What Do Further Audit Procedures Include? Controls and Substantive Tests

Further audit procedures are the testing an auditor performs after planning, once risks of material misstatement have been assessed for each significant account and assertion. What further audit procedures include falls into two categories: tests of controls, which evaluate whether the company’s internal controls actually work, and substantive procedures, which test whether the recorded numbers are right. Substantive procedures then split further into substantive analytical procedures and tests of details. The auditor picks the mix, the timing, and the sample size for each based on how risky the area is.

How Assessed Risk Drives the Choice

Every decision about further audit procedures traces back to the assessed risk of material misstatement. Under PCAOB standards, the auditor must design procedures that address the assessed risks for each relevant assertion of each significant account and disclosure.1Public Company Accounting Oversight Board. AS 2301 – The Auditor’s Responses to the Risks of Material Misstatement The higher the assessed risk, the more persuasive the evidence has to be.

Three levers do the work. Nature is the type of procedure selected: a high-risk account might get confirmed directly with a third party, while a low-risk predictable account might be tested with an analytical procedure. Timing is when the work happens; lower-risk accounts can sometimes be tested before year-end, while higher-risk areas are tested at or very close to period end. Extent is sample size and coverage: higher risk means larger samples, more locations, or in extreme cases, testing every item.

The auditor also weighs what kinds of misstatements the identified risks could produce, and how likely and large those misstatements might be.1Public Company Accounting Oversight Board. AS 2301 – The Auditor’s Responses to the Risks of Material Misstatement That keeps effort concentrated where it matters instead of spread evenly across every account.

Tests of Controls

Tests of controls evaluate whether a company’s internal controls operate as designed. The auditor performs them when planning to rely on those controls to reduce assessed control risk, which can make the audit more efficient, especially for high-volume routine transactions like sales processing or payroll.

Controls testing is mandatory in two situations. First, when the auditor plans to assess control risk below the maximum and build substantive testing around that lower assessment, the auditor must obtain evidence that the selected controls were designed effectively and operated effectively throughout the entire period of reliance. Second, tests of controls are required whenever substantive procedures alone cannot provide sufficient evidence for a particular assertion. This comes up often with highly automated systems where transaction data exists only in electronic form and its accuracy depends entirely on the surrounding controls.1Public Company Accounting Oversight Board. AS 2301 – The Auditor’s Responses to the Risks of Material Misstatement

Four methods are used to test controls:

  • Inquiry: asking staff how a control is applied and under what circumstances.
  • Observation: watching personnel perform the control activity in real time.
  • Inspection: reviewing documentation that the control operated, such as a signed authorization, an exception report, or a system access log.
  • Reperformance: the auditor independently executes the control step to verify it produces the expected result. This is the most persuasive method because it doesn’t depend on the client’s own records or explanations.

When a control fails during testing, the auditor can no longer rely on it. The practical consequence is a larger scope of substantive testing for every account balance that control was supposed to protect.

Substantive Procedures

Substantive procedures are designed to detect material misstatements in the financial statements themselves. Where tests of controls ask whether the process is working, substantive procedures ask whether the numbers are right. The auditor must perform substantive procedures for each relevant assertion of each significant account and disclosure, regardless of the assessed level of control risk.1Public Company Accounting Oversight Board. AS 2301 – The Auditor’s Responses to the Risks of Material Misstatement Even with excellent controls, some direct testing of the numbers is always required.

Substantive procedures take two forms: substantive analytical procedures and tests of details. Different combinations of the two can satisfy the evidence requirement for any assertion, and the auditor decides which mix fits based on the nature of the account and the level of risk.2Public Company Accounting Oversight Board. AS 2305 – Substantive Analytical Procedures One limit applies: for significant risks, the auditor must perform tests of details that respond specifically to those risks. Analytical procedures alone are not enough for the highest-risk areas.1Public Company Accounting Oversight Board. AS 2301 – The Auditor’s Responses to the Risks of Material Misstatement

Substantive Analytical Procedures

Substantive analytical procedures build an independent expectation of what a financial balance or ratio should be, then compare that expectation to the recorded amount. They are most useful when the relationship between data points is predictable and the underlying information is reliable. For a stable manufacturer, comparing gross margins by product line against prior periods and known cost changes can flag misstatements efficiently.

The sequence is straightforward. The auditor develops an expectation using prior-period data, industry benchmarks, known business changes, or non-financial data. A tolerable difference is set: the maximum gap between expectation and recorded amount the auditor would accept without further work. The recorded amount is compared to the expectation, and any gap exceeding the tolerable threshold has to be investigated to determine whether it reflects a misstatement or a legitimate business change not captured in the expectation.

How persuasive the evidence is depends on how precise the expectation is. An estimate built from detailed, independently verifiable data carries more weight than one built from unaudited internal forecasts. Disaggregated data, such as revenue by month and product line rather than a single annual total, generally produces a tighter expectation and a more useful test.2Public Company Accounting Oversight Board. AS 2305 – Substantive Analytical Procedures

Tests of Details

Tests of details examine the supporting documentation behind individual transactions or balances. They link general ledger amounts back to external or internal source documents, giving direct evidence about whether recorded amounts are correct. They carry more weight for accounts that are inherently subjective, unpredictable, or involve complex estimates.

Common techniques include:

  • Confirmation: obtaining a direct written response from a third party. Bank confirmations verify cash balances; customer confirmations verify accounts receivable.
  • Inspection: examining physical assets, such as counting inventory, or reviewing documents, such as a property deed to verify ownership.
  • Recalculation: independently verifying mathematical accuracy, such as recomputing depreciation expense or interest accruals.

Vouching Versus Tracing

Two specific techniques test opposing assertions, and their direction matters. Vouching starts with a recorded transaction in the general ledger and works backward to the supporting source document. If a recorded sale can be traced back to a shipping document and a customer order, the auditor has evidence the transaction actually occurred. Vouching tests the existence assertion.

Tracing runs the other way. The auditor starts with a source document such as a shipping report and follows it forward into the general ledger to confirm it was recorded. If goods were shipped but never invoiced, tracing catches the gap. Tracing tests the completeness assertion. Mixing up the direction of these tests is where practical mistakes happen; the direction determines which assertion the test addresses.

Sampling

Examining every transaction is impractical for most accounts, so tests of details typically rely on sampling. The sample must be representative of the full population so results can be projected. Misstatements found in the sample are extrapolated to estimate the total likely error in the account, and that projected misstatement feeds into the overall evaluation of whether the financial statements are materially misstated.

Dual-Purpose Tests

A single procedure can sometimes test a control and verify a transaction amount at the same time. While testing whether sales transactions were properly authorized (a control), the auditor can simultaneously verify that the recorded amounts agree to shipping documents (a substantive test). When performing a dual-purpose test, the auditor evaluates the results separately for each objective, drawing conclusions about both the control’s effectiveness and the accuracy of the recorded amount.1Public Company Accounting Oversight Board. AS 2301 – The Auditor’s Responses to the Risks of Material Misstatement A control failure in the sample does not automatically mean the dollar amounts are wrong, or the reverse, but both conclusions must be documented independently.

Interim Testing and Roll-Forward Procedures

Auditors sometimes perform substantive procedures before the balance sheet date to spread the work and catch problems early. Interim testing creates a gap, though: if accounts receivable was tested as of September 30 but the financial statements are dated December 31, three months of transactions went untested.

To close that gap, the auditor performs roll-forward procedures covering the remaining period. These typically involve comparing balances at the interim date to year-end balances and investigating unusual changes, along with targeted testing on transactions during the remaining period. The higher the risk of misstatement, the less appropriate it is to rely on interim testing, and for significant risks, period-end testing is almost always necessary. If evidence obtained during the remaining period contradicts earlier conclusions, the auditor must revise risk assessments and potentially expand testing, which can mean repeating the same procedures at year-end.1Public Company Accounting Oversight Board. AS 2301 – The Auditor’s Responses to the Risks of Material Misstatement

Procedures That Respond to Fraud Risk

Fraud risk calls for procedures that a company cannot fully anticipate. Beyond the standard work, the auditor is expected to incorporate an element of unpredictability so that personnel cannot know exactly what will be tested and when. Predictable audit routines create opportunities for concealment.

Practical examples include surprise inventory observations on unannounced dates, cash counts without prior notice, testing accounts or locations that are normally treated as immaterial, and adjusting sampling thresholds to levels the company would not expect.3Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit These unpredictable elements should change from year to year, otherwise they become predictable themselves.

Revenue recognition carries a presumed fraud risk under PCAOB standards. Auditors often respond by comparing revenue by month and product line against prior periods, confirming contract terms directly with customers, inquiring about unusual sales arrangements near period end, and physically observing shipping activity at the close of the reporting period.3Public Company Accounting Oversight Board. AS 2401 – Consideration of Fraud in a Financial Statement Audit

Using the Work of a Specialist

Some account balances require expertise the audit team doesn’t have. Fair value measurements of complex financial instruments, actuarial calculations for pension liabilities, and environmental remediation estimates commonly involve specialists. Under PCAOB standards, a specialist is someone with special skill or knowledge in a field other than accounting or auditing. Tax professionals and IT specialists who participate in the audit do not fall under this definition.4Public Company Accounting Oversight Board. AS 1210 – Using the Work of an Auditor-Engaged Specialist

Before relying on a specialist’s work, the engagement partner assesses the specialist’s qualifications, including professional certifications, relevant experience, and reputation in the field. The auditor also evaluates the specialist’s objectivity, looking for relationships with the company that could compromise impartial judgment.4Public Company Accounting Oversight Board. AS 1210 – Using the Work of an Auditor-Engaged Specialist Using a specialist does not reduce the auditor’s responsibility. The auditor still has to evaluate whether the specialist’s work supports the conclusions about the relevant assertion.