procedures alone cannot provide enough evidence. That second case is common in heavily automated environments where transactions initiate, process, and record electronically with no paper trail. Documents alone won’t verify completeness; you have to test the IT general controls and application controls that govern the system.

Evidence has to cover the entire period of intended reliance, not a single day. The amount depends on two factors: how often the control operates and how much reliance is planned. A control that runs with every transaction, such as an automated three-way match, is tested differently from a monthly bank reconciliation review. Higher reliance means a larger sample.

Using Prior-Period Evidence on Controls

The standard permits the use of evidence from a prior audit about control effectiveness, but with guardrails. Before relying on last year’s testing, the auditor performs inquiry combined with observation or inspection to confirm the control has not changed. Inquiry alone is not enough. If the environment, personnel, or systems have changed in ways that affect the control, prior-period evidence is no longer relevant and the control must be retested.3CeriFi CPEdge. Companion to PPC’s Guide to Audit Risk Assessment

Even when nothing has changed, each control must be tested at least once every third audit on a rotation basis. Controls that address a significant risk get no such grace period. Those are tested in the current period every year.3CeriFi CPEdge. Companion to PPC’s Guide to Audit Risk Assessment

When a Control Fails

If testing shows a control isn’t working as designed, the auditor can’t simply note the failure and move on. The initial control risk assessment has to be revised upward, and the planned substantive procedures have to be expanded in nature, timing, or extent, often all three. A control that was supposed to reduce the risk of revenue overstatement now leaves that risk unaddressed, and detailed testing of revenue transactions has to fill the gap.

Substantive Procedures

Every material class of transactions, account balance, and disclosure requires substantive procedures, regardless of the assessed risk level. Even if controls look strong and inherent risk is low, some substantive work is always required. Testing controls alone and calling it a day is not permitted.

For significant risks the bar is higher. When the approach relies only on substantive procedures with no control reliance, those procedures must include tests of details. Substantive analytical procedures alone are not sufficient for a significant risk.4PASAI. International Standard on Auditing 330 – The Auditor’s Responses to Assessed Risks Analytical procedures identify anomalies but don’t examine individual items, and significant risks by definition need the most direct evidence available.

Substantive analytical procedures work best on large, predictable populations. Payroll expense at a company with stable headcount and known salary rates is a natural candidate: you can build an expectation and compare it to the recorded amount with high precision. For judgment-heavy areas, unusual transactions, or existence questions, tests of details are typically necessary. You can’t analytically review whether inventory physically exists. You have to count it.

External Confirmations

When the combined assessed level of inherent and control risk is high, external confirmations carry particular weight because they come from a source independent of the entity. For unusual or complex transactions with elevated risk, the auditor should consider confirming the terms directly with the other party rather than relying only on documents the entity holds. A year-end sale with unusual terms and high inherent risk is exactly the kind of transaction where a confirmation of the sale terms provides evidence that internal documents cannot match.

Interim Testing and Roll-Forward Procedures

Performing substantive work before year-end saves time but creates a gap. Any misstatement that arises between the interim date and the balance sheet date would be missed by the interim work. The auditor bridges that gap with additional procedures.

Roll-forward procedures typically involve comparing the interim balance to the year-end balance and investigating unusual movements, or targeted substantive tests on transactions during the intervening period. Control effectiveness over the roll-forward window also matters. If controls are weak during that stretch, the roll-forward procedures have to be more extensive, potentially negating the efficiency gain of interim testing in the first place.

Evaluating the Evidence Obtained

Once planned procedures are complete, the auditor evaluates whether the initial risk assessments still hold up in light of the evidence gathered. If evidence suggests risk is higher than originally assessed, whether because a control failed or a test of details produced more errors than expected, additional procedures are required. The risk assessment is not locked in at planning.

Contradictory evidence gets special attention. If one procedure points one direction and another points the opposite way, the auditor cannot cherry-pick the favorable result. The discrepancy has to be investigated and resolved before an opinion is formed. This is where professional skepticism is most tested: rationalizing away a single anomaly is easy, and AU-C 330 requires following the thread.

The auditor also aggregates all identified misstatements, both the specific errors found in testing and projected misstatements extrapolated from samples, and compares the total to materiality. If the aggregate exceeds materiality, the financial statements are materially misstated, and either management corrects them or the opinion reflects the problem.

When Evidence Remains Insufficient

If sufficient appropriate evidence hasn’t been obtained despite all feasible procedures, AU-C 330 requires action. The auditor first attempts additional procedures to close the gap. If the gap can’t be closed, perhaps because the client can’t produce needed records or a confirmation response never arrives and alternative procedures fall short, the opinion has to be modified. Depending on severity and pervasiveness, the result is either a qualified opinion or a disclaimer of opinion.

Near-End Analytical Procedures

A related requirement lives in AU-C 520 rather than AU-C 330. The auditor performs analytical procedures near the end of the audit to form an overall conclusion about whether the financial statements are consistent with the auditor’s understanding of the entity.5PCAOB. Comparison of Proposed AS 2305 with ISA 520 and AU-C Section 520 Comparing year-end balances against prior-year trends, industry data, or the auditor’s expectations can surface relationships that procedure-level testing missed, such as a division whose revenue growth is inconsistent with its headcount or capital spending.

Documentation Requirements

AU-C 330 requires the auditor to document the linkage between the assessed risks of material misstatement and the further audit procedures performed in response.1Wiley Online Library. AU-C 330 Performing Audit Procedures in Response to Assessed Risks and Evaluating the Audit Evidence Obtained An experienced auditor reviewing the workpapers should be able to trace from a risk identified under AU-C 315 to the specific procedure designed to address it, and then to the results and conclusions drawn from that procedure. If the trail breaks, the documentation fails.

The documentation must cover the overall responses at the financial statement level, the nature, timing, and extent of the further audit procedures performed, the results of those procedures, and the conclusions about sufficiency. For tests of controls, the auditor also documents the basis for any reliance on prior-period testing and the evidence obtained to confirm the control hasn’t changed.

Communicating Control Deficiencies

When AU-C 330 testing reveals that a control isn’t operating effectively, the auditor’s obligations continue under a separate standard. AU-C 265 requires the auditor to evaluate whether any identified deficiencies, alone or in combination, rise to the level of a significant deficiency or material weakness, and to communicate those in writing to those charged with governance and to management no later than 60 days after the report release date.6AICPA. AU-C 265 Communicating Internal Control Related Matters Identified in an Audit AU-C 265 doesn’t add a requirement to hunt for deficiencies beyond what AU-C 315 and AU-C 330 already produce; the obligation is to communicate what the audit finds, not to expand control testing for its own sake.