AU-C Section 330: Tests of Controls and Substantive Procedures

AU-C Section 330 is the AICPA auditing standard that tells an auditor how to respond to the risks of material misstatement identified during risk assessment. It requires the auditor to design and perform further audit procedures whose nature, timing, and extent are clearly linked to those assessed risks, to obtain sufficient appropriate audit evidence, and to document both the procedures and the reasoning that ties them to specific risks. In short, it is the bridge between what the auditor knows about an entity’s risks under AU-C Section 315 and what the auditor actually does during fieldwork.

Overall Responses at the Financial Statement Level

Before designing procedures for individual accounts or assertions, the auditor addresses risks that sit at the financial statement level with broad, engagement-wide responses. These shape the audit’s overall posture rather than target a single assertion. The standard also requires the engagement team to maintain professional skepticism throughout the audit, and the overall responses reinforce that mindset from the top down.

Typical overall responses include assigning more experienced personnel or specialists, adjusting the level of supervision given to team members, and modifying the overall audit strategy. When the control environment is weak or management’s integrity is in question, the auditor may shift procedures toward period-end rather than relying on interim work, increase sample sizes, or change the mix of procedures to lean more heavily on external evidence.

Incorporating Unpredictability

AU-C 330 also requires the auditor to build elements of unpredictability into the audit. The purpose is to keep management from anticipating and working around the auditor’s procedures, which is primarily a fraud-prevention measure. Unpredictability can come from performing substantive procedures on balances not otherwise selected for testing, adjusting the timing of procedures from what the client expects, using different sampling methods, or visiting locations without prior notice.

Practical examples include lowering the threshold for a search for unrecorded liabilities well below prior years, confirming an immaterial bank account that has never been confirmed before, testing a bank reconciliation for a mid-year month, or verifying the existence of randomly selected vendors to test for fictitious payees. These procedures need to change from year to year. An “unpredictable” test performed the same way every engagement stops being unpredictable.

Designing Procedures at the Assertion Level

At the assertion level, AU-C 330 requires further audit procedures whose nature, timing, and extent respond to the assessed risk of material misstatement. The three dimensions work together, and a higher assessed risk demands more persuasive evidence across all of them.

  • Nature covers the purpose of the procedure (test of controls or substantive procedure) and its type (inspection, observation, confirmation, recalculation, reperformance, analytical procedure, or inquiry). A high-risk assertion calls for inherently more reliable procedure types. External confirmation from a third party produces stronger evidence than inspection of internally generated documents.
  • Timing refers to whether procedures are performed at an interim date or at period-end. Higher-risk assertions generally push testing toward the balance sheet date. Interim testing creates an additional obligation to cover the remaining period.
  • Extent is the quantity of testing, most commonly expressed as sample size. Higher risk means larger samples or more thorough analytical procedures. Increasing extent alone, without adjusting nature or timing, may not produce persuasive enough evidence for a high-risk area.

The design process is not formulaic. Two assertions carrying the same risk rating can warrant different procedure combinations depending on the account’s characteristics, the control environment, and the evidence available. What matters is that the auditor can articulate why each procedure addresses the specific risk it targets.

Tests of Controls

The auditor designs and performs tests of controls in two situations. First, when the risk assessment relies on an expectation that controls operate effectively and the auditor plans to reduce substantive testing based on that reliance. Second, when substantive procedures alone cannot provide sufficient appropriate evidence for a given assertion. The second scenario arises more often than expected, particularly for highly automated processes where transaction volume makes substantive testing of every item impractical.

Testing operating effectiveness involves reperformance (independently executing the control to see if you reach the same result), inspection of documentary evidence that the control was applied, and observation of the control being performed. The auditor must test the control across the entire period of intended reliance, not just a snapshot. Evidence that a control operated effectively in March tells you nothing about September.

Relying on Prior Period Evidence

The standard permits using evidence about a control’s effectiveness from a prior audit, but only within limits. The control must not have changed since the prior assessment, and the auditor still needs to test at least some controls each year. Relevant factors include whether the control environment has changed, whether the control is manual or automated, and how strong the operating effectiveness was in prior testing. Significant changes in the control or the related risk require retesting in the current period regardless of prior results. Automated controls embedded in IT systems, where the general IT controls are also effective, generally warrant less frequent retesting than manual controls that depend on human judgment.

Handling Control Deviations

When testing identifies a deviation, the auditor cannot simply note the exception and move on. The standard requires further inquiry into the deviation’s nature and potential consequences. A single deviation in a sample might indicate a one-off error or signal a systemic breakdown. The auditor must evaluate whether the initial risk assessment remains appropriate. If it does not, the planned substantive procedures must be modified to compensate for the reduced reliance on that control.

Substantive Procedures

Regardless of the assessed level of risk, and regardless of how well controls performed in testing, AU-C 330 requires substantive procedures for each material class of transactions, account balance, and disclosure. This is a floor, not a ceiling. Even when controls are tested and found operating effectively, the auditor cannot skip substantive testing entirely for a material account.

Substantive procedures come in two categories: tests of details and substantive analytical procedures. When the auditor’s approach to a significant risk relies only on substantive procedures, the standard requires those procedures to include tests of details rather than analytics alone.

The Financial Statement Closing Process

AU-C 330 specifically requires substantive procedures related to the financial statement closing process. This includes evaluating journal entries recorded during the closing, testing the consolidation and aggregation of financial data, and examining adjustments made during preparation of the financial statements. The closing process is where many misstatements land because it involves significant management judgment and manual intervention outside the normal transaction-processing controls.

Responding to the Risk of Management Override

Management override of controls is treated as a significant risk in every audit. Because management can manipulate records by overriding controls that otherwise function properly, the auditor cannot rely on controls alone to address this risk. Required responses include examining journal entries and other adjustments for evidence of possible material misstatement due to fraud, reviewing accounting estimates for biases, and evaluating whether the business rationale for significant unusual transactions suggests they were entered into for fraudulent purposes.1Public Company Accounting Oversight Board. AS 2401 Consideration of Fraud in a Financial Statement Audit

Journal entry testing deserves particular attention. The auditor needs to understand the entity’s financial reporting process, identify and select entries for testing (with a focus on entries made at unusual times, by unexpected individuals, or to unusual accounts), and inquire of individuals involved in the financial reporting process about inappropriate activity. A retrospective review of prior-year accounting estimates compared to actual results can also reveal patterns of management bias that would not be visible in any single period.1Public Company Accounting Oversight Board. AS 2401 Consideration of Fraud in a Financial Statement Audit

Interim Testing and Covering the Remaining Period

When substantive procedures are performed at an interim date, the auditor must cover the remaining period between that date and the balance sheet date. This can be done through additional substantive procedures, through a combination of substantive procedures and tests of controls, or, in some cases, by performing the substantive procedures again at period-end when extending interim conclusions would not be reliable.

The auditor considers whether the interim procedures revealed unexpected misstatements, whether the period-end balances are reasonably predictable, and whether controls over the remaining period are effective. If unexpected misstatements are detected at the interim date, the auditor must reevaluate the related risk assessment and consider whether the nature, timing, or extent of procedures for the remaining period needs to change.

For significant risks, the standard effectively discourages heavy reliance on interim testing. Substantive procedures for those assertions should be performed near or at period-end, because the consequences of missing a misstatement in a high-risk area are too severe to bridge with rollforward procedures alone.

Evaluating Sufficiency and Appropriateness of Evidence

After performing the planned procedures, the auditor evaluates whether the evidence obtained is enough. Sufficiency refers to quantity; appropriateness refers to quality, meaning relevance to the assertion tested and reliability given the source and circumstances. The two dimensions interact. Higher-quality evidence means you need less of it, while lower-quality evidence demands more volume to compensate.

This evaluation runs throughout the engagement, not just at the end. Evidence gathered during testing may contradict the original risk assessment, reveal previously unidentified risks, or raise questions about whether other planned procedures remain adequate. When that happens, the auditor revises the risk assessment and modifies the remaining procedures. A material misstatement discovered in accounts receivable, for example, should prompt reconsideration of whether the revenue procedures already performed are still sufficient.

Evidence from independent external sources is generally more reliable than evidence generated internally, and evidence obtained directly by the auditor is more reliable than evidence obtained indirectly.

When Evidence Falls Short

If the auditor cannot obtain sufficient appropriate evidence for a material assertion, the first step is to attempt further evidence through alternative procedures. If that effort also fails, the auditor faces a scope limitation that affects the audit opinion. Depending on the magnitude and pervasiveness of the limitation, the result is either a qualified opinion (when the possible effects are material but not pervasive) or a disclaimer of opinion (when the possible effects are both material and pervasive).

Documentation Requirements

AU-C 330 requires the auditor to document the overall responses to assessed risks at the financial statement level, the nature, timing, and extent of the further audit procedures performed, the linkage between those procedures and the assessed risks at the assertion level, and the results of the procedures. The documentation must also include the auditor’s conclusion about whether sufficient appropriate audit evidence has been obtained.

The linkage requirement is the one that trips up engagement teams most often. Documenting what was done is not enough. The file must show why each procedure was selected and which specific risk it addresses. The documentation should make clear that the procedures were tailored to the assessed risks rather than drawn from a standard template.