AU-C 505, External Confirmations, sets the rules auditors follow when they gather evidence by contacting third parties directly. Under the standard, the auditor selects what to confirm based on assessed risk, maintains control over sending requests and receiving responses, chooses between positive and negative confirmation formats, evaluates every response for reliability, and performs alternative procedures whenever a confirmation goes unreturned. The standard applies to audits of nonpublic entities conducted under AICPA standards; audits of SEC-reporting companies follow a separate PCAOB standard.
When Confirmations Apply
The decision to confirm turns on the assessed risk of material misstatement at both the financial statement and assertion levels. As risk rises, confirmations become a more important tool for driving audit risk to an acceptable level. The account’s nature matters too. Confirmations produce the strongest evidence for assertions about existence and about rights and obligations tied to an asset or liability.
Accounts receivable is the classic case. A direct response from a customer stating what they owe corroborates that the receivable exists and belongs to the entity. The same logic applies to notes payable, loan covenants, inventory held at third-party warehouses, securities held by custodians, and the terms of complex sales contracts. In each case, an independent party verifies something the client’s own records cannot prove as persuasively on their own.
Not every confirming party produces useful evidence. If the recipient is unsophisticated, lacks access to the relevant records, or has a close relationship with the client, the response carries less weight. The request itself should ask for information the third party can verify from their own records: an outstanding balance, a due date, an interest rate.
Positive and Negative Confirmations
AU-C 505 recognizes two request types.
A positive confirmation asks the recipient to respond in every case, whether they agree or disagree with the stated information. Silence itself becomes a signal that alternative procedures are needed. Positive confirmations are the default when the risk of material misstatement is high or when individual balances are large.1Public Company Accounting Oversight Board. Comparison of New Proposed Standard AS 2310 with ISA 505 and AU-C Section 505
A variation is the blank confirmation, which omits the balance and asks the recipient to fill it in from their own records. Because the third party supplies the figure independently rather than checking a pre-printed number, blank confirmations can produce more reliable evidence. The trade-off is a lower response rate.
A negative confirmation asks the recipient to respond only if they disagree. When nothing comes back, the auditor assumes agreement. That assumption is weak: silence may mean the recipient never received the request, never opened it, or ignored it. The evidential value is substantially lower, and the standard restricts when this format can stand alone.1Public Company Accounting Oversight Board. Comparison of New Proposed Standard AS 2310 with ISA 505 and AU-C Section 505
The Four Conditions for Using Negative Confirmations
AU-C 505 prohibits auditors from using negative confirmations as the sole substantive procedure unless all four of the following are true at the same time:1Public Company Accounting Oversight Board. Comparison of New Proposed Standard AS 2310 with ISA 505 and AU-C Section 505
- The assessed risk of material misstatement is low, and the auditor has obtained sufficient evidence that relevant internal controls operate effectively.
- The population consists of a large number of small, homogeneous balances or transactions.
- The expected exception rate is very low.
- The auditor has no reason to believe recipients will disregard the request.
If a negative-confirmation approach later produces a significant number of exceptions or non-responses, the initial risk assessment has to be revisited. That reassessment may force a switch to positive confirmations or additional substantive testing.
Keeping Control of the Process
A confirmation is only as strong as the auditor’s grip on how it is designed and moved. The standard assigns three control points to the auditor: selecting the items, sending the requests, and receiving the responses.
The request should be clearly identified as an audit confirmation and must direct the response back to the auditor’s own address, never the client’s. The form should ask for information the recipient can actually verify from their records and avoid ambiguous language. For a debt balance, that means principal, interest rate, and origination date. For a receivable, it means outstanding balance and payment terms.
Client staff can help with mechanical tasks, such as printing requests on company letterhead, but the auditor must verify every detail before anything goes out. The auditor personally seals, addresses, and mails the requests, or sends them through a secure electronic channel. This blocks management from tampering with the selection, intercepting outgoing requests, or altering incoming responses.1Public Company Accounting Oversight Board. Comparison of New Proposed Standard AS 2310 with ISA 505 and AU-C Section 505
Electronic confirmation platforms can strengthen control when properly implemented, because the auditor accesses the platform directly and the client never handles responses. The auditor still needs to evaluate whether the platform’s security controls are adequate and whether the respondent’s identity has been properly authenticated. An electronic response carries the same reliability requirements as a paper one.
Before any request goes out, the auditor must obtain management’s authorization to contact the third parties. A refusal has consequences described further down.
Evaluating What Comes Back
Every response needs a reliability check. For paper confirmations, that means examining the letterhead, postmark, and sender information for consistency. For electronic responses, source verification may require calling the sender or using another independent method to confirm the response actually came from the intended party. If anything raises doubt about a response’s reliability, the auditor must obtain further audit evidence to resolve it.1Public Company Accounting Oversight Board. Comparison of New Proposed Standard AS 2310 with ISA 505 and AU-C Section 505
When a response is determined unreliable, the auditor must evaluate what that means for the overall risk assessment, including the risk of fraud, and adjust the nature, timing, and extent of other procedures accordingly.1Public Company Accounting Oversight Board. Comparison of New Proposed Standard AS 2310 with ISA 505 and AU-C Section 505
Disclaimers and Restrictive Language
Third-party respondents increasingly attach legal disclaimers and boilerplate limitations. A bank might confirm a balance while disclaiming any responsibility for its accuracy. When a response carries restrictive language, the auditor must determine whether the disclaimer is so broad that it effectively negates the evidential value. If it does, the confirmation cannot be relied on without additional corroborating procedures.2Public Company Accounting Oversight Board. Statement on Proposed Auditing Standard Related to Confirmation
Exceptions and Discrepancies
An exception is a response reporting a different amount or different terms than the request stated. Most exceptions turn out to be timing differences, such as a customer payment mailed but not yet posted, or goods in transit at the confirmation date. The auditor investigates each one by communicating with both the client and the third party to reconcile it.
Where an exception reveals an actual misstatement rather than a timing issue, the auditor must project that error to the population and assess whether total projected misstatement exceeds the tolerable threshold. Unreconciled exceptions are treated as potential misstatements until resolved. A high rate of exceptions where the client’s records are consistently wrong in the same direction is a strong fraud indicator and calls for a reassessment of risk.
Handling Non-Responses
When a positive confirmation is not returned, the auditor must perform alternative procedures aimed at the same assertions the confirmation was designed to address.
For accounts receivable, the most common alternative is examining subsequent cash receipts, tracing the balance to payments received from the customer after the confirmation date. Reviewing shipping documents such as bills of lading or delivery receipts provides evidence that the underlying sale actually occurred. For accounts payable, the auditor can review subsequent cash disbursements and examine vendor invoices or statements.
If the alternative procedures still fail to produce sufficient evidence, the auditor must consider the implications for the audit opinion. A pattern of non-responses concentrated in a particular account or customer group can itself be a risk indicator that warrants further investigation.
When Management Refuses to Allow a Confirmation
A management request to block confirmation of a specific account or balance is treated as a potential scope limitation, and the standard takes it seriously because the restriction originates with the client rather than with an uncooperative third party.
The auditor first asks why management objects and evaluates whether the reasons hold up. Sometimes there is a legitimate business rationale, such as a delicate negotiation with a customer that a confirmation request might disrupt. Even where the explanation is reasonable, the auditor must evaluate the implications for the risk of material misstatement, including the risk of fraud, and must still perform alternative procedures to obtain sufficient evidence.1Public Company Accounting Oversight Board. Comparison of New Proposed Standard AS 2310 with ISA 505 and AU-C Section 505
If the alternative procedures produce adequate evidence, the audit can proceed without modifying the opinion. If the auditor concludes management’s refusal is unreasonable, or if the alternative procedures cannot fill the gap, the matter must be communicated to those charged with governance. When the resulting scope limitation is material and pervasive, the auditor must issue either a qualified opinion or a disclaimer of opinion. A management refusal that cannot be worked around is not a workpaper footnote. It goes directly to the opinion.
Confirmations and Fraud Risk
AU-C 240 recognizes that auditors may design confirmation requests as a response to assessed risks of material misstatement due to fraud. The process can work as both a detection tool and a deterrent, because when management knows balances will be independently verified, the incentive to manipulate those accounts drops.1Public Company Accounting Oversight Board. Comparison of New Proposed Standard AS 2310 with ISA 505 and AU-C Section 505
Several outcomes should sharpen skepticism. A management refusal with no compelling reason is one. Patterns of exceptions consistently favoring the client’s position are another. Non-responses concentrated in accounts where management has the greatest incentive to misstate deserve extra scrutiny. None of these individually prove fraud, but each calls for a reassessment of fraud risk and a possible expansion of audit procedures.
Public Company Audits Follow a Different Standard
AU-C 505 governs audits of nonpublic entities. Auditors of SEC-reporting companies apply PCAOB AS 2310, which includes a near-presumption that the auditor will confirm cash and accounts receivable and imposes requirements that AU-C 505 does not.3Public Company Accounting Oversight Board. AS 2310 The Auditors Use of Confirmation If the engagement is a public company audit, the AS 2310 rules apply instead of the ones described above.