Evaluating the Evidence Obtained
16. The auditor shall evaluate whether the results of the external confirmation procedures provide relevant and reliable audit evidence, or whether performing further audit procedures is necessary. (Ref: Para A24-A25) ***
Application and Other Explanatory Material
External Confirmation Procedures
Determining the Information to be Confirmed or Requested (Ref: Para. 7(a))
A1. External confirmation procedures frequently are performed to confirm or request information regarding account balances and their elements. They may also be used to confirm terms of agreements, contracts, or transactions between an entity and other parties, or to confirm the absence of certain conditions, such as a “side agreement”.
Selecting the Appropriate Confirming Party (Ref: Para. 7(b))
A2. Responses to confirmation requests provide more relevant and reliable audit evidence when confirmation requests are sent to a confirming party the auditor believes is knowledgeable about the information to be confirmed. For example, a financial institution official who is knowledgeable about the transactions or arrangements for which confirmation is requested may be the most appropriate person at the financial institution from whom to request confirmation.
Designing Confirmation Requests (Ref: Para. 7(c))
A3. The design of a confirmation request may directly affect the confirmation response rate, and the reliability and the nature of the audit evidence obtained from responses.
A4. Factors to consider when designing confirmation requests include: The assertions being addressed. Specific identified risks of material misstatement, including fraud risks. The layout and presentation of the confirmation request. Prior experience on the audit or similar engagements. The method of communication (for example, in paper form, or by electronic or other medium). Management’s authorisation or encouragement to the confirming parties to respond to the auditor. Confirming parties may only be willing to respond to a confirmation request containing management’s authorisation. The ability of the intended confirming party to confirm or provide the requested information (for example, individual invoice amount versus total balance).
A5. A positive external confirmation request asks the confirming party to reply to the auditor in all cases, either by indicating the confirming party’s agreement with the given information, or by asking the confirming party to provide information. A response to a positive confirmation request ordinarily is expected to provide reliable audit evidence. There is a risk, however, that a confirming party may reply to the confirmation request without verifying that the information is correct. The auditor may reduce this risk by using positive confirmation requests that do not state the amount (or other information) on the confirmation request, and ask the confirming party to fill in the amount or furnish other information. On the other hand, use of this type of “blank” confirmation request may result in lower response rates because additional effort is required of the confirming parties.
A6. Determining that requests are properly addressed includes testing the validity of some or all of the addresses on confirmation requests before they are sent out.
Follow-Up on Confirmation Requests (Ref: Para. 7(d))
A7. The auditor may send an additional confirmation request when a reply to a previous request has not been received within a reasonable time. For example, the auditor may, having re-verified the accuracy of the original address, send an additional or follow-up request.
Management’s Refusal to Allow the Auditor to Send a Confirmation
Reasonableness of Management’s Refusal (Ref: Para. 8(a))
A8. A refusal by management to allow the auditor to send a confirmation request is a limitation on the audit evidence the auditor may wish to obtain. The auditor is therefore required to inquire as to the reasons for the limitation. A common reason advanced is the existence of a legal dispute or ongoing negotiation with the intended confirming party, the resolution of which may be affected by an untimely confirmation request. The auditor is required to seek audit evidence as to the validity and reasonableness of the reasons because of the risk that management may be attempting to deny the auditor access to audit evidence that may reveal fraud or error. Implications for the Assessment of Risks of Material Misstatement (Ref:
A9. The auditor may conclude from the evaluation in paragraph 8(b) that it would be appropriate to revise the assessment of the risks of material misstatement at the assertion level and modify planned audit procedures in accordance with SA 31514. For example, if management’s request to not confirm is unreasonable, this may indicate a fraud risk factor that requires evaluation in accordance with SA 24015.
Alternative Audit Procedures (Ref: Para. 8(c))
A10. The alternative audit procedures performed may be similar to those appropriate for a non-response as set out in paragraphs A18-A19 of this SA. Such procedures also would take account of the results of the auditor’s evaluation in paragraph 8(b) of this SA.
Results of the External Confirmation Procedures
Reliability of Responses to Confirmation Requests (Ref: Para. 10)
A11. SA 500 indicates that even when audit evidence is obtained from sources 14 SA 315, paragraph 31. 15 SA 240, paragraph 24. external to the entity, circumstances may exist that affect its reliability16. All responses carry some risk of interception, alteration or fraud. Such risk exists regardless of whether a response is obtained in paper form, or by electronic or other medium. Factors that may indicate doubts about the reliability of a response include that it:
Was received by the auditor indirectly; or
Appeared not to come from the originally intended confirming party.
A12. Responses received electronically, for example by facsimile or electronic mail, involve risks as to reliability because proof of origin and authority of the respondent may be difficult to establish, and alterations may be difficult to detect. A process used by the auditor and the respondent that creates a secure environment for responses received electronically may mitigate these risks. If the auditor is satisfied that such a process is secure and properly controlled, the reliability of the related responses is enhanced. An electronic confirmation process might incorporate various techniques for validating the identity of a sender of information in electronic form, for example, through the use of encryption, electronic digital signatures, and procedures to verify website authenticity.
A13. If a confirming party uses a third party to coordinate and provide responses to confirmation requests, the auditor may perform procedures to address the risks that: