SA 330 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
SA 330 is where the audit moves from risk assessment to evidence-gathering. It tells the auditor how to shape the work to answer the risks identified under SA 315: whether to rely on controls, what substantive testing to do, when to do it and how to conclude.
SA 330, as effective for audits of financial statements for periods beginning on or after 1 April 2008, applies to every audit. ICAI may revise standards, so check icai.org for the current text.
The auditor must design overall responses to statement-level risks and further audit procedures whose nature, timing and extent respond to the assertion-level risks, with more persuasive evidence for higher risk. Controls are tested when the auditor plans to rely on them or when substantive procedures alone are not enough. Substantive procedures are required for each material class of transactions, balance and disclosure whatever the assessed risk. The auditor then evaluates whether the evidence is sufficient and appropriate.
Objective and definitions (paragraphs 3-4)
The objective is to obtain sufficient appropriate evidence about the assessed risks of material misstatement through appropriate responses (paragraph 3). Two terms matter:
| Term | Meaning |
|---|---|
| Test of controls | A procedure to evaluate the operating effectiveness of controls in preventing, or detecting and correcting, material misstatements at assertion level |
| Substantive procedure | A procedure to detect material misstatements at assertion level; made up of tests of details and substantive analytical procedures |
Overall responses and further procedures (paragraphs 5-7)
The auditor designs overall responses to financial statement level risks (paragraph 5). For assertion-level risks, the auditor designs and performs further audit procedures whose nature, timing and extent respond to the assessed risks (paragraph 6). In designing them (paragraph 7) the auditor considers the reasons for the risk assessment: the inherent risk of the class, balance or disclosure, and whether the assessment takes controls into account, meaning the auditor intends to rely on the operating effectiveness of controls to determine the nature, timing and extent of substantive work. The higher the assessed risk, the more persuasive the evidence needed.
The risk-assessment inputs come from SA 315 part 1 and SA 315 part 2.
Tests of controls (paragraphs 8-17)
When controls must be tested (paragraph 8). The auditor tests controls when (a) the risk assessment expects the controls to operate effectively and the auditor intends to rely on them, or (b) substantive procedures alone cannot provide sufficient appropriate evidence. The greater the reliance, the more persuasive the evidence (paragraph 9).
How (paragraph 10). The auditor combines other procedures with inquiry to learn how the controls were applied at relevant times, how consistently, and by whom or by what means. The auditor also decides whether the controls depend on other, indirect controls that need testing.
When (paragraphs 11-15).
| Situation | Requirement | Paragraph |
|---|---|---|
| Reliance for a time or the whole period | Test the controls for that time or throughout the period | 11 |
| Evidence from an interim period | Get evidence on significant changes after the interim date, and decide what more is needed for the remaining period | 12 |
| Evidence from previous audits | Consider the effectiveness of the control environment, monitoring and risk assessment; manual or automated nature; general IT controls; past deviations and personnel changes; changing circumstances; and the risk and extent of reliance | 13 |
| Using previous audit evidence | Confirm continuing relevance by inquiry combined with observation or inspection; test again in the current audit if controls changed; otherwise test at least once in every third audit and some controls each audit | 14 |
| Significant risks | If relying on controls over a significant risk, test them in the current period | 15 |
Evaluating results (paragraphs 16-17). Misstatements found by substantive procedures may show that controls are not working, but the absence of misstatements does not prove controls are effective (paragraph 16). When deviations from controls are found, the auditor makes specific inquiries and decides whether the tests still support reliance, whether more tests are needed, or whether substantive procedures should address the risk (paragraph 17).
Substantive procedures (paragraphs 18-23)
- Always required. Whatever the assessed risk, the auditor designs and performs substantive procedures for each material class of transactions, balance and disclosure (paragraph 18).
- External confirmation. The auditor considers whether to perform confirmation as a substantive procedure (paragraph 19). See SA 505.
- Closing process. Substantive procedures include agreeing or reconciling the financial statements with the underlying records, and examining material journal entries and other adjustments made while preparing the statements (paragraph 20).
- Significant risks. Procedures must specifically respond to the risk, and where the response is only substantive, they must include tests of details (paragraph 21).
- Interim dates. If substantive procedures are done at an interim date, the auditor covers the remaining period by substantive procedures combined with tests of controls, or by further substantive procedures only if sufficient, so as to extend the conclusion to year end (paragraph 22). Unexpected misstatements at the interim date lead to reconsidering the risk assessment and the planned work (paragraph 23).
Analytical procedures as substantive tests are covered in SA 520, and the choice of items to test in SA 500.
Presentation and disclosure (paragraph 24)
The auditor performs procedures to evaluate whether the overall presentation of the financial statements, including the related disclosures, is in accordance with the framework. Typical work is checking that the statements are consistent with the framework's required format and notes.
Evaluating the evidence (paragraphs 25-27)
Before the conclusion, the auditor evaluates whether the assessments of risk at assertion level remain appropriate (paragraph 25). The auditor concludes on whether sufficient appropriate evidence has been obtained, considering all relevant evidence, whether it corroborates or contradicts the assertions (paragraph 26). If sufficient appropriate evidence on a material assertion has not been obtained, the auditor tries to obtain more; if unable, the auditor expresses a qualified opinion or disclaims an opinion (paragraph 27). See SA 705.
Documentation (paragraphs 28-30)
The auditor documents the overall responses and the nature, timing and extent of further procedures; the link between those procedures and the assessed risks at assertion level; and the results, including conclusions where not otherwise clear (paragraph 28). If evidence from earlier audits on controls is used, the conclusions about relying on those controls are documented (paragraph 29). The documentation must also demonstrate that the financial statements agree or reconcile with the underlying accounting records (paragraph 30).
Illustrative example
Chauhan Retail Pvt Ltd, an invented company, runs a point-of-sale system. The auditor judges that sales recording is highly automated and plans to rely on the controls over daily posting, so tests them in the current period, as well as the access controls. Controls were tested last year without changes; since the company changed its software in January, the auditor retests rather than relying on last year's work. Substantive work covers sales cut-off, a reconciliation of the sales ledger to the financial statements and the material year-end journal entries. For a one-off sale-and-leaseback, treated as a significant risk, the auditor performs tests of details directly on the contract and the accounting entries.
Need help with the audit trail?
If you want your system reports, reconciliations and journal entry approvals ready for the testing described above, TaxClue's books of accounts compliance team can help you assemble them. Accounts teams can also use our books of accounts compliance support to keep a year-end reconciliation pack.
Key takeaways
- Responses to risk are scaled: higher risk means more persuasive evidence.
- Test controls where the auditor relies on them, and where substantive procedures alone are not enough.
- Evidence about controls from earlier audits can be used only with conditions; controls over significant risks are tested in the current year.
- Substantive procedures are mandatory for every material class, balance and disclosure.
- The statements must agree or reconcile to the books, and this must be shown on the file.
Read next
- SA 315, part 2: assessing risks
- SA 500: audit evidence
- SA 520: analytical procedures
- SA 240, part 2: responses to fraud risks
Disclaimer: Based on the Standards on Auditing and quality standards issued by the Institute of Chartered Accountants of India, in the versions named in the article, and ICAI's announcement of 31 March 2026 on SQM 1 and SQM 2, as consulted on 3 October 2026. ICAI revises standards from time to time; check the current text and effective dates on icai.org. This article is general information, not legal advice; check the official text before acting.
