Historical Context & Motivation
The modern concept of a planned audit response did not materialize overnight; it evolved over more than a century of financial scandals, regulatory reforms, and the accounting profession's gradual shift from a vouching-every-transaction approach to a risk-based methodology. Early audits in the nineteenth century were essentially complete examinations of books and records, which became impractical as businesses grew in scale and complexity. The profession recognized that limited resources demanded a smarter allocation of effort—one driven by where things were most likely to go wrong. This insight eventually produced the risk-based audit model that underpins today's auditing standards, requiring auditors to assess risks of material misstatement and then design procedures—both tests of controls and substantive tests—that respond directly to those risks.
The central question that emerged from this evolution is deceptively simple: once an auditor identifies and assesses the risks of material misstatement at both the financial-statement level and the assertion level, how should the audit team design procedures that are responsive to those risks? The answer requires understanding the interplay between tests of controls and substantive procedures—their purposes, how they complement each other, and the professional judgment involved in calibrating the nature, timing, and extent of each.
Core Principles & Definitions
Designing an effective audit response requires fluency in several foundational concepts. Under AU-C Section 330 (Performing Audit Procedures in Response to Assessed Risks and Evaluating the Audit Evidence Obtained), the auditor must design and implement overall responses to assessed risks at the financial-statement level and further audit procedures at the assertion level. Further audit procedures comprise tests of controls and substantive procedures, and their design is governed by three dimensions: nature, timing, and extent.
Tests of Controls
Substantive Procedures
Nature, Timing, and Extent (NTE)
Relevant Assertions
Detection Risk
Visual Explanation — The Risk Response Framework
As the diagram illustrates, the auditor's journey begins with risk assessment—understanding the entity and its environment, evaluating internal control, and identifying risks of material misstatement at both the financial-statement level and the assertion level. Financial-statement-level risks (such as management override of controls or a pervasive weak control environment) call for overall responses—for example, assigning more experienced staff, incorporating additional unpredictability into testing, or performing more procedures at period-end rather than interim. Assertion-level risks, by contrast, demand specific further audit procedures tailored to the particular assertion at risk—existence of receivables, completeness of payables, valuation of inventory, and so forth. These further procedures are the subject of the rest of this lesson.
The Audit Risk Model & Designing the Response
The audit risk model provides the conceptual scaffold for understanding how auditors calibrate their response. While the model is not used as a precise mathematical formula in practice, its logic drives every planning decision. The model expresses audit risk as the product of three component risks, and the auditor's planned response is fundamentally about managing the one component the auditor controls—detection risk.
The practical implication is straightforward but powerful. If the auditor plans to rely on internal controls (i.e., assesses control risk below the maximum), the auditor must first test those controls to confirm they are operating effectively. Successful control testing justifies a reduced assessment of control risk, which in turn allows the auditor to accept a higher detection risk and, consequently, reduce the extent of substantive procedures. If the auditor does not plan to rely on controls—or if control testing reveals deficiencies—the auditor must set control risk at the maximum and compensate by expanding substantive work.
Nature, Timing & Extent — Designing Specific Procedures
The three dimensions of any audit procedure—nature, timing, and extent—must be calibrated to the assessed risk. Higher assessed risk demands more persuasive evidence, which translates into procedures that are more reliable in nature, performed closer to the period-end in timing, and applied to larger samples in extent. The table below contrasts how these dimensions differ between tests of controls and substantive procedures.
The matrix reveals a key architectural insight: while tests of controls and substantive procedures serve different purposes, they share the same three design levers. For tests of controls, the auditor is asking whether the control operated consistently and effectively throughout the period; the more critical the control, the more transactions the auditor samples and the more persuasive the technique (reperformance over mere inquiry). For substantive procedures, the auditor is asking whether the account balance or transaction class is free of material misstatement; higher risk drives the auditor toward external confirmations and detailed vouching rather than relying solely on analytical procedures, toward year-end testing rather than interim testing, and toward larger sample sizes or even 100% examination of certain populations.
| Assertion at Risk | Example Control Test | Example Substantive Procedure |
|---|---|---|
| Existence — Accounts Receivable | Inspect credit approval documentation for a sample of new customers | Send positive external confirmations to a sample of debtors at year-end |
| Completeness — Accounts Payable | Reperform three-way matching (PO, receiving report, invoice) for a sample of disbursements | Search for unrecorded liabilities by examining subsequent disbursements and open invoices after year-end |
| Valuation — Inventory | Inspect evidence that management reviews and approves obsolescence reserves quarterly | Test net realizable value by comparing carrying amounts to recent sales prices less costs to complete and sell |
| Occurrence — Revenue | Reperform IT general controls over system-generated revenue entries | Vouch recorded revenue transactions to shipping documents, contracts, and customer acceptance |
Worked Example — Designing an Audit Response for Revenue
Consider a mid-size manufacturing company, Apex Industries, that recognizes revenue at the point of shipment under ASC 606. The audit team has assessed the risk of material misstatement for the occurrence assertion of revenue as significant risk because of aggressive sales targets, a history of side agreements, and complex bill-and-hold arrangements. Revenue is presumed to be a fraud risk under AU-C 240. The following worked example demonstrates how the audit team designs its planned response.
Substantive-Only vs. Combined Approach — Strengths & Limitations
Auditors face a strategic decision at the planning stage: pursue a substantive-only approach (assessing control risk at the maximum and relying entirely on substantive procedures) or a combined approach (testing controls to reduce the assessed level of control risk and then performing a reduced level of substantive testing). Neither approach is inherently superior; the choice depends on the entity's control environment, the nature of the assertions at risk, and efficiency considerations.
| Factor | Substantive-Only Approach | Combined Approach |
|---|---|---|
| When appropriate | Weak control environment; controls not designed effectively; small entity with limited segregation of duties; auditor concludes control testing would not be efficient | Strong control environment; well-designed controls operate consistently; high-volume transactions where substantive testing of every item is impractical |
| Effect on detection risk | Control risk assessed at maximum; tolerable detection risk is low; requires extensive substantive testing | Control risk assessed below maximum; tolerable detection risk is higher; permits reduced substantive extent |
| Efficiency | Can be efficient for small populations or low-volume accounts; avoids cost of control testing | Often more efficient for high-volume areas; initial investment in control testing pays off through reduced sample sizes in substantive work |
| Limitations | Does not provide evidence about control effectiveness; may not address risks from process breakdowns; may be impractical for highly automated processes | Requires additional audit effort upfront; control deficiencies may force reversion to substantive-only, wasting initial testing investment |
| For significant risks | Substantive procedures must be performed at period-end regardless; no relief from timing requirements | Tests of controls in the current period are required (no reliance on prior-period results); substantive testing at period-end still mandatory |
Connection to Integrated Audits & Advanced Risk Concepts
For public companies subject to PCAOB standards, the planned audit response extends into the realm of the integrated audit under AS 2201 (Audit of Internal Control Over Financial Reporting). In an integrated audit, the auditor performs both the financial statement audit and the audit of internal control in a coordinated manner. The planned response must therefore serve dual objectives: providing an opinion on the financial statements and providing an opinion on the effectiveness of internal control over financial reporting (ICFR). Understanding how the planned response for a financial statement audit relates to—and differs from—the integrated audit context is essential for CPA candidates.
| Dimension | Financial Statement Audit (AU-C 330) | Integrated Audit (AS 2201) |
|---|---|---|
| Control testing requirement | Optional — only required if auditor intends to rely on controls to reduce substantive testing | Mandatory — auditor must test controls sufficient to opine on ICFR effectiveness |
| Scope of control testing | Limited to controls the auditor plans to rely upon | Broad — must cover all significant accounts and relevant assertions, including entity-level controls |
| Use of prior-period results | May use if controls unchanged and not significant risk areas | Cannot solely rely on prior-period results; must test each control in the current period |
| Deficiency evaluation | Communicate significant deficiencies and material weaknesses to governance | Must evaluate and classify deficiencies; material weakness results in adverse ICFR opinion |
| Impact on substantive testing | Effective controls allow reduced substantive extent | Control testing evidence can be leveraged for the financial statement audit, creating efficiencies |
Beyond the integrated audit, advanced risk concepts that connect to the planned audit response include the distinction between pervasive risks and specific risks, the concept of stand-back evaluation (where the auditor assesses whether the overall audit response adequately addresses the identified risks before issuing the opinion), and the emerging role of data analytics in designing more targeted substantive procedures. As the profession continues evolving, auditors increasingly use technology to analyze entire populations rather than samples, fundamentally reshaping the extent dimension of the planned response.
Practice Problems
Lesson Summary
The planned audit response is the critical bridge between risk assessment and evidence gathering. After identifying and assessing risks of material misstatement, auditors design overall responses at the financial-statement level and further audit procedures at the assertion level. Further audit procedures consist of tests of controls (evaluating operating effectiveness) and substantive procedures (detecting material misstatements directly), each calibrated across three design dimensions: nature, timing, and extent.
The audit risk model (AR = IR × CR × DR) provides the conceptual logic: the auditor manages detection risk to achieve an acceptably low audit risk, and the choice between a substantive-only approach and a combined approach depends on the entity's control environment, transaction volume, and efficiency considerations. For significant risks, standards impose additional requirements: substantive procedures must be performed at or near the period-end, and the auditor may not rely on prior-period control test results. Regardless of the approach taken, substantive procedures are always required for every material class of transactions, account balance, and disclosure—control testing can reduce but never eliminate the need for direct substantive evidence.