This section highlights revisions related to:
- material classes of transactions, account balances, and disclosures (COTABDs) that are not significant COTABDs, including conforming amendments proposed to ISA 315, Identifying and Assessing Risks of Material Misstatement;
- responding to assessed risks of material misstatement (ROMMs) at the assertion level through tests of controls alone; and
- clarifying the auditor’s work on internal controls.
The section presents key proposed changes, explains why they matter, and, where relevant, identifies key scalability considerations. Relevant references to the IAASB’s Exposure Draft.
Material COTABDs that are not significant COTABDs
Key proposed changes
- Removal of the requirement in extant paragraph ISA 330.18 for the auditor to design and perform substantive procedures for each material COTABD, irrespective of the assessed risks of material misstatement (ROMMs).
- As a consequence of removing extant paragraph ISA 330.18, proposed paragraph ISA 330.9, requires the auditor to design and perform substantive procedures in response to assessed ROMMs at the assertion level, unless the auditor responds through tests of controls alone under proposed paragraph ISA 330.16.
- Conforming and consequential amendments to ISA 315 strengthen the existing requirements and application material by providing additional support for auditor judgment when determining whether a material COTABD is not a significant COTABD. The amendments also proposed a documentation requirement in paragraph ISA 315.38(e) for the basis of the determination under paragraph ISA 315.36.
The PDF below shows the application of proposed paragraphs in ISA 315.

Why it matters
- Focuses work effort on financial statement items where ROMMs are identified and assessed, while avoiding unnecessary work in areas where no ROMM has not been identified.
- Allows flexibility in documenting the basis for determining that material COTABDs are not significant COTABDs by clarifying that it is based on professional judgment, and that assertion-level documentation is not required. Key scalability consideration
Relevant sections
ED-ISA 330
- Explanatory Memorandum – Section 1–C, paragraphs 18-37.
- Proposed paragraphs ISA 330.9 and A27-A33.
Overall ED
- Explanatory Memorandum – Section 1–A, paragraphs 38 and Section 1-D, paragraph 66.
- Proposed conforming and consequential amendments to paragraphs ISA 315.35-36, 38(e), A204A-A204B, and A230B-A238A.
Responding to assessed ROMMs at the assertion level through tests of controls alone
Key proposed changes
- Removal of extant paragraph ISA 330.18, the existing restriction of a control alone approach for an entire COTABD.
- Proposed paragraph ISA 330.16 explicitly permits the auditor to respond to assessed ROMMs at the assertion level through tests of controls alone only when:
- the assessed inherent risk is not at the higher end of the spectrum, and no such risks are determined to be significant risks; and
- the auditor’s expectation of the operating effectiveness of controls that address inherent risks is such that the ROMMs at the assertion level are at an acceptably low level.
- Proposed application material to paragraph ISA 330.16 supports auditor judgment when determining whether controls alone approach is appropriate, including:
- obtaining more persuasive evidence about the operating effectiveness of controls when further audit procedures consist primarily, or only, of tests of controls, and includes factors that affect persuasiveness.
- determine whether controls are capable of reducing ROMMs to an acceptably low level.
- Proposed paragraph ISA 330.20 requires current period testing when relying on tests of controls alone.
- Proposed paragraph ISA 330.31 introduces a stand-back evaluation specific to further audit procedures. If sufficient appropriate audit evidence has not been obtained, proposed paragraph ISA 330.32 requires to auditor to obtain further evidence, which likely involve substantive procedures.
Why it matters
- Clarifies that a tests-of-controls-alone approach that addresses ROMMs at the assertion level is conceptually sound and consistent with the audit-risk model in a narrow range of circumstances.
- Supports the use of professional judgment about whether responding to assessed ROMMs at the assertion level through tests of controls alone is appropriate and permissible.
- Supports audits in a rapidly evolving technology environment where testing automated controls may, in some circumstances, be more persuasive than evidence obtained through substantive procedures.
Relevant sections
ED-ISA 330
- Explanatory Memorandum - Section 1–E, paragraphs 49–56.
- Proposed ISA 330 - paragraphs 16, 20, 31-32, A52, A66 and A87.
Overall ED
- Explanatory Memorandum - Section 1-A, paragraph 42.
Clarifying the auditor’s work on internal controls
When substantive procedures alone are unable to provide sufficient appropriate audit evidence
Key proposed changes
- Proposed paragraph ISA 330.14 retains the principle in extant paragraph ISA 330.8 and does not require the auditor to perform tests of controls, unless substantive procedures alone cannot provide sufficient appropriate audit evidence.
- Enhanced application material:
- Expands the examples of circumstances when this may arise, including highly automated processing, complex estimates, cycle counts, and multi-location environments.
- Clarifies that the phrase “cannot provide sufficient appropriate audit evidence” includes situations were obtaining evidence through substantive procedures alone may be impossible or possible, but impracticable.
Why it matters
- Supports more consistent judgment in identifying when substantive procedures alone cannot provide sufficient appropriate audit evidence, and therefore, control testing is necessary.
Relevant sections
ED-ISA 330
- Explanatory Memorandum – Section 1–E, paragraphs 47-48.
- Proposed paragraphs ISA 330.14 and A48-A49.
Direct controls, indirect controls and general information technology controls (GITCs)
Key proposed changes
- Removal of extant paragraph ISA 330.10(b), which required auditors to determine whether indirect controls need to be tested. This proposed removal is because the auditor’s determination of which controls to test is already addressed in ISA 315, making a separate requirement in ISA 330 redundant.
- Accordingly, in redrafting proposed paragraph ISA 330.17 on the nature and extent of tests of controls, the reference to “controls” already includes indirect controls when necessary.
- Enhanced application material:
- Explains how direct controls and indirect controls (including GITCs) work together.
- Clarifies when indirect controls and GITCs may need to be tested.
- Recognizes that a GITC deficiency does not automatically mean a direct control is ineffective.
- Clarifies that auditors may leverage GITCs testing already performed for other purposes.
Why it matters
- Improves alignment with ISA 315.
- Supports auditor judgment about which controls need to be tested. Key scalability consideration
Relevant sections
ED-ISA 330
- Explanatory Memorandum – ISA 330 Section 1–E, paragraphs 57-61.
- Proposed paragraphs ISA 330.17 and ISA 330.A54-A57.
Overall ED
- Explanatory Memorandum – Section 1–A, paragraph 41.
Impact of technology on automated controls
Key proposed changes
- New application material about the implications of emerging technologies on the consistency of the operations of controls, such as:
- Some controls may use technologies that produce consistent outputs, while others may evolve, be updated, or generate variable outputs over time.
- The characteristics of the automated control may affect the auditor’s judgment about the level of consistency with which an automated control operates, and therefore, impact the auditor’s determination of the nature, timing, and extent of testing to perform on the controls.
Why it matters
- Responsive to the increased use of emerging technologies by entities and informs the auditor’s judgment on how the principle-based requirements apply in such circumstances.
Relevant sections
ED-ISA 330
- Explanatory Memorandum – Section 1–E, paragraphs 62-63.
- Proposed paragraphs ISA 330.A59, and A62-A63.
Using prior-year control testing
Key proposed changes
- Additional factors added in proposed paragraph ISA 330.22. Before using audit evidence about the operating effectiveness of controls obtained in previous audits, the auditor considers:
- the persuasiveness of evidence needed;
- current-period risks arising from IT;
- related GITCs; and
- changes in circumstances that suggest that controls should have changed.
- Proposed paragraph ISA 330.23 clarifies the time period for retesting a control as at least once in every third year (rather than “every third audit” in extant), irrespective of how many audits are conducted during that period.
- Proposed application material:
- Paragraph ISA 330.A70 explains that prior-year evidence about the operating effectiveness of manual controls does not provide audit evidence about the effectiveness of such controls in the current period.
- Paragraph ISA 330.A71 explains that prior-year evidence about the operating effectiveness of automated controls may no longer be relevant and reliable for the current year if related GITCs are not effective.
- Paragraph ISA 330.A72 explains that prior-year evidence about the operating effectiveness of controls may not be used when changes in circumstances require the controls to be redesigned or operated differently to address current-period assessed risks.
Why it matters
- Strengthens auditor judgment in deciding whether prior-year audit evidence about the operating effectiveness of controls can be used in the current period, particularly in changing technology and control environments.
Relevant sections
ED-ISA 330
- Explanatory Memorandum – Section 1–E, paragraph 64.
- Proposed paragraphs ISA 330.22-23, A66, and A69-A76.
Evaluating control deviations and test of controls results
Key proposed changes
- Paragraph ISA 330.25(a) expands the extant requirement to clarify that, while inquiry remains necessary when a control deviation is identified, auditors are also required to obtain audit evidence to support the explanations received.
- Proposed application material in paragraph ISA 330.A79 recognizes that an identified deviation in a control does not necessarily mean that the control is ineffective. Additional procedures may be performed to determine whether the control can still be relied upon.
- Proposed paragraph ISA 330.26 requires the auditor to revise the assessment of control risk and modify the substantive procedures if the auditor is unable to obtain an appropriate basis for confirming the auditor’s assessment of controls risk.
Why it matters
- As test of controls may be used more frequently as a response to ROMMs, particularly in technology-enabled environments, the proposals support auditor judgement in evaluating control deviations and assessing the impact of testing results on the planned audit approach.
Relevant sections
ED-ISA 330
- Explanatory Memorandum – Section 1–E, paragraph 65.
- Proposed paragraphs ISA 330. 24-26 and A77-A81.