What a financial statement audit is
A financial statement audit is an independent examination in which an auditor obtains enough evidence to express an opinion on whether the financial statements are prepared, in all material respects, in accordance with the applicable framework, such as IFRS. It matters because the opinion gives lenders, investors and regulators reasonable assurance that the numbers are free from material misstatement, whether caused by fraud or error.
Reasonable assurance is a high level of assurance, but not absolute. ISA 200 explains why: testing is selective, much evidence is persuasive rather than conclusive, and many balances depend on estimates. The auditor manages this through the audit risk model. Audit risk is the risk of a clean opinion on materially misstated statements, and it is the product of the risk of material misstatement (inherent risk and control risk, which belong to the entity) and detection risk (which the auditor controls through the nature, timing and extent of procedures).
Every International Standard on Auditing (ISA) hangs off that model. The higher the assessed risk for an account and assertion, the lower the detection risk the auditor can accept, so the more persuasive the evidence must be. The rest of this guide follows the engagement in the order the work is actually done.
- Acceptance and continuance: ISA 210, ISA 220 (Revised), ISQM 1 and the ethics code
- Planning and materiality: ISA 300 and ISA 320
- Understanding the entity and assessing risk: ISA 315 (Revised 2019)
- Responding to assessed risks: ISA 330
- Obtaining evidence: ISA 500 to ISA 580
- Completion and evaluation of misstatements: ISA 450, ISA 560, ISA 580
- Forming and reporting the opinion: ISA 700 (Revised), ISA 705 (Revised), ISA 706 (Revised), ISA 701
Stage 1: acceptance, independence and the engagement letter
Before any testing, the firm decides whether it may and should take the engagement. ISQM 1 and ISA 220 (Revised) require the firm to consider the integrity of the owners and management, whether the team has the competence and time, and whether independence can be maintained under the IESBA Code or the local equivalent. For a new client, the incoming auditor normally contacts the predecessor to ask whether there is any professional reason not to accept.
ISA 210 then requires the auditor to confirm the preconditions for an audit: the reporting framework is acceptable, and management acknowledges in writing that it is responsible for preparing the statements, for the internal control needed to prevent material misstatement, and for giving the auditor unrestricted access to records and people. These terms go into the engagement letter. If management will not accept them, the auditor should not accept the engagement.
Stage 2: planning, strategy and materiality
ISA 300 separates the overall audit strategy (scope, timing, reporting deadlines, team, use of experts or component auditors) from the detailed audit plan (the procedures for each area). Planning is not a phase that ends; the plan is updated whenever risk assessment or testing changes the picture.
Materiality under ISA 320 is set at the same time. Take a trading company with revenue of EUR 40 million and steady profit before tax of EUR 2.4 million. A benchmark of 5% of profit before tax gives overall materiality of EUR 120,000. Performance materiality, set lower to leave room for undetected errors, might be 75% of that, EUR 90,000, and the clearly trivial threshold under ISA 450 might be 5% of overall materiality, EUR 6,000. These percentages are common in firm methodologies, not rules in the standards. Our guide on audit materiality and sampling works through the benchmark choice and the sample sizes that follow from it.
Stage 3: understanding the entity and assessing risk (ISA 315 Revised 2019)
ISA 315 (Revised 2019), effective for periods beginning on or after 15 December 2021, requires the auditor to understand the entity, its environment, the reporting framework and its system of internal control well enough to identify where material misstatement could arise. Risk assessment procedures are inquiry, analytical procedures, observation and inspection, and the team must discuss the susceptibility of the statements to misstatement, including fraud.
Inherent risk is now assessed on a spectrum, driven by five inherent risk factors, and separately from control risk. A risk at the upper end of the spectrum is a significant risk and attracts specific responses. The auditor also identifies significant classes of transactions, account balances and disclosures, and then applies a stand-back test: any material item not identified as significant is reconsidered so nothing large escapes the risk assessment.
Understanding internal control covers five components: the control environment, the entity's risk assessment process, its process to monitor internal control, the information system and communication, and control activities. For a business running on an ERP, the information system work includes IT general controls: user access, change management and the way automatic postings reach the ledger.
- Complexity: for example, revenue contracts with multiple performance obligations under IFRS 15
- Subjectivity: estimates such as expected credit losses or inventory write-downs
- Change: new systems, acquisitions, new standards or a new finance team
- Uncertainty: outcomes that cannot be measured precisely, such as litigation provisions
- Susceptibility to misstatement due to management bias or other fraud risk factors
Stage 4: designing responses under ISA 330
Responses work at two levels. Financial-statement-level risks, such as a weak control environment or pressure to meet a covenant, get overall responses: more experienced staff, closer supervision, and deliberately unpredictable procedures. Assertion-level risks get further audit procedures designed around nature, timing and extent.
The auditor may test controls and rely on them, or go substantive, or combine both. Two requirements are absolute. ISA 330 para 18 requires substantive procedures for each material class of transactions, account balance and disclosure regardless of the risk assessment, and ISA 330 para 21 requires substantive procedures specifically responsive to each significant risk. Analytical procedures alone are not enough for a significant risk.
A practical way to see the link is to follow a risk from assessment to procedure. The examples below are typical pairings for a trading or manufacturing entity.
- Revenue cut-off (occurrence, cut-off): test dispatches and invoices either side of year end against delivery evidence
- Receivables existence: external confirmations under ISA 505, or cash received after year end
- Inventory existence: attend the count under ISA 501 and test counts both floor-to-sheet and sheet-to-floor
- Inventory valuation: compare cost with post-year-end selling prices to test net realisable value under IAS 2
- Completeness of liabilities: search for unrecorded liabilities in payments and invoices after year end
- Estimates: evaluate method, data and assumptions under ISA 540 (Revised), including a retrospective review of last year's estimates
Stage 5: gathering sufficient appropriate evidence
ISA 500 asks for evidence that is sufficient (enough of it) and appropriate (relevant and reliable). Reliability rises when evidence comes from independent external sources, when it is obtained directly by the auditor, when it is documentary rather than oral, and when documents are originals rather than copies. The procedures available are inspection, observation, external confirmation, recalculation, reperformance, analytical procedures and inquiry. Inquiry on its own is never sufficient for a material assertion.
Much modern evidence is information produced by the entity, such as an ageing report, a stock valuation or a list of journals exported from the ERP. Before using it, the auditor must evaluate whether it is accurate and complete for the purpose, typically by reconciling the report total to the trial balance and testing the logic or a sample of its lines. Substantive analytical procedures under ISA 520 need an independent expectation and a threshold for investigating differences, and sampling decisions follow ISA 530. Our guide on financial ratio analysis shows the ratios that typically drive those expectations.
Fraud and going concern run through every stage
ISA 240 requires the auditor to presume a fraud risk in revenue recognition (a presumption that can be rebutted with documented reasons) and to treat management override of controls as a risk in every audit, which cannot be rebutted. The mandatory responses include testing journal entries and other adjustments, reviewing estimates for bias and evaluating the business rationale of significant unusual transactions. Our guide on journal entry testing and fraud red flags covers the selection criteria in detail.
As of September 2026, the IAASB has issued ISA 240 (Revised) and ISA 570 (Revised 2024) on going concern, both effective for audits of periods beginning on or after 15 December 2026. For calendar-year entities that means the 2027 financial statements. Both strengthen the auditor's evaluation and add transparency in the auditor's report, so finance teams should expect more questions on fraud risk and on the going concern assessment period.
Stage 6: completion and evaluating misstatements
Completion pulls the file together. The auditor performs a final analytical review, completes subsequent events work under ISA 560 up to the report date, obtains written representations under ISA 580 dated as near as practicable to, but not after, the report date, and communicates with those charged with governance under ISA 260 and ISA 265. An engagement quality review under ISQM 2 is completed where ISQM 1 or the firm's policies require one, as they do for audits of listed entities.
The centre of completion is the summary of unadjusted differences required by ISA 450. Using the earlier materiality of EUR 120,000, suppose the team found a factual cut-off error overstating revenue by EUR 40,000, a judgemental difference of EUR 30,000 on the inventory provision, and a projected misstatement of EUR 25,000 from a receivables sample. The aggregate is EUR 95,000, below overall materiality.
That does not close the matter. Headroom of EUR 25,000 leaves little allowance for misstatements that were not detected, so the auditor either asks management to correct the factual item, which brings the total to EUR 55,000, or performs more work. The auditor also considers qualitative factors: a misstatement that turns a profit into a loss, breaches a covenant or conceals an illegal act can be material at any size.
Stage 7: the auditor's report and the four opinions
ISA 700 (Revised) sets out the unmodified opinion: the statements present fairly, or give a true and fair view, in all material respects. ISA 705 (Revised) modifies it on two questions: is the problem a misstatement or an inability to obtain evidence, and are its possible effects pervasive, meaning not confined to specific elements or fundamental to users' understanding?
ISA 706 (Revised) adds paragraphs without modifying the opinion. An emphasis of matter paragraph draws attention to something already properly disclosed; an other matter paragraph covers a matter not presented or disclosed in the statements that is relevant to users' understanding of the audit, the auditor's responsibilities or the report. For listed entities, ISA 701 key audit matters describe the areas of most significance in the audit, and a material uncertainty related to going concern gets its own section under ISA 570.
- Material misstatement, not pervasive: qualified opinion (except for)
- Material misstatement, pervasive: adverse opinion
- Unable to obtain sufficient appropriate evidence, material but not pervasive: qualified opinion
- Unable to obtain evidence, possible effects material and pervasive: disclaimer of opinion
What the audit looks like from the finance team's side
For a December year end, a typical rhythm is a planning meeting in the autumn, an interim visit in November to test controls and walk through processes, attendance at the year-end stock count, a hard close in the first two to three weeks of January, fieldwork of two to six weeks depending on size, a clearance meeting to agree adjustments, and signing once representations are given. After signing, ISA 230 gives the auditor a limited window, ordinarily not more than 60 days, to assemble the final file.
The finance team controls most of the timetable. Clean reconciliations, a trial balance that ties to the sub-ledgers, and a documented rationale for every estimate shorten fieldwork more than anything the auditor can do. Our guide on preparing for an external audit sets out the PBC list and lead schedules, and the guide on trial balance to financial statements explains the numbers the auditor starts from.
How Skyline Nexus ERP supports the audit
Skyline Nexus ERP gives the audit team most of its standard extracts from one place. Fiscal Authority > Reports offers an Audit Pack (Excel) that produces a single workbook with a sheet per report, including Chart of Accounts, Trial Balance, Balance Sheet, Profit & Loss, Journal Entries, Journal Lines, General Ledger, Customer Dues (AR), Supplier Dues (AP) and VAT Summary (GL). The year selector picks a calendar year, so an entity with a non-calendar year end should run the individual reports by date range instead.
For risk assessment and journal testing, the Audit Trail report records who created, updated, approved, posted, reversed or deleted accounting entries, with old and new values, IP address and browser. The Trial Balance has an Opening / Movement / Closing view that makes the roll-forward from last year's audited balances easy to test, and the Data Verification report compares the trial balance with GL and POS transactions, which helps the auditor assess the completeness of information produced by the system.
Common questions
What are the stages of a financial statement audit?
A financial statement audit under the ISAs runs through acceptance and the engagement letter, planning and materiality, understanding the entity and assessing risk under ISA 315, designing responses under ISA 330, gathering evidence, completion and evaluation of misstatements, and finally the auditor's report. Planning and risk assessment are revisited throughout, so a financial statement audit is iterative rather than strictly sequential.
What is the difference between reasonable assurance and absolute assurance?
Reasonable assurance is a high but not absolute level of assurance that the financial statements are free from material misstatement. Absolute assurance is impossible in an audit because testing is selective, evidence is persuasive rather than conclusive, estimates involve judgement and fraud may involve collusion or forgery. ISA 200 defines reasonable assurance as the level every audit opinion is designed to deliver.
What is the difference between a qualified opinion and an adverse opinion?
A qualified opinion says the financial statements are fairly presented except for a material matter whose effects are not pervasive. An adverse opinion says the financial statements are not fairly presented because a material misstatement is pervasive. Both come from ISA 705 (Revised); the deciding question is whether the misstatement is confined to specific items or undermines the statements as a whole.
What is the audit risk model?
The audit risk model states that audit risk equals the risk of material misstatement multiplied by detection risk. The risk of material misstatement combines inherent risk and control risk and belongs to the entity. Detection risk is the part the auditor controls through the nature, timing and extent of procedures. The audit risk model explains why higher assessed risk demands more persuasive evidence.
What is a significant risk in an audit?
A significant risk is an identified risk of material misstatement assessed close to the upper end of the spectrum of inherent risk under ISA 315 (Revised 2019). Management override of controls is always a significant risk, and revenue recognition is presumed to be one. Each significant risk requires substantive procedures specifically responsive to it, and analytical procedures alone are not sufficient.
How long does a financial statement audit take?
A financial statement audit for a mid-sized company typically involves an interim visit, a stock count, and two to six weeks of year-end fieldwork, with the whole cycle running from planning in the autumn to signing a few months after year end. The duration depends mostly on the quality of the client's close, reconciliations and supporting schedules, not on the auditor alone.
What is the difference between an emphasis of matter paragraph and a key audit matter?
An emphasis of matter paragraph under ISA 706 draws attention to a matter already properly disclosed that is fundamental to users' understanding, such as a major subsequent event. A key audit matter under ISA 701 describes an area of most significance in the audit and how the auditor addressed it. Neither an emphasis of matter paragraph nor a key audit matter modifies the opinion.
This guide is general information, not tax, accounting or legal advice. Rules differ from country to country and change over time; confirm the current position with your tax authority or a qualified adviser before acting on anything here.
Ready to run your operation on a single workspace?