ReadSafety.com
Auditing StandardInternational Auditing and Assurance Standards Board (IAASB)Last reviewed: August 2026

ISA

ISA is the set of international standards that tells auditors how to plan, perform, and report on audits of financial statements - ensuring consistency and quality worldwide.

What You'll Learn

  • What ISA is and who issues it
  • The objective of a financial statement audit
  • Key concepts: reasonable assurance, materiality, audit risk
  • The audit process from engagement to opinion
  • Types of audit opinions
  • Professional skepticism and judgment
  • How ISA differs from PCAOB and GAAS

First: What Is This?

International Standards on Auditing (ISA) are issued by the International Auditing and Assurance Standards Board (IAASB), part of the International Federation of Accountants (IFAC). They provide a comprehensive framework for how auditors should conduct audits of financial statements.

ISA is used in over 130 jurisdictions worldwide. The standards cover everything from accepting an engagement, planning the audit, gathering evidence, evaluating misstatements, to forming and expressing an opinion. They are designed to ensure that audits provide 'reasonable assurance' - a high but not absolute level of assurance - that financial statements are free from material misstatement.

Who Does It Apply To?

Audit firms conducting statutory audits
Auditors of IFRS-reporting entities
Regulators adopting ISA as their auditing framework
U.S. auditors (PCAOB standards apply for public companies, GAAS for private)
Jurisdictions that have adopted ISA with modifications
Internal auditors (IIA standards apply)
Tax advisors
Management consultants

Is It Mandatory?

ISA is mandatory in jurisdictions that have adopted it as their auditing framework (most of Europe, Australia, Canada, South Africa, and many others). In the United States, PCAOB standards apply to public company audits and AICPA GAAS to private company audits - though GAAS is substantially converged with ISA.

Reasonable Assurance

Professional

The objective of an audit is to obtain reasonable assurance about whether the financial statements as a whole are free from material misstatement, whether due to fraud or error, thereby enabling the auditor to express an opinion on whether the financial statements are prepared, in all material respects, in accordance with an applicable financial reporting framework (ISA 200).

In Plain English

An audit does not guarantee the financial statements are perfect. It provides 'reasonable assurance' - a high level of confidence - that there are no errors or fraud big enough to mislead someone reading the statements. Think of it as a thorough check, not a complete re-creation of every transaction.

🧠Explain Like I'm 10

Imagine a teacher checking 1,000 homework papers. She cannot re-do every single math problem on every paper. Instead, she checks enough problems on enough papers to be very confident that any big mistakes have been caught. She might miss a tiny error here or there, but she is very sure there are no huge wrong answers that would change a student's grade.

Practical Example

AuditCo audits a company with $500 million in revenue. They set materiality at $5 million (1% of revenue). They do not check every $50 invoice - that would take forever. Instead, they test samples, analyze patterns, and focus on areas with the highest risk of material misstatement. Their opinion says the statements are 'fairly presented in all material respects' - not that every number is perfectly correct.

Why Does This Rule Exist?

Without a defined assurance level, users might expect auditors to catch every error (impossible and prohibitively expensive) or might not trust audits at all. 'Reasonable assurance' sets clear expectations: audits are rigorous and reliable, but not infallible.

Common Mistake

Believing an audit guarantees no fraud exists. Auditors are responsible for obtaining reasonable assurance that statements are free from MATERIAL misstatement due to fraud or error. They are not guarantors against all fraud, especially sophisticated collusion designed to evade detection.

Audit Risk Model

Professional

Audit risk is the risk that the auditor expresses an inappropriate opinion when the financial statements are materially misstated. It is a function of: inherent risk (susceptibility to misstatement before controls), control risk (risk that controls fail to prevent/detect misstatement), and detection risk (risk that audit procedures fail to detect a misstatement). The auditor manages audit risk by adjusting detection risk through the nature, timing, and extent of procedures.

In Plain English

Audit risk = the chance the auditor says 'looks fine' when it is actually wrong. It depends on three things: how likely is an error in the first place (inherent risk), how likely are the company's controls to catch it (control risk), and how likely are the auditor's own tests to miss it (detection risk). The auditor cannot control the first two, but can reduce the third by doing more work.

🧠Explain Like I'm 10

Imagine you are checking if cookies are burned. Inherent risk: some cookies are near the back of the oven where it is hotter (more likely to burn). Control risk: maybe the timer is broken so nobody notices (controls failed). Detection risk: maybe you only checked the front cookies and missed the burned ones in the back (your checking missed it). You can reduce detection risk by checking ALL the cookies, not just the front ones.

Common Mistake

Thinking the auditor can reduce inherent risk or control risk. The auditor can only assess these risks - they cannot change them. The auditor reduces overall audit risk by adjusting detection risk: doing more testing, using larger samples, or applying more substantive procedures in high-risk areas.

Types of Audit Opinions

Professional

ISA 700-706 govern the auditor's report. Four types of opinion exist: unmodified (clean) - statements are fairly presented; qualified - except for a specific matter; adverse - statements are materially misstated; disclaimer - auditor cannot obtain sufficient evidence to form an opinion. Modifications are based on the nature (misstatement vs inability to obtain evidence) and pervasiveness of the matter.

In Plain English

After the audit, the auditor issues one of four verdicts: (1) Clean bill of health - everything looks good. (2) Qualified - mostly fine except for one specific issue. (3) Adverse - the statements are seriously wrong and misleading. (4) Disclaimer - we could not get enough information to even form an opinion. Most companies get a clean opinion.

🧠Explain Like I'm 10

It is like a report card for the company's financial statements. A+ (unmodified): great job, everything checks out. B (qualified): good overall, but you got one question wrong. F (adverse): this is seriously wrong and needs to be redone. Incomplete (disclaimer): I could not even grade this because you did not show me enough of your work.

Practical Example

Scenario: A company refuses to let auditors count inventory at a warehouse representing 30% of total assets. The auditor cannot verify $150 million of inventory. If the matter is material but not pervasive to the statements as a whole: qualified opinion. If it is so significant that the auditor cannot form an opinion on the statements overall: disclaimer of opinion.

Common Mistake

Confusing a qualified opinion with a bad outcome. A qualified opinion means 'everything is fine EXCEPT for this one thing.' It is not a failing grade - it is a specific, limited exception. An adverse opinion is the truly negative outcome.

Frequently Asked Questions

What is the difference between ISA and GAAS?

ISA is issued by the IAASB for international use. GAAS (Generally Accepted Auditing Standards) is the U.S. equivalent issued by the AICPA for private company audits. They are substantially converged - most requirements are the same - but differ in some areas like group audits and going concern reporting.

What is the difference between ISA and PCAOB standards?

PCAOB standards apply to audits of U.S. public companies (SEC registrants). ISA applies internationally. Key differences: PCAOB requires an opinion on internal controls (ICFR) in addition to financial statements, has more prescriptive documentation requirements, and has different going concern and fraud standards.

What is professional skepticism?

Professional skepticism is an attitude that includes a questioning mind, being alert to conditions that may indicate possible misstatement due to fraud or error, and a critical assessment of audit evidence. It means not simply accepting management's explanations at face value - always asking 'what if this is wrong?'

Related Guides

Issuing organization: International Auditing and Assurance Standards Board (IAASB)
Current version: ISA (2009 Clarity Project, continuously updated)
Effective date: Various (ongoing revisions)
Last reviewed: August 2026
Back to Finance