Snapshot
ISSAI, ISA and IIA families, ethics, independence threats, materiality, assurance and engagement quality.
Module status
- •Track: Audit execution
- •Last verified: 2026-07-31
- •Scope: Independent competition training; official sources always prevail.
Standards families
Public-sector auditors work with overlapping standards. ISSAIs provide INTOSAI's public-sector auditing framework. ISAs from the IAASB provide financial-audit requirements and guidance. The IIA Global Internal Audit Standards govern internal-audit practice. An engagement's mandate and adopted methodology determine which standards apply; an auditor must not casually combine requirements or claim compliance without meeting the relevant conditions.
INTOSAI-P 1 contains the Lima Declaration's foundational principles. INTOSAI-P 10 contains the Mexico Declaration on Supreme Audit Institution independence. ISSAI 100 states fundamental principles of public-sector auditing. ISSAI 200, 300 and 400 address financial, performance and compliance audit respectively.
Ethical principles
Public-sector audit ethics centre on integrity, independence and objectivity, competence, professional behaviour, confidentiality and transparency. A code alone is insufficient. The organisation needs declarations, conflict checks, rotation or safeguards, consultation channels and enforcement.
Independence threats
Common threats include:
- •self-interest: a financial or career interest biases judgement;
- •self-review: the auditor evaluates work they previously designed or performed;
- •advocacy: the auditor promotes the auditee's position;
- •familiarity: a close or long relationship weakens professional scepticism;
- •intimidation: pressure or fear influences scope, evidence or reporting.
Responses can include removing the conflicted person, changing responsibilities, adding independent review, declining non-audit work, rotating staff, escalating interference or, when no safeguard is adequate, declining or withdrawing from the engagement.
Professional judgement and scepticism
Professional judgement applies knowledge, experience and standards to decisions. Professional scepticism is an alert, questioning mindset that critically assesses evidence and remains attentive to contradiction, fraud risk and management bias. Scepticism does not mean assuming dishonesty. It means neither accepting claims uncritically nor rejecting them without evidence.
Competence and due care
The team collectively needs knowledge of the subject matter, audit method, relevant law, accounting, data and IT. Specialists may support technical areas. The auditor remains responsible for evaluating whether specialist work is adequate for the audit purpose.
Due professional care is proportionate to complexity, significance and risk. It does not guarantee detection of every error or fraud. Documentation should show the reasoning behind significant judgements.
Quality management
Quality is built throughout the audit, not added at report clearance. Key controls include:
- •clear responsibilities and acceptance decisions;
- •competent staffing and adequate time;
- •direction, supervision and review;
- •consultation on difficult or contentious matters;
- •engagement quality review where criteria require it;
- •resolution of differences of opinion;
- •documented completion and archiving;
- •monitoring and remediation at organisational level.
An engagement quality reviewer provides an objective evaluation of significant judgements before report release. The reviewer does not assume engagement-leader responsibility or replace normal supervision.
Audit risk model
For financial audit, audit risk is commonly analysed through inherent risk, control risk and detection risk. In simplified form:
`Audit risk = risk of material misstatement × detection risk`
Risk of material misstatement combines inherent and control risk. Auditors assess rather than directly control those components. They adjust the nature, timing and extent of audit procedures to reduce detection risk to an acceptably low level.
Materiality
Materiality reflects whether an omission or misstatement could reasonably influence users' decisions. It has quantitative and qualitative dimensions. A small amount may be material because of illegality, fraud, sensitivity, disclosure or management behaviour. Performance materiality is set below overall materiality to reduce aggregation risk.
Reasonable and limited assurance
Reasonable assurance is high but not absolute. Limited assurance uses less extensive work and normally supports a negatively expressed conclusion. The engagement terms, applicable standards and evidence determine the assurance level; the label cannot compensate for inadequate procedures.
Quality failure patterns
- •Back-dating review evidence after report issue.
- •Treating a checklist tick as proof of substantive review.
- •Letting budget pressure override necessary work without revising scope or reporting the limitation.
- •Allowing the auditee to select the sample.
- •Clearing contradictory evidence without documenting resolution.
- •Confusing consultation with transfer of responsibility.