Statutory Audit Process: A Step-by-Step Walkthrough From Appointment to Opinion
Most CA articles can define a statutory audit before they have ever actually walked through one. Here is the real sequence, from the engagement letter to the signed opinion, and how each stage feeds the next.
CA Helper Editorial Team
How we research and reviewPublished · 8 min read
Key takeaways
- A statutory audit runs as a fixed sequence, appointment and acceptance, planning and risk assessment, controls evaluation, substantive fieldwork, documentation, review, and reporting, and each stage's output feeds directly into the next.
- Acceptance is not automatic: it requires an independence check, a disqualification check under Section 141, written communication with the outgoing auditor, and a signed engagement letter before fieldwork starts.
- How much substantive testing is needed is driven directly by how much reliance the auditor can place on internal controls, which has to be tested for both design and operating effectiveness, never assumed.
- Sampling, third-party confirmations, and analytical procedures let the auditor cover large populations without testing every single transaction, provided the sample size and method actually match the assessed risk.
- The final opinion, along with any CARO or internal financial controls reporting that comes with it, rests on the evidence, resolved queries, and representations built up through every earlier stage, not a separate judgement made fresh at the end.
Ask a first-year article what a statutory audit actually involves, and the answer is usually a list of standards rather than a sequence of events: SA 230 for documentation, an opinion at the end, materiality somewhere in between. None of that is wrong, but it is not what an audit feels like from inside the engagement. A statutory audit runs as a fixed sequence of stages, each one built on the output of the last: who gets appointed and how, what gets planned before a single voucher is checked, how much the auditor can lean on the client's own controls, what fieldwork actually tests, how it all gets written down, who reviews it, and what opinion comes out the other end. This walkthrough follows that sequence stage by stage, the way an engagement actually runs on the ground.
The Process at a Glance
| Stage | What Happens | Why It Matters |
|---|---|---|
| Appointment and acceptance | Auditor appointed by members or the Board, independence and disqualification checked, engagement letter signed | Whether the engagement can legally and ethically begin at all |
| Planning and risk assessment | Business and industry understood, materiality set, risks identified and assessed | Decides where audit effort actually concentrates |
| Internal controls evaluation | Design and operating effectiveness of relevant controls tested | Decides how much substantive testing is actually needed |
| Fieldwork and substantive testing | Vouching, verification, third-party confirmations, analytical procedures, sampling | Generates the evidence the opinion will rest on |
| Documentation | Working papers created alongside every stage above, to the SA 230 standard | Decides whether the audit can be defended afterward |
| Review and finalisation | Partner and manager review, open queries resolved, management representation letter obtained | Confirms the file is actually ready to report on |
| Reporting | Opinion formed and issued, along with CARO and internal financial controls reporting where applicable | What shareholders and regulators actually receive |
Stage 1: Appointment and Acceptance
Most statutory auditors are appointed the way the Companies Act, 2013 treats as the default: by shareholders, at the annual general meeting, under Section 139, to hold office from the conclusion of that meeting until the conclusion of the sixth AGM after it, commonly described as a five-year term. The Board appoints directly only in two narrower situations. The first is the company's very first auditor, appointed by the Board within thirty days of incorporation; if the Board misses that window, members appoint within the next ninety days at an extraordinary general meeting, and that first auditor holds office only until the first AGM. The second is a casual vacancy, an auditor resigning, dying, or becoming disqualified mid-term, filled by the Board within thirty days; if the vacancy arose from resignation, it also needs member approval within three months, and the auditor holds office only until the next AGM. The company then has fifteen days from the appointment meeting to notify the Registrar by filing Form ADT-1.
None of that matters if the auditor cannot actually accept. Four things need to happen first, and skipping any of them tends to surface later, at the worst possible time.
- Independence check: no prohibited financial interest, indebtedness, or guarantee connected to the company's obligations, and no business relationship the Code of Ethics rules out. Section 144 separately bars specified non-audit services, accounting, internal audit, and investment advisory among them, to the same client.
- Disqualification check under Section 141: a body corporate other than an LLP cannot be appointed, nor can an officer or employee of the company, nor someone whose relative is a director or holds a specified role.
- Written communication with the outgoing auditor before accepting. This is a professional obligation under the ICAI Code of Ethics, giving the previous auditor a chance to flag any professional reason the appointment should not be accepted. A fee dispute alone does not justify withholding a response, and silence after a reasonable period is generally treated as no objection, but the attempt still has to be made and recorded.
- An engagement letter setting out the scope, each party's responsibilities, the applicable reporting framework, and the form the report will take, agreed before fieldwork starts and reconfirmed every year rather than assumed to carry over.
Stage 2: Planning and Risk Assessment
Planning starts with understanding the client, not rolling last year's file forward. That means the industry and regulatory environment, ownership and governance structure, the business model, accounting policies applied, and how management itself reviews financial performance internally. Preliminary analytical procedures belong here too, comparing current numbers against budgets, prior years, and available industry data, not to conclude anything yet but to see what looks unusual before a single voucher is tested. Materiality gets set at this stage under SA 320, and it is not one number but three: an overall figure for the financial statements as a whole, a lower performance materiality figure actually used to design and evaluate testing, and a threshold below which items are treated as clearly trivial. Where these figures land is professional judgement applied to the specific entity, though practitioners commonly anchor the overall figure to a benchmark like revenue, profit before tax, or total assets.
All of that feeds into identifying and assessing risks of material misstatement under SA 315, distinguishing risks that are pervasive across the financial statements, a weak control environment or a genuine going concern doubt, from risks specific to one account or transaction class, like revenue cutoff or inventory existence. This is also where the engagement team should explicitly discuss where the entity is vulnerable to fraud, not just error. The output is the audit plan and, underneath it, a detailed audit programme, under SA 300 and SA 330, translating the risk assessment into specific procedures assigned to specific team members. This is what separates a well-run audit from a mechanical one: real depth where risk actually concentrates, a complex revenue policy, a related-party-heavy structure, an estimate-driven provision, rather than a fixed level of testing spread evenly regardless of how risky a balance actually is.
Stage 3: Internal Controls Evaluation
Once risk is assessed, the auditor decides how much reliance to place on the client's own controls, and that decision drives how much substantive testing follows. The process runs in two steps. First, understanding the design of controls relevant to the risks identified, and confirming they are genuinely implemented, usually through a walkthrough: tracing one transaction end-to-end to see whether the control operates the way it is described on paper. Second, if the auditor intends to rely on a control to reduce substantive work, testing its operating effectiveness across the period under audit, not just at one point in time, since a control followed for nine months and ignored for three gives no safe basis for reliance over the full year.
This reliance decision is a genuine cost-benefit judgement, not an assumption that testing controls is always worthwhile. It only pays off if it lets the auditor reduce substantive testing elsewhere by more than the cost of testing the control itself. For smaller entities, or areas where controls are informal, it is often more efficient to skip reliance altogether and go straight to a fully substantive approach. Where a real deficiency is found, it has to be evaluated for whether it rises to a significant deficiency requiring written communication to management and those charged with governance, separately from the eventual opinion, under SA 265. For companies where the auditor also reports separately on internal financial controls under Section 143(3)(i), this same evaluation does double duty, feeding both the reliance decision and that separate reporting requirement.
Stage 4: Fieldwork and Substantive Testing
Fieldwork splits into distinct kinds of work rather than one generic activity called testing. Vouching means tracing recorded transactions back to supporting documentation, invoices, contracts, bank statements, board approvals, to confirm they are genuine, correctly recorded, and sitting in the right period and account. Verification is related but different: confirming the existence, ownership, valuation, and disclosure of assets and liabilities as they actually stand at the reporting date, physically counting inventory or fixed assets, checking title deeds, examining how investments were valued. Vouching asks whether a transaction really happened the way it was recorded; verification asks whether what the balance sheet claims exists today actually exists, at the value stated.
Confirmation from third parties carries more weight than anything generated inside the client's own systems, because the client cannot influence what comes back. Bank confirmation letters, requested directly from the bank, verify balances and flag charges or liens the client may not have disclosed. Debtor and creditor circularisation send confirmation requests directly to customers and suppliers, under SA 505. A non-response is not a pass; it has to be followed up, and any discrepancy reported back has to be investigated. Analytical procedures run through fieldwork differently from the preliminary review at planning: here, the auditor develops a specific expectation for a balance, from prior years, budgets, or a related non-financial metric, and investigates variance beyond what was considered tolerable, using the result as actual substantive evidence under SA 520.
For any large population, thousands of sales invoices, hundreds of payment vouchers, testing every item is neither practical nor necessary. The auditor selects a representative sample using a defined method, statistical or judgemental, under SA 530, tests it, and projects the results across the population, while separately testing items individually significant enough to warrant examination regardless of what sampling would have picked up, unusually large transactions, related-party dealings, anything out of pattern. Sample size and method scale with the risk assessed back in stage two, so a higher-risk balance gets a larger or more targeted sample. Fieldwork is also genuinely iterative: a finding in one area can change the risk assessment and trigger more work elsewhere, even though the engagement still runs through these stages in order.
Stage 5: Documentation Throughout
Documentation is not a stage that starts once fieldwork wraps up. It runs alongside every stage above, and the working paper for a procedure should be created when that procedure is actually performed, not reconstructed from memory once the file needs to close. The standard governing what a working paper must show, SA 230, sets a single test: could an experienced auditor with no prior connection to the engagement understand what was done, what was found, and the reasoning behind the conclusions, from the paper alone. That test, along with the rules on when the file must be assembled and how long it has to be retained, is covered in full in our companion piece on audit documentation and SA 230 working papers. The short version here: a procedure genuinely performed but poorly documented is, for every purpose that matters once the engagement is over, indistinguishable from one never performed at all.
Stage 6: Review and Finalisation
Review happens at more than one level. A senior or manager reviews each working paper as it is completed, checking whether the procedure actually addresses the risk it was designed for, whether the conclusion follows from the evidence, and whether the documentation meets the SA 230 standard. Above that sits partner or engagement quality review at the level of the financial statements as a whole, under the quality control requirements in SA 220, looking at significant judgements, the summary of misstatements found, and whether the evidence collectively supports the opinion about to be formed. Review at this stage is not a rubber stamp; it is where individual conclusions get tested against the engagement as a whole before anyone signs anything.
Review almost always throws up open points: a variance not fully explained, a document still missing, a conclusion that does not quite follow from the file. These get logged, tracked, and cleared with evidence of how each was actually resolved, not waved through with a tick mark. Individually immaterial misstatements found during fieldwork get accumulated rather than corrected in isolation, and evaluated again here, both individually and added together, since a pile of small differences can become material in aggregate. Before signing, the auditor also needs a management representation letter, dated as close as possible to, but not after, the date of the auditor's report, under SA 580. It confirms management's responsibility for the financial statements and covers matters the auditor cannot easily corroborate elsewhere, related-party completeness, litigation, the reasoning behind estimates, management's own fraud risk assessment. It is corroborative for those specific matters, not a substitute for the evidence gathered everywhere else.
Stage 7: Reporting the Opinion
Everything from the earlier stages funnels into this one. The significant judgements made along the way, the summary of uncorrected misstatements measured against materiality, the resolved queries, and the representations obtained from management together give the team the evidence base to reach a professional judgement: whether the financial statements, taken as a whole, are free of material misstatement. That judgement produces one of a small set of defined opinions, unmodified, qualified, adverse, or a disclaimer, and which one applies turns on materiality and pervasiveness evaluated together, not a general sense of how the engagement went. How auditors actually work through that decision is covered in our companion piece on qualified versus unqualified opinions; the opinion here is the direct output of everything documented and resolved in the stages before it, not a fresh judgement made at the end.
For a company, the report usually carries more than the opinion itself. Where the Companies (Auditor's Report) Order applies, it carries a separate annexure addressing a defined set of additional matters. Where Section 143(3)(i) applies, the auditor separately reports on whether the company has adequate internal financial controls over financial reporting and whether they operated effectively, drawing directly on the controls evaluation from stage three. The report is signed by the auditor in their own name, or by a partner signing personally for and on behalf of the firm, with the individual's ICAI membership number and the firm's registration number both appearing near the signature. Generating a UDIN on ICAI's portal is a mandatory last step before it goes out. Only then is the report placed before the members at the AGM, closing the loop that started with those same shareholders appointing the auditor.
None of these seven stages is optional, and none works well done out of order. An engagement that skips straight to vouching without a real risk assessment tests the wrong things at the wrong depth; one that tests controls without deciding what the testing is meant to justify wastes the effort; one that treats documentation as a file-closing exercise usually cannot reconstruct, months later, why a judgement was made the way it was. Appointment has to happen before planning can start, planning before controls testing can be scoped sensibly, controls testing before the substantive programme is finalised, and fieldwork, documentation, and review all have to be genuinely complete before an opinion can honestly be formed. For a CA article learning the process for the first time, that sequence is worth understanding on its own terms, not just as a list of standards to recite.
Frequently asked questions
Who actually appoints a company's statutory auditor?
The shareholders appoint the auditor at the annual general meeting under Section 139, where the auditor then holds office until the conclusion of the sixth AGM after that one. The Board of Directors only appoints an auditor directly in two narrower situations: the company's first auditor, appointed within thirty days of incorporation, and a casual vacancy, such as a resignation or disqualification mid-term, which still needs the members' approval within three months if the vacancy arose from resignation.
Why does the incoming auditor have to contact the outgoing auditor before accepting an appointment?
It is a professional obligation under the ICAI Code of Ethics, not an optional courtesy. Writing to the outgoing auditor gives them a chance to flag any professional reason the appointment should not be accepted. A fee dispute alone is not a valid reason to withhold a response, and a reasonable period of silence is generally treated as no objection, but the incoming auditor still has to make the attempt and keep a record of it before accepting.
How does testing internal controls actually reduce the amount of audit work needed?
If the auditor tests a control and confirms it operated effectively throughout the period, that lets the auditor reduce the extent of substantive testing on the related account balances, since the control itself is providing some assurance. If controls are weak, undocumented, or simply not tested, the auditor has no basis for that reliance and has to fall back on a fully substantive approach for the affected areas, which usually means more items tested, not fewer.
Why confirm balances directly with banks and customers instead of relying on the client's own records?
Evidence obtained directly from an independent third party is considered more reliable than evidence generated inside the client's own books, since the client has no ability to influence what the bank or the customer sends back. Bank confirmations and debtor or creditor circularisation exist specifically to corroborate balances from a source outside the client's own records, and a non-response or an inconsistency has to be followed up, not treated as good as a confirmation received.
Does every statutory audit end in the same kind of report?
No. The opinion depends on what the evidence actually shows, evaluated against materiality and pervasiveness, and can range from an unmodified opinion through to a qualified, adverse, or disclaimer opinion. How auditors actually decide between them is covered in our companion piece on qualified versus unqualified opinions. This walkthrough is about how the process gets an engagement to that decision point, not about how the decision itself gets made.
Isn't documentation something you finish at the end of the audit?
No, and treating it that way is one of the more common reasons a well-performed audit ends up with a weak file. Working papers should be created as each procedure is actually carried out, not reconstructed afterward from memory once the report is ready to sign. What the file specifically needs to show, and how long it has to be retained, is covered in our dedicated piece on audit documentation under SA 230.
Sources and official references
Rules and rates change. These are the primary sources for the topics covered above, and the place to confirm anything before you act on it.
Disclaimer
This article is for general informational purposes only and does not constitute professional tax, legal, or financial advice. Rules and rates change, so consult a qualified Chartered Accountant for advice specific to your situation.
Related reading
Stock Audit Basics: What It Covers and Why Banks Insist on It
A stock audit is not a scaled-down statutory audit. It exists because a bank has lent working capital against stock it has never physically seen, and wants independent proof the collateral is real.
Auditor Rotation, Resignation, and Removal: What Section 139 Actually Requires
An auditor can walk away from an audit with a letter and a filing. A company that wants to walk an auditor out the door before their term ends needs a special resolution and the government's approval first. That asymmetry is deliberate, and it runs through rotation, resignation, and removal alike.
UDIN: What It Is, When It's Mandatory, and How to Generate One
Every certificate, audit report, and attestation a practising CA signs needs a UDIN. Here is what the number actually does, which documents are covered, and the deadline most members get wrong.