4.1 Audit Evidence Concepts, Reliability Hierarchy & Working Papers

Key Takeaways

  • ISA 500 mandates that auditors obtain sufficient appropriate audit evidence to draw reasonable conclusions on which to base the audit opinion.
  • Sufficiency measures the quantity of audit evidence, influenced by the risk of material misstatement and materiality, whereas appropriateness measures quality in terms of relevance and reliability.
  • The reliability hierarchy establishes that external, direct, documentary, original, and control-tested evidence is inherently superior to internal, indirect, oral, or photocopy evidence.
  • ISA 230 requires audit documentation to be sufficient to enable an experienced auditor with no previous connection to the audit to understand the nature, timing, extent, and results of procedures performed.
  • Working papers are confidential properties of the audit firm, structured into Permanent Audit Files (PAF) and Current Audit Files (CAF), and should ordinarily be assembled into the final file within 60 days of the auditor's report date and retained for no less than five years from that date under ISQM 1.
Last updated: August 2026

Audit Evidence Concepts, Reliability Hierarchy & Working Papers

1. Overview of Audit Evidence (ISA 500)

Audit evidence is the foundation of any assurance engagement. Under ISA 500 (Audit Evidence), as adopted by the Institute of Chartered Accountants of Bangladesh (ICAB), the auditor is required to design and perform audit procedures to obtain sufficient appropriate audit evidence to be able to draw reasonable conclusions on which to base the audit opinion.

Audit evidence comprises both information that supports and corroborates management's assertions in the financial statements and any information that contradicts such assertions. It includes information contained within the accounting records underlying the financial statements (such as books of original entry, general ledgers, journal entries, and electronic spreadsheets) as well as corroborative information from external sources (such as bank confirmations, supplier statements, contracts, and analyst reports).

In Bangladesh, where commercial practices often involve a mix of computerized accounting systems and paper-based documentation, obtaining robust audit evidence requires practitioners to evaluate both digital logs and physical supporting vouchers. The primary objective is to reduce audit risk—the risk that the auditor expresses an inappropriate audit opinion when the financial statements are materially misstated—to an acceptably low level.


2. Sufficiency vs. Appropriateness of Audit Evidence

ISA 500 establishes two distinct but interrelated dimensions of audit evidence: sufficiency and appropriateness.

Audit Evidence Quality = Sufficiency (Quantity) + Appropriateness (Relevance + Reliability)

Sufficiency (The Quantitative Dimension)

Sufficiency is the measure of the quantity of audit evidence required. The auditor's determination of sample size and the extent of audit procedures is influenced primarily by:

  1. Assessment of Risk of Material Misstatement (RMM): As the assessed risk of material misstatement increases, the quantity of evidence required also increases (a direct relationship).
  2. Quality of Evidence Obtained: As the quality, relevance, and reliability of evidence increase, the quantity required may decrease (an inverse relationship). However, obtaining more evidence cannot compensate for evidence that is of low quality or irrelevant.
  3. Materiality: Items that are material by value or nature demand a larger volume of corroborative evidence.
  4. Population Heterogeneity: Diverse or highly variable account balances require larger sample sizes than homogenous populations.

Important ICAB Exam Note: High cost or difficulty in obtaining evidence is not a valid basis for omitting an audit procedure for which there is no acceptable alternative!

Appropriateness (The Qualitative Dimension)

Appropriateness is the measure of the quality of audit evidence—specifically, its relevance and its reliability in providing support for the conclusions on which the auditor's opinion is based.

  • Relevance: Refers to the logical connection with, or bearing upon, the purpose of the audit procedure and the assertion under consideration. For example, inspecting physical inventory items provides relevant evidence for the assertion of existence, but does not provide relevant evidence for the assertion of rights and obligations (the goods might be held on consignment).
  • Reliability: Refers to the trustfulness and authenticity of the information. The reliability of evidence is influenced by its source, its nature, and the circumstances under which it is obtained.

3. The Reliability Hierarchy of Audit Evidence

ISA 500 establishes general rules regarding the reliability of audit evidence. Understanding this hierarchy is vital for both practical auditing and passing the ICAB Certificate Level examination.

RankingReliability CriterionExplanation & Practical Context
1 (Highest)External Independent SourcesEvidence obtained from independent sources outside the entity (e.g., direct bank confirmation, customer confirmation) is more reliable than internal evidence.
2Effective Internal ControlsEvidence generated internally is more reliable when the entity's related internal controls (e.g., automated sequence checks, authorization controls) operate effectively.
3Direct Auditor KnowledgeEvidence obtained directly by the auditor (e.g., physical observation of an asset or reperformance of a calculation) is more reliable than evidence obtained indirectly or by inference.
4Documentary FormEvidence existing in documentary form (paper, electronic, or other medium) is more reliable than oral representations.
5 (Lowest)Original DocumentsEvidence provided by original documents is more reliable than evidence provided by photocopies, faxes, or digitized scans, which may be altered.

Summary Reliability Comparison Table

More Reliable EvidenceLess Reliable EvidenceUnderlying Reason
External bank confirmation letterManagement statement on cash balancesIndependent third-party source
Inventory count observed by auditorClient's warehouse stock sheetDirect auditor observation
Supplier invoice received directlyCopy of internal purchase orderExternal original document
Sales ledger extract from automated systemManual sales summary spreadsheetEffective internal control system
Signed written board minutesVerbal explanation from Chief Financial OfficerPermanent written record

4. Primary Audit Procedures to Gather Evidence

Auditors perform seven fundamental audit procedures to obtain audit evidence during risk assessment, tests of controls, and substantive testing:

  1. Inspection: Examining records, documents (whether internal or external, paper or electronic), or physical assets. Inspection of tangible assets provides reliable evidence of existence.
  2. Observation: Looking at a process or procedure being performed by others (e.g., observing inventory counting by client personnel or observing control activities). Observation is limited to the point in time at which it takes place.
  3. External Confirmation: A direct written response obtained by the auditor from a third party (confirming party) in paper or electronic form (governed by ISA 505).
  4. Recalculation: Checking the mathematical accuracy of documents or records (e.g., re-footing a sales journal or recalculating depreciation expense).
  5. Reperformance: The auditor's independent execution of procedures or controls that were originally performed as part of the entity's internal control (e.g., reperforming the aging of accounts receivable).
  6. Analytical Procedures: Evaluations of financial information made by a study of plausible relationships among both financial and non-financial data (governed by ISA 520).
  7. Inquiry: Seeking information from knowledgeable persons, both financial and non-financial, within the entity or outside the entity. Inquiry alone does not provide sufficient audit evidence to support an audit opinion.

5. Audit Documentation & Working Papers (ISA 230)

ISA 230 (Audit Documentation) defines audit documentation (commonly referred to as working papers) as the record of audit procedures performed, relevant audit evidence obtained, and conclusions the auditor reached.

Objectives of Working Papers

  • Providing evidence of the auditor's basis for a conclusion about the achievement of overall audit objectives.
  • Providing evidence that the audit was planned and performed in accordance with ISAs/BSAs and applicable legal and regulatory requirements (e.g., Companies Act 1994, Financial Reporting Act 2015).
  • Assisting the engagement team to plan and perform the audit, and enabling supervisory review and engagement quality reviews.

The "Experienced Auditor" Standard

ISA 230 mandates that working papers must be prepared in such detail that an experienced auditor, having no previous connection with the audit, can understand:

  1. The nature, timing, and extent of audit procedures performed to comply with ISAs and legal requirements.
  2. The results of the audit procedures performed and the audit evidence obtained.
  3. Significant matters arising during the audit, conclusions reached, and significant professional judgments made in reaching those conclusions.

Structure of Working Paper Files: PAF vs. CAF

Audit files are systematically categorized into two main folders:

FeaturePermanent Audit File (PAF)Current Audit File (CAF)
NatureContains matters of continuing, long-term importance to the engagement across multiple years.Contains documentation relevant specifically to the financial period under current audit.
Key Contents• Memorandum & Articles of Association<br/>• Statutory registers & capital structure<br/>• Long-term lease agreements & debt instruments<br/>• Overview of business & legal history<br/>• Historical internal control evaluations• Current financial statements & trial balance<br/>• Audit plan, strategy & risk assessment<br/>• Completed audit programs & test schedules<br/>• Bank, customer & supplier confirmations<br/>• Summary of Audit Differences (SAD)<br/>• Final review notes & representation letters
UpdatingReviewed and updated annually for structural changes.Compiled fresh for every financial year.

Archiving, Ownership & Confidentiality Requirements

  • Assembly of Final Audit File: The auditor must assemble the audit documentation into a final audit file on a timely basis after the date of the auditor's report. Under ISA 230, the assembly period should not exceed 60 days after the date of the auditor's report.
  • Retention Period: The retention period for audit documentation is typically not shorter than 5 years (or 7 years under specific ICAB guidelines and regulatory requirements in Bangladesh) from the date of the auditor's report.
  • Ownership: Audit working papers are the property of the auditor/audit firm, not the client. While clients have a right to inspect financial records, they have no statutory right to demand access to the auditor's internal working papers.
  • Confidentiality: Under the ICAB Code of Ethics, auditors must maintain strict confidentiality regarding client working papers. Documents cannot be disclosed to third parties unless client permission is granted or a statutory/legal duty obligates disclosure (e.g., order from a court or request from the Financial Reporting Council - FRC).
Loading diagram...
Audit Evidence Reliability Hierarchy and Working Paper Structure
Test Your Knowledge

According to ISA 500, what is the primary distinction between the sufficiency and appropriateness of audit evidence?

A
B
C
D
Test Your Knowledge

Which of the following sources of audit evidence is considered inherently most reliable under the ISA 500 evidence hierarchy?

A
B
C
D
Test Your Knowledge

Where should a copy of a client's 10-year factory lease agreement and Memorandum of Association be archived under ISA 230?

A
B
C
D