2.1 International Standards on Auditing (ISA) & IAASB Framework

Key Takeaways

  • The IAASB operates under IFAC with public interest oversight from the PIOB to establish global standards for audit, quality management, and assurance engagements.

  • The Clarity Project established a standardized five-element architecture for each ISA: Introduction, Objective, Definitions, Requirements (mandatory 'the auditor shall'), and Application and Other Explanatory Material.

  • Reasonable assurance represents a high, but not absolute, level of assurance due to the inherent limitations of an audit, including the nature of financial reporting, the nature of audit procedures, and the balance between benefit and cost.

  • Audit evidence must be both sufficient (quantitative measure) and appropriate (qualitative measure of relevance and reliability), with external and direct documentary evidence generally carrying higher reliability.

  • Professional engagements exist along an assurance spectrum: reasonable assurance audits provide positive conclusions, limited assurance reviews provide negative conclusions, and agreed-upon procedures offer factual findings with no assurance.

Last updated: October 2026

2.1 International Standards on Auditing (ISA) & IAASB Framework

Modern public and commercial accountability rests upon globally harmonized auditing standards that ensure audit opinions are consistent, rigorous, and credible. For candidates preparing for the EPSO AD7 Audit competition, mastering the International Standards on Auditing (ISA) framework is essential. The European Court of Auditors (ECA) and EU internal audit bodies benchmark their financial audit methodologies against the ISAs issued by the International Auditing and Assurance Standards Board (IAASB).


1. Standard-Setting Architecture: IAASB, IFEA and Public-Interest Oversight

The International Auditing and Assurance Standards Board (IAASB) develops international standards for auditing, quality management, review and other assurance work. Since 2023 it has operated as part of the International Foundation for Ethics and Audit (IFEA) rather than under IFAC. The independent Public Interest Oversight Board (PIOB) oversees the standard-setting process from a public-interest perspective. A joint Stakeholder Advisory Council for the IAASB and IESBA provides strategic advice from a broad stakeholder group.

This governance distinction does not change the technical role of the ISAs, but it matters when describing who currently hosts, oversees and advises the standard setter.

2. The Clarity Project & Anatomy of an ISA

Between 2004 and 2009, the IAASB executed the comprehensive Clarity Project, redrafting all auditing standards to eliminate ambiguity, enhance readability, and establish clear demarcation between mandatory requirements and non-mandatory guidance. Every modern ISA follows a uniform, five-part architecture:

  1. Introduction: Delineates the scope, effective date, subject matter, and specific context of the standard, as well as the respective responsibilities of the auditor and management.
  2. Objective: States the overarching outcome the auditor must achieve in applying the standard. The objective provides the conceptual link between individual procedures and overall audit goals.
  3. Definitions: Clarifies the precise technical terminology used within the standard to ensure consistent global interpretation.
  4. Requirements: Contains the mandatory obligations of the standard, consistently identified by the phrase "the auditor shall". The auditor must comply with every applicable requirement unless the entire standard is irrelevant to the engagement.
  5. Application and Other Explanatory Material: Cross-referenced directly to the requirements (using paragraphs prefixed with "A", such as A1, A2), this section provides contextual explanations, practical examples, and considerations specific to public-sector or smaller entities. It does not impose new obligations.
ISA SectionMandatory NatureDrafting ConventionPrimary Purpose
IntroductionContextualDescriptive proseSets engagement scope and context
ObjectiveFoundational"The objective of the auditor is..."Defines the desired audit outcome
DefinitionsDefinitional"For purposes of the ISAs, the following terms..."Fixes precise technical meanings
RequirementsStrictly Mandatory"The auditor shall..."Imposes binding audit obligations
Application MaterialGuidanceNumbered with "A" prefix (e.g., A1, A2)Practical implementation techniques

3. Core Standards: ISA 200, ISA 210 & ISA 220

Three foundational standards govern the initiation, execution, and quality control of any financial audit engagement:

ISA 200: Overall Objectives of the Independent Auditor

ISA 200 establishes the conceptual cornerstone of financial auditing. It stipulates that the auditor's overall objectives are:

  • To obtain reasonable assurance about whether the financial statements as a whole are free from material misstatement, whether due to fraud or error, thereby enabling the auditor to express an opinion on whether the financial statements are prepared, in all material respects, in accordance with an applicable financial reporting framework.
  • To report on the financial statements and communicate findings as required by the ISAs in accordance with the auditor's findings.

ISA 200 mandates that the auditor maintain professional skepticism and exercise professional judgment throughout the planning and performance of the audit, complying with relevant ethical requirements.

ISA 210: Agreeing the Terms of Audit Engagements

ISA 210 governs engagement acceptance and recurring terms. The auditor may accept or continue an audit engagement only when the preconditions for an audit are present:

  • Determination that the financial reporting framework to be applied (such as IFRS, IPSAS, or the EU Financial Regulation rules) is acceptable.
  • Agreement from management acknowledging and understanding its responsibilities for: preparing the financial statements; establishing internal controls necessary to prevent material misstatement; and providing the auditor with unrestricted access to all relevant information, documentation, and personnel.

The agreed terms must be formalized in an audit engagement letter or equivalent statutory instrument before fieldwork begins.

ISA 220: Quality Management for an Audit of Financial Statements

Aligned with the International Standard on Quality Management (ISQM 1 and ISQM 2), ISA 220 centers on the engagement partner's responsibility for achieving engagement quality. The engagement partner must be actively involved throughout the engagement, ensuring:

  • The engagement team possesses appropriate competence, capabilities, and time.
  • Direction, supervision, and review of work comply with professional standards.
  • Consultation on difficult or contentious matters is undertaken and documented.
  • An engagement quality reviewer (EQR) is appointed for audits of listed entities and other engagements for which law, regulation or the firm’s criteria require a review; ISQM 2 governs the reviewer’s eligibility and performance.

4. The Concept of Reasonable Assurance & Inherent Limitations

An audit conducted in accordance with ISAs provides reasonable assurance, defined as a high, but not absolute, level of assurance. The auditor cannot deliver absolute certainty that financial statements are free from all misstatements due to the inherent limitations of an audit:

  1. Nature of Financial Reporting: Preparing financial statements requires management to make subjective judgments, accounting estimates (such as provisions, fair values, or asset impairments), and choices among acceptable accounting methods. These areas inherently involve uncertainty.
  2. Nature of Audit Procedures: Audit evidence is persuasive rather than conclusive. Management or third parties may intentionally or unintentionally fail to provide complete information. Furthermore, sophisticated fraud schemes involving forgery, collusion, or management override of controls are designed to conceal evidence from auditors, who do not possess legal search and seizure powers.
  3. Timeliness and the Balance Between Benefit and Cost: Users expect the audit report within a reasonable timeframe and at a proportionate cost. Consequently, the auditor cannot examine every single transaction. Instead, the auditor relies on selective testing, sampling, and analytical procedures to form a conclusion.

5. Sufficiency and Appropriateness of Audit Evidence

Under ISA 500, the auditor must obtain sufficient appropriate audit evidence to reduce audit risk to an acceptably low level:

  • Sufficiency is the quantitative measure of evidence. The quantity of evidence needed is affected by the auditor's assessment of the risks of material misstatement (higher risk requires more evidence) and the quality of the evidence obtained (higher quality may allow less evidence).
  • Appropriateness is the qualitative measure of evidence, encompassing:
    • Relevance: The logical connection between the audit procedure and the assertion being tested (e.g., verifying physical inventory confirms existence, but not necessarily ownership or valuation).
    • Reliability: The credibility and trustworthiness of the information source. Evidence is generally more reliable when obtained from independent external sources, generated through effective internal controls, obtained directly by the auditor (such as physical observation), documented in writing, and presented as original documents rather than photocopies or digitized representations.

6. The Spectrum of Assurance Engagements

Auditors perform different types of engagements governed by distinct IAASB standards, varying in the level of assurance provided and the reporting format:

Engagement TypeGoverning StandardLevel of AssuranceNature of ProceduresReporting Expression
AuditISA 100–899Reasonable Assurance (High)Risk assessment, tests of controls, substantive tests, physical inspectionPositive form: "In our opinion, the financial statements present fairly, in all material respects..."
ReviewISRE 2400 / 2410Limited Assurance (Moderate)Primarily inquiries of management and analytical review proceduresNegative form: "Nothing has come to our attention that causes us to believe..."
Agreed-Upon Procedures (AUP)ISRS 4400 (Revised)No AssuranceSpecific factual procedures agreed upon with the engaging partyFactual findings report: Users evaluate procedures and draw own conclusions
CompilationISRS 4410 (Revised)No AssuranceCollecting, classifying, and summarizing financial informationCompilation report: Assisting management in compiling figures without verification

7. Practical Audit Scenario: Preconditions in an EU Agency Audit

An audit team assigned to audit a newly established EU decentralised agency discovers during the ISA 210 planning phase that the agency's executive management has not formalized its accounting rules, claiming that "standard EU practice applies implicitly." Furthermore, management refuses to grant the audit team direct access to its procurement evaluation committee minutes, citing commercial confidentiality.

Under ISA 210, the auditor cannot accept this engagement as a valid statutory audit until these preconditions are resolved:

  1. The applicable financial reporting framework must be formally adopted and identified (the EU Accounting Rules based on IPSAS).
  2. Management must sign a written agreement acknowledging its responsibility to provide unrestricted access to all records, including procurement minutes.

If management refuses to establish these preconditions, the auditor must not enter into the audit engagement, or in a statutory public mandate, must formally notify the budgetary authority (the European Parliament and the Council) of a fundamental scope limitation.

Loading diagram...
Spectrum of IAASB Engagements & Assurance Levels
Test Your Knowledge

In the structural architecture of an International Standard on Auditing (ISA) resulting from the Clarity Project, which drafting convention designates a strictly mandatory requirement?

A

The phrase 'the auditor shall'

B

Guidance paragraphs designated with an 'A' prefix

C

Introductory paragraphs specifying scope and subject matter

D

Explanatory text included in the Objective section

Test Your Knowledge

Why does an audit conducted in accordance with International Standards on Auditing provide reasonable assurance rather than absolute assurance?

A

Because auditors lack formal training in forensic investigation and criminal law

B

Because of inherent limitations including the nature of financial reporting, the persuasive nature of audit evidence, and sampling constraints

C

Because engagement quality reviewers only review public-interest entity engagements

D

Because management retains the legal right to redact sensitive procurement documents

Test Your Knowledge

Under ISA 210, which of the following is an indispensable precondition that must be confirmed before the auditor agrees to the terms of an audit engagement?

A

Confirmation that internal audit has completed an operational review of all spending lines

B

An undertaking by management to eliminate all control deficiencies identified in prior periods

C

Written acknowledgement by management of its responsibility for internal controls and for providing unrestricted access to all relevant information

D

Formal pre-approval of all substantive sampling sizes by the external oversight board

Test Your Knowledge

How does a financial review engagement conducted under ISRE 2400 differ from a full statutory audit conducted under the ISAs?

A

A review provides absolute assurance on compliance with laws, whereas an audit focuses exclusively on accounting disclosures

B

A review results in a report of factual findings with zero assurance, whereas an audit provides moderate negative assurance

C

A review requires extensive physical inventory observation and direct confirmation of balances, whereas an audit relies solely on analytical review

D

A review provides limited assurance expressed in a negative form based primarily on inquiry and analytical procedures, whereas an audit provides reasonable assurance expressed in a positive form

Sections you finish are checked off in the contents.