Audit Evidence: Types, Reliability, and Gathering Procedures

Audit evidence is all of the information an independent auditor collects and evaluates to reach the conclusions that support an audit opinion on a company’s financial statements. It includes information that corroborates what management says about the numbers and information that contradicts it. Under PCAOB standards, both directions count, and every conclusion in the auditor’s report has to trace back to evidence that is sufficient in quantity and appropriate in quality.1Public Company Accounting Oversight Board. AS 1105 Audit Evidence

The purpose is narrow and specific: to test whether the financial statements are fairly presented under the applicable reporting framework. Every balance, transaction, and disclosure reflects an assertion by management, whether stated outright or implied. The audit program exists to test those assertions with evidence strong enough to justify the opinion the auditor eventually signs.

What the Evidence Has to Prove

When management issues financial statements, it implicitly or explicitly makes claims about the numbers in specific ways. PCAOB standards group those claims into five categories, and every piece of audit evidence connects to at least one of them.

  • Existence or occurrence: assets and liabilities actually exist at the balance sheet date, and recorded transactions actually happened during the period.
  • Completeness: every transaction and account that should appear is included, with nothing left out.
  • Valuation or allocation: assets, liabilities, revenues, and expenses are recorded at the right amounts.
  • Rights and obligations: the company actually owns or controls its assets, and the liabilities are genuinely its own.
  • Presentation and disclosure: items are properly classified, described, and disclosed in the statements and notes.

These categories give the audit its structure. A bank confirmation is aimed at existence. A search for unrecorded liabilities after year-end is aimed at completeness. A well-designed audit program maps each procedure to the specific assertion it addresses, which stops the auditor from stacking up evidence that all tests the same thing while other assertions go untested.1Public Company Accounting Oversight Board. AS 1105 Audit Evidence

Sufficient and Appropriate

Two standards decide whether the auditor has enough of the right evidence. Both have to be satisfied. More of the wrong kind doesn’t fix a deficiency, and higher quality doesn’t excuse a sample that is too small.

Sufficiency Is About Quantity

Sufficiency asks whether there is enough evidence to support the opinion with reasonable assurance. How much “enough” turns out to be depends heavily on risk. When the risk of material misstatement is high, whether because of weak internal controls, a complex accounting estimate, or a fraud risk factor, more evidence is needed. Lower risk means smaller samples and less extensive testing can be defensible.2Public Company Accounting Oversight Board. AS 2301 The Auditors Responses to the Risks of Material Misstatement

Materiality feeds into this too. When the auditor sets a lower materiality threshold, smaller misstatements start to matter, and the volume of testing goes up to catch them. The relationship is inverse: tighter materiality, more evidence.

Appropriateness Is About Relevance and Reliability

Appropriateness has two parts. The evidence must be relevant to the assertion being tested; a bank confirmation is relevant to the existence of cash, while a sales invoice is not relevant to inventory valuation. And it must be reliable enough that the auditor can trust it.

No formula tells the auditor to gather exactly 47 confirmations. It’s a judgment call, but not an unconstrained one. The judgment has to account for the assessed risk, the materiality threshold, the quality of the company’s internal controls, and the nature of what is being tested. An auditor who claims to have used professional judgment but can’t explain the reasoning behind the scope of testing will struggle to defend the work.

What Makes Some Evidence More Reliable Than Others

Not all evidence carries equal weight. PCAOB standards set out several principles that experienced auditors treat as second nature.

  • Independent sources beat internal ones. Evidence from a knowledgeable outside source, like a bank or a customer, is more reliable than a document the company prepared itself. The risk of manipulation drops when someone with no stake in the outcome provides the information.
  • Direct evidence beats indirect evidence. Something the auditor observes firsthand, such as counting inventory or inspecting equipment, is more reliable than something learned by asking management.
  • Original documents beat copies. An original signed contract is stronger than a photocopy or a scanned PDF. When documents have been converted to electronic form, reliability depends on the controls over that conversion process.
  • Strong internal controls raise reliability. Information produced by a company with effective controls, including IT general controls and automated application controls, is more reliable than the same type of information from a company with weak controls.

These principles work together. A bank confirmation is powerful because it comes from an independent source and goes directly to the auditor. A client-prepared reconciliation is weaker on its own, but if controls are strong and the auditor can reperform the reconciliation independently, the combined evidence may be persuasive enough.1Public Company Accounting Oversight Board. AS 1105 Audit Evidence

One nuance is worth flagging. When a third party provides evidence subject to restrictions, limitations, or disclaimers, the auditor has to evaluate what effect those caveats have on reliability. A confirmation response that says the information is provided without guarantee of accuracy is worth less than one without that language.1Public Company Accounting Oversight Board. AS 1105 Audit Evidence

Types of Evidence by Physical Form

Audit evidence takes three basic forms, each with different strengths and limitations.

Documentary Evidence

Paper and electronic records form the backbone of most audits. Vendor invoices, purchase agreements, board minutes, loan agreements, bank statements, and shipping documents all fall into this category. Documentary evidence is used to test nearly every balance in the financial statements. Its reliability depends on whether the document originated inside or outside the company and whether the auditor obtained it directly or received it from the client.

Physical Evidence

Physical evidence comes from the auditor’s direct observation or examination of tangible assets. Counting inventory, inspecting equipment, and verifying the condition of property all produce physical evidence. It is highly reliable because the auditor gathers it firsthand, and it directly supports the existence assertion. Observed condition can also inform valuation when it suggests impairment.

Electronic Evidence

System-generated data, access logs, automated transaction records, and database extracts increasingly dominate modern audits. When an auditor tests whether an automated control is working, the evidence is almost entirely electronic. The catch is that electronic evidence is only as reliable as the IT environment that produced it. If general IT controls around access management, change management, and backup procedures are weak, the data those systems generate cannot be trusted at face value, and the auditor has to evaluate those controls before relying on any system-produced information.

Internal Versus External Sources

Beyond physical form, evidence is classified by where it originates, and that classification drives how much weight the auditor can place on it.

External evidence comes from sources independent of the company: bank confirmations, customer responses, vendor statements, brokerage reports, and legal letters from outside counsel. Its value lies in the fact that the source has no incentive to help management present a favorable picture. A bank has no reason to overstate a client’s cash balance. External evidence provides the strongest independent verification of a balance or transaction.

Internal evidence is anything the company generated itself: journal entries, general ledger trial balances, internal memos, management-prepared reconciliations, and depreciation schedules. It is essential for understanding how transactions flow through the company’s systems, but it carries inherent risk because the people who prepared it are the same people whose work is being audited. Effective internal controls raise the reliability of internal evidence, and auditors routinely corroborate internal documents with external sources where possible.

How Auditors Gather Evidence

Auditors use a defined set of procedures to collect evidence. Each technique generates a different type of evidence and tests different assertions. A well-planned audit combines several of them to build a body of evidence that is both sufficient and appropriate.

Inspection

Inspection means examining records, documents, or tangible assets. For documents, it can run in two directions. Vouching starts with a recorded entry and traces backward to the supporting document, which tests whether recorded transactions actually occurred. Tracing starts with a source document and follows it forward into the accounting records, which tests whether real transactions were captured. The distinction matters: vouching primarily tests existence, tracing primarily tests completeness.

Inspecting tangible assets works differently. The auditor might check serial numbers on equipment against the fixed asset register, or examine the physical condition of inventory to assess whether write-downs are needed.

Observation

Observation is watching a process as someone else performs it. The classic example is the year-end inventory count: the auditor watches client personnel count items, notes whether they follow the counting procedures, and performs independent test counts. Observation provides real-time evidence about how a process works, but it has a built-in limitation. People tend to perform better when they know they’re being watched, and the observation only covers the specific moment it occurs. The auditor cannot assume the process runs the same way on every other day of the year.

Inquiry

Inquiry means asking knowledgeable people, inside or outside the company, about facts, plans, or intentions. It is the most common audit procedure and also the weakest standing alone. Responses almost always need corroboration from other evidence. An auditor who asks management whether any litigation is pending and accepts the answer without checking with outside legal counsel or reviewing correspondence has not done enough. Professional skepticism matters here because the people being asked often have an interest in presenting the most favorable picture.

Confirmation

Confirmation involves sending a request directly to a third party and receiving a direct written response. The auditor must maintain control over the entire process, from selecting which items to confirm through receiving the responses, to prevent interception or alteration by the client.3Public Company Accounting Oversight Board. AS 2310 The Auditors Use of Confirmation

Two forms are common. A positive confirmation asks the recipient to respond whether they agree or disagree with the stated balance. A negative confirmation asks the recipient to respond only if they disagree. Positive confirmations provide stronger evidence because the auditor gets an explicit response either way. Negative confirmations are appropriate only when the risk of misstatement is low, individual balances are small, and the auditor reasonably expects recipients will actually read and consider the request.

When a positive confirmation gets no response, silence is not agreement. Nonresponses provide no evidence about the assertion being tested. The auditor has to follow up, and if a response still doesn’t arrive, alternative procedures are required, such as examining subsequent cash receipts for accounts receivable or reviewing shipping documents. The only exception is when the nonresponses, even if projected as 100 percent misstatements, would not change the overall conclusion about whether the financial statements are materially misstated.3Public Company Accounting Oversight Board. AS 2310 The Auditors Use of Confirmation

Recalculation and Reperformance

Recalculation is checking the math: re-footing an invoice total, recalculating depreciation expense, or verifying the interest computation on a loan schedule. It is highly reliable because the auditor does the work independently and any error becomes immediately apparent.

Reperformance is broader. The auditor independently re-executes a control or procedure that client staff originally performed. If the client reconciles the bank account monthly as a control activity, the auditor might reperform the reconciliation from scratch. Reperformance tests both the accuracy of the underlying data and the operating effectiveness of the control.

Analytical Procedures

Analytical procedures evaluate financial information by studying relationships among financial and nonfinancial data. Comparing the current year’s gross profit margin to the prior year, or comparing revenue per employee to an industry benchmark, are straightforward examples.4Public Company Accounting Oversight Board. AS 2305 Substantive Analytical Procedures

PCAOB standards require analytical procedures at two stages of the audit: during planning to identify areas with elevated risk, and near the end as an overall review of the financial statements. Between those bookends, they can also be used as substantive procedures to test specific account balances.4Public Company Accounting Oversight Board. AS 2305 Substantive Analytical Procedures

Effectiveness depends on the precision of the auditor’s expectation. Analyzing data at the business unit level is more effective than analyzing consolidated totals, because offsetting changes in different segments can mask errors at the aggregate level. Monthly data catches things that annual data buries. When a significant unexpected fluctuation appears, or an expected fluctuation doesn’t materialize, the auditor investigates by performing additional substantive procedures.

When Evidence Falls Short

Sometimes the auditor cannot gather sufficient appropriate evidence, and that has consequences that reach the audit report itself.

An unqualified (clean) opinion requires that the audit was performed fully in accordance with PCAOB standards, including every procedure considered necessary. When a scope limitation prevents that, whether because the client restricts access to information, records are inadequate, or circumstances make a necessary procedure impossible, the auditor must issue either a qualified opinion or a disclaimer of opinion.5Public Company Accounting Oversight Board. AS 3105 Departures from Unqualified Opinions and Other Reporting Circumstances

The choice between qualified and disclaimer depends on how significant the missing evidence is. If the limitation affects a single account but the auditor can still form an opinion on the financial statements as a whole, a qualified opinion may be appropriate. If the missing evidence is so pervasive that the auditor cannot form any opinion, a disclaimer is required. When the client itself imposes the scope restriction, a disclaimer is ordinarily the right call.5Public Company Accounting Oversight Board. AS 3105 Departures from Unqualified Opinions and Other Reporting Circumstances

Fraud risk raises the bar further. When the auditor identifies a risk of material misstatement due to fraud, the evidence-gathering has to be more persuasive, and PCAOB standards describe three levers the auditor can adjust. The nature of procedures can shift toward techniques that produce more reliable evidence, such as moving from inquiry to confirmation. The timing can move closer to period end, or target the specific points during the year when fraudulent transactions are more likely. The extent can increase, through larger samples or computer-assisted techniques applied to the entire population. The standard also calls for certain procedures to be performed on a surprise or unannounced basis, so employees who might be concealing fraud cannot prepare for the auditor’s visit.6Public Company Accounting Oversight Board. AS 2401 Consideration of Fraud in a Financial Statement Audit

Increasing the extent of testing alone is not enough if the evidence isn’t reliable or relevant. Testing more items from an unreliable source doesn’t make the evidence persuasive; it just produces more of the same weak information. The nature of the procedure has to match the risk.2Public Company Accounting Oversight Board. AS 2301 The Auditors Responses to the Risks of Material Misstatement