7.3 Types of Audit Procedures & Audit Data Analytics (ADA)
Key Takeaways
- AU-C 500 audit procedures are inspection (of records or tangible assets), observation, inquiry, external confirmation, recalculation, reperformance, and analytical procedures.
- Observation is strictly limited to the point in time observed and can be influenced by the Hawthorne effect; Inquiry alone never provides sufficient appropriate evidence to support an audit conclusion or evaluate control effectiveness.
- Audit Data Analytics (ADA) transforms traditional audit sampling into 100% population analysis, identifying patterns, outliers, anomalies, and hidden relationships across entire transaction streams.
- ADA applies across all audit stages: risk assessment (anomaly discovery), tests of controls (segregation of duties and 3-way match validation), substantive procedures (recalculation, full ledger reconciliations), and overall review.
- Evaluating notable items requires the auditor to filter false positives, group items by risk characteristics, assess whether they reveal new or elevated RMM, and design targeted procedures to address unexplained anomalies.
7.3 Types of Audit Procedures & Audit Data Analytics (ADA)
Core Principle: Audit procedures are the specific operational acts performed by the auditor to gather audit evidence. Under AU-C 500 and AU-C 330, the auditor combines various procedures to execute risk assessment, tests of controls, and substantive procedures. In modern auditing, traditional manual procedures are significantly expanded by Audit Data Analytics (ADA) and Automated Tools and Techniques (ATT), enabling the analysis of 100% of transaction populations.
1. The Eight Standard Types of Audit Procedures
AU-C 500 describes seven types of audit procedures: inspection, observation, external confirmation, recalculation, reperformance, analytical procedures, and inquiry. Splitting inspection into records and tangible assets gives the eight categories below.
THE EIGHT PROCEDURE CATEGORIES
|
+-------------+-------------+-----------+-----------+-------------+-------------+-------------+
| | | | | | | |
[I] [C] [P] [A] [I] [R] [R] [O]
Inspection Confirmation Physical Analytical Inquiry Recalculation Reperformance Observation
(Records) (External) Inspection Procedures (Internal/ (Math) (Controls) (Real-time)
(Assets) External)
Detailed Analysis of Each Audit Procedure
1. Inspection of Records or Documents
Examining internal or external records or documents, in paper form, electronic form, or other media.
- Application: Covers both vouching (examining documents supporting recorded entries) and tracing (following source documents to accounting records).
- Evidential Weight: Varies depending on source (external vs. internal) and internal control strength over electronic document generation.
2. Inspection of Tangible Assets (Physical Count)
Direct physical examination of tangible assets, such as inventory, plant, machinery, or securities.
- Assertions Tested: Highly reliable for Existence.
- Crucial Limitation: Provides virtually no evidence regarding Rights and Obligations (the asset could be leased, pledged as collateral, or held on consignment) and limited evidence regarding Valuation (a machine may be physically intact but obsolete or impaired).
3. Observation
Looking at a process or procedure being performed by others (e.g., the auditor observing client personnel conducting the physical inventory count or watching the execution of control activities).
- Crucial Limitations:
- Time-Bound: Observation provides evidence strictly limited to the point in time at which the observation occurs.
- Hawthorne Effect: The mere presence of the auditor observing a control may alter employee behavior, causing staff to perform duties more diligently than when unobserved.
4. Inquiry
Seeking information of knowledgeable persons, both financial and non-financial, within the entity or outside the entity.
- Application: Used extensively throughout every audit phase (evaluating management intent, fraud brainstorming, understanding business processes).
- The Golden Rule of Inquiry: Inquiry alone NEVER provides sufficient appropriate audit evidence to detect a material misstatement at the assertion level or to evaluate the operating effectiveness of internal controls. Inquiry must always be corroborated with additional documentary or physical evidence.
- Interviewing Well: The blueprint expects you to analyze interview responses and ask effective follow-up questions. Plan open-ended prompts (for example, "Walk me through how a customer's credit limit gets raised"), listen for inconsistencies, and follow up with questions such as "Who else reviews that report?" or "What happens when the system is down?" Interview people outside finance (sales, warehouse, IT, legal) because their knowledge and incentives differ, note evasive or rehearsed answers, and corroborate what you hear with documents or observation.
5. External Confirmation
Audit evidence obtained as a direct written response from a third party (the confirming party) to the auditor, in paper form or by electronic or other medium.
- Application: Positive and negative accounts receivable confirmations, bank confirmations, debt covenant letters, legal inquiry letters.
- Evidential Weight: Extremely high reliability due to independent third-party origination, provided direct transmission protocols prevent client interception.
6. Recalculation
Checking the mathematical accuracy of documents or records.
- Application: Checking extensions and footings on sales invoices, recalculating depreciation schedules, verifying accrued interest, re-computing tax provisions.
- Evidential Weight: Highly reliable for mathematical Accuracy, but does not verify whether the underlying input data or assumptions are valid.
7. Reperformance
The auditor's independent execution of procedures or controls that were originally performed as part of the entity's internal control.
- Application: Most often used in tests of controls (for example, reperforming the matching of purchase orders, receiving reports, and vendor invoices), but it can also support substantive work, such as independently re-running the receivables aging.
- Evidential Weight: Highly persuasive evidence regarding the operating effectiveness of controls.
8. Analytical Procedures
Evaluations of financial information made by a study of plausible relationships among both financial and non-financial data.
- Application: Mandatory in planning and final review; optional as substantive procedures.
Comprehensive Audit Procedure Comparison Matrix
| Procedure | Core Action | Primary Assertions Addressed | Relative Reliability | Audit Phase Applicable | Primary Limitations |
|---|---|---|---|---|---|
| Inspection of Records | Examining paper or electronic documents | Occurrence, Completeness, Cutoff, Accuracy | Moderate to High (source dependent) | All Phases | Electronic records can be altered if ITGCs are weak. |
| Inspection of Assets | Physical inspection and counting of physical items | Existence | High | Substantive Testing | Does NOT test ownership (rights) or market valuation. |
| Observation | Watching client personnel perform actions | Occurrence, Control Effectiveness | Moderate | Tests of Controls, Substantive | Limited to point in time; behavior alters when watched. |
| Inquiry | Interviewing internal staff or external parties | All Assertions (Exploratory) | Low (Lowest tier) | All Phases | Never sufficient alone; client bias; must be corroborated. |
| External Confirmation | Direct third-party written/digital response | Existence, Rights & Obligations, Cutoff | High | Substantive Testing | Non-response risk; confirmation bias; third-party carelessness. |
| Recalculation | Recomputing client arithmetic and formulas | Accuracy, Valuation & Allocation | High (for math) | Substantive Testing | Only proves math; does not prove validity of inputs. |
| Reperformance | Independently re-executing procedures or controls | Control operating effectiveness; accuracy | High | Mainly Tests of Controls | Time-intensive; shows only that the procedure works as re-executed. |
| Analytical Procedures | Comparing recorded data to expected relationships | Completeness, Accuracy, Occurrence | Moderate to High | Planning, Substantive, Final Review | Dependent on expectation precision and data reliability. |
2. Audit Data Analytics (ADA) in Modern Auditing
Definition and Evolution
Under the AICPA Guide to Audit Data Analytics, ADA is defined as:
"The science and art of discovering and analyzing patterns, identifying anomalies, and extracting other useful information in data underlying or related to the subject matter of an audit through analysis, modeling, and visualization for the purpose of planning or performing the audit."
Traditionally, auditors were constrained by manual testing and had to rely on sample testing (introducing sampling risk). Modern ERP systems and big data allow auditors to analyze 100% of the transactions in a population, entirely eliminating sampling risk for those populations.
TRADITIONAL AUDIT TESTING vs. AUDIT DATA ANALYTICS (ADA)
TRADITIONAL SAMPLE TESTING AUDIT DATA ANALYTICS (ADA)
+-----------------------------------+ +-----------------------------------+
| - Population: 500,000 invoices | | - Population: 500,000 invoices |
| - Sample Size: 60 invoices | | - Analyzed: 500,000 (100%) |
| - Subject to SAMPLING RISK | | - ZERO SAMPLING RISK |
| - Manual vouching/tracing | | - Automated pattern recognition |
| - May miss unusual outliers | | - Identifies all anomalies |
+-----------------------------------+ +-----------------------------------+
ADA Across the Audit Lifecycle
ADA is not a standalone procedure; rather, it is an automated execution vehicle utilized across all four phases of the audit:
- Risk Assessment (Planning Phase):
- Exploring vast general ledger datasets to identify unexpected trends, volatile accounts, or unusual transaction volumes.
- Visual heatmaps identifying transaction spikes at quarter-end or unusual manual journal entries posted by senior executives.
- Tests of Controls:
- Evaluating 100% of transactions to verify that automated controls functioned continuously (e.g., verifying whether any invoice was paid without an electronic purchase order matching).
- Identifying Segregation of Duties (SOD) violations across enterprise user access logs (e.g., flagging individuals who created purchase orders AND approved disbursements).
- Substantive Procedures:
- 100% Matching: Executing a complete three-way match between sales orders, shipping records, and sales invoices across millions of transactions.
- Recalculation: Automatically recalculating depreciation for 100% of fixed asset master records in seconds.
- Predictive Regressions: Building predictive models that correlate multi-year daily sales against external weather patterns, foot traffic, or flight hours.
- Final Overall Review:
- Re-evaluating macro-level general ledger flows to confirm that all adjusted journal entries fit expected corporate performance parameters.
3. Core ADA Techniques & Methodologies
PRIMARY ADA TECHNIQUES
|
+-----------------------+---------------+---------------+-----------------------+
| | | |
[ 100% MATCHING ] [ ANOMALY DETECTION ] [ STRATIFICATION ] [ REGRESSION & AI ]
- 3-Way matching - Benford's Law analysis - High-dollar clustering- Econometric modeling
- Ledger to bank - Split purchase order checks - Dormant account slices- Predictive sales
- Subledger to GL - Off-hours/Weekend postings - Risk-weighted groups baselines
1. 100% Population Matching (Three-Way Match)
Auditors use ADA tools to merge and reconcile three distinct data streams across an entire fiscal year:
- Stream A: Purchase Orders (authorized pricing and quantity).
- Stream B: Receiving Reports (quantities physically received at loading docks).
- Stream C: Vendor Invoices (amounts billed by vendors).
Result: The ADA tool instantly identifies all instances of price variances, quantity discrepancies, unbilled receipts, or payments made without receiving documentation.
2. Anomaly and Outlier Detection
A. Benford's Law Analysis
Benford's Law establishes that in naturally occurring numerical datasets, the number 1 will appear as the leading first digit approximately 30.1% of the time, whereas the number 9 will appear as the leading digit only 4.6% of the time. When individuals fabricate numbers or create fictitious invoices, they violate this natural distribution.
- Application: Auditors run Benford's Law algorithms across vendor disbursement files. An abnormal spike in leading digits (e.g., an unusual spike at "4" or "9") points directly to potentially fraudulent transactions or unauthorized invoices.
B. Split Purchase Order Analysis (Threshold Evasion)
If a company requires supervisory approval for disbursements exceeding $10,000, dishonest employees or managers may split a $19,000 expense into two invoices of $9,500 each to bypass the approval limit. ADA algorithms search for duplicate vendors with multiple invoices just below approval thresholds within short time intervals.
C. Temporal Anomalies (Off-Hour Postings)
ADA scripts filter general ledger journal entries posted:
- Between 10:00 PM and 5:00 AM.
- On weekends or recognized corporate holidays.
- During post-closing adjustment windows without supervisory authorization codes.
3. Cluster Analysis and Stratification
Grouping transactions based on multivariate characteristics (such as transaction amount, geographic location, account type, and processing user). This isolates high-risk transaction clusters from routine, low-risk operating transactions.
4. The Notable Item Decision Framework
A central concept in audit data analytics is the identification and evaluation of Notable Items.
Definition: A Notable Item is an item identified from the application of an ADA that has characteristics indicating a risk of material misstatement not previously identified, a higher level of risk of material misstatement than previously assessed, or that provides evidence to support or refute an assertion.
NOTABLE ITEM RESOLUTION WORKFLOW
[ RUN AUDIT DATA ANALYTIC (ADA) ]
|
v
[ POPULATION OF NOTABLE ITEMS ]
(Anomalies, outliers, deviations)
|
v
[ STEP 1: FILTER & REFINE DATASET ]
- Remove verifiable false positives
- Exclude expected business operational differences
|
v
[ STEP 2: GROUP NOTABLE ITEMS ]
- Group items by shared characteristics
- Examples: specific branch, specific user, system error
|
v
[ STEP 3: ASSESS RISK OF MISSTATEMENT ]
- Does this reveal a new, unidentified risk?
- Does this elevate previously assessed RMM?
|
v
[ STEP 4: PERFORM TARGETED PROCEDURES ]
- Vouch notable items to source documents
- Conduct inquiries and corroborate management explanations
- Quantify misstatement and propose adjustments
Operational Rules for Notable Items
- Do Not Ignore Notable Items: When an ADA routine flags 200 notable items out of 100,000 transactions, the auditor cannot treat them as "acceptable noise." Each group of notable items must be evaluated.
- No Extrapolation When Testing 100%: Because the auditor analyzed the entire population, sampling error is zero. The auditor does not extrapolate the results using sampling formulas; rather, the auditor determines whether the identified items represent actual misstatements or control deviations.
- Refinement of False Positives: If an initial run flags 1,500 notable items because of a scheduled system maintenance date, the auditor refines the analytical filter to eliminate those known non-risk items while documenting the rationale.
5. Automated Tools and Techniques (ATT) & Data Integrity (IPE)
Under AU-C 500, before an auditor can perform audit data analytics on client-provided data, the auditor must establish the reliability of the Information Produced by the Entity (IPE):
+-------------------------------------------------------------------------------------------------------+
| DATA INTEGRITY PREREQUISITES (IPE) |
| |
| 1. COMPLETENESS OF EXTRACTED DATA: |
| - Reconcile data extract row counts and total balances to the audited General Ledger Trial |
| Balance before executing analytics. |
| - Verify that no transactions or time periods were excluded. |
| |
| 2. ACCURACY OF EXTRACTED DATA: |
| - Test the extraction script or query logic. |
| - Validate source data against underlying databases or test Information Technology General |
| Controls (ITGCs) governing data warehouses. |
+-------------------------------------------------------------------------------------------------------+
Exam Trap: Running a brilliant audit data analytic on an unverified, incomplete spreadsheet extract violates GAAS. If the underlying data is incomplete, the analytic's conclusions are invalid.
While performing tests of controls over cash disbursements, an auditor uses an automated audit routine to inspect all 145,000 purchase orders, receiving reports, and vendor invoices recorded during the year. The tool identifies 82 instances where the invoice amount exceeded the purchase order amount by more than 10% without documented management re-approval. Under audit data analytics guidance, how should the auditor classify and treat these 82 items?
Which of the following audit procedures provides audit evidence regarding the existence of an asset, but provides virtually NO audit evidence regarding the client's ownership rights to that asset or its net realizable valuation?
An audit engagement team is evaluating the reliability and evidentiary weight of various audit procedures performed during an annual audit. Which of the following statements regarding audit procedures is completely accurate?
An auditor applies Benford's Law analysis to an entire population of 75,000 vendor disbursement records. The analysis reveals an abnormal spike in invoices where the leading digits are "49" and "98," specifically clustering just below the $5,000 and $10,000 supervisory authorization thresholds. What is the auditor's primary objective in executing this audit data analytic?