AuditXYZ

Compliance Framework

International Standards on Auditing (ISAs) (IAASB ISA)

The ISAs are the global standards governing financial statement audits. This guide covers key ISAs, the risk-based audit approach, auditor reporting, and how ISAs relate to national auditing standards.

$10,000–$500,0002–6 monthsAudit Required2024 (ongoing updates including ISA 600 Revised)
Issuing BodyInternational Auditing and Assurance Standards Board (IAASB)
First Published1991-01-01
Latest Version2024 (ongoing updates including ISA 600 Revised)
Typical Cost$10,000–$500,000
Typical Timeline2–6 months
Audit RequiredYes
Audit FrequencyAnnual financial statement audit is standard for listed companies and entities meeting statutory audit thresholds in most jurisdictions.
Geographyglobal

IAASB ISA: International Standards on Auditing Guide

The International Standards on Auditing (ISAs) are the globally recognized standards for performing financial statement audits. Issued by the IAASB under the oversight of the International Federation of Accountants (IFAC), ISAs are adopted or used as the basis for national auditing standards in over 130 jurisdictions. They establish the auditor's responsibilities for planning, performing, and reporting on financial statement audits with the objective of obtaining reasonable assurance about whether the financial statements are free from material misstatement.

What the ISAs Are and Who Issues Them

The International Auditing and Assurance Standards Board (IAASB) is an independent standard-setting body supported by IFAC. Its members include audit practitioners, preparers, investors, regulators, and public interest representatives from around the world. The IAASB's due process requires extensive public consultation — proposed standards are exposed for comment periods and the Board considers responses from over 100 jurisdictions and hundreds of respondents before finalizing standards.

ISAs are developed to serve the public interest by improving audit quality and enhancing confidence in financial reporting. They are not primarily designed to be compliance documents for audited entities — they govern auditor behavior. However, entities undergoing audits benefit significantly from understanding ISA requirements because they directly affect what auditors will do, what evidence they will need, and how they will form and express their opinions.

The ISAs are organized by the Handbook of International Quality Management, Auditing, Review, Other Assurance, and Related Services Pronouncements, updated annually. As of 2024, major active work includes the recently effective ISA 600 (Revised) for group audits, ongoing development of ISA for Less Complex Entities (LCE), and work on auditing estimates, going concern, and the impact of technology on auditing.

The ISAs coexist with — and in many jurisdictions are adopted as — national auditing standards. In the UK, the Financial Reporting Council issues ISAs (UK) which are based on IAASB ISAs but contain UK-specific additions. In the US, the AICPA's Generally Accepted Auditing Standards (GAAS) and the PCAOB's auditing standards serve listed and non-listed entities respectively. Understanding which standard set applies requires knowing the audited entity's jurisdiction and listing status.

Who Needs to Understand ISAs

Audit firms performing financial statement audits in ISA-adopting jurisdictions must comply with the ISAs as professional requirements. Audit quality monitoring and peer review programs assess compliance.

Companies undergoing annual audits benefit from ISA literacy in several practical ways: they can prepare more efficiently for audit requests, engage more productively with audit teams, understand why auditors focus on certain areas, and anticipate issues before they arise during fieldwork.

Audit committees and boards have governance responsibility for the external audit relationship. ISA literacy — particularly understanding ISA 260 (auditor communications with governance), ISA 570 (going concern), and ISA 700-706 (auditor reporting) — enables audit committees to fulfill their oversight role effectively.

CFOs and financial controllers who manage the audit process daily need practical ISA knowledge to manage timelines, prepare schedules, respond to auditor requests efficiently, and understand the implications of audit findings.

Compliance and internal audit professionals working alongside external auditors — providing work-product, coordinating testing, or relying on external audit findings for compliance purposes — benefit from understanding the ISA framework within which external auditors operate.

Key ISAs Explained in Depth

ISA 200 — Overall Objectives of the Independent Auditor

The foundation standard. ISA 200 establishes that the auditor's objective is to obtain reasonable assurance about whether the financial statements are free from material misstatement (due to error or fraud) and to report on the financial statements. It defines fundamental concepts: professional skepticism (a questioning mind, alert to conditions indicating possible misstatement), professional judgment (applying knowledge and experience), audit evidence, and the risk-based audit approach. Every specific ISA requirement derives from ISA 200's foundational principles.

ISA 315 (Revised 2019) — Identifying and Assessing the Risks of Material Misstatement

ISA 315 governs how auditors understand the entity and its environment to identify risks of material misstatement in the financial statements. The 2019 revision substantially enhanced the risk assessment requirements, requiring auditors to assess inherent risk (likelihood of misstatement before controls) and control risk (likelihood that controls fail to prevent or detect misstatements) separately. Auditors must identify significant risks — those requiring special audit consideration — and risks for which substantive procedures alone are insufficient. ISA 315 directly shapes the scope and focus of every audit engagement.

ISA 330 — The Auditor's Responses to Assessed Risks

Having identified risks under ISA 315, ISA 330 requires the auditor to design and perform responses. These include overall responses (such as assigning more experienced personnel) and specific procedures: tests of controls (evaluating whether controls are operating effectively) and substantive procedures (detecting material misstatements regardless of controls). The design of ISA 330 responses determines how much audit work will occur in each area and directly drives audit costs.

ISA 500 — Audit Evidence

ISA 500 establishes the sufficiency and appropriateness requirements for audit evidence. Sufficiency relates to quantity — enough evidence to support the auditor's conclusions. Appropriateness relates to quality — evidence must be relevant and reliable. The reliability hierarchy places evidence from external sources (confirmations) above internal documents and corroborated evidence above uncorroborated evidence. ISA 500 guides auditors in evaluating whether the evidence they have gathered is adequate.

ISA 520 — Analytical Procedures

Analytical procedures use comparisons and relationships among financial and non-financial data to identify unusual fluctuations or relationships that may indicate risks of misstatement. ISA 520 requires analytical procedures in risk assessment (ISA 315) and in the review at the conclusion of the audit, and permits their use as substantive procedures where appropriate. Technology-enabled analytical procedures are increasingly replacing manual calculations.

ISA 540 (Revised) — Auditing Accounting Estimates

Accounting estimates — revenue recognition, expected credit losses, fair values, warranty provisions, and similar items — are areas of significant judgment and fraud risk. The 2019 revision of ISA 540 substantially strengthened requirements for auditing estimates, reflecting lessons from the global financial crisis. Auditors must now understand the inherent risk in each estimate, evaluate management's process, and test assumptions and data used in estimates. This standard drives significant audit attention in financial services, real estate, and any industry with material estimates.

ISA 570 — Going Concern

ISA 570 requires auditors to evaluate whether substantial doubt exists about an entity's ability to continue as a going concern. Auditors review management's assessment, evaluate the basis for that assessment, and determine appropriate reporting implications. Going concern assessments have become more prominent following economic disruptions affecting companies across sectors.

ISA 600 (Revised 2022) — Special Considerations — Audits of Group Financial Statements

The revised ISA 600 fundamentally changed how group audits work. The group engagement team has enhanced responsibilities for planning and supervising component auditors and must take direct responsibility for the sufficiency and appropriateness of evidence obtained at all components. Component auditors must now communicate more fully with the group team. The revision responds to high-profile group audit failures where group engagement partners were insufficiently involved in key component audit work.

ISA 700-706 — Forming and Reporting the Auditor's Opinion

This cluster of standards governs the most visible output of the audit: the auditor's report. ISA 700 covers forming the opinion and the standard report structure. ISA 701 requires Key Audit Matters (KAMs) — matters most significant in the audit — to be disclosed in reports for listed entities. ISA 705 addresses modifications (qualified, adverse, or disclaimer of opinion). ISA 706 covers emphasis-of-matter and other-matter paragraphs. Enhanced reporting requirements introduced through these standards have made audit reports considerably more informative and entity-specific.

The Risk-Based Audit Approach

Understanding the ISA framework means understanding that modern auditing is fundamentally risk-based. The auditor does not test every transaction or balance. Instead, the auditor:

  1. Understands the entity and its environment to identify where material misstatements are most likely to occur
  2. Assesses risks of material misstatement at the financial statement and assertion levels
  3. Designs responses proportionate to assessed risks — more work where risks are higher, less where risks are lower
  4. Evaluates whether evidence obtained is sufficient to support conclusions
  5. Reports findings in a structured, standardized format

This approach means that audit scope is not fixed — it varies based on the specific entity, its industry, economic conditions, management quality, and the nature of financial statement balances and transactions. Entities that help auditors understand their business efficiently, maintain strong documentation, and implement effective internal controls will experience more efficient audits.

Costs and Timeline

Entity SizeTypical Annual Audit FeeTimeline
Small company (revenue under $10M)$10,000 – $50,0004–8 weeks
Mid-size company ($10M–$500M revenue)$50,000 – $300,0006–12 weeks
Large listed company ($500M+ revenue)$300,000 – $3,000,000+10–20 weeks
Multinational group$1,000,000 – $10,000,000+4–6 months

Fees are set by the audit firm based on assessed audit risk, entity complexity, internal control quality, and the estimated hours required. Organizations that invest in strong internal controls, well-documented processes, and organized evidence can materially reduce their audit fees over time.

US GAAS / PCAOB Standards (85% overlap): The ISAs and US auditing standards share the same fundamental risk-based approach, evidence standards, and reporting concepts. Listed US companies' audits are governed by PCAOB standards, which have some additional requirements reflecting the Sarbanes-Oxley environment. Non-listed US companies use AICPA GAAS. For multinational companies with both US and non-US operations, understanding both frameworks helps manage group audit relationships.

ISAE 3000 (parent relationship): The ISAs govern financial statement audits (historical financial information). ISAE 3000 governs non-financial assurance. Both operate within the IAASB framework with compatible ethical and evidence principles. Many organizations engage the same audit firm for both ISA-governed financial audits and ISAE 3000-governed non-financial assurance. See the ISAE 3000 guide.

ISAE 3402 (complementary): When a company uses service organizations that affect its financial statements, ISA 402 (Audit Considerations Relating to an Entity Using a Service Organization) governs how the entity's auditor considers those controls — including by reviewing the service organization's ISAE 3402 report. See the ISAE 3402 guide.

How Automation Helps

While the ISAs govern auditors, not audited entities, organizations that use compliance automation tools benefit in their audit relationships through better-organized documentation, automated evidence collection, and audit-ready control libraries. LowerPlane supports 50+ frameworks and generates the organized, time-stamped evidence packages that auditors prefer when assessing internal controls. Starting at $4,000 per year with a free tier, it is rated 9.4/10 by AuditXYZ users. Well-organized audit evidence directly reduces auditor time and the associated audit fee. See our compliance automation comparison.

Frequently Asked Questions

Why do ISAs matter to companies that are just trying to pass their audit? Understanding ISA requirements helps companies anticipate what their auditors will focus on, prepare appropriate documentation proactively, and engage more constructively during fieldwork. Companies that understand why auditors request certain evidence and how auditors evaluate it can structure their processes and documentation to make the audit faster and less disruptive — directly reducing both audit costs and the demands on internal teams.

What is the difference between a qualified opinion and an adverse opinion under ISA 705? A qualified opinion is issued when a misstatement is material but not pervasive — it affects certain elements of the financial statements but does not undermine them as a whole. An adverse opinion is issued when misstatements are both material and pervasive — so significant that the financial statements as a whole are misleading. A disclaimer of opinion is issued when the auditor cannot obtain sufficient appropriate evidence and the potential effects are both material and pervasive. Adverse opinions and disclaimers are relatively rare events with serious consequences.

How does ISA 315 (Revised) affect what auditors ask for? ISA 315 (Revised 2019) increased the evidence standard for auditors' understanding of internal controls — particularly IT general controls and automated controls. Auditors must now document their understanding of IT environments, application controls, and data flows more thoroughly. This has led many companies to see increased auditor focus on IT controls, access management, and the completeness and accuracy of information produced by IT systems (IPE — information produced by the entity).

What is an Emphasis of Matter paragraph and when is it used? An Emphasis of Matter paragraph draws attention to a specific matter disclosed in the financial statements that is fundamental to users' understanding, but does not modify the auditor's opinion. Common uses include going concern uncertainty (where the doubt is disclosed but does not yet warrant a qualification), significant uncertainty in estimates, or restatements of comparative figures. The auditor uses this paragraph to ensure users notice important matters even when the opinion remains unmodified.

How does ISA 701 (Key Audit Matters) change the audit report? ISA 701 requires auditors of listed entities to include a Key Audit Matters section identifying and describing the matters that required the most significant auditor judgment during the period. Each KAM must explain why it was significant and describe how it was addressed. This makes audit reports substantially more informative and entity-specific — a significant change from the boilerplate reports of prior decades. KAMs are now read closely by investors and analysts as signals of audit risk areas.

Request a IAASB ISA consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

ISAs (UK)High95%

Related frameworks

Get matched with a IAASB ISA auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.