Blog, ICAI Updates & Amendments

SA 330 Explained: The Auditor’s Responses to Assessed Risks

SA 330, “The Auditor’s Responses to Assessed Risks,” is the standard that connects risk assessment to actual audit work. SA 315 tells you how to identify and assess risk. SA 330 tells you what to do about it. In the exam, that link is what most answers miss.

Objective of SA 330

To obtain sufficient appropriate audit evidence about the assessed risks of material misstatement, by designing and implementing appropriate responses to those risks.

1. Overall responses — at the financial statement level

Where risk is assessed at the overall financial statement level, the response is broad rather than procedure-specific:

  • Emphasising to the team the need for professional scepticism
  • Assigning more experienced staff, or those with special skills
  • Providing more supervision
  • Incorporating unpredictability in the selection of procedures
  • Making general changes to the nature, timing or extent of procedures

2. Further audit procedures — at the assertion level

Design and perform procedures whose nature, timing and extent are based on and responsive to the assessed risks at the assertion level. Two categories:

Tests of controls

Required when either:

  • The auditor intends to rely on the operating effectiveness of controls, or
  • Substantive procedures alone cannot provide sufficient appropriate evidence at the assertion level — typically in highly automated environments where evidence exists only in electronic form.

Substantive procedures

This is the point students most often get wrong: irrespective of the assessed risk, the auditor must design and perform substantive procedures for each material class of transactions, account balance and disclosure. Good controls reduce substantive work — they never eliminate it.

Where the assessed risk is a significant risk, the auditor must perform substantive procedures specifically responsive to it, and if the approach is substantive only, those must include tests of details.

3. The three-year rule on tests of controls

Testing controls every single year is not mandatory. If the auditor plans to rely on controls tested in a previous audit, he must establish their continuing relevance — and where there has been no change in those controls, they must be tested at least once in every third audit.

The exception that carries marks: controls that address a significant risk — where the likelihood and impact of misstatement are high — must be tested in the current period, every year. No rotation is permitted for these.

4. Timing

Procedures may be performed at an interim date or at the period end. Where evidence is obtained at an interim date, the auditor must cover the remaining period — through substantive procedures for the intervening period, combined with tests of controls where appropriate.

5. Presentation and disclosure

The auditor must perform procedures to evaluate whether the overall presentation of the financial statements, including disclosures, is in accordance with the applicable financial reporting framework.

6. Evaluating sufficiency and appropriateness

Before concluding, the auditor evaluates whether the assessments of risk remain appropriate and whether sufficient appropriate audit evidence has been obtained. If not — obtain further evidence. If that is not possible, consider the implications for the opinion.

7. Documentation

Document the overall responses, the nature, timing and extent of further audit procedures, their linkage with the assessed risks, the results, and — where controls tested in prior audits are relied upon — the conclusions reached about that reliance.

Frequently asked questions

Is it compulsory to test controls every year under SA 330?

No. Where controls have not changed, they must be tested at least once in every third audit. But controls addressing a significant risk must be tested every year, without exception.

Can substantive procedures be skipped if controls are strong?

No. SA 330 requires substantive procedures for every material class of transactions, balance and disclosure regardless of how effective the controls are. Strong controls reduce the extent of substantive work; they do not remove the requirement.

What is the difference between SA 315 and SA 330?

SA 315 is about identifying and assessing risk. SA 330 is about responding to it. One diagnoses, the other treats.

What does “nature, timing and extent” mean?

Nature is which procedure and its purpose. Timing is when it is performed and the period covered. Extent is the quantity — sample size, or the number of observations of a control.


Studying CA Inter or CA Final Audit?

SA 330 is examined most often through case studies asking you to justify a response to a stated risk. Practice those from the CA Inter PARAM Question Bank or the CA Final PARAM Question Bank.

Mast raho. Smart padho. — CA Ravi Taori

About CA Ravi Taori

CA Ravi Taori is the founder of AuditGuru and has taught Audit - and nothing else - since 2007, to CA Inter and CA Final students. AIR 45 in CA Inter. Three years of article training in statutory audit at PricewaterhouseCoopers (PwC), Mumbai. Author of the Bhaskar, Titanium, PARAM, FADU and MCQ book series. Eight of his students have placed in the All India Top 20. He also mentors CA Foundation, Inter and Final students one to one through the AuditGuru mentorship programme.