CPA AUDITING & ATTESTATION (AUD) • ASSESSING RISK AND DEVELOPING A PLANNED RESPONSE

Planned Audit Response — Design Substantive And Control Testing Procedures

How auditors translate assessed risks into targeted testing strategies that provide sufficient appropriate audit evidence.

Historical Context & Motivation

The modern concept of a planned audit response did not materialize overnight; it evolved over more than a century of financial scandals, regulatory reforms, and the accounting profession's gradual shift from a vouching-every-transaction approach to a risk-based methodology. Early audits in the nineteenth century were essentially complete examinations of books and records, which became impractical as businesses grew in scale and complexity. The profession recognized that limited resources demanded a smarter allocation of effort—one driven by where things were most likely to go wrong. This insight eventually produced the risk-based audit model that underpins today's auditing standards, requiring auditors to assess risks of material misstatement and then design procedures—both tests of controls and substantive tests—that respond directly to those risks.

1941
SAS Predecessor Standards
The AICPA issued Statements on Auditing Procedure, codifying the idea that auditors should exercise professional judgment in selecting which transactions to examine rather than checking every entry.
1988
SAS No. 55 — Internal Control
Required auditors to obtain a sufficient understanding of internal control to plan the audit, formally linking control evaluation to the nature, timing, and extent of substantive procedures.
2002
Sarbanes-Oxley Act (SOX)
Enacted after major corporate frauds (Enron, WorldCom), SOX mandated integrated audits of internal control over financial reporting for public companies, dramatically elevating the role of control testing.
2006
PCAOB AS No. 5 (now AS 2201)
Replaced AS No. 2 with a top-down, risk-based approach to the audit of internal control, requiring auditors to focus testing on controls that address the most significant risks of material misstatement.
2021
AICPA Clarified SASs (AU-C 315 Revised)
AU-C Section 315 was significantly revised to enhance risk identification and assessment, requiring a more rigorous linkage between assessed risks and the auditor's planned response—including explicit documentation of how each substantive and control procedure addresses identified risks.

The central question that emerged from this evolution is deceptively simple: once an auditor identifies and assesses the risks of material misstatement at both the financial-statement level and the assertion level, how should the audit team design procedures that are responsive to those risks? The answer requires understanding the interplay between tests of controls and substantive procedures—their purposes, how they complement each other, and the professional judgment involved in calibrating the nature, timing, and extent of each.

Core Principles & Definitions

Designing an effective audit response requires fluency in several foundational concepts. Under AU-C Section 330 (Performing Audit Procedures in Response to Assessed Risks and Evaluating the Audit Evidence Obtained), the auditor must design and implement overall responses to assessed risks at the financial-statement level and further audit procedures at the assertion level. Further audit procedures comprise tests of controls and substantive procedures, and their design is governed by three dimensions: nature, timing, and extent.

1

Tests of Controls

Procedures designed to evaluate the operating effectiveness of controls in preventing or detecting material misstatements at the assertion level. Required when the auditor's risk assessment assumes controls are operating effectively or when substantive procedures alone cannot provide sufficient evidence.
2

Substantive Procedures

Procedures designed to detect material misstatements at the assertion level. They include tests of details (of classes of transactions, account balances, and disclosures) and substantive analytical procedures. At least one substantive procedure must be performed for every significant class of transactions, account balance, and disclosure.
3

Nature, Timing, and Extent (NTE)

Nature refers to the purpose and type of procedure (e.g., inspection vs. confirmation). Timing refers to when the procedure is performed (interim vs. year-end). Extent refers to the quantity of testing (sample size, number of items). All three are modulated by the assessed level of risk.
4

Relevant Assertions

Management's implicit or explicit claims about financial statement elements—existence/occurrence, completeness, valuation/allocation, rights and obligations, and presentation and disclosure. Each audit procedure should clearly target one or more specific assertions.
5

Detection Risk

The risk that audit procedures will fail to detect a misstatement that exists and could be material. The auditor controls detection risk by adjusting the nature, timing, and extent of substantive and control testing. Lower acceptable detection risk demands more persuasive evidence.
KEY TAKEAWAY
Think of the planned audit response like a physician ordering diagnostic tests after a preliminary examination. The physician (auditor) first identifies symptoms and risk factors (assessed risks of material misstatement), then prescribes specific lab work or imaging (tests of controls and substantive procedures) calibrated to the seriousness and nature of the suspected condition. A patient with multiple cardiac risk factors gets a stress test and an echocardiogram—not just a basic blood panel. Similarly, a high-risk revenue assertion triggers more rigorous, precisely targeted audit procedures.

Visual Explanation — The Risk Response Framework

The diagram shows the audit response hierarchy. Risk assessment feeds into both overall responses (financial-statement level) and further audit procedures (assertion level). Further audit procedures split into tests of controls and substantive procedures, each designed across three dimensions—nature, timing, and extent—ultimately converging on sufficient appropriate audit evidence.

As the diagram illustrates, the auditor's journey begins with risk assessment—understanding the entity and its environment, evaluating internal control, and identifying risks of material misstatement at both the financial-statement level and the assertion level. Financial-statement-level risks (such as management override of controls or a pervasive weak control environment) call for overall responses—for example, assigning more experienced staff, incorporating additional unpredictability into testing, or performing more procedures at period-end rather than interim. Assertion-level risks, by contrast, demand specific further audit procedures tailored to the particular assertion at risk—existence of receivables, completeness of payables, valuation of inventory, and so forth. These further procedures are the subject of the rest of this lesson.

The Audit Risk Model & Designing the Response

The audit risk model provides the conceptual scaffold for understanding how auditors calibrate their response. While the model is not used as a precise mathematical formula in practice, its logic drives every planning decision. The model expresses audit risk as the product of three component risks, and the auditor's planned response is fundamentally about managing the one component the auditor controls—detection risk.

AUDIT RISK MODEL
AR = IR × CR × DR
AR = Audit Risk (the risk of issuing an inappropriate opinion); IR = Inherent Risk (susceptibility to material misstatement absent controls); CR = Control Risk (risk that controls fail to prevent/detect misstatement); DR = Detection Risk (risk that audit procedures fail to detect misstatement). The auditor sets an acceptably low AR, assesses IR and CR, and solves for the maximum tolerable DR.
DETECTION RISK (REARRANGED)
DR = AR ÷ (IR × CR)
When IR and CR are assessed as high, the denominator is large relative to AR, driving DR to a very low level. A low tolerable DR means the auditor must design more effective and extensive procedures. Conversely, when controls are strong (low CR), the auditor may accept a higher DR, permitting less extensive substantive testing.

The practical implication is straightforward but powerful. If the auditor plans to rely on internal controls (i.e., assesses control risk below the maximum), the auditor must first test those controls to confirm they are operating effectively. Successful control testing justifies a reduced assessment of control risk, which in turn allows the auditor to accept a higher detection risk and, consequently, reduce the extent of substantive procedures. If the auditor does not plan to rely on controls—or if control testing reveals deficiencies—the auditor must set control risk at the maximum and compensate by expanding substantive work.

INVERSE RELATIONSHIP — CONTROL RELIANCE & SUBSTANTIVE TESTING
↑ Control Reliance → ↓ CR → ↑ Tolerable DR → ↓ Substantive Extent
Greater reliance on controls (supported by successful tests of controls) reduces control risk, increases tolerable detection risk, and permits a reduction in the nature, timing, or extent of substantive procedures. The converse also holds: no control reliance means maximum substantive effort.
⚠️ Important Constraint
Regardless of the assessed level of control risk, AU-C 330 requires the auditor to design and perform substantive procedures for each material class of transactions, account balance, and disclosure. Substantive procedures can never be entirely eliminated through control testing alone.

Nature, Timing & Extent — Designing Specific Procedures

The three dimensions of any audit procedure—nature, timing, and extent—must be calibrated to the assessed risk. Higher assessed risk demands more persuasive evidence, which translates into procedures that are more reliable in nature, performed closer to the period-end in timing, and applied to larger samples in extent. The table below contrasts how these dimensions differ between tests of controls and substantive procedures.

This matrix shows how the three dimensions of audit procedure design—nature, timing, and extent—are applied to tests of controls (green) and substantive procedures (blue). Higher assessed risk pushes each dimension toward more persuasive, later-timed, and more extensive procedures.

The matrix reveals a key architectural insight: while tests of controls and substantive procedures serve different purposes, they share the same three design levers. For tests of controls, the auditor is asking whether the control operated consistently and effectively throughout the period; the more critical the control, the more transactions the auditor samples and the more persuasive the technique (reperformance over mere inquiry). For substantive procedures, the auditor is asking whether the account balance or transaction class is free of material misstatement; higher risk drives the auditor toward external confirmations and detailed vouching rather than relying solely on analytical procedures, toward year-end testing rather than interim testing, and toward larger sample sizes or even 100% examination of certain populations.

Mapping assertions to illustrative control and substantive procedures
Assertion at RiskExample Control TestExample Substantive Procedure
Existence — Accounts ReceivableInspect credit approval documentation for a sample of new customersSend positive external confirmations to a sample of debtors at year-end
Completeness — Accounts PayableReperform three-way matching (PO, receiving report, invoice) for a sample of disbursementsSearch for unrecorded liabilities by examining subsequent disbursements and open invoices after year-end
Valuation — InventoryInspect evidence that management reviews and approves obsolescence reserves quarterlyTest net realizable value by comparing carrying amounts to recent sales prices less costs to complete and sell
Occurrence — RevenueReperform IT general controls over system-generated revenue entriesVouch recorded revenue transactions to shipping documents, contracts, and customer acceptance

Worked Example — Designing an Audit Response for Revenue

Consider a mid-size manufacturing company, Apex Industries, that recognizes revenue at the point of shipment under ASC 606. The audit team has assessed the risk of material misstatement for the occurrence assertion of revenue as significant risk because of aggressive sales targets, a history of side agreements, and complex bill-and-hold arrangements. Revenue is presumed to be a fraud risk under AU-C 240. The following worked example demonstrates how the audit team designs its planned response.

Designing the Planned Audit Response for Apex Industries' Revenue
1
Step 1 — Document the Assessed RiskThe team formally documents that the occurrence assertion for revenue is a significant risk. Because the presumed fraud risk applies, the team must design procedures that address the possibility that revenue transactions have been fictitiously recorded. They note the specific factors: aggressive sales targets and bill-and-hold arrangements.
Risk classification: Significant Risk — Revenue Occurrence (fraud presumption)
2
Step 2 — Determine Overall ResponsesAt the financial-statement level, the engagement partner decides to assign a more experienced senior manager to lead revenue testing, to increase supervision of junior staff on this area, and to incorporate elements of unpredictability—such as testing revenue at a non-standard interim date and selecting sample items from an unusual stratum.
Overall responses: Senior staffing, increased supervision, unpredictability
3
Step 3 — Evaluate Whether to Test ControlsThe team identifies a key control: the shipping manager independently verifies that goods physically left the warehouse before the revenue system records the sale, and this verification is logged in the ERP system. The team also identifies an IT application control that prevents revenue recognition unless a valid shipping confirmation exists. Because these controls directly address the occurrence assertion and the team plans to rely on them to reduce substantive sample sizes, tests of controls are required.
Decision: Test controls — shipping verification (manual) and ERP application control (automated)
4
Step 4 — Design Tests of Controls (NTE)Nature: For the manual shipping verification, the team will reperform the control by independently matching a sample of revenue entries to shipping log confirmations and bill of lading documents. For the automated IT control, the team will inspect the configuration settings and test the logic with sample transactions. Timing: Since this is a significant risk, controls will be tested at interim and then updated through the remaining period to year-end. Extent: Given that the manual control operates for each shipment (daily frequency), the team selects a sample of 40 items (exceeding the common 25-item baseline for higher-risk controls), spread across the full year.
Control test: Reperformance, 40-item sample, interim + roll-forward
5
Step 5 — Design Substantive Procedures (NTE)Because revenue occurrence is a significant risk, substantive procedures alone must be performed at or near the period end, regardless of control effectiveness. Nature: The team designs a dual-direction test—vouching recorded revenue entries to shipping documents, contracts, and customer acceptance (testing occurrence/existence), and also performing a cutoff test examining transactions in the final five days of the fiscal year and the first five days of the subsequent year. The team will also send external confirmations to a sample of customers for significant year-end balances. They add a substantive analytical procedure comparing monthly revenue trends to prior year, industry data, and production volumes. Timing: Tests of details will be performed at year-end; the analytical procedure will cover all twelve months. Extent: Given the significant risk, the team increases the sample to 60 revenue transactions for vouching (compared to 25 they might use for a normally assessed risk) and confirms balances representing 70% of the receivable balance by dollar value.
Substantive plan: Vouching (60 items), cutoff test, confirmations (70% by value), analytical procedure — all at year-end
6
Step 6 — Evaluate Sufficiency and DocumentThe team evaluates whether the combined evidence from control testing and substantive procedures provides sufficient appropriate audit evidence to reduce audit risk to an acceptably low level for the occurrence assertion. They document the linkage between each procedure and the specific risk factor it addresses (e.g., cutoff testing addresses bill-and-hold risk; confirmations address fictitious revenue). The audit program is reviewed by the engagement partner before fieldwork begins.
Documented linkage: Each procedure → specific risk factor → assertion-level evidence

Substantive-Only vs. Combined Approach — Strengths & Limitations

Auditors face a strategic decision at the planning stage: pursue a substantive-only approach (assessing control risk at the maximum and relying entirely on substantive procedures) or a combined approach (testing controls to reduce the assessed level of control risk and then performing a reduced level of substantive testing). Neither approach is inherently superior; the choice depends on the entity's control environment, the nature of the assertions at risk, and efficiency considerations.

Strategic comparison of audit approaches
FactorSubstantive-Only ApproachCombined Approach
When appropriateWeak control environment; controls not designed effectively; small entity with limited segregation of duties; auditor concludes control testing would not be efficientStrong control environment; well-designed controls operate consistently; high-volume transactions where substantive testing of every item is impractical
Effect on detection riskControl risk assessed at maximum; tolerable detection risk is low; requires extensive substantive testingControl risk assessed below maximum; tolerable detection risk is higher; permits reduced substantive extent
EfficiencyCan be efficient for small populations or low-volume accounts; avoids cost of control testingOften more efficient for high-volume areas; initial investment in control testing pays off through reduced sample sizes in substantive work
LimitationsDoes not provide evidence about control effectiveness; may not address risks from process breakdowns; may be impractical for highly automated processesRequires additional audit effort upfront; control deficiencies may force reversion to substantive-only, wasting initial testing investment
For significant risksSubstantive procedures must be performed at period-end regardless; no relief from timing requirementsTests of controls in the current period are required (no reliance on prior-period results); substantive testing at period-end still mandatory
KEY TAKEAWAY
Choosing between a substantive-only and combined approach is analogous to deciding whether to invest upfront in quality-assurance infrastructure on a manufacturing line. If the product line is small and simple, direct inspection of every finished good (substantive-only) may be faster and cheaper. But as volume and complexity increase, investing in automated quality-control checkpoints (tests of controls) pays dividends by allowing you to inspect a smaller sample of output with confidence that the process itself catches most defects. The auditor's decision follows the same cost-benefit logic.

Connection to Integrated Audits & Advanced Risk Concepts

For public companies subject to PCAOB standards, the planned audit response extends into the realm of the integrated audit under AS 2201 (Audit of Internal Control Over Financial Reporting). In an integrated audit, the auditor performs both the financial statement audit and the audit of internal control in a coordinated manner. The planned response must therefore serve dual objectives: providing an opinion on the financial statements and providing an opinion on the effectiveness of internal control over financial reporting (ICFR). Understanding how the planned response for a financial statement audit relates to—and differs from—the integrated audit context is essential for CPA candidates.

Financial statement audit vs. integrated audit — control testing differences
DimensionFinancial Statement Audit (AU-C 330)Integrated Audit (AS 2201)
Control testing requirementOptional — only required if auditor intends to rely on controls to reduce substantive testingMandatory — auditor must test controls sufficient to opine on ICFR effectiveness
Scope of control testingLimited to controls the auditor plans to rely uponBroad — must cover all significant accounts and relevant assertions, including entity-level controls
Use of prior-period resultsMay use if controls unchanged and not significant risk areasCannot solely rely on prior-period results; must test each control in the current period
Deficiency evaluationCommunicate significant deficiencies and material weaknesses to governanceMust evaluate and classify deficiencies; material weakness results in adverse ICFR opinion
Impact on substantive testingEffective controls allow reduced substantive extentControl testing evidence can be leveraged for the financial statement audit, creating efficiencies

Beyond the integrated audit, advanced risk concepts that connect to the planned audit response include the distinction between pervasive risks and specific risks, the concept of stand-back evaluation (where the auditor assesses whether the overall audit response adequately addresses the identified risks before issuing the opinion), and the emerging role of data analytics in designing more targeted substantive procedures. As the profession continues evolving, auditors increasingly use technology to analyze entire populations rather than samples, fundamentally reshaping the extent dimension of the planned response.

Practice Problems

PROBLEM 1CONCEPTUAL
Explain why an auditor is required to perform substantive procedures for every material class of transactions, account balance, and disclosure, even when tests of controls indicate that controls are operating effectively. What fundamental limitation of control testing makes this requirement necessary?
PROBLEM 2BASIC CALCULATION
An auditor sets the acceptable level of audit risk (AR) at 5%. The assessed inherent risk (IR) for the completeness assertion of accounts payable is 80%, and the assessed control risk (CR) is 50% (the auditor plans to test controls). Using the audit risk model, calculate the maximum tolerable detection risk (DR). Then recalculate DR assuming the auditor decides not to test controls and sets CR at 100%.
PROBLEM 3INTERMEDIATE
An auditor identifies the valuation of a complex derivative financial instrument as a significant risk. The client's internal control relevant to this assertion involves a monthly review by the CFO comparing the instrument's fair value to an independent pricing service. Describe how the auditor should design both tests of controls and substantive procedures, specifying the nature, timing, and extent for each category. Explain how the significant risk classification affects your design.
PROBLEM 4APPLIED
You are the senior auditor on the engagement for TechStream Corp., a rapidly growing SaaS company. The company processes 500,000 subscription revenue transactions annually through an automated billing system. Revenue recognition under ASC 606 is complex because contracts include multiple performance obligations (software licenses, implementation services, and ongoing support). The audit team has assessed the occurrence and allocation assertions for revenue as significant risks. Management tells you they have strong automated controls in their billing system. Draft a planning memo section that outlines your recommended audit approach, including: (a) whether to use a combined or substantive-only approach and why; (b) specific tests of controls you would design; (c) specific substantive procedures; and (d) how the high volume of transactions affects your NTE decisions.
PROBLEM 5CRITICAL THINKING
A colleague argues that with advances in data analytics, auditors can now test 100% of a transaction population substantively (e.g., using automated algorithms to flag anomalies in all revenue transactions), making tests of controls obsolete. Critically evaluate this argument. Under what circumstances might a 100% substantive analytical approach still be insufficient? When would control testing remain essential despite the availability of full-population analytics?

Lesson Summary

The planned audit response is the critical bridge between risk assessment and evidence gathering. After identifying and assessing risks of material misstatement, auditors design overall responses at the financial-statement level and further audit procedures at the assertion level. Further audit procedures consist of tests of controls (evaluating operating effectiveness) and substantive procedures (detecting material misstatements directly), each calibrated across three design dimensions: nature, timing, and extent.

The audit risk model (AR = IR × CR × DR) provides the conceptual logic: the auditor manages detection risk to achieve an acceptably low audit risk, and the choice between a substantive-only approach and a combined approach depends on the entity's control environment, transaction volume, and efficiency considerations. For significant risks, standards impose additional requirements: substantive procedures must be performed at or near the period-end, and the auditor may not rely on prior-period control test results. Regardless of the approach taken, substantive procedures are always required for every material class of transactions, account balance, and disclosure—control testing can reduce but never eliminate the need for direct substantive evidence.

Varsity Tutors • CPA Auditing & Attestation (AUD) • Planned Audit Response — Design Substantive And Control Testing Procedures