top of page
Search

PCAOB AS 1105: Audit Evidence Is Where the Auditor’s Opinion Becomes Defensible—or Falls Apart

Learn How to Obtain, Evaluate and Document Sufficient Appropriate Audit Evidence


Every PCAOB audit eventually comes down to one question:

What evidence supports the auditor’s conclusion?

Risk assessment matters.


Internal controls matter.


Sampling matters.


Professional skepticism matters.


But none of those disciplines has value unless the engagement team ultimately obtains sufficient appropriate audit evidence to support the opinion.


That is the purpose of PCAOB Auditing Standard AS 1105 — Audit Evidence.


PCAOB AS 1105 explains what constitutes audit evidence and establishes requirements for designing and performing procedures to obtain evidence that is both sufficient and appropriate. The standard also makes an important point that every auditor should remember: audit evidence includes information that supports management’s assertions and information that contradicts them.


Corporate Compliance Seminars’ PCAOB Audit Evidence CPE webinar is designed to help auditors understand those requirements and translate them into stronger audit procedures, better supervision and more defensible workpapers. The live two-hour program provides 2 NASBA-approved CPE credits and covers AS 1105 together with related PCAOB requirements involving supervision and documentation.


The Auditor’s Opinion Is Only as Good as the Evidence Behind It


External auditors do not provide absolute assurance.


They obtain evidence sufficient to reduce audit risk to an appropriately low level and support the opinion expressed in the auditor’s report.


PCAOB AS 1105 defines audit evidence broadly. It includes information obtained through audit procedures as well as information from other sources. Importantly, it includes both corroborating and contradictory information.


That distinction is central to professional skepticism.


A weak auditor asks:

“What evidence supports management’s position?”

A stronger auditor also asks:

“What evidence could contradict management’s position?”

That second question is frequently where the real audit begins.


Sufficiency and Appropriateness Are Not the Same Thing


Auditors often talk about obtaining “enough evidence.”


But quantity alone is not sufficient.


PCAOB AS 1105 distinguishes between sufficiency and appropriateness.


Sufficiency concerns the quantity of evidence obtained.


Appropriateness concerns its quality—particularly its relevance and reliability.


An auditor can therefore collect an enormous amount of poor evidence and still have an audit problem.


Consider two situations.


Example One

The auditor receives 300 internally generated spreadsheets prepared by management but never tests their completeness or accuracy.


There is a lot of evidence.


Its reliability may be questionable.


Example Two

The auditor directly obtains independent bank confirmation evidence addressing the relevant assertion.


There may be much less documentation.


But the evidence may be considerably more persuasive.


Audit quality depends on both dimensions.


Relevance Means the Evidence Must Actually Address the Assertion


Evidence is not useful merely because it relates generally to the account being audited.

It must address the particular assertion or control objective.


PCAOB AS 1105 states that relevance depends partly on whether the audit procedure is designed to test the assertion or control directly, its timing, and the level of detail necessary to achieve the audit objective.


Suppose the auditor is testing the completeness of Accounts Payable.


Selecting recorded invoices from the Accounts Payable ledger and tracing them back to supporting documentation primarily addresses whether recorded liabilities actually exist.


It does relatively little to identify liabilities that were never recorded.


To address completeness, the auditor might instead examine:

  • Subsequent cash disbursements

  • Unmatched receiving reports

  • Vendor statements

  • Unprocessed invoices

  • Goods received before year-end

  • Payments after year-end relating to pre-year-end obligations


The evidence must align with the assertion.


That is audit design—not simply audit execution.


Reliability Depends on the Source and Circumstances


Not all evidence deserves equal weight.


PCAOB AS 1105 provides several general principles affecting reliability.


Evidence obtained from an independent, knowledgeable external source is generally more reliable than evidence obtained solely from internal company sources.


Evidence obtained directly by the auditor is generally more reliable than evidence obtained indirectly.


Original information can be more reliable than copies or converted versions, depending on the controls over the conversion and maintenance process.


These are not absolute rules.


They are professional judgment considerations.


The auditor should always ask:

  • Who created the information?

  • Who controls it?

  • Can it be modified?

  • Is the source independent?

  • Was it obtained directly?

  • What controls protect its integrity?

  • Does other evidence corroborate it?


Information Produced by the Company Has Become a Major PCAOB Issue


One of the most important PCAOB AS 1105 issues involves Information Produced by the Company, often called IPC or IPE.


Examples include:

  • Trial balances

  • Aging reports

  • Inventory listings

  • Revenue reports

  • Journal-entry populations

  • Reconciliation reports

  • User-access reports

  • Exception reports

  • Spreadsheets

  • System-generated data extracts


The auditor may use these reports to:

  • Select samples

  • Perform substantive testing

  • Test internal controls

  • Perform analytics

  • Evaluate estimates


But if the report itself is unreliable, everything built on it can also become unreliable.


PCAOB AS 1105 requires auditors using company-produced information to test its accuracy and completeness, or test controls over that accuracy and completeness, and to evaluate whether the information is sufficiently precise and detailed for the audit purpose.


This is not a minor technical concern.


The PCAOB reported that in both the 2021 and 2022 inspection cycles, approximately 17% of inspected audits contained deficiencies involving insufficient procedures over the accuracy and completeness of company-produced information or externally sourced information.


That should get every engagement team’s attention.


Never Sample from a Population You Haven’t Validated


Consider a journal-entry test.


The audit team receives a system-generated file containing 75,000 journal entries.


The team immediately applies filters and selects entries for testing.


But no one determines whether:

  • The population includes every journal entry.

  • Reversals are included.

  • Post-close entries are included.

  • Entries from all relevant ledgers are included.

  • The extraction parameters were correct.

  • Data were altered before the auditor received them.


If the population is incomplete, an excellent sampling methodology can still produce a bad audit.


The first question should therefore be:

Can we rely on the population?

Only then should the auditor begin selecting items.


External Electronic Information Now Requires Additional Attention


PCAOB AS 1105 has also evolved to address electronic information received by the company from external sources.


Under paragraph .10A, when the company provides externally sourced information to the auditor in electronic form, the auditor must understand where it came from and how the company received, maintained and potentially modified it. The auditor then must either test whether the company modified the information and evaluate those modifications or test relevant controls over receiving, maintaining and processing the information.


Examples might include:

  • Electronic bank records

  • Customer purchase information

  • Pricing feeds

  • Market information

  • Third-party valuation data

  • Vendor information


This reflects the modern reality of auditing.


Evidence no longer arrives primarily as paper sent directly to the auditor.


It moves through systems.


That makes data provenance and integrity central audit concerns.


Inquiry Is Important—but Inquiry Alone Is Not Enough


Auditors ask questions continuously.


Inquiry helps them:

  • Understand processes

  • Identify risks

  • Understand controls

  • Follow up exceptions

  • Evaluate management judgments


But PCAOB AS 1105 is explicit:

Inquiry of company personnel, by itself, does not provide sufficient audit evidence to reduce audit risk appropriately for a relevant assertion or support a conclusion about control effectiveness.

Suppose the Controller says:

“We independently review every unusual journal entry.”

That statement is useful.


But the auditor still needs to determine:

  • Who performs the review?

  • What qualifies as unusual?

  • What evidence exists?

  • What entries were reviewed?

  • What exceptions were found?

  • What happened when an issue was identified?


The auditor should move from:

Ask

to

Verify

to

Conclude.


Observation Has Limitations Too


Observation can be valuable.


The auditor may observe:

  • Inventory counting

  • A reconciliation

  • A review control

  • Cash handling

  • Physical security

  • A system process


But PCAOB AS 1105 notes that observation is limited to the moment being observed, and behavior may change because people know the auditor is watching.


Watching an employee perform a control correctly once does not prove that the control operated effectively for the entire year.


That is why effective audits usually combine different evidence-gathering techniques.


Reperformance Can Produce Powerful Evidence


Reperformance involves the auditor independently executing procedures or controls originally performed by company personnel.


For example, the auditor may:

  • Reperform a reconciliation

  • Recalculate depreciation

  • Recreate a three-way match

  • Reperform an access review

  • Recalculate a reserve

  • Independently apply a control threshold


Reperformance gives the auditor direct evidence.


That can be especially persuasive when audit risk is high.


Confirmation Remains Important Because the Auditor Obtains It Directly


Confirmations can provide strong evidence because they are obtained directly from an external confirming party.


Examples include:

  • Cash balances

  • Accounts receivable

  • Debt

  • Legal arrangements

  • Certain contract terms


The effectiveness of confirmation depends on proper auditor control over the process and the reliability of the responding party.


Technology changes how confirmations are delivered.


The basic evidence principle remains the same: direct independent evidence is often more persuasive than information filtered through management.


Analytical Procedures Are Evidence—but Expectations Must Be Credible


Analytical procedures involve evaluating plausible relationships among financial and nonfinancial information and investigating significant differences from expected amounts.


The quality of the evidence depends heavily on the quality of the expectation.


A weak analytical procedure might say:

Revenue increased 7% and that seems reasonable.

A stronger procedure asks:

  • What should revenue have been?

  • Which operational factors drive revenue?

  • How precise is our expectation?

  • What variance would be significant?

  • How do we investigate deviations?

  • What evidence supports management’s explanation?


Analytics become audit evidence only when properly designed and evaluated.


Contradictory Evidence Cannot Be Ignored


Paragraph .29 of AS 1105 is one of the most important requirements in the standard.


If evidence from one source is inconsistent with evidence from another, or the auditor doubts the reliability of information, the auditor must perform procedures necessary to resolve the matter and determine what effect the issue has on other aspects of the audit.


This is professional skepticism in operational form.


Suppose:

  • Management says the reserve calculation was independently reviewed.

  • The workpaper contains a review signature.

  • But email evidence shows the reviewer questioned the underlying assumptions and management never resolved the concern.

  • The auditor does not get to select the more convenient evidence.

  • The inconsistency must be resolved.


Contradictory Evidence May Be the Most Important Evidence in the Audit


Auditors naturally prefer evidence that fits the expected conclusion.


That creates the risk of confirmation bias.


An effective auditor intentionally looks for information that could prove the preliminary conclusion wrong.


Ask:

  • What would contradict management’s assertion?

  • Have we encountered inconsistent explanations?

  • Does operational data agree with financial data?

  • Do subsequent events support the estimate?

  • Are customer statements consistent with management’s representation?

  • Did one employee describe the process differently from another?


PCAOB AS 1105’s explicit inclusion of contradictory information within the definition of audit evidence makes this discipline essential.


Selecting Items for Testing Is Part of the Evidence Strategy


PCAOB AS 1105 also addresses how auditors select items for testing.


Depending on the audit objective and risk, auditors might:

  • Examine all items

  • Select specific items

  • Use audit sampling


The correct approach depends on what the auditor is trying to establish.


For example, examining all individually significant transactions may be appropriate where a small number of transactions constitute most of an account balance.


Selecting unusual transactions may help address specific fraud risks.


Sampling may support conclusions about a broader population.


The important point is that selection methodology must support the audit objective.


Specialists Do Not Transfer Responsibility Away from the Auditor


Complex audits increasingly depend on specialists.


Examples include:

  • Actuaries

  • Valuation experts

  • Engineers

  • Appraisers

  • Cybersecurity specialists


Appendix A of PCAOB AS 1105 addresses the auditor’s use of a company specialist’s work as evidence.


The auditor still needs to evaluate matters including:

  • The specialist’s knowledge, skill and ability

  • The risk of material misstatement

  • The company’s ability to influence the specialist

  • Data used by the specialist

  • Significant assumptions

  • Methods applied


As risk or management influence increases, the auditor may need more persuasive evidence.


A specialist’s report is not automatically reliable because the word “expert” appears on the cover.


Audit Documentation Must Show What the Evidence Actually Supported


The CCS PCAOB Audit Evidence course does not stop with PCAOB AS 1105.

It also addresses related standards, including PCAOB AS 1201 — Supervision of the Audit Engagement and PCAOB AS 1215 — Audit Documentation, because evidence has little value if the engagement team cannot demonstrate what it obtained, evaluated and concluded.


Good workpapers should answer:

  • What assertion or control were we testing?

  • What evidence did we obtain?

  • Where did it come from?

  • Why was it relevant?

  • Why was it reliable?

  • What contradictory evidence existed?

  • What additional procedures were performed?

  • What conclusion did we reach?

  • Who performed the work?

  • Who reviewed it?


The workpaper should allow an experienced reviewer to understand the audit trail without reconstructing it from memory.


Audit Supervision Matters Because Evidence Requires Judgment


PCAOB AS 1105 is not simply a staff-level standard.


Audit supervisors and engagement partners need to determine whether the engagement team has obtained enough persuasive evidence to support significant conclusions.


CCS therefore includes audit supervision and leadership among the course topics. The program addresses PCAOB AS 1201 and practical strategies for maintaining audit quality across the engagement team.


A supervisor should not review only whether:

  • The sample was completed.

  • The workpaper was signed.

  • The checklist was filled out.


The reviewer should ask:

Does this evidence actually support the conclusion?

That question is considerably harder.


AI Creates New Audit Evidence Questions


Artificial intelligence can now assist auditors in:

  • Analyzing documents

  • Comparing contracts

  • Identifying anomalies

  • Summarizing transactions

  • Reviewing large populations

  • Organizing workpapers


But AI output itself creates evidence questions.


The auditor must consider:

  • What information was provided to the model?

  • Is the source data reliable?

  • Could information have been omitted?

  • Did the AI alter or infer facts?

  • Can the result be reproduced?

  • Was the output independently validated?

  • Does the firm permit the tool’s use?

  • Is confidential client information protected?


An AI-generated summary can be useful.


It does not become sufficient appropriate audit evidence simply because it sounds convincing.


The principles of PCAOB AS 1105 still apply.


A Practical PCAOB AS 1105 Mindset


For every important piece of evidence, the auditor should ask:

  • What assertion am I testing?

  • Why is this information relevant?

  • Where did it come from?

  • Who controlled it?

  • Is it complete?

  • Is it accurate?

  • Is it sufficiently detailed?

  • Does other information contradict it?

  • What additional evidence would make the conclusion more persuasive?


If those questions are answered clearly, the audit work becomes considerably more defensible.


Why This Course Matters in Light of PCAOB Inspections


The PCAOB’s inspection experience demonstrates that audit evidence remains a persistent weakness.


Its 2024 staff report on auditor use of data and reports noted that about 17% of audits inspected in both the 2021 and 2022 cycles had deficiencies where auditors failed to perform sufficient procedures over the accuracy and completeness of company-produced or externally sourced information.


That means the problem is not theoretical.


Audit firms continue to get this wrong.


Understanding PCAOB AS 1105 can help auditors avoid fundamental failures involving:

  • Unreliable populations

  • Unsupported management reports

  • Weak corroboration

  • Insufficient evidence

  • Unresolved contradictory information

  • Poorly documented conclusions


What You Will Learn in PCAOB Audit Evidence


Corporate Compliance Seminars’ two-hour PCAOB Audit Evidence seminar addresses the major standards and practical disciplines surrounding evidence, including:

  • PCAOB AS 1105 — Audit Evidence

  • Characteristics of sufficient appropriate evidence

  • Collecting and evaluating evidence

  • PCAOB AS 1201 — Audit Supervision

  • Managing and reviewing engagement work

  • PCAOB AS 1215 — Audit Documentation

  • Building systematic and defensible workpapers

  • Practical evidence-gathering techniques

  • Real-world audit scenarios

  • Quality-control considerations


The objective is to help auditors move beyond simply collecting documentation and instead evaluate whether the evidence actually supports the audit conclusion.


Who Should Attend?


The event is particularly useful for:

  • External Auditors

  • CPA Firm Staff

  • Audit Associates

  • Senior Auditors

  • Audit Managers

  • Engagement Supervisors

  • Financial Professionals

  • SOX Professionals

  • Professionals responsible for PCAOB audit documentation


CCS lists the event as a live Group Internet-Based seminar, generally presented every eight weeks on Thursdays from 1:00–3:00 p.m. Central Time. The program provides 2 NASBA-approved CPE credits and is priced at $140. Private sessions can also be scheduled for groups of two or more.


The Bottom Line: Evidence Must Be Persuasive Enough to Support the Opinion


PCAOB auditing ultimately comes down to evidence.


The engagement team must demonstrate:

  • We identified the assertion.

  • We designed procedures addressing that assertion.

  • We obtained relevant evidence.

  • We evaluated its reliability.

  • We validated company-produced information.

  • We considered contradictory evidence.

  • We performed additional work when necessary.

  • We documented why the evidence supports the conclusion.


That is the foundation of a defensible audit.


Corporate Compliance Seminars’ PCAOB Audit Evidence CPE program is designed to help auditors strengthen that foundation and better understand how PCAOB AS 1105, supervision and audit documentation work together in a high-quality PCAOB engagement.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page