International Auditing Standards

ISA 400, Risk Assessments and Internal Control, provides guidance in the understanding of the "accounting and internal control systems and on audit risk and its components: inherent risk, control risk and detection risk" (ISA 400, par. 4). The main purpose of this is not to assess the effectiveness of the internal control system but to understand those procedures and controls that may impact the "nature, timing and extent of substantive procedures" (ISA 400, par.


ISA 400 provided a description of internal control and the types of internal controls, as well as the factors and procedures included in each type.
One of management's responsibilities is to ensure that there are adequate internal controls implemented in an entity. What is required of the auditor is to have a "sufficient understanding of the internal control" as such an understanding will mean a more efficient and effective audit planning and audit approach". ...
