7.1 Audit Evidence: Sufficiency, Appropriateness & Management Assertions (AU-C 500)

Key Takeaways

  • Audit evidence encompasses all information utilized by the auditor to arrive at audit conclusions; it must be both sufficient (a quantity measure driven by RMM and evidence quality) and appropriate (a quality measure encompassing relevance and reliability).
  • A common study ladder built on AU-C 500's generalizations ranks direct personal knowledge of the auditor highest, followed by direct external third-party evidence, client-held external documents, internal documents under effective controls, internal documents under weak controls, and oral client representations lowest.
  • Management assertions are divided into classes of transactions and events for the period under audit (Occurrence, Completeness, Accuracy, Cutoff, Classification, Presentation) and period-end account balances (Existence, Rights and Obligations, Completeness, Accuracy/Valuation and Allocation, Classification, Presentation).
  • Directional testing dictates procedure relevance: testing Existence or Occurrence requires vouching backward from accounting records to source documents (addressing overstatement risk), whereas testing Completeness requires tracing forward from source documents to accounting records (addressing understatement risk).
  • Original documents provide greater reliability than photocopies, faxes, or scanned digital images; inquiry alone can never provide sufficient appropriate audit evidence to substantiate an assertion without corroborating procedures.
Last updated: September 2026

7.1 Audit Evidence: Sufficiency, Appropriateness & Management Assertions (AU-C 500)

Core Principle: Under AU-C 500 (Audit Evidence), the auditor must design and perform audit procedures to obtain sufficient appropriate audit evidence to be able to draw reasonable conclusions on which to base the auditor's opinion. Audit evidence is cumulative in nature and is primarily obtained from audit procedures performed during the course of the audit. It includes both information that supports and corroborates management's assertions, and any information that contradicts such assertions.


1. Foundational Architecture: Sufficiency vs. Appropriateness

Audit evidence is evaluated across two distinct, interrelated dimensions: Sufficiency (a quantitative measure) and Appropriateness (a qualitative measure).

                                    TOTAL AUDIT EVIDENCE
                                              |
                     +------------------------+------------------------+
                     |                                                 |
             [ SUFFICIENCY ]                                  [ APPROPRIATENESS ]
           QUANTITY OF EVIDENCE                              QUALITY OF EVIDENCE
                     |                                                 |
        +------------+------------+                       +------------+------------+
        |                         |                       |                         |
     Assessed                 Quality of               Relevance               Reliability
       RMM                     Evidence               (Assertion &              (Source &
  (Higher RMM =              (Higher Quality =         Directional             Circumstances
  More Evidence)             Less Quantity)             Validity)               of Evidence)

Sufficiency (The Quantity Dimension)

Sufficiency is the measure of the quantity of audit evidence. The quantity of evidence needed is affected by:

  1. The Assessed Risk of Material Misstatement (RMM): As the assessed risk of material misstatement increases (at either the financial statement level or assertion level), the required quantity of evidence increases. Greater inherent risk or control risk demands more extensive substantive testing.
  2. The Quality of the Audit Evidence Obtained: As the quality (appropriateness) of evidence increases, the quantity of evidence required decreases. Highly reliable evidence obtained directly from independent external sources reduces the volume of internal testing necessary.
  3. Materiality and Tolerable Misstatement: Lower materiality thresholds or smaller tolerable misstatements necessitate larger sample sizes and a greater quantity of evidence.

Critical Exam Rule (The One-Way Street): Although the quality of evidence affects the quantity needed, merely obtaining a large volume of low-quality evidence CANNOT compensate for a lack of appropriateness. If evidence is unreliable or irrelevant, accumulating more of it provides zero incremental assurance.

Appropriateness (The Quality Dimension)

Appropriateness is the measure of the quality of audit evidence, consisting of two indispensable components: Relevance and Reliability.

A. Relevance

Relevance deals with the logical connection with, or bearing upon, the purpose of the audit procedure and the assertion under consideration. Evidence may be highly reliable in the abstract, but if it does not test the specific assertion at risk, it is useless.

  • Direction of Testing: Relevance is heavily governed by the direction of testing. For example, testing the existence of sales requires vouching recorded ledger entries backward to shipping documents; tracing forward from shipping documents to the sales journal is irrelevant for existence (though highly relevant for completeness).
  • Dual Purpose Testing: A single audit procedure may provide evidence for multiple assertions (e.g., inspecting an inventory item confirms existence and helps evaluate valuation if damage is noted), or multiple procedures may be required to validate a single assertion.

B. Reliability

Reliability refers to the nature and source of the evidence, and the circumstances under which it is obtained. The reliability of evidence is influenced by its source (internal vs. external), its nature (visual, documentary, or oral), and the effectiveness of controls over its production.

C. Attributes Emphasized by SAS No. 142

SAS No. 142 (effective for periods ending on or after December 15, 2022) directs the auditor to evaluate information intended as audit evidence for relevance and reliability, including its accuracy, completeness, authenticity, and susceptibility to management bias. It stresses professional skepticism toward evidence that contradicts management's assertions and recognizes evidence produced with automated tools and techniques such as audit data analytics.


2. A Study Ladder for Evidence Reliability

AU-C 500 offers generalizations about reliability that are subject to important exceptions: evidence from independent external sources is generally more reliable; internally generated evidence is more reliable when related controls are effective; evidence obtained directly by the auditor beats evidence obtained indirectly or by inference; documentary evidence beats oral evidence; and originals beat copies. Review courses arrange these generalizations into the ladder below, which is a study aid rather than a rule.

The Evidence Reliability Pyramid

                             ▲
                            / \  [ TIER 1: HIGHEST RELIABILITY ]
                           /   \ Direct Personal Knowledge of the Auditor
                          /     \ (Physical count, direct observation, recalculation)
                         /-------\ 
                        /         \ [ TIER 2: HIGH RELIABILITY ]
                       /           \ Direct External Third-Party Evidence
                      /             \ (Bank confirmations, AR confirmations, attorney letters)
                     /---------------\ 
                    /                 \ [ TIER 3: MODERATE-HIGH RELIABILITY ]
                   /                   \ External Evidence Held by Client
                  /                     \ (Vendor invoices, bank statements provided by client)
                 /-----------------------\ 
                /                         \ [ TIER 4: MODERATE RELIABILITY ]
               /                           \ Internal Evidence under Strong Controls
              /                             \ (Client-generated sales orders, prenumbered shipping docs)
             /-------------------------------\ 
            /                                 \ [ TIER 5: LOW RELIABILITY ]
           /                                   \ Internal Evidence under Weak/Untested Controls
          /                                     \ (Unnumbered forms, informal spreadsheets, unverified logs)
         /---------------------------------------\ 
        /                                         \ [ TIER 6: LOWEST RELIABILITY ]
       /                                           \ Oral Client Representations & Inquiries
      /_____________________________________________\ (Verbal explanations; inquiry alone NEVER sufficient)

Detailed Breakdown of Reliability Tiers

TierSource / NatureConcrete Audit ExamplesKey Strengths & Vulnerabilities
Tier 1: Direct Personal KnowledgeFirst-hand inspection, physical examination, direct observation, or mathematical recalculation by the auditor.- Inspecting physical inventory counts in warehouse.<br>- Recalculating depreciation schedules or bond amortization.<br>- Observing client staff execute segregation-of-duties controls.Strengths: Free from client bias or third-party manipulation.<br>Vulnerabilities: Observation is limited strictly to the point in time observed; physical inspection proves existence but not ownership or valuation.
Tier 2: Direct External EvidenceEvidence originated by an independent third party and transmitted directly to the auditor without entering client possession.- Bank confirmations received via secure digital platforms.<br>- Accounts receivable positive confirmations.<br>- Direct confirmations from external debt holders or legal counsel.Strengths: Independent source; lower risk of interception or alteration when the auditor controls the process.<br>Vulnerabilities: Third-party confirmation bias, clerical carelessness by respondent.
Tier 3: Client-Held External EvidenceDocuments originated by an external third party that were received and maintained in the client's custody.- Vendor invoices attached to voucher packages.<br>- Monthly bank statements provided by the client.<br>- Executed property deeds, equipment lease agreements.Strengths: Originates outside the client organization.<br>Vulnerabilities: Susceptible to physical alteration, electronic forgery, or selective omission by client management.
Tier 4: Internal Evidence (Effective Controls)Documents and data generated internally by the client under an operating environment with validated, effective internal controls.- Prenumbered sales orders and shipping reports generated by an ERP with strict automated general IT controls.<br>- Approved purchase requisitions with dual sign-offs.Strengths: Systemic consistency; reduced risk of human error or unrecorded omissions.<br>Vulnerabilities: Still subject to management override of controls or systemic programming errors.
Tier 5: Internal Evidence (Weak Controls)Internal documents generated where internal controls are defective, untested, or absent.- Manually typed journal vouchers without supervisory sign-off.<br>- Unnumbered receiving logs.<br>- Ad-hoc Excel spreadsheets without access restrictions.Strengths: Minimal cost to obtain.<br>Vulnerabilities: Highly unreliable; prone to error, fabrication, and unauthorized alterations.
Tier 6: Oral Client RepresentationsVerbal statements and explanations made by management or employees during interviews and inquiries.- Inquiring of CFO about the business rationale for a reserve adjustment.<br>- Asking plant managers about obsolete machinery.Strengths: Efficient for preliminary inquiry and understanding operations.<br>Vulnerabilities: Lowest reliability. Inquiry alone is NEVER sufficient to substantiate an assertion or evaluate control effectiveness. Must be corroborated.

Document Form: Originals vs. Copies and Digital Data

  • Original Documents: Auditing standards presume that original documents provide greater evidential reliability than photocopies, facsimiles, or digitized scans. Originals contain verifiable security features (watermarks, embossed seals, ink variations) that deter and reveal alterations.
  • Photocopies and Electronic Records: While modern audits rely heavily on electronic records, scanned PDFs, and electronic data interchange (EDI), the auditor must recognize that digital images are susceptible to alteration. The reliability of electronic records depends directly on the operating effectiveness of Information Technology General Controls (ITGCs)—including user access controls, system change management, and automated audit trails.

3. Management Assertions under AU-C 315 & AU-C 500

Management assertions are explicit or implicit representations embodied in the financial statements, as used by the auditor to consider the different types of potential misstatements that may occur. Under clarified auditing standards (AU-C 315 and AU-C 500), assertions are divided into two distinct categories:

                                MANAGEMENT ASSERTIONS FRAMEWORK
                                                |
                     +--------------------------+--------------------------+
                     |                                                     |
        [ CLASSES OF TRANSACTIONS ]                               [ ACCOUNT BALANCES ]
           AND EVENTS FOR PERIOD                                     AT PERIOD-END
         (Income Statement / P&L)                                   (Balance Sheet)
                     |                                                     |
        - Occurrence                                              - Existence
        - Completeness                                            - Rights and Obligations
        - Accuracy                                                - Completeness
        - Cutoff                                                  - Accuracy, Valuation & Allocation
        - Classification                                          - Classification
        - Presentation                                            - Presentation

Category 1: Classes of Transactions and Events (Income Statement Focus)

  1. Occurrence: Recorded transactions and events have actually occurred and pertain to the entity. (Audit objective: Detect overstatement or fictitious revenues/expenses).
  2. Completeness: All transactions and events that should have been recorded have been recorded. (Audit objective: Detect understatement or unrecorded transactions).
  3. Accuracy: Amounts and other data relating to recorded transactions and events have been recorded appropriately. (Audit objective: Verify pricing, math, footing, and extension calculations).
  4. Cutoff: Transactions and events have been recorded in the correct accounting period. (Audit objective: Prevent shifting revenues/expenses between fiscal years; shipping and receiving cutoff).
  5. Classification: Transactions and events have been recorded in the proper general ledger accounts. (Audit objective: Ensure operating expenses are not capitalized as fixed assets, or financing flows misclassified as revenue).
  6. Presentation: Transactions and events are appropriately aggregated or disaggregated, clearly described, and related disclosures are relevant and understandable.

Category 2: Account Balances at Period-End (Balance Sheet Focus)

  1. Existence: Assets, liabilities, and equity interests recorded on the balance sheet actually exist at the specified date. (Audit objective: Detect overstatement or ghost assets).
  2. Rights and Obligations: The entity holds or controls the legal rights to assets, and liabilities are the true legal obligations of the entity. (Audit objective: Verify ownership, identify factored receivables, consigned inventory, or unrecorded liens).
  3. Completeness: All assets, liabilities, and equity interests that should have been recorded have been recorded. (Audit objective: Detect understatement, specifically searching for unrecorded liabilities or omitted debt).
  4. Accuracy, Valuation, and Allocation: Assets, liabilities, and equity interests are included in the financial statements at appropriate dollar amounts, and any resulting valuation or allocation adjustments (e.g., allowance for credit losses, depreciation, lower-of-cost-or-net-realizable-value) are properly recorded.
  5. Classification: Assets, liabilities, and equity interests have been recorded in the proper accounts (e.g., current vs. non-current debt classification).
  6. Presentation: Assets, liabilities, and equity interests are appropriately aggregated or disaggregated and clearly described, and disclosures are relevant and understandable.

Comprehensive Assertion Mapping Matrix

Account / CycleSpecific AssertionPrimary Audit RiskConcrete Illustrative Audit Procedure
Revenue / SalesOccurrenceOverstatement (Fictitious sales recorded to inflate revenue)Vouch sample of sales transactions from the sales journal backward to customer purchase orders, approved shipping documents, and sales contracts.
Accounts PayableCompletenessUnderstatement (Omitted vendor liabilities to inflate working capital)Perform the "Search for Unrecorded Liabilities" by tracing cash disbursements made after year-end and unpaid vendor invoices backward to receiving reports dated before year-end.
InventoryExistenceOverstatement (Non-existent or phantom inventory on balance sheet)Physically inspect inventory items selected from the perpetual inventory records during the annual physical count.
InventoryValuation & AllocationOverstatement (Obsolete or damaged inventory carried above NRV)Test cost-to-market calculations, examine inventory turnover ratios, inspect scrap logs, and evaluate allowance for obsolete goods.
Machinery & EquipmentRights & ObligationsOverstatement (Assets reported that are leased or pledged as collateral)Inspect property deeds, purchase invoices, title registrations, and examine debt covenants for pledged asset liens.
Operating ExpensesCutoffMisstatement (Expenses recorded in wrong fiscal period)Examine vendor invoices and receiving documentation recorded 10 days before and 10 days after year-end.

4. Directional Testing: The Dual-Direction Engine

Directional testing is the operational technique that connects the assertion being tested with the physical pathway of evidence inspection. The starting point of the audit procedure dictates the assertion tested.

                       DIRECTIONAL TESTING OPERATIONAL MODEL

       ACCOUNTING RECORDS                                  SOURCE DOCUMENTS
  (Financial Statements, GL,                            (Shipping Documents, Receiving
   Sales / Voucher Journals)                             Reports, Customer Orders, Invoices)
              |                                                        |
              | ========= [ VOUCHING (BACKWARD / DOWNWARD) ] ========> | 
              | - Starting Point: Accounting Records / General Ledger  |
              | - Destination: Source Documents                        |
              | - Core Assertion Tested: EXISTENCE / OCCURRENCE        |
              | - Primary Audit Risk: OVERSTATEMENT (Fictitious Items) |
              |                                                        |
              | <========= [ TRACING (FORWARD / UPWARD) ] ============ | 
              | - Starting Point: Source Documents                     |
              | - Destination: Accounting Records / General Ledger     |
              | - Core Assertion Tested: COMPLETENESS                  |
              | - Primary Audit Risk: UNDERSTATEMENT (Omissions)       |

Vouching (Testing for Overstatement: Existence / Occurrence)

  • Operational Direction: Moving backward from the final accounting records (financial statements, trial balance, subsidiary ledger, journal entries) down to the underlying source documentation.
  • The Question Being Answered: "Does this recorded journal entry represent an event that actually occurred, and is there valid supporting documentation?"
  • Primary Vulnerability Addressed: Overstatement. If management creates fictitious sales or phantom assets, the entries appear in the general ledger but lack legitimate underlying source documentation (e.g., missing bills of lading or shipping reports).

Tracing (Testing for Understatement: Completeness)

  • Operational Direction: Moving forward from the initial source documents (bills of lading, receiving reports, customer purchase orders, time cards) up to the accounting journals and general ledger.
  • The Question Being Answered: "Did all economic events that generated source documents actually make it into the financial statements?"
  • Primary Vulnerability Addressed: Understatement. If management seeks to minimize liabilities or omit taxable revenues, the physical documents exist in the warehouse or mailroom, but the transactions are never recorded in the ledger.

Common CPA Exam Traps in Directional Testing

CPA Exam Trap 1: The "Wrong Direction" Fallacy An exam question states: "To test for completeness of sales, the auditor selected a sample of entries from the sales journal and verified them against customer invoices and shipping documents." Reality: This procedure tests OCCURRENCE, not completeness! Starting with the sales journal can never detect unrecorded sales because unrecorded sales are, by definition, absent from the sales journal. Completeness must start from the shipping records.

CPA Exam Trap 2: Invoices as the Starting Point for Completeness An exam question asks how to test completeness of accounts receivable and offers an option to "sample sales invoices and trace to customer accounts receivable ledgers." Reality: A sales invoice is an internal billing document. If a dishonest shipping clerk dispatches goods without creating an invoice, sampling invoices will miss the omission entirely. The true starting point for sales completeness is the independent shipping document (bill of lading).

CPA Exam Trap 3: Confusing Accounts Payable Cutoff with Existence of Cash Testing post-year-end cash disbursements is often mistaken as a test of the existence of cash. Reality: Tracing post-year-end cash disbursements to underlying receiving reports is the definitive test for COMPLETENESS of accounts payable (the search for unrecorded liabilities). Cash disbursements after year-end prove that an obligation existed at year-end that may have been omitted from the balance sheet.


5. Comprehensive Summary of Evidence Rules

+-------------------------------------------------------------------------------------------------------+
|                                 CORE AUDIT EVIDENCE DECISION MATRIX                                  |
|                                                                                                       |
|  1. Sufficiency = Quantity (driven by RMM, materiality, and evidence quality).                        |
|  2. Appropriateness = Quality (comprises Relevance to assertion and Reliability of source).          |
|  3. Reliability Hierarchy: Direct Auditor Knowledge > External Confirmation > Client-Held External   |
|     > Internal (Strong Controls) > Internal (Weak Controls) > Oral Inquiries.                         |
|  4. Inquiry alone NEVER provides sufficient appropriate evidence; it must always be corroborated.     |
|  5. Overstatement Risk (Existence/Occurrence) --> VOUCH from Accounting Records to Source Documents.  |
|  6. Understatement Risk (Completeness) ---------> TRACE from Source Documents to Accounting Records.  |
+-------------------------------------------------------------------------------------------------------+
Test Your Knowledge

When auditing accounts payable, an audit senior selects a sample of receiving reports generated during the last two weeks of the fiscal year and compares them to the vendor invoices, voucher register, and general ledger postings. Which management assertion is the auditor primarily testing with this procedure, and what directional risk does it address?

A
B
C
D
Test Your Knowledge

An auditor is evaluating the appropriateness of audit evidence gathered across several financial statement cycles. In accordance with AU-C 500, which of the following forms of audit evidence possesses the highest degree of reliability?

A
B
C
D
Test Your Knowledge

During the audit of equipment and leasehold improvements, the auditor inspects purchase invoices, titles, and loan covenants to verify that newly acquired heavy machinery is owned entirely by the client rather than leased under an operating lease or pledged as unrecorded collateral. Which assertion is the auditor directly evaluating?

A
B
C
D
Test Your Knowledge

An auditor discovers that the client recorded a $2,500,000 sale on December 31 for goods that were not packed or shipped until January 4 of the subsequent fiscal year. The sales invoice was posted to the general ledger before year-end. Which pair of assertions was violated by this premature recording?

A
B
C
D